In addition to the system-level indicator types, you can create custom indicator types in Cortex XSIAM.
Indicators are categorized by indicator type, which determines the indicator layout and fields that are displayed and which scripts are run on indicators of that type. Cortex XSIAM includes several out-of-the-box indicator types, such as:
IP Address
Domain
URL
File
For more information about file indicators and how to configure the file hash, see File indicators.
When you create a new indicator type, you define its properties, including whether and how to format the indicator data and how the verdict is calculated.
Go to
→ → → → .Click New.
In the Settings tab, add the required indicator profile, such as name and Regex.
For more information, see Indicator type profile.
In the Custom Fields tab, map the fields, as required.
For more information, see Map custom indicator fields.