Creating enrichment policies
Enrichment policies define when and what enrichment is applied to a log entry. Using enrichment policies, you can apply multiple enrichments to a log entry.
To create an enrichment policy
On the Enrichment > Enrichment Policies page, click Create, and perform the following actions:
- Specify a unique name, optional description, and precedence number for the policy.
Create the log selection criteria based on which the policy is applied to the logs.
When the condition is met, enrichment is applied to the identified log entries.In the Enrichments Source section, click Add Enrichment and perform the following actions:
- Select the enrichment type that you want to apply to the identified logs.
For example, you select CSV. - From the Select Enrichment Source list, select the enrichment source that you have configured.
For a CSV enrichment source, the field that you selected in Source Field is displayed in Source Field Name. The enrichment fields are displayed in Target Fields. - In Source Field Path, enter the field in the logs with which the field in the Source Field Name is matched.
Example: You configured UserID as Source Field in the enrichment source. In logs, you get user ID in the user_ID field. Enter $.user_ID in Source Field Path.
- (Optional) In Target Fields, remove the fields from enriching the identified log entry.
- Save the enrichment configuration.
- Select the enrichment type that you want to apply to the identified logs.
- (Optional) Add more enrichment configurations.
- Enable and save the policy.
View the enrichment policies on the Enrichment Policies page. Use the Actions menu to edit, disable, or delete a policy:
Related topic
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*