This component is responsible for including additional information to the events. For example, if you have real-time data of the network traffic flows in a Wi-Fi network, and you also have data on the location of the WiFi access points, you can enrich the traffic flow data by incorporating geolocation data, enabling to get a geospatial perspective of the network’s usage.
You can also enrich data with external information sources. For example, the IP address can be used to geolocate the events (continent, country, coordinates, etc.), obtain their reputation value, add the server or workstation hostname in their network, the users connected to said hostnames, etc. And the MAC address can be used to obtain the manufacturer of the device, its hostname, etc.
In addition to this, any additional data source available to your organization can be used to enrich the data received in WDP.