You can configure mapping of different keys from the Logpoint UI:
Click on Enrichment Sources > threat intelligence
On the menu click on mapping:
There you can map client_ip as an ip_address to participate in threat intelligence.
Similarly you can use endpoint hashes for enrichment as well. add a similar mapping to hash with column hash.
For static enrichment you’d have to configure the enrichment policy accordingly as well. If not you can use the process ti
1 comment