Learn more about lookup datasets to correlate data from a data source with events in your environment.
Prerequisite
Dataset Management requires View/Edit RBAC permissions for Data Management (under → ), which are the same permissions required for Parsing Rules, Data Model Rules, and Event Forwarding.
Lookup datasets enable you to correlate data from a data source you provide with the events in your environment. For example, you can create a lookup with a list of high-value assets, terminated employees, or service accounts in your environment. Use lookups in your search, detection rules, and threat hunting. Lookups are stored as name-value pairs and are cached for optimal query performance and low latency.
Lookup tables support low-frequency changes of up to 1200 modifications per day. Changes are implemented whenever a lookup dataset is edited, where only one person or user can edit the file at a given time. Concurrent users editing the file are not supported.