When alerts come into BigPanda they go through our data pipeline. Understanding the order of the pipeline can help you effectively enrich alerts.

  1. Normalizer - Alerts get formatted into a BigPanda event
  2. Enrichment mapping - The alert gets enriched according to mapping uploaded by the user.
  3. Maintenance - Alerts that match any maintenance query get marked for maintenance.
  4. Custom tags (Extraction) - Relevant custom extraction tag logic is executed and applied.
  5. Custom tags (Composition) - Relevant custom composition tag logic is executed and applied.

Did this answer your question?