Create a starring configuration ↗
Create a Cortex XSIAM starring configuration to automatically flag priority issues and linked cases. Define issue-based criteria to focus investigations on the most relevant cases.
Create an issue and case starring rule
- Select Cases & Issues → Case Configuration → Starred Issues.
- Select Add Starring Configuration.
- Under Configuration Name, enter a name for the issue and case starring rule.
- (Optional) Under Comment, enter a descriptive comment.
-
In the issue table, use the filters to define the issue attributes you want to include in the match criteria. For example, you can select issues with High severity, issues by category, or issues associated with certain assets or asset providers.
Tip
Right-click an issue field to add it as match criteria.
- Click Create.
Scope-Based Access Control for starring configurations
Case starring supports Scope-Based Access Control (SBAC). The following parameters apply when you edit a starring configuration:
- If Scope-Based Access Control (SBAC) is enabled and the Endpoint Scoping Mode is set to restrictive mode, you can edit a configuration if you are scoped to all tags in the configuration.
- If Scope-Based Access Control (SBAC) is enabled and the Endpoint Scoping Mode is set to permissive mode, you can edit a configuration if you are scoped to at least one tag listed in the configuration.
- If a policy was added when set to restrictive mode, and then changed to permissive (or vice versa), you will only have view permissions.