Set the indicator extraction mode for a playbook task - Create indicator extraction rules for a playbook task in Cortex XSIAM. Auto extract for a playbook task. Edit task. Use case indicator extraction. - Threat Intel Management Guide - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-16
Category
Administrator Guide
Abstract

Create indicator extraction rules for a playbook task in Cortex XSIAM. Auto extract for a playbook task. Edit task. Use case indicator extraction.

By default, system-wide indicator extraction is disabled. You can set the indicator extraction mode for specific playbook tasks.

  1. Select the playbook where you want to add indicator extraction to a task, and click Edit.

  2. In the playbook, click a task to open the Edit Task window.

  3. Click the Advanced tab.

  4. In the indicator extraction drop-down menu, select the mode you want to use.

  5. Click OK.