Pull HBase identity mapping through a Trellix Enterprise Security Manager - Event Receiver to enrich events with Hadoop HBase.
On the system navigation tree, select System Properties, then click Data Enrichment.
On the Data Enrichment Wizard, fill in the fields on the Main tab, then click the Source tab.
In the Type field, select Hadoop HBase (REST), then type the host name, port, and name of the table.
On the Query tab, fill in the lookup column and query information:
Format Lookup Column as
columnFamily:columnNamePopulate the query with a scanner filter, where the values are Base64 encoded. For example:
<Scanner batch="1024"> <filter> { "type": "SingleColumnValueFilter", "op": "EQUAL", "family": " ZW1wbG95ZWVJbmZv", "qualifier": "dXNlcm5hbWU=","latestVersion": true, "comparator": { "type": "BinaryComparator", "value": "c2NhcGVnb2F0" } } </filter> </Scanner>
Complete the Scoring and Destination tabs.