Sorry to hear about your frustration with McAfee ESM. Sounds like you have some deeper issues than can likely address on this forum. If you will PM me your contact information, I think I can get you the assistance you need.
We have a Data Enrichment Rule that runs against a CSV file of Terminated Users, we had to manipulate the format to find what worked (in the CSV).
We have it scheduled to run every day at a certain time, and it updates a custom field with the term "Former" for a terminated employee.
We then have an Alarm that triggers for activity by a user that has "Former" in this particular custom field.
We plan to expand this to include "Service Accts" "Prviliged Users" etc...
Where do you have the Data Enrichment setup on?
I have found in my testing that it did not work when setup to the ESM, when I set it up on each of my receivers it started to work.
The Data Enrichment task is defined on the ESM Properties, under Data Enrichment.
The Source is the CSV on a CIFS Share
The Destination is all of our Windows Servers (on 8 different receivers) with a Lookup field of Source User and an Enrichment Field of "Employee_Status" mapped to Custom Field 9
The thing to be careful on is which Custom Field you are trying to use, to make sure it will not be over-written by something else.
There are very few Custom Fields that are actually usable, the system uses most of the others, not sure why they call them custom.
You can look in the Help for "Predefined custom types table" to see the current mappings.