We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Enrichment rule is a piece of business logic that transforms original JSON event. The rule properties are:
The rule takes should be represented as F(json_node) → json_node.
So far we need to support two rules:
We already have the code, we just need to wrap it into new structures.
Rules should be configured on per destination basis:
destinations: destination_name: enrichment: - name: ip_lookup from: /ip_address to: /geo/
Some rules should always exist. They mainly needed for events coming from web browser
enrichment: - name: ip_lookup from: /source_ip to: /eventn_ctx/location - name: user_agent_parse from: /eventn_ctx/user_agent to: /eventn_ctx/parsed_ua
Also, It is supported in server to server integration
enrichment: - name: ip_lookup from: /device_ctx/location/ip to: /eventn_ctx/location - name: user_agent_parse from: /device_ctx/user_agent to: /eventn_ctx/parsed_ua
The text was updated successfully, but these errors were encountered:
xtreding
Successfully merging a pull request may close this issue.
Concept
Enrichment rule is a piece of business logic that transforms original JSON event. The rule properties are:
The rule takes should be represented as F(json_node) → json_node.
Supported rules
So far we need to support two rules:
We already have the code, we just need to wrap it into new structures.
Rules configuration
Rules should be configured on per destination basis:
Implicit rules
Some rules should always exist. They mainly needed for events coming from web browser
Also, It is supported in server to server integration
The text was updated successfully, but these errors were encountered: