Enrichment Policies

An enrichment policy is a set of enrichment specifications. Each log from a device configured for a particular enrichment policy goes through all the enrichment specifications in ascending order. You can configure multiple enrichment policies in LogPoint. However, a single device can only have one enrichment policy.

An enrichment specification consists of a set of enrichment criteria and enrichment rules. Enrichment criteria are the conditions that must match the key-value pairs of the normalized event logs. Once the criteria meet, LogPoint uses the enrichment rules to enrich the logs.

Note

You can view the details of each enrichment policy by clicking the Details icon under the Actions column.

Adding an Enrichment Policy

  1. Go to Settings >> Configuration from the navigation bar and click Enrichment Policies.

../_images/LP_Config_EnrichmentPolicies_List_Add.png

Enrichment Policies

  1. Click Add.

../_images/LP_Config_EnrichmentPolicies_Add.png

Adding an Enrichment Policy

  1. Provide a Policy Name and Description.

  2. In the Specification section, provide Enrichment Criteria.

    • If you select Key Presents, provide the name of the key. In this case, the policy checks if the specified key is present in the log.

    • If you select Value Matches, provide the name of the key and the value (or a Regular Expression). In this case, the policy checks if the specified key is present in the log, and the value of the key matches the specified value.

    • Click the plus (plus_icon) icon to add a new criterion and the minus (minus_icon) icon to remove a criterion.

  3. In the Enrichment Rule section, select an Enrichment Source from the drop-down menu.

    ../_images/LP_Config_EnrichmentPolicies_Rule_Add.png

    Enrichment Rule Section

    • Choose a Source from the drop-down menu.

    • Choose a type of Operation. It is set to Equals by default.

    • Choose a Category from the drop-down menu.

      1. If you select the Simple category, provide the Event Key suitable for the source.

      2. If you select the Type Based category, choose an Event Key Type from the drop-down menu. In this case, all the fields of the selected type are eligible to be taken into consideration.

      In LogPoint, the value associated with a key is either string or number. The value of the IP type is considered a distinct case of the string type and is compared using simple string comparison.

      Select Enable prefixing if you want to prefix the results with the event key. In this case, LogPoint presents the results in alphabetical order of the event key.

    Note

    • Click the plus (plus_icon) icon to add a new rule and the minus (minus_icon) icon to remove a rule.

    • You cannot add more than 5 enrichment rules in an enrichment specification.

  4. Click Submit.

Note

In a Distributed LogPoints setup, you cannot view or use the enrichment policies of remote LogPoints from the Search Head.

Warning

You cannot use an enriched field as a criterion for the type-based enrichment category. For example, if source_address is an enriched field, then you cannot use that field as an enrichment criteria value.

Editing an Enrichment Policy

  1. Go to Settings >> Configuration from the navigation bar and click Enrichment Policies.

  2. Select the required enrichment policy.

../_images/LP_Config_EnrichmentPolicies_List_Edit.png

Enrichment Policies

  1. Update the information.

  2. Click Submit.

Deleting an Enrichment Policy

Before deleting an enrichment policy, make sure it is not in use.

  1. Go to Settings >> Configuration from the navigation bar and click Enrichment Policies.

  2. Click the Delete icon under the Actions column of the enrichment policy.

    ../_images/LP_Config_EnrichmentPolicies_List_Delete.png

    Enrichment Policies

    1. To delete multiple enrichment policies, select the groups, click the More drop-down menu and choose Delete Selected.

    ../_images/LP_Config_EnrichmentPolicies_List_DeleteSelected.png

    Enrichment Policies

    1. To delete all the enrichment policies, click the More drop-down menu, and choose Delete All.

    ../_images/LP_Config_EnrichmentPolicies_List_DeleteAll.png

    Enrichment Policies

  3. Click Yes on the delete confirmation dialog box.


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support