dt-sec-semantic-mapping
Installation
SKILL.md
dt-sec-semantic-mapping
Build and validate semantic-dictionary-aligned mappings for new security integrations.
Purpose
Use this skill when a user wants to:
- Suggest a mapping from vendor API output to Dynatrace
security.eventsfields (Workflow A). - Validate an existing mapping for completeness and quality against:
- Local baseline samples and semantic dictionary (Workflow B1 — static, offline validation), or
- Live tenant data via live tenant access (Workflow B2 — runtime validation)
- Highlight discrepancies vs. the Semantic Dictionary and local references.
- Get actionable mapping improvements.
Semantic Dictionary
The Semantic Dictionary (SD) defines the canonical field set for security.events. See references/semantic-reference.md for the canonical reference: local-vs-live sources, queryable Grail tables, when-to-query decision matrix, and the authority rule (live SD wins on disagreement).