Right after logs are ingested to Azure Sentinel, i need to add an additional key/value pair to the schema and get it populated for every log based on the value of a specific existing key.
For example, all logs should have a new field named Country. If the value of Tenant ID in the ingested logs = xyz, then the Country field should be populated as United Stated, and so on. So i have pre-known TenantID - Country mappings, and i would like to insert the country values in all logs.
In other SIEM solutions such requirement can be done by using "feeds".