Kaspersky Unified Monitoring and Analysis Platform

Enrichment rules

Enrichment rule resources are used to update the event fields.

Available Enrichment rule resource parameters:

  • Name (required)—a unique name for this type of resource. Must contain from 1 to 128 Unicode characters.
  • Tenant (required)—name of the tenant that owns the resource.
  • Source kind (required)—drop-down list for selecting the type of incoming events. Depending on the selected type, you may see the following additional settings:
    • constant
    • dictionary
    • event
    • template
    • dns
    • cybertrace
    • timezone
    • geographic data
  • Debug—you can use this drop-down list to enable logging of service operations. Logging is disabled by default.
  • Description—up to 256 Unicode characters describing the resource.
  • Filter—settings block in which you can specify the conditions for identifying events that will be processed by this resource. You can select an existing filter resource from the drop-down list, or select Create new to create a new filter.

    Creating a filter in resources