What is enriched log data?¶
Enriched log data combines a source event with context added by another system, such as identity, asset, location, reputation or risk information.
Added fields have their own provenance¶
Directory details may reflect the current account owner rather than the historical one. IP geolocation is estimated, threat intelligence changes and inventory errors can propagate. Values may be calculated at event, ingestion or display time and confidence may be hidden.
Separate observation from later context¶
Identify which fields are original, which source supplied enrichment, when it was queried and how any score was calculated. Preserve the source event beside the enriched version.
Verify enrichment used for attribution or risk against its underlying source and report whether a fact was observed, inferred or added later.
The point to remember
Enrichment can illuminate an event, but its source, date and uncertainty must not be mistaken for original log evidence.