Additional context should be incorporated by adding enriched fields during search execution . A correlation search should return not merely evidence that a detection condition occurred, but sufficient contextual fields for an analyst to understand and triage the resulting finding efficiently.
For example, a detection can enrich results with normalized entity fields such as user, src, dest, asset priority, identity information, process details, authentication attributes, threat-intelligence context, or other fields relevant to the analytic. Those values can then be carried into the notable/finding and used for investigation, drilldowns, risk analysis, and downstream automation.
The dedup command addresses duplicate search results; it does not inherently enrich the notable. Adding indexers improves ingestion and search scalability rather than investigative context. Search-head memory optimization is an infrastructure-performance activity and likewise does not add meaningful fields to a finding.
This principle aligns directly with the supplied course material ' s guidance that, once a detection is known to fire, engineers should ensure that the fields analysts need are present in the detection output .
Study Guide topics: correlation searches, analyst context, field enrichment, actionable findings, CIM fields, Assets & Identities, drilldowns.