# Get user.name from user.id in Entity Analytics Azure Entra ID dataset

**URL:** <https://discuss.elastic.co/t/get-user-name-from-user-id-in-entity-analytics-azure-entra-id-dataset/359019>\
**Category:** Logstash\
**Created:** [May 8, 2024, 6:46am UTC](https://discuss.elastic.co/t/get-user-name-from-user-id-in-entity-analytics-azure-entra-id-dataset/359019 "2024-05-08T06:46:19Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [May 8, 2024, 6:46am UTC](https://discuss.elastic.co/t/get-user-name-from-user-id-in-entity-analytics-azure-entra-id-dataset/359019/1 "2024-05-08T06:46:19Z")

</div>

Hello,

So now we have the entity analytics, is it on Elastic's to do to enrich certain datasets with the real `user.name` from the `user.id` ?

For example in the Azure Graph API logs only a `user.id` field is known. The username could be added from the entity analytics entra id dataset.

Because we need to use the Elastic Integration Logstash filter, we cannot use enrich processor, as that is unsupported. So is the only way to achieve this, by doing it in Logstash with the Elasticsearch filter plugin then?

[Elasticsearch filter plugin | Logstash Reference [8.13] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html)

Willem

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [May 8, 2024, 8:20pm UTC](https://discuss.elastic.co/t/get-user-name-from-user-id-in-entity-analytics-azure-entra-id-dataset/359019/2 "2024-05-08T20:20:59Z")

</div>

Hi!

Have you explored doing the enrichment via an elasticsearch Ingest pipeline: [Enrich processor | Elasticsearch Guide [8.13] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/enrich-processor.html)

You could also do this enrichment at query time if you're working with ES|QL: [Data enrichment | Elasticsearch Guide [8.13] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/esql-enrich-data.html)

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [May 20, 2024, 3:03pm UTC](https://discuss.elastic.co/t/get-user-name-from-user-id-in-entity-analytics-azure-entra-id-dataset/359019/3 "2024-05-20T15:03:56Z")

</div>

Hey,

Tried

```auto
PUT /_enrich/policy/microsoft-azure-entra-id-users-policy
{
  "match": {
    "indices": "logs-entityanalytics_entra_id.user-default",
    "match_field": "user.id",
    "enrich_fields": ["user.full_name", "user.name", "user.email"]
  }
}

```

But I get:

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "index_not_found_exception",
        "reason": "no such index [logs-entityanalytics_entra_id.user-default]",
        "index_uuid": "_na_",
        "resource.type": "index_or_alias",
        "excluded_ds": "true",
        "resource.id": "logs-entityanalytics_entra_id.user-default",
        "index": "logs-entityanalytics_entra_id.user-default"
      }
    ],
    "type": "index_not_found_exception",
    "reason": "no such index [logs-entityanalytics_entra_id.user-default]",
    "index_uuid": "_na_",
    "resource.type": "index_or_alias",
    "excluded_ds": "true",
    "resource.id": "logs-entityanalytics_entra_id.user-default",
    "index": "logs-entityanalytics_entra_id.user-default"
  },
  "status": 404
}

```

I guess it doesnt work on datastreams. Is there a builtin way to schedule it? So that it contains the most recent entra id user info?

Willem

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [May 22, 2024, 9:26pm UTC](https://discuss.elastic.co/t/get-user-name-from-user-id-in-entity-analytics-azure-entra-id-dataset/359019/4 "2024-05-22T21:26:32Z")

</div>

> I guess it doesnt work on datastreams. Is there a builtin way to schedule it? So that it contains the most recent entra id user info?

I'm not exactly sure but I would probably start by looking at making a transform on your data stream to a summarized index and then using that summarized index as the source for your enrich policy

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [May 30, 2024, 7:48pm UTC](https://discuss.elastic.co/t/get-user-name-from-user-id-in-entity-analytics-azure-entra-id-dataset/359019/5 "2024-05-30T19:48:08Z")

</div>

Hey @willemdh

Enrich policies do work on datastreams  
In your example:

`"indices": "logs-entityanalytics_entra_id.user-default"`

you to update like this:  
`"indices": "logs-entityanalytics_entra_id.user-default-*"`

---

<div class="post-metadata">

**Author:** ![tokcum](https://avatars.discourse-cdn.com/v4/letter/t/b5ac83/32.png) [@tokcum](https://discuss.elastic.co/u/tokcum)\
**Post date:** [June 19, 2024, 7:25pm UTC](https://discuss.elastic.co/t/get-user-name-from-user-id-in-entity-analytics-azure-entra-id-dataset/359019/6 "2024-06-19T19:25:20Z")

</div>

Thank you @erikg . That worked for me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2024, 7:26pm UTC](https://discuss.elastic.co/t/get-user-name-from-user-id-in-entity-analytics-azure-entra-id-dataset/359019/7 "2024-07-17T19:26:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
