Enrichments object schema includes the following attributes:
Whether the enrichment is applied to all incoming alert data.
System-generated unique identifier for the enrichment.
Internal version number of the current data mapping table for this enrichment. This number is incremented automatically each time the table is updated.
Enrichment technique used to create custom tags (
Configuration details associated with the enrichment technique. For a mapping enrichment, this attribute contains a description of the data mapping table.
The following attributes describe how to enrich alerts based on a given data mapping table.
Column name in the data mapping table.
How data in the column is used in the enrichment process:
(Optional) Override the column name with a different tag name in BigPanda.
(Optional) Whether to override an existing tag with this value, if applicable.