The Threat Lookup enrichment area opens in the right part of the screen.
Select check boxes next to the data types you want to request.
If neither check box is selected, all information types are requested.
In the Maximum number of records in each data group field enter the number of entries per selected information type you want to receive. The default value is 10.
Click Request.
A ktl task has been created. When it is completed, events are enriched with data from Kaspersky Threat Intelligence Portal which can be viewed from the events table, Alert window, or correlation event window.