Terminology Index
Glossary
2953 terms
E32
Enrichment
Adding context to raw events and alerts, such as resolving an IP to a host and owner, tagging asset criticality, or attaching threat intelligence, so analysts can interpret and prioritize them faster and more accurately.
Raw telemetry is often cryptic, an IP, a username, a hash, and enrichment automatically attaches the context needed to make sense of it: who owns the host, how critical the asset is, whether an indicator is known-bad, the user's department. Performed in the logging and detection pipeline, enrichment reduces the manual lookups analysts would otherwise do, speeds triage, and improves alert quality and prioritization.
Introduced in: Logging, Monitoring, and Telemetry
Examples
- Resolving an alert's IP to a hostname, owner, and asset criticality automatically.
- Tagging an indicator with threat-intelligence context as events are ingested.
- Attaching a user's role and department to an identity alert.
Related
Context Gatheringrelates_toLookup Tablesrelates_toAlert Fatiguerelates_toIntelligence in Detectionrelates_toIdentity Telemetryrelates_toAlert Volumerelates_toEventsrelates_toIdentity Telemetryrelates_toIntelligence in Detectionrelates_toIntelligence in Triagerelates_toLookup Tablesrelates_toMulti-Source Correlationrelates_to
