AlphaSOC now includes OCSF mappings for network log categories — HTTP, TLS, DNS, IP, and audit logs — with full support for array fields. Sigma rules targeting these log types can use AlphaSOC's array extensions directly with OCSF schema paths, enabling portable detections across OCSF-normalized data sources.

## [Learn More](/content/changelog/2026-05-21/sigma-array-support-for-ocsf/#learn-more/index.html)

- [OCSF Schema](https://schema.ocsf.io/1.5.0/)
- [AlphaSOC: OCSF for Sigma](https://docs.alphasoc.com/detections_and_findings/sigma/alphasoc_extensions/custom_prefixes/ocsf/)
