Dynamically enriching events with external data
While creating a dynamic enrichment policy, you import an external CSV file and then define the match values and the enrichment values in the policy. Based on these inputs, the policy processes each incoming event to automatically match the correct values in the external file and use the corresponding values in the file to enrich the event data. Therefore, this policy is very useful when you want to perform enrichment based on multiple If-Then scenarios.
The following table covers the steps required for creating a dynamic enrichment policy:
To see an end-to-end process of creating this policy, see Example-Dynamically-enriching-events-from-an-external-file.
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*