Skip to main content
Version: 2.12.0

Data Enrichment: Transforming Flows into Context

Data Enrichment is the process of transforming "naked" network telemetry into actionable business intelligence. While raw flow records (NetFlow, IPFIX) provide essential data like IP addresses and ports, they lack the identity, location, and reputation context required for rapid security response and advanced AI/ML analysis.

NFO bridges this gap by correlating raw flows in real-time with external data sources, appending human-readable metadata to every record before it reaches your SIEM or analytics platform.


The Enrichment Engine

Contextual data is managed and updated by the External Data Feeder for NFO (EDFN). While the EDFN Admin page covers security, proxy, and certificate management for external communications, this section focuses on the specific intelligence feeds applied to your traffic:

  1. Ingestion: Raw flow packets arrive at the NFO engine.
  2. Real-Time Correlation: NFO performs sub-millisecond lookups against in-memory tables provided by EDFN.
  3. Contextual Tagging: New metadata fields (e.g., username, dest_country, reputation) are appended to the flow.
  4. Optimized Output: The enriched data is sent to your SIEM, providing the "who, what, where, and why" behind every connection.

Enrichment Types