Alerting: Enrichment Sources

Document created by RSA Information Design and Development on Sep 12, 2017Last modified by RSA Information Design and Development on Apr 11, 2019
Version 8Show Document
  • View in full screen mode
 

This topic explains options for adding an external data source to provide additional information in alerts. Enrichment sources provide additional information in alerts. For example, an in-memory table can provide a full name, title, office location, and employee number if a user matches rule criteria. The following types of enrichment sources are available:

  • Context Hub List (Preferred)
  • In-Memory Table
  • GeoIP

Note: Database, Database Connection, and Warehouse Analytics as enrichment sources are not supported for the ESA Correlation service in NetWitness Platform 11.3 and later.

RSA recommends that you use Context Hub List enrichment sources instead of In-Memory Table enrichment sources. You can share Context Hub List enrichment sources across the NetWitness Platform. You can only use the In-Memory Table with ESA.

Note: The geoIP enrichment source can neither be created nor deleted. It is provided out of the box to the user.

You are here
Table of Contents > Add a Data Enrichment Source > Enrichment Sources

Attachments

    Outcomes