query logo white
  • Query logo
  • Products
    • Query Federated Search
    • Query Federated Search for Splunk
    • AI Agents
    • Security Data Pipelines
  • Platform
    • The Future is Federated
    • Federated Search
    • Connectors
    • Documentation
  • Use Cases
    • Compliance
    • Incident Response
    • Security Investigations
    • SIEM Migration
    • Splunk Cost Reduction
    • Threat Hunting
    • Examples
      • Amazon Security Lake
      • CrowdStrike/S3
      • EDR Data
  • Resources
    • Blogs
    • Datasheets
    • Events
    • Newsroom
    • Videos
    • Webinars
    • White Papers
  • Company
    • About Us
    • Partners
      • Splunk Services Partner Program
    • Leadership
    • Board of Directors
    • Careers
  • Book a Demo

Author: Jonathan Rau

VP/Distinguished Engineer, Query
ocsf 1.4.0 blog

Blogs

What’s new in Open Cybersecurity Schema Framework (OCSF) version 1.4.0

February 6, 2025 by Jonathan Rau | Leave a Comment

Introduction As of January 31st 2025, the latest version of the Open Cybersecurity Schema Framework (OCSF)–version 1.4.0–has been released! The 1.4.0 release represents a very large increment to the schema, and was nearly six months in the making. The schema expanded greatly in this release to include a brand new category and profile, several new […]

Read more »

ALB Access Logs OCSF Mapping Blog

Blogs

Mapping Amazon Application Load Balancer Access Logs to the Open Cybersecurity Schema Framework (OCSF)

January 28, 2025 / February 6, 2025 by Jonathan Rau | Leave a Comment

Introduction Query SecDataOps operators are standing by with another entry in our Open Cybersecurity Schema Framework (OCSF) mapping series. In this blog, we’ll focus on mapping Amazon Application Load Balancer (ALB) access logs to the OCSF format. OCSF is a standardized schema designed to help organizations normalize and correlate data from different sources, making it […]

Read more »

ocsf mapping guide

Blogs

Definitive Guide to Open Cybersecurity Schema Framework (OCSF) Mapping

November 6, 2024 / October 1, 2025 by Jonathan Rau | Leave a Comment

Map stuff real good, by the Query SecDataOps Goons Introduction The Open Cybersecurity Schema Framework (OCSF) is an open-source and collaborative effort across the industry to define a vendor- and platform-agnostic schema for security and IT observability data. It has been contributed to by Query, Amazon Web Services (AWS), Splunk, Cisco, Crowdstrike, and several dozen […]

Read more »

searching aws transit gateway logs with query blog

Blogs

Searching AWS Transit Gateway Flow Logs with Amazon Athena

September 25, 2024 / September 26, 2024 by Jonathan Rau | Leave a Comment

Introduction Amazon Web Services (AWS) Transit Gateway (TGW) is an AWS that acts as a highly scalable cloud network router. Released in November 2018, TGW allows you to connect many different Amazon Virtual Private Clouds (VPCs), AWS Direct Connect (DX) Gateways, and AWS Site-to-Site VPNs together in a centralized hub. This greatly simplifies hybrid and […]

Read more »

Query SQL for SecOps DuckDB

Blogs

Introductory SQL for SecOps: Exploratory Data Analysis with DuckDB

September 18, 2024 / January 23, 2025 by Jonathan Rau | Leave a Comment

Introduction The most effective Security Operations (SecOps) teams are those who harness and operationalize their data. This Security Data Operations (SecDataOps) process is long and fraught with pitfalls and dogmatic debates over data repositories, making it far too easy to become stuck and unsure where to progress. The easiest way to start is with Exploratory […]

Read more »

Query Open Pipeline

Blogs

Query Announces Query Open Pipeline

June 11, 2024 / June 11, 2024 by Jonathan Rau | Leave a Comment

Today, Query is announcing and making available as an open source tool, Query Open Pipeline (QOP). Query Open Pipeline will initially have support for CrowdStrike Falcon Data Replicator. QOP is an AWS native data mobility solution. It allows CrowdStrike Falcon Data Replicator ETL into the Amazon Security Lake, which provides automatic partitioning, format conversion, and […]

Read more »

pyspark partitioning blog

Blogs

Auto-partitioning your Security Data Lake with Apache PySpark and Amazon EMR Serverless

March 11, 2024 / March 12, 2024 by Jonathan Rau

Partitioning your data is one of the most important things you can do to improve the query performance of your data lake in Amazon S3. When building tables in AWS Glue Data Catalog and querying with Amazon Athena, as your data volumes grow, so do your query wait times.In this blog you will learn how […]

Read more »

Athena Iceberg Tables

Blogs

Amazon Athena and Apache Iceberg for Your SecDataOps Journey

February 19, 2024 / May 2, 2024 by Jonathan Rau

Data exhaust is increasing exponentially, and the variety and volume of this data has shown no indication of slowing down. Even the lowly Ubuntu OS or simple containerized workload running in Kubernetes can produce all sorts of user, system, infrastructure, authentication, and networking logs. This data increase necessitates security teams become SecDataOps teams. By using […]

Read more »

Amazon Flow Log Limitations

Blogs

Limitations and Applicability of Flow Logs

November 14, 2023 / November 6, 2024 by Jonathan Rau

​​​Public cloud and networking make for odd bedfellows. Cloud networking is not just the virtualization of networking. In traditional setups, appliances and network taps are used to monitor traffic, but in cloud environments, this is virtualized, making direct monitoring more complex. At the OSI Layers 1 through 4 you’d be able to directly tap appliances […]

Read more »

Page navigation
  • ‹
  • Page 1
  • Page 2
  • Current Page 3
COMPANY

Product

About

Careers

Partners

Leadership

Board of Directors

RESOURCES

Documentation

Blogs

Events

Newsroom

Videos

Webinars

White Papers

LEGAL

BETA Terms

Data Processing Agreement

Privacy & Cookie Policy

Security Protocols

Service Level Agreement

Subprocessors

Support Agreement

Terms and Conditions

CONTACT

Book a Demo

Contact Sales

query on linkedinquery on Xquery on youtube


Query

3423 Piedmont Road NE
• Atlanta, GA 30305
©2025 Query, All Rights Reserved.