Enrichment Policies

An Enrichment Policy is a set of enrichment specifications. Each log from a device configured for a particular enrichment policy goes through all the enrichment specifications in ascending order. You can configure multiple enrichment policies in Logpoint. However, a single device can only have one enrichment policy. In addition, you cannot add more than 5 enrichment rules to an enrichment specification.

An enrichment specification consists of a set of enrichment criteria and enrichment rules. Enrichment criteria are the conditions that must match the key-value pairs of the normalized event logs. Once the criteria meet, Logpoint uses the enrichment rules to enrich the logs.

Adding an Enrichment Policy

  1. Go to Settings >> Configuration from the navigation bar and click Enrichment Policies.

../_images/LP_Config_EnrichmentPolicies_List_Add.png

Enrichment Policies

  1. Click Add.

../_images/LP_Config_EnrichmentPolicies_Add.png

Adding an Enrichment Policy

  1. Enter a Policy Name and Description.

  2. In Specification, enter Enrichment Criteria.

    • If you select Key Presents, enter the name of the key. In this case, the policy checks if the specified key is present in the log.

    • If you select Value Matches, enter the name of the key and the value (or a Regular Expression). In this case, the policy checks if the specified key is present in the log, and the value of the key matches the specified value.

    • Click the plus (plus_icon) icon to add a new criterion and the minus (minus_icon) icon to remove a criterion.

  3. In Enrichment Rule, select an Enrichment Source from the dropdown. Click the plus (plus_icon) icon to add a new rule and the minus (minus_icon) icon to remove a rule.

    ../_images/LP_Config_EnrichmentPolicies_Rule_Add.png

    Enrichment Rule

    • Choose a Source from the dropdown.

    • Choose a type of Operation. It is set to Equals by default.

    • Choose a Category from the dropdown.

      1. If you select the Simple category, enter the Event Key suitable for the source.

      2. If you select the Type Based category, choose an Event Key Type from the dropdown. In this case, all the fields of the selected type are eligible to be taken into consideration.

      In Logpoint, the value associated with a key is either string or number. The value of the IP type is considered a distinct case of the string type and is compared using simple string comparison.

      Select Enable prefixing if you want to prefix the results with the event key. In this case, Logpoint presents the results in alphabetical order of the event key.

  4. Click Submit.

Note

In a Distributed Logpoints setup, you cannot view or use the enrichment policies of remote Logpoints from the Search Head.

Warning

You cannot use an enriched field as a criterion for the type-based enrichment category. For example, if source_address is an enriched field, then you cannot use that field as an enrichment criteria value.

Editing an Enrichment Policy

  1. Go to Settings >> Configuration from the navigation bar and click Enrichment Policies. To view the details of each enrichment policy, click Details icon under Actions.

  2. Select the required enrichment policy and update the information.

../_images/LP_Config_EnrichmentPolicies_List_Edit.png

Enrichment Policies

  1. Click Submit.

Deleting an Enrichment Policy

Before deleting an enrichment policy, make sure it is not in use.

  1. Go to Settings >> Configuration from the navigation bar and click Enrichment Policies.

  2. Click the Delete icon under Actions.

    ../_images/LP_Config_EnrichmentPolicies_List_Delete.png

    Enrichment Policies

    1. To delete multiple enrichment policies, select the groups, click More and choose Delete Selected.

    ../_images/LP_Config_EnrichmentPolicies_List_DeleteSelected.png

    Enrichment Policies

    1. To delete all the enrichment policies, click More and choose Delete All.

    ../_images/LP_Config_EnrichmentPolicies_List_DeleteAll.png

    Enrichment Policies

  3. Click Yes to confirm deletion.


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support