Indicator layout customization
Customize indicator layouts in Cortex XSOAR 8 SaaS.
Each indicator type has a unique set of data relevant to that specific indicator type, including layouts. It is important to display the most relevant data for users. Each out-of-the-box indicator comes with a layout. You can customize almost every aspect of the layout, including which tabs appear, in which order they appear, who has permission to view the tabs, what information appears, and how it is displayed.
You can see which indicator type uses the indicator layout in the Types tab under Settings & Info → Settings → Object Setup → Indicators. The indicator layout name appears in the Layout column.
You can customize the display information including fields for existing indicators, by modifying the sections and fields for the following views:
Indicator Summary
You can customize almost every aspect of the layout, including which tabs appear, the order they appear, and who has permission. In each field or tab, you can add filters by clicking the eye icon, which enables you to add conditions that show specific fields or tabs relevant to the indicator.
You can add a script in the indicator layout, such as a mapping script, which determines where an IP address originates and displays it on a map.
Quick View
Add, edit, and delete sections, fields, and filters in the Quick View section from an incident.
"New"/"Edit" form
Add, edit, and delete fields and buttons to be displayed when creating or editing an indicator.
Note
By default, when editing a list or text values in an incident/indicator layout, the changes are not saved until you confirm your changes (clicking the checkmark icon in the value field). These icons are designed to give you additional security when updating fields in incidents and indicators.
You can change this default behavior by adding a server configuration. For more information, see Configure inline value fields.
Last updated
Was this helpful?

