Create a new prevention policy rule for serverless function

From Inventory → Endpoints → Policy Management → Prevention → Profiles, right-click the profile and select Create a new policy rule using this profile.

Cortex XSIAM automatically populates the Platform selection based on your profile configuration as well as the Restricitons selection with the selected profile.

For Policy Name, enter a meaningful name, and optionally, add a description for the policy rule, and then click Next.

Use the filters to define criteria for the policy rule to apply, and then click Next.

Select from the following function parameters:

  • Cloud provider
  • Region
  • Runtime
  • Function version
  • Endpoint name

Review the policy rule summary, and then click Done.

The filter is stored within the policy definition and assessed during runtime to extract the functions that match the filter criteria.