Create an Indicator Type - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Administrator Guide

Cortex XSIAM
Creation date
Last date published
Administrator Guide

In addition to the system-level indicator types, you can create custom indicator types in Cortex XSIAM.

When you create a custom indicator type, you configure fields and settings that impact how indicators of that type are enriched, how they are expired, how the verdict is calculated, etc.

Before you create a custom indicator type, you should familiarize yourself with the indicator type profile.

  1. SelectSettingsConfigurationsObject SetupIndicatorsNew.

  2. In the Attributes tab, add the required Indicator Type Profile parameters, such as name, regex, etc.

  3. In the Custom Fields tab, map the custom indicator fields, as required.