p_enrichmentfield is appended to the event and accessed within a detection using a
p_enrichmentfields will contain:
p_enrichmentis not stored in the Data Lake, but you can join against the Lookup Table directly to any table in the Data Explorer with a query similar to the following:
p_enrichmentin the following JSON structure:
p_enrichment, click Enrich Test Data in the upper right side of the JSON code editor to populate it with your Lookup Table data. This allows you to test a Python function with an event that contains
Company CIDR Blocks.
AWS.VPCFlowlogs and associated the source IP (
srcAddr) and destination (
CIDRvalidation applied in the schema to indicate that this lookup table will do CIDR block matching on IP addresses. See our log schema reference.
.jsonlformat. The maximum file size supported is 5MB.