Kaspersky Unified Monitoring and Analysis Platform

Enrichment rules

Enrichment rule resources are used to update the event fields.

Available Enrichment rule resource parameters:

  • Name (required)—a unique name for this type of resource. Must contain from 1 to 128 Unicode characters.
  • Tenant (required)—name of the tenant that owns the resource.
  • Source kind (required)—drop-down list for selecting the type of incoming events. Depending on the selected type, you may see the following additional settings:
    • constant
    • dictionary
    • event
    • template
    • dns
    • cybertrace
  • Debug—you can use this drop-down list to enable logging of service operations. Logging is disabled by default.
  • Description—up to 256 Unicode characters describing the resource.
  • Filter—settings block in which you can specify the conditions for identifying events that will be processed by the aggregation rule resource. You can select an existing filter resource from the drop-down list, or select Create new to create a new filter.

    Creating a filter in resources