After you establish dataflow to the HBase table, you must use the HCP Management
module or the CLI to ensure that the enrichment topology is enriching the data flowing past.
You can use the Management module to refine the parser output in three ways: transformations,
enrichments, threat intel.
Your sensor must be running and producing data to load sample
data.
-
From the list of sensors in the main window, select your new sensor.
-
Click the pencil icon in the toolbar.
The Management module displays the sensor panel for the new sensor.
-
In the Schema panel, click .
-
Review the resulting message, field, and value information displayed in the Schema
panel.
The Sample field displays a parsed version of a sample message from the sensor.
The Management module tests your transformations against these parsed
messages.
You can use the right and left arrow to view the parsed version of each sample
message available from the sensor.
-
Apply transformations to an existing field by clicking or
create a new field by clicking .
-
If you create a new field, complete the fields.
-
Click SAVE.
-
If you want to suppress fields from showing in the Index, click .
-
Click SAVE.