Terminology Index

Glossary

2953 terms

Open concept maps
E
32

Enrichment

Adding context to raw events and alerts, such as resolving an IP to a host and owner, tagging asset criticality, or attaching threat intelligence, so analysts can interpret and prioritize them faster and more accurately.

Raw telemetry is often cryptic, an IP, a username, a hash, and enrichment automatically attaches the context needed to make sense of it: who owns the host, how critical the asset is, whether an indicator is known-bad, the user's department. Performed in the logging and detection pipeline, enrichment reduces the manual lookups analysts would otherwise do, speeds triage, and improves alert quality and prioritization.

Introduced in: Logging, Monitoring, and Telemetry

Examples

  • Resolving an alert's IP to a hostname, owner, and asset criticality automatically.
  • Tagging an indicator with threat-intelligence context as events are ingested.
  • Attaching a user's role and department to an identity alert.