You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
…L log transform pipeline (#111)
### Summary
This pull request introduces support for real-time data enrichment in
Matano during ingest, addressing #99 and #21. The new
`get_enrichment_table_record` function has been added to the VRL log
transform pipeline, enabling retrieval of enrichment data and adding it
to the incoming data stream in real-time, before the detection / lake
writing steps.
For many use cases, this feature means users no longer need to perform
manual JOINS in their queries or do manual lookups in their detection
rules and improves downstream analytics performance by providing
pre-joined/enriched records in the data lake and detection engine.
<img width="820" alt="Screenshot 2023-03-07 at 11 42 46 PM"
src="https://user-images.githubusercontent.com/13088492/223651670-702b7191-d844-418c-a0dc-6a360d869e05.png">
### Up next
Next step, will be to add extend support to GeoIP enrichment tables
(MaxMind), which will require special handling logic.
Tracking issue for enrichment support
Goal
Provide enrichment through enrichment tables in Matano
Managed Integrations
Forward looking
The text was updated successfully, but these errors were encountered: