Create a featured alert field - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Documentation

Product
Cortex XSIAM
Creation date
2024-03-06
Last date published
2025-01-21
Category
Administrator Guide
Abstract

You can label specific alert attributes as featured alert fields.

To help you to track alerts involving specific hosts, users, and IP addresses, you can label specific alert attributes as featured fields. Alerts that contain a matching featured field value are identified with a featured-alert-field-flag.png flag in the Alert Name field of the Alerts table. After setting up featured fields, you can use them filter the Alerts table and to create incident scoring rules.

Note

Featured Active Directory values are displayed in the User and Host fields accordingly.

How to create a featured alert field
  1. Go to Incident ResponseIncident ConfigurationFeatured Fields and select a type of featured field.

  2. Click Add featured <field-type> and select one of the following options:

    • Create New

      To create a new featured alert field from scratch, enter one or more field-type values and click Add.

    • Upload from File

      To upload field values from a CSV file, upload your file and click Import. Click Download example file to ensure you are using the correct format.

  3. Find alerts containing featured alert fields.

    In the Alerts table, use the Contains Featured filters.

  4. (Optional) Create an incident scoring rule using the Contains Featured fields to further highlight and prioritize alerts containing the Host, User, and IP address attributes. For more information, see Set up incident scoring.