Skip to main content
Panther Knowledge Base

Why is p_enrichment null in my Panther event?

QUESTION

I tried to enrich an event in Panther, but the p_enrichment field shows a value of null instead of Lookup Table data. Why?

ANSWER

The most common cause of a null p_enrichment is that the log type isn't specified. Ensure the log has the p_log_type field set, and that there are Lookup Tables associated with the Log Type.

Note that a p_enrichment with an empty dictionary, {}, is not the same as one that is null. The former simply means there weren't any matches in the Lookup Tables, where as the latter means that Panther was unable to determine which Lookup Tables to use.

  • Was this article helpful?