AlphaSOC Data Lake: Query Commands and Activity Search

New Release

/v1/lake/query now supports command-style searches for evidence, activity, and event records. Each command queries a different OCSF layer: evidence returns collections of OCSF evidences, activity extends evidences with source and timing information, and event searches the raw events received by the lake.

These commands are available from Splunk through the alphasoc generating command in AlphaSOC for Splunk, so teams can hunt across AlphaSOC's OCSF Data Lake directly from Splunk Search.

Learn More