To enrich the data for analysis, the security analyst needs to compare the legitimate domains against those used in phishing campaigns. Creating a parser that matches domains allows the SIEM to automatically identify and analyze the domains in the logs, helping detect typosquatting and other malicious domain usage. This method allows for efficient and automated processing of log data to identify potential threats.