Classify Attributes for Indicator Types - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Administrator Guide

Product
Cortex XSIAM
Creation date
2024-02-26
Last date published
2024-04-25
Category
Administrator Guide
Abstract

Classify events using a classification key in an integration ingestion.

When an integration fetches indicators, it populates the rawJSON object in the indicator object. When classifying data, you want to select an attribute that can determine the indicator.

You can use this procedure for creating a classifier or duplicating an existing classifier.

  1. Under Get data, select from where you want to pull the information based on which you will classify the incident types.

    • Pull from instance: Select an existing integration instance.

    • Select schema: When supported by the integration, this will pull all the fields for the integration from the database from which you can select by which to classify the events.

    • Upload JSON: Upload a formatted JSON file which includes the field by which you want to classify.

  2. Select SettingsConfigurationsObject SetupIndicatorsClassification & MappingNewIndicator Classifier.

    If you want to duplicate the classifier, select the relevant classifier and then duplicate it.

  3. In the Get data field, select how to retrieve the data to classify the events.

  4. In the Select Instance field, select the instance or JSON file from where you want to choose the value.

  5. Save the classifier.

  6. Go to SettingsAutomation & Feed Integrations.

    1. Select the integration to which you want to apply the classifier.

    2. In the integration settings, under Classifier, select the classifier you created and click Save.