Define filter and aggregation criteria
Define and set filter conditions to specify which incoming Cortex XSIAM Incidents should create security incidents. You can also define additional Incident field criteria that allows an incoming Incident to be appended to an open security incident instead of creating an incident.
Set filtering conditions
Set filter conditions for which Palo Alto Cortex XSIAM incidents create security incidents in ServiceNow.
Vorbereitungen
Role required: sn_si.admin, sn_si.ingestion_profile_admin
Warum und wann dieser Vorgang ausgeführt wird
Filtering helps you isolate security incidents and limits the number of security incidents that you create. If you set additional filtering criteria, only the required incidents are ingested without having to change the query or the triggered incident configuration.
Prozedur
The options in the first field in the Filter Conditions match the fields that are displayed on the Cortex XSIAM Sample Incident Ingestion section for the Incident that you ingested. These fields are dynamic and change depending on the Incident that you ingest. The criteria that you enter is case-sensitive. Verify that the criteria that you define matches the values of the Incident.
Use the filter condition incident_id for the following fields with multiple values:- Severity
- creation_time
- alert_categories
- alert_count
Because the filter condition can retrieve only strings, you must use the incident_id filter condition for the above fields to ensure that the data is filtered correctly.
Define aggregation conditions
Select Aggregation Conditions to define additional incident field criteria that allows an incoming incident to be appended to an open security incident instead of creating a new one.
Vorbereitungen
Role required: sn_si.admin, sn_si.ingestion_profile_admin
Prozedur
Nächste Maßnahme
Set a schedule to retrieve the incident data and ingested incidents that match the criteria in the profile. For more information, see Schedule incident retrieval.