Case fields

Cortex XSIAM includes out-of-the-box case fields, fields from installed content packs, and user-defined custom fields. Use case fields in custom case layouts and the Cases table.

Custom case fields can be exported and imported. To export a single custom case field, right-click on the field in the fields table, and select Export. To export all custom case fields in a single JSON file, click the Export All button above the fields table. System case fields cannot be exported or imported.

After a custom case field is created, it can be edited, deleted, or exported by right-clicking on the row. The field name and field type cannot be changed after the field is created. System fields cannot be edited, deleted, or exported.

Deleting a case field or uninstalling a content pack containing a case field may affect capabilities based on the deleted field, layouts and case scoring.