The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enrich Windows events with Active Directory

Prev Next

Use Microsoft Active Directory to populate Windows events with the full user display names.

Verify that you have the System Management privilege.

  1. On the system navigation tree, select System Properties.

  2. Click Data Enrichment, then click Add.

  3. On the Main tab, enter a descriptive Enrichment Name, in the form Full_Name_From_User_ID.

  4. Set both the Lookup Type and Enrichment Type to String.

  5. Set Pull Frequency to daily, unless Active Directory is updated more frequently.

  6. Click Next or the Source tab.

    1. In the Type field, select LDAP.

    2. Fill in the IP address, user name, and password.

  7. Click Next or the Query tab.

    1. In the Lookup Attribute field, enter sAMAccountName.

    2. In the Enrichment Attribute field, enter displayName.

    3. In Query, enter (objectClass=person) to return a list of all objects in Active Directory classified as a person.

    4. Test the query, which returns a maximum of five values, regardless of the number of actual entries.

  8. Click Next or the Destination tab.

    1. Click Add.

    2. Select your Microsoft Windows data source.

    3. In the Lookup Field, select the Source User field.

      This field is the value that exists in the event, which is used as the index for the lookup.

    4. Select the Enrichment Field, where the enrichment value is written in the form User_Nickname or Contact_Name.

  9. Click Finish to save.

  10. After writing the enrichment settings to the devices, click Run Now to retrieve the enrichment values from the data source until the Daily Trigger Time value occurs.

    The Full Name is written into the Contact_name field.