> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-fields/create-a-custom-indicator-field.md).

# Create a Custom Indicator Field

Indicator Fields are used to add specific indicator information to incidents. When you create an indicator field, you can associate the field to a specific indicator type or to all indicator types.

1. Go to Settings → OBJECTS SETUP → Indicators → **Fields**.
2. Click **New Field**.
3. Configure the basic settings.

   | Field          | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
   | -------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Field Type     | <p>Determines the acceptable values for the field. You can add the following field types:</p><ul><li>Boolean (checkbox)</li><li>Date picker</li><li>Grid (table): Include an interactive, editable grid.</li><li><p>HTML: Create and view HTML content, which can be used in any type of indicator. By default, HTML fields do not use Cortex XSOAR theme styles, but can be <a href="#UUID-a1fb53a8-da8b-28ad-d319-13b338d48c2e">configured</a> to use existing user themes.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>The following HTML tags are not permitted: <code>blockquote</code>, <code>del</code>, <code>dd</code>, <code>div</code>, <code>dl</code>, <code>dt</code>, <code>fieldset</code>, <code>form</code>, <code>h1</code>, <code>h2</code>, <code>h3</code>, <code>h4</code>, <code>h5</code>, <code>h6</code>, <code>hr</code>, <code>iframe</code>, <code>ins</code>, <code>li</code>, <code>math</code>, <code>noscript</code>, <code>ol</code>, <code>pre</code>, <code>p</code>, <code>script</code>, <code>style</code>, <code>table</code>, <code>ul</code>, <code>address</code>, <code>article</code>, <code>aside</code>, <code>canvas</code>, <code>details</code>, <code>dialog</code>, <code>figcaption</code>, <code>figure</code>, <code>footer</code>, <code>header</code>, <code>hgroup</code>, <code>main</code>, <code>nav</code>, <code>output</code>, <code>progress</code>, <code>section</code>, <code>video</code>.</p><p>The following CSS tags are not permitted: <code>background-color</code>, <code>text-align</code>, <code>font-size</code>, <code>font-family</code>, <code>font-weight</code>, <code>color</code>, <code>line-height</code>, <code>border-style</code>, <code>border</code>, <code>page-break-inside</code>, <code>tablelayout</code>, <code>padding</code>, <code>background-size</code>, <code>display</code>, <code>padding-top</code>, <code>padding-right</code>, <code>padding-bottom</code>, <code>padding-left</code>, <code>text-size-adjust</code>, <code>break-inside</code>, <code>word-break</code>, <code>width</code>, <code>height</code>, <code>-ms-text-size-adjust</code>, <code>-webkit-text-size-adjust</code>.</p></div></li><li>Long text: Long text is analyzed and tokenized, and entries are indexed as individual words, enabling you to perform advanced searches and use wildcards. Long text fields cannot be sorted and cannot be used in graphical dashboard widgets. While editing a long text field, pressing enter will create a new line. Case is insensitive.</li><li>Markdown: Add markdown-formatted text as a <strong>Template</strong> which will be displayed to users in the field after the indicator is created. Markdown lets you add basic formatting to text to provide a better end-user experience.</li><li>Multi select / Array: Includes two options a) Multi select from a pre-filled list b) An empty array field for the user to add one or more values as a comma-separated list.</li><li>Number: Can contain any number. Default is 0.</li><li>Role: Role assigned to the indicator. Determines which users (by role) can view the indicator.</li><li>Short text: Short text is treated as a single unit of text, and is not indexed by word. Advanced search, including wildcards, is not supported. Short text fields are case sensitive by default, but can be changed to case insensitive when creating the field. While editing a short text field, pressing enter will save the change. Maximum length 60,000 characters. Recommended use is one word entries. Examples: username, email address, etc.</li><li>Single select</li><li>URL</li><li>User: A user in the system.</li></ul> |
   | Case Sensitive | If selected, the field is case sensitive, which affects how the search results for this field are returned in Cortex XSOAR.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
   | Mandatory      | If selected, this field is mandatory when used in a form.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
   | Field Name     | A meaningful display name for the field. After you type a name, you will see below the field that the **Machine name** is automatically populated. The field’s machine name is applicable for searching and the CLI.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
   | Tooltip        | An optional tooltip for the field.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
   | Placeholder    | Optional text to display in the field when it is empty. This text will appear in the layout, but not in the created indicator. Available for Short text, Long text, Multi select / Array, Tags.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
4. Configure the attributes.

   | Field                                  | Description                                                                                                                                                                                                                                                                                                                                                                                                                    |
   | -------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
   | Script to run when field value changes | The script that dynamically changes the field value when script conditions are met. For a script to be available, it must have the **`field-change-triggered-indicator`** tag, when defining an automation. For more information, see [Indicator Field Trigger Scripts](/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-fields/indicator-field-trigger-scripts.md). |
   | Add to indicator types                 | <p>By default, the <strong>Associate to all</strong> option is selected, which means this field will be available to use in all incident types.</p><p>Clear the checkbox to associate this field to a subset of indicator types.</p>                                                                                                                                                                                           |
   | Make data available for search         | The values for this field can be returned in searches.                                                                                                                                                                                                                                                                                                                                                                         |
5. Save the changes.
6. (Optional) [Add the custom field to a section of the indicator layout](/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-layouts/customize-an-indicator-type-layout.md).
7. (Optional) [Map Custom Indicator Fields](/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-types/map-custom-indicator-fields.md).

   Mapping a field enables you to automatically update the indicator without the analyst having to change it.

### **Configure the HTML Field**

From version 6.0.1, when adding an HTML field, by default, Cortex XSOAR does not apply its own style themes to the HTML field.

If you have existing HTML fields and upgrade from an earlier version, the HTML fields may not appear as expected. You can change the default behavior to allow HTML fields to utilize style themes from existing user styles.

You can also change the HTML maximum siz, and append any missing HTML styles to default styles. By default, HTML fields populated by integrations are limited to 50KB of data. When working with Threat Intel Feeds, content greater than 50KB is truncated.

{% hint style="info" %}

### Note

Relevant for all HTML entries and fields, such as in widgets, dashboards, incidents, indicators, etc.
{% endhint %}

1. Select Settings → ABOUT → Troubleshooting → **Add Server Configuration**.
2. To change the styles to utilize style themes from existing user styles, add the following key and value.

   By default, this configuration is set to false, so you cannot use Cortex XSOAR theme styles.

   | Key                         | Value      |
   | --------------------------- | ---------- |
   | **`UI.html.use.theme.css`** | **`true`** |
3. To change the maximum size to display the HTML field, add the following key and value:

   | Key                                               | Value                                                                              |
   | ------------------------------------------------- | ---------------------------------------------------------------------------------- |
   | **`indicator.feed.html.field.truncate.maxChars`** | Default is 50KB. If you increase the limit substantially, it may slow performance. |
4. To change the style attributes, add the following key and value:

   If the HTML is missing some of the styles and it does not appear as expected, you should append the missing styles to the default styles.

   | Key                                  | Value                                                                                                                                                                                                                                                                                                                                                                                |
   | ------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
   | **`incident.html.style.attributes`** | <p>Supports the following styles:</p><p><strong><code>text-align,font-size,font-family,font-weight,color,line-height,border-style,border,page-break-inside,tablelayout,padding,background-size,display,padding-top,padding-right,padding-bottom,padding-left,text-size-adjust,break-inside,word-break,width,height,-ms-text-size-adjust,-webkit-text-size-adjust</code></strong></p> |
5. Click **Save** to save any configuration.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-6-threat-intel-management-guides/6.14/configure-indicators/indicator-customization/indicator-fields/create-a-custom-indicator-field.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
