LogoLogo
WebsiteBlogLogin
  • Onum Docs
  • Use Cases
  • Videos
  • Release Notes
  • Welcome
  • Getting Started
    • About Onum
    • Architecture
    • Deployment
    • Getting Started with Onum
    • Understanding The Essentials
      • Cards and Table Views
      • Data Types
      • Graph Calculations
      • The Time Range Selector
    • Key Terminology
  • THE WORKSPACE
    • Home
    • Listeners
      • Cloud Listeners
      • Listener Integrations
        • Amazon SQS
        • Amazon S3
        • Apache Kafka
        • Azure Event Hubs
        • Cisco NetFlow
        • Google Pub/Sub
        • HTTP
        • HTTP Pull
        • Microsoft 365
        • OpenTelemetry
        • Syslog
        • TCP
      • Labels
    • Pipelines
      • Building a Pipeline
        • AI Assistant
          • AI Pipeline Assistant
          • AI Action Assistant
      • Listeners
      • Actions
        • Advanced
          • Anonymizer
          • Bring Your Own Code
          • Field Generator
          • For Each
          • Google DLP
          • HTTP Request
          • Redis
        • Aggregation
          • Accumulator
          • Group By
        • AI
          • Amazon GenAI
          • BLIP-2
          • Cog
          • Google GenAI
          • Llama
          • Replicate
        • Detection
          • Sigma Rules
        • Enrichment
          • Lookup
        • Filtering
          • Conditional
          • Sampling
        • Formatting
          • Message Builder
        • Transformation
          • Field Transformation
            • Field Transformation Operations
              • Arithmetic / Logic
                • Divide Operation
                • Median
                • Multiply Operation
                • Subtract Operation
                • Sum Operation
              • Code tidy
                • JSON Minify
              • Control characters
                • Escape String
                • Unescape String
              • Conversion
                • Convert Area
                • Convert Data Units
                • Convert Distance
                • Convert Mass
                • Convert Speed
                • List to String
                • String to List
              • Data format
                • From Base
                • From Base64
                • From Hex
                • To Base
                • To Base64
                • To Hex
              • Date / Time
                • From Unix Timestamp
                • To Timestamp
                • To Unix Timestamp
                • Translate Datetime Format
              • Encoding / Decoding
                • From Binary
                • To Binary
                • To Decimal
              • Encryption / Encoding
                • JWT Decode
              • File system permissions
                • Parse Unix file permissions
              • Format conversion
                • CSV to JSON
                • JSON to CSV
              • Hashing
                • Keccak
                • MD2
                • MD4
                • MD5
                • SHA0
                • SHA1
                • SHA2
                • SHA3
                • Shake
                • SM3
              • Networking
                • Defang IP Address
                • Defang URL
                • Extract IP Address
                • Fang IP Address
                • Fang URLs
                • IP to Hexadecimal
                • Parse URI
                • URL Decode
                • URL Encode
              • Other
                • Parse Int
              • String
                • Length
              • Text sample adding
                • Pad Lines
              • Utils
                • Byte to Human Readable
                • Count Occurrences
                • CRC8 Checksum
                • CRC16 Checksum
                • CRC24 Checksum
                • CRC32 Checksum
                • Credit Card Obfuscator
                • Filter
                • Find and Replace
                • Regex
                • Remove Whitespace
                • Reverse String
                • Shuffle
                • Sort
                • Substring
                • Swap Case
                • To Lower Case
                • To Upper Case
          • Flat JSON
          • JSON Transformation
          • JSON Unroll
          • Math Expression
          • Parser
            • PCL (Parser Configuration Language)
        • Utils
          • Unique
      • Data sinks
      • Bulk Changes
      • Publishing & Versioning
      • Test your Pipeline
    • Data sinks
      • Data sink Integrations
        • Amazon S3
        • Amazon SQS
        • Azure Blob Storage
        • Azure Event Hubs
        • Devo
        • Google BigQuery
        • Google Cloud Storage
        • Google Pub/Sub
        • HTTP
        • Jira
        • Mail
        • Null
        • OpenTelemetry
        • PagerDuty
        • Pushover
        • Qradar
        • Relational Databases
        • ServiceNow
        • Slack
        • Splunk HEC
        • Syslog
        • TCP
        • Telegram
        • Twilio
    • Alerts
  • YOUR VAULT
    • Enrichment
    • Data History
    • Actions
  • ADMINISTRATION
    • Tenant Menu
    • Global Settings
      • Your Account
      • Organization Settings
        • Secrets Management
      • Tenant
        • Authentication
        • Users
        • Activity Log
  • MARKETPLACE
    • Onum Marketplace
      • Pulling Pipelines
        • Netskope Events Alert
        • OKTA System Log API
        • Sophos Connector SIEM
Powered by GitBook
On this page
  • Overview
  • How to use your lookups
  • Upload a lookup
  • Upload a new lookup version
  • Manage your lookups
  • Lookup statuses
  • Filter your lookups
  • Download a lookup
  • Remove a lookup

Was this helpful?

Export as PDF
  1. YOUR VAULT

Enrichment

Enrich your data using lookup tables

PreviousAlertsNextData History

Last updated 9 days ago

Was this helpful?

Overview

The Onum Enrichment feature allows you to upload tables and use them as lookups to enhance existing data by adding new information from external sources to your Pipelines.

Go to Your Vault > Enrichment to start creating your lookups.

You will see a general overview of all the lookups uploaded in your Tenant and the events generated, if there are any. Here's what you will find:

Each lookup card displays the following information:

  • The Key column assigned to your lookup upon upload.

  • The total number of columns it contains.

  • The size of the lookup (in KB).

  • When your lookup was last updated.

  • The lookup version and any tags assigned to it. You can create these tags here, by clicking Add tag or the number that indicates the tags added. Press the Enter key to confirm the tag, then Save.

How to use your lookups

Upload a lookup

Follow these steps to create a new lookup table:

1

Click the New enrichment button at the top right corner of the Enrichment area.

2

Enter a unique Name for your new lookup.

3

Optionally, add a Description and any Tags to identify your uploaded data easily.

4

Click to upload your file or drag it to add it. You can include a Version description for the first version of your lookup.

5

You'll see your lookup preview with the data types of each column. You can click the ellipsis button and select Change type if you want to modify any of your column types.

To avoid performance problems, note that you will only see a preview of the columns of your lookups so you can choose your key column.

6

Click the header of the column you want to set as key. The key column is the field in the lookup table that will be used to match the original data. Additional values will be added to the original table whenever there is a match between the key column values and the original table.

7

Choose if you want to use the first row as a header or not.

8

Click Create once you're done. You're lookup will appear as a card in the general view once it is processed.

Note that there's a file size limit of 3.91 GB.

Upload a new lookup version

You can update a lookup to its newest version without deleting a previous one. To do it, simply click a lookup card and click the Create version button. Then, click Update to save any modifications.

Note that tables you upload as new versions must have the same columns as the previous ones, plus additional columns you may want to include. You can only change the data types of those new columns when you define a new version.

The last version you update will become the active one automatically. All versions are available to access via the version tree that appears in the lookup details. Click one to see details of the logs it contains.

Manage your lookups

Lookup statuses

You can see the status of your lookups in their details, checking the version tree. These are the available statuses:

Status
Description

The latest and active version of the lookup.

Previous lookup versions.

Lookups with any processing errors. The lookup card version will appear in red when the lookup has any errors.

Filter your lookups

You can add filters to narrow down the lookups you see in the list. Click the + Add filter button and select the required filter type(s). You can filter by:

  • Name: Select a Condition (Contains, Equals, or Matches) and a Value to filter lookups by their names.

  • Status: Choose the required status(es) among the available ones in your lookups.

The filters applied will appear as tags at the top of the view.

Note that you can only add one filter of each type.

You can also choose to view only those lookups that have been assigned the desired tags. To filter by tags, click the + Tags button, select the required tag(s), and click Save.

Download a lookup

Click the ellipsis icon in a lookup card and select Download CSV to download the last version of the lookup as a CSV file. You'll receive an email with the Download file button once it is processed.

If you need to download a previous version of a lookup, access its details and click the ellipsis icon > Download CSV in the required lookup version to do it.

Remove a lookup

To remove a lookup, click the ellipses icon in the card and select Remove.

If your lookup is in use, you can see where it is being used in the window that appears before deleting it. Pipelines with removed lookups will be paused automatically.

You can use the Action Lookup in your Pipelines to enrich your information. There, you'll be able to select any of the lookups in your Tenant. To learn more about how to use the Lookup Action, go to .

this article