Article Number
000001184
Applies To
RSA Product Set: Security Analytics, RSA NetWitness Logs & Network
RSA Product/Service Type: SA Event Stream Analysis
RSA Version/Condition: 10.5.x,10.6.x
Platform: CentOS
O/S Version: 6
Issue
Enrichment Sources can be added to an ESA rule by following the
SA user guide.
However, the additional information does not get added to the Syslog notification.
Resolution
In order to add the information included by an Enrichment Source, please follow the steps below:
- Open the ESA rule and make a note of the Enrichment Source name under Enrichment Source column.
e.g. TestEnrichment from the following screenshot.