Use an existing rule to create a new Custom Detection Rule - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-16
Category
Administrator Guide
  1. Navigate to Posture ManagementRules & PoliciesRulesCloud Workload.

  2. In the Cloud Workload Rules page, click the policy you want to enable or disable.

  3. In the Details page, click the More Options icon () and then select Save as new.

  4. Modify the fields as required.

  5. Click Create to create the new custom detection rule.