Enrichment

enrichment

The Enrichment object provides inline enrichment data for specific attributes of interest within an event. It serves as a mechanism to enhance or supplement the information associated with the event by adding additional relevant details or context.

Attributes

CaptionNameTypeDescription
Created Timecreated_timeTimestamp

The time when the enrichment data was generated.

DatadataJSON

The enrichment data associated with the attribute and value. The meaning of this data depends on the type the enrichment record.

DescriptiondescString

A long description of the enrichment data.

NamenameString

The name of the attribute to which the enriched data pertains.

ProviderproviderString

The enrichment data provider name.

Raw Dataraw_dataJSON

Group:context
The event data as received from the event source.

Record IDrecord_idString

Group:primary
Unique identifier for the object

Reputation ScoresreputationReputation[]

The reputation of the enrichment data.

Short Descriptionshort_descString

A short description of the enrichment data.

Source URLsrc_urlURL String

Entity:URL_STRING
The URL of the source of the enrichment data.

TypetypeString

The enrichment type. For example: location.

UnmappedunmappedUnmapped[]

Data from the source that was not mapped into the schema.

ValuevalueString

The value of the attribute to which the enriched data pertains.

Relationships

Enrichment shown in context

Inbound Relationships

These objects and events reference Enrichment in their attributes:

Outbound Relationships

Enrichment references the following objects and events in its attributes:

This page describes ocsf-1.4.0