Lets say I bring in context data, which contains the entities of a asset(hostname, username, mac, IP, agents installed, etc...).
I have created a parser to parse all the required entities.
Will this help me in enriching other missing entities in other log sources ? for example I have a firewall log, where only the hostname and username is present in the log. Will it enrich the remaining entites associated to the host and username like mac and its associated IP ?