Follow these instructions to create custom incident fields.
You can define custom incident fields based
on the information you want to display in your incident layout,
including information ingested from third party integrations.
If
you try to create a new incident field with a name that already exists
in the system such as
Account
, you may receive
a message similar to this:
[Could not create incidentfield with ID '' and name 'Account'. Field already exists as a builtin field (100709)]
.
If so, you should select a different name as the incident field is
already reserved for system use.
Select
Settings
ADVANCED
Fields
+
New Field
.
Depending on the field type, you can determine if the field
contents are case-sensitive, as well as if the field is mandatory.
Select the check box for the incident type you want
to edit.
Click
Duplicate
. A copy of
the incident type appears with the string _copy appended to the
name of the incident type. If more than one copy of the incident
type is created, a number is appended to the _copy string. The number
is increased with each additional duplication.
Click the name of the newly created incident type.
You are presented with the current layout, which is populated
with demo data so you can see how the fields fit.
To add the field to a custom incident type:
Go to
Settings
Advanced
Incident Types
.
Select the incident type whose layout you want to
edit and click the
Edit Layout
.
You are presented with the current layout, which is populated
with demo data so you can see how the fields fit.
Make sure you select an incident type where the
Layout
field
is empty.
In the
Library
dialog box, in the
Cortex
XSOAR Sections
tab, drag and drop
+ New Section
on
to the required tab.
In the
Incident
field tab, drag
and drop the field that you have created into the