Fields and Types permissions - Configure Fields and Types permissions under Objects. - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-04
Category
Administrator Guide
Abstract

Configure Fields and Types permissions under Objects.

Controls access to custom fields and indicator types within Object Setup SettingsConfigurationsObject Setup:

  • Case fields (CasesFields): Custom fields that extend the case data schema, appearing in case views, queries, and layouts.

  • Issue fields (IssuesFields): Custom fields for the issue data schema, often used for automation rules and filtering.

  • Indicator fields and types: Definitions for custom indicator fields and new indicator types (e.g., Cloud Resource ID), including extraction regex patterns.

  • SLA rules: Service Level Agreement rules that define time-based expectations for issue handling.

Permission

Description

Roles Example

None

No access to define fields, types, or SLA rules. Users can still view and use existing fields in case/issue views, but cannot modify their definitions

SOC Tier 1 Analyst: Schema changes are outside Tier-1 scope; they use existing fields but don't need to see field configuration.

View

Read-only access to all field definitions, indicator types, and SLA rule configurations. Allows exporting definitions to CSV.

  • SOC Tier 2 and 3 Analysts: Need to understand field definitions for advanced queries, custom field usage, and investigation workflows.

  • Threat Hunter: Needs to understand field definitions for hunting queries (XQL) and custom field usage.

View/Edit

Full read/write access. Users can create, modify, or delete custom fields and indicator types, write extraction regex, and set SLA rules.