Use Microsoft Active Directory to populate Windows events with the full user display names.
Verify that you have the System Management privilege.
On the system navigation tree, select System Properties.
Click Data Enrichment, then click Add.
On the Main tab, enter a descriptive Enrichment Name, in the form
Full_Name_From_User_ID.Set both the Lookup Type and Enrichment Type to String.
Set Pull Frequency to daily, unless Active Directory is updated more frequently.
Click Next or the Source tab.
In the Type field, select LDAP.
Fill in the IP address, user name, and password.
Click Next or the Query tab.
In the Lookup Attribute field, enter
sAMAccountName.In the Enrichment Attribute field, enter
displayName.In Query, enter
(objectClass=person)to return a list of all objects in Active Directory classified as a person.Test the query, which returns a maximum of five values, regardless of the number of actual entries.
Click Next or the Destination tab.
Click Add.
Select your Microsoft Windows data source.
In the Lookup Field, select the Source User field.
This field is the value that exists in the event, which is used as the index for the lookup.
Select the Enrichment Field, where the enrichment value is written in the form
User_NicknameorContact_Name.
Click Finish to save.
After writing the enrichment settings to the devices, click Run Now to retrieve the enrichment values from the data source until the Daily Trigger Time value occurs.
The Full Name is written into the Contact_name field.