> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/reference/server-configurations/indicator-server-configurations.md).

# Indicator Server Configurations

| Key                                                              | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | Default               |
| ---------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------- |
| **`create.indicators.limit.by.time.range`**                      | Whether to limit the period of time to fetch indicators.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | **`true`**            |
| **`create.indicators.limit.by.time.range.hour`**                 | The period of time (hours) within which to limit indicators that can be fetched.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | **`24`**              |
| **`create.indicators.limit.by.time.range.max.allowed`**          | The maximum number of indicators that can be fetched within the time period defined in the following server configuration: **`create.indicators.limit.by.time.range.hours`**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | **`1000`**            |
| **`create.indicators.limit.by.total.amount`**                    | Whether to limit the total number of indicators that can be fetched.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | **`false`**           |
| **`create.indicators.limit.by.total.amount.max.allowed`**        | The maximum number of total indicators that can be fetched by default.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | **`5000000`**         |
| **`create.indicators.limit.by.total.amount.warning.percentage`** | The percentage of indicators fetched, calculated from **`create.indicators.limit.by.total.amount.max.allowed`**, after which warning messages are sent to defined users.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | **`75`**              |
| **`create.related.indicators.entry`**                            | Whether to disable War Room notifications for related indicators. For more information, see [War Room Overview](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview.md).                                                                                                                                                                                                                                                                                                                                                                                                              | **`true`**            |
| **`enrichment.reputationScript.reliability`**                    | The reliability of the score from a reputation script. For more information, see [Indicator Type Profile](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization.md#UUID-c9437af0-7c2f-0f21-6c44-f2a314b7a5e8).                                                                                                                                                                                                                                                                                                                                                                   | **`A++`**             |
| **`Export.utf8bom`**                                             | Whether to [export an incident to CSV using the UTF8-BOM format](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/day-to-day-tasks-in-cortex-xsoar/incident-management/export-an-incident-to-csv-using-the-utf8-bom-format.md).                                                                                                                                                                                                                                                                                                                                                                                                                     | **`false`**           |
| **`indicator.feed.html.field.truncate.maxChars`**                | To change the maximum size in KB to display the HTML field. If you increase the limit substantially, it may slow performance. For more information, see [Configure the HTML Field](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization.md#UUID-e8d5accb-b5ad-8550-54ca-32b3705c8eb3).                                                                                                                                                                                                                                                                                          | **`50`**              |
| **`indicator.html.style.attributes`**                            | If HTML is missing some styles, add the missing styles. For more information, see [Configure the HTML Field](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization.md#UUID-e8d5accb-b5ad-8550-54ca-32b3705c8eb3).                                                                                                                                                                                                                                                                                                                                                                | N/a                   |
| **`indicator.investigationids.maxlen`**                          | The maximum number of investigation IDs saved per indicator prevents the number of related incidents of an indicator from increasing significantly, causing memory issues/outage on the server. When defined, the number of associated investigation IDs will be limited to "maxlen". If a new ID is associated with the indicator, the oldest ID will be removed. Use 0 for "unlimited" (the default and current behavior).                                                                                                                                                                                                                                  | **`0`**               |
| **`indicator.timeline.auto.extract.enabled`**                    | Enables the indicator timeline in the indicator extraction flow. For more information, see [Configure the Indicator Timeline](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/day-to-day-tasks-in-cortex-xsoar/indicator-management/configure-the-indicator-timeline.md).                                                                                                                                                                                                                                                                                                                                                                          | **`true`**            |
| **`indicator.timeline.enabled`**                                 | Enables the indicator timeline in all flows. For more information, see [Configure the Indicator Timeline](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/day-to-day-tasks-in-cortex-xsoar/indicator-management/configure-the-indicator-timeline.md).                                                                                                                                                                                                                                                                                                                                                                                              | **`true`**            |
| **`indicator.timeline.enabled.type.`*****`<indicatorType>`***    | Enables the indicator timeline for a specific indicator type. For more information, see [Configure the Indicator Timeline](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/day-to-day-tasks-in-cortex-xsoar/indicator-management/configure-the-indicator-timeline.md).                                                                                                                                                                                                                                                                                                                                                                             | **`true`**            |
| **`indicator.timeline.max.size`**                                | The maximum number of indicator comments (timeline and regular). For more information, see [Configure the Indicator Timeline](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/day-to-day-tasks-in-cortex-xsoar/indicator-management/configure-the-indicator-timeline.md).                                                                                                                                                                                                                                                                                                                                                                          | **`100`**             |
| **`indicator.timeline.worker.enabled`**                          | Enables you to add timeline comments through content integrations. For more information, see [Configure the Indicator Timeline](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/day-to-day-tasks-in-cortex-xsoar/indicator-management/configure-the-indicator-timeline.md).                                                                                                                                                                                                                                                                                                                                                                        | **`true`**            |
| **`message.ignore.fetchIndicator.warning`**                      | <p>Indicates whether to send warning messages to defined users.</p><p>This is an alternative to the previous set of configurations, which sets the limit according to the total number and the defined time period.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                       | **`false`**           |
| **`reputation.calc.algorithm.tasks`**                            | Applies to the result of the task. You can change the value when editing a task, which overrides the system configuration for this task. For more information, see [Indicator Extraction Modes](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction.md#UUID-89130134-639e-fbf0-6924-e1f86f1aa7eb).                                                                                                                                                                                                                                                                                | **`none`**            |
| **`reputation.calc.algorithm`**                                  | <p>Sets the global indicator extraction mode, which affects all extraction processes, including incident creation, playbooks, and automation. It is also used to troubleshoot performance issues, such as playbooks taking a long time to start.</p><p>Available modes:</p><ul><li>1- None</li><li>2 - Inline</li><li>3 - Out of band</li></ul><p>For more information, see <a href="/pages/hcVmIUBSRGfQkYdYkJUF#UUID-89130134-639e-fbf0-6924-e1f86f1aa7eb">Indicator Extraction Modes</a>.</p>                                                                                                                                                               | **`2`** (inline)      |
| **`reputation.calc.algorithm.fields.change`**                    | Sets the indicator extraction mode for incident field change. You can change the value when editing an incident type, which overrides this system configuration for this incident type. For more information, see [Indicator Extraction Modes](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-extraction.md#UUID-89130134-639e-fbf0-6924-e1f86f1aa7eb).                                                                                                                                                                                                                                 | **`3`** (out of band) |
| **`reputation.calc.algorithm.manual`**                           | <p>Applies to commands triggered from the CLI. You can change the value when using the auto-extract parameter, which overrides the system configuration for this command.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>This configuration disables extraction on command outputs (for example, Print automation) but does not apply to manual entries. Indicators are still extracted from War Room notes and manual tasks.</p></div><p>For more information, see <a href="/pages/hcVmIUBSRGfQkYdYkJUF#UUID-89130134-639e-fbf0-6924-e1f86f1aa7eb">Indicator Extraction Modes</a>.</p> | **`3`** (Out of band) |
| **`reputation.notification.max.count`**                          | The maximum number of notifications of reputation indicators in a batch update.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | **`100`**             |
| **`ThreatIntelReport.default.readonly.roles`**                   | Grants read-only access to Threat Intel reports. Value: List of comma-separated users.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | N/a                   |
| **`ThreatIntelReport.default.roles`**                            | Grands read and write access to Threat Intel Reports. Value: List of comma-separated users.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | N/a                   |
| **`UI.html.use.theme.css`**                                      | Whether to use Cortex XSOAR theme styles. For more information, see [Configure the HTML Field](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization.md#UUID-e8d5accb-b5ad-8550-54ca-32b3705c8eb3).                                                                                                                                                                                                                                                                                                                                                                              | **`true`**            |
| **`UI.investigation.page`**                                      | <p>Customizes the default landing page within the incident view. Values:</p><ul><li><strong><code>/Details/</code></strong></li><li><strong><code>/WarRoom/</code></strong></li><li><strong><code>/WorkPlan/</code></strong></li><li><strong><code>/EvidenceBoard/</code></strong></li></ul>                                                                                                                                                                                                                                                                                                                                                                  | **`/Details/`**       |
| **`UI.summary.page.hide.empty.fields`**                          | Whether to hide empty fields in the incident summary tab. For more information, see [Indicator Layouts](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators/indicator-customization.md#UUID-0a1b13cb-8b3a-f018-dd86-8499cfe2d988).                                                                                                                                                                                                                                                                                                                                                                     | **`true`**            |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/reference/server-configurations/indicator-server-configurations.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
