Set the indicator extraction mode for a playbook task ↗
By default, system-wide indicator extraction is disabled. You can set the indicator extraction mode for specific playbook tasks.
- Select the playbook where you want to add indicator extraction to a task, and click Edit.
- In the playbook, click a task to open the Edit Task window.
- Click the Advanced tab.
- In the indicator extraction drop-down menu, select the mode you want to use.
- Click OK.