Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Table of Contents

In the previous section, Adding a New Telemetry Data, we walked through how to add a new Squid data source to Apache Metron. The inevitable next question is how I can I enrich the telemetry events in real-time as they flow through the platform? Enrichment is critical when identifying threats or as we like to call it "finding the needle in the haystack." The customers requirements are the following:

...