Enrichment

The Enrichment object provides inline enrichment data for specific attributes of interest within an event. It serves as a mechanism to enhance or supplement the information associated with the event by adding additional relevant details or context.

Attributes

CaptionNameTypeDescription
Created Time created_time Timestamp The time when the enrichment data was generated.
Data data JSON The enrichment data associated with the attribute and value. The meaning of this data depends on the type the enrichment record.
Description desc String A long description of the enrichment data.
Name name String The name of the attribute to which the enriched data pertains.
Provider provider String The enrichment data provider name.
Raw Data raw_data JSON The event data as received from the event source.
Record ID record_id String Unique identifier for the object
Reputation Scores reputation Reputation[] The reputation of the enrichment data.
Short Description short_desc String A short description of the enrichment data.
Source URL src_url URL String The URL of the source of the enrichment data.
Type type String The enrichment type. For example: location.
Unmapped Data unmapped Unmapped[] The attributes that are not mapped to the event schema. The names and values of those attributes are specific to the event source.
Value value String The value of the attribute to which the enriched data pertains.

Relationships

Enrichment shown in context

Inbound Relationships

These objects and events reference Enrichment in their attributes:

Outbound Relationships

Enrichment references the following objects and events in its attributes:

This page describes qdm-1.3.2+ocsf-1.3.0