Logs Enriched using ODBC Enrichment Source

After applying enrichment, a log displays additional information not collected initially during log collection. For example, consider a device with the IP address 129.26.3.192 used by an employee named Bob. The logs collected from this device may lack details about Bob, such as his department, email, location, and manager. However, configuring an enrichment source fetches these details from the ODBC server and inserts them into the logs whenever the IP address in a log matches Bob’s IP.

The second of the following two screenshots shows what an enriched log looks like compared to an unenriched one.

_images/LP_ODBC_Unenriched_Log.png

Unenriched Log Sample

_images/LP_ODBC_Enriched_Log.png

Enriched Log Sample


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support