The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enrich Hadoop HBase events

Prev Next

Pull HBase identity mapping through a Trellix Enterprise Security Manager - Event Receiver to enrich events with Hadoop HBase.

  1. On the system navigation tree, select System Properties, then click Data Enrichment.

  2. On the Data Enrichment Wizard, fill in the fields on the Main tab, then click the Source tab.

  3. In the Type field, select Hadoop HBase (REST), then type the host name, port, and name of the table.

  4. On the Query tab, fill in the lookup column and query information:

    1. Format Lookup Column as columnFamily:columnName

    2. Populate the query with a scanner filter, where the values are Base64 encoded. For example:

      <Scanner batch="1024">
      <filter>
      {
      "type": "SingleColumnValueFilter",
      "op": "EQUAL",
      "family": " ZW1wbG95ZWVJbmZv",
      "qualifier": "dXNlcm5hbWU=","latestVersion": true,
      "comparator": {
      "type": "BinaryComparator",
      "value": "c2NhcGVnb2F0"
      }
      }
      </filter>
      </Scanner>
      
  5. Complete the Scoring and Destination tabs.