Create a Mapper
Starting with version 6.0, you can create independent
mappers for your integrations.
Mappers enable you to map the information
from incoming events to the incident or indicator layouts that you
have in your system.
Mapping event attributes or indicator
fields now takes place in two stages. At first, you map all of the
fields that are common to all incident or indicator types in the
default mapping. After that, you can map the additional fields that
are specific for each incident or indicator type, or overwrite the
mapping that you used in the default mapping.
In
the
Classification & Mapping
screen, the
mappings do not indicate for which incident types they are configured.
Therefore, when creating a mapper, it is best practice to add to
the mapper name the incident types the mapper is for. For example,
Mail Listener - Phishing.- Navigate toClassification & Mapping.
- ClickNewand select the mapper that you want to create.
- Incident Mapper (Incoming) - maps all of the fields you are pulling from the integrations to the incident fields in your layouts
- Incident Mapper (Outgoing) - maps fields from Cortex XSOAR to the fields in the integration to which you are pushing the data. This is useful for mirroring.
- Indicator Mapping (Incoming) - maps all of the indicator fields to their indicator layout.
- UnderGet data, select from where you want to pull the information based on which you will map the incident types.
- Pull from instance - select an existing integration instance.Select schema - when supported by the integration, this will pull all of the fields for the integration from the database. This enables you to see all of the fields for each given event type that the integration supports.
- Upload JSON - upload a formatted JSON file which includes the field you want to map.
- UnderIncident Type, start by mapping out theDefault Mapping. This mapping includes the fields that are common to all of the incident types and will save you time having to define these fields individually in each incident type.
- Click the event attribute to which you want to map. You can further manipulate the field using filters and transformers.You can clickAuto Mapto automatically map fields with common or similar names to fields in Cortex XSOAR. For example, Severity to Importance or Description to Description.
- Repeat this process for the other incident types for which this mapping is relevant.
- ClickSave.
- Navigate to theServers and Servicespage.
- Select the integration to which you want to apply the mapper.
- In the integration settings, underMapper, select the classifier you created and clickDone.
Recommended For You
Recommended Videos
Recommended videos not found.