Populating base events with Active List data
I have rules in place that are tracking VPN users logging on and off the network. Their IP and associated username are being stored in an Active List. Right now if an analyst needs to know what username is associated with the base events they are investigating then they have to open the Active List and look it up.
What I'd like to do is have my connectors read the Active List and if the Source IP of the base event matches an IP in the Active List, then populate a DeviceCustomString field with the VPN username. This would save a lot of time during investigations.
I know that you can use a static map file for connectors to reference, but that won't work for me as this Active List changes hundreds of times a day. I also know that I could use a rule in ESM to populate correlated events with the Active List content, but I'm really looking to add more data to base events.
Has anyone had any luck doing something similar? Thanks in advance!