Create issue layout rules

Create Cortex XSIAM issue layout rules to assign custom layouts based on issue criteria. For example, apply a specific layout to issues generated by a correlation rule.

You can create multiple issue layout rules. Cortex XSIAM checks each rule until one applies to an incoming issue. Content pack layout rules appear first by default. Drag and drop rules to change their order. Filter rules by name, description, rule, layout, or source. If no rule applies, Cortex XSIAM uses the default issue layout.

To edit or delete an existing issue layout rule, right-click it in the list. Then select **Edit** or **Delete**.

### Create a Cortex XSIAM issue layout rule

1. Go to Settings → Configurations → Object Setup → Issues → Layout Rules → New Rule.
2. Enter a rule name, select the layout to use if the rule is met, and provide a description.
3. Search for issues matching the issue layout rule criteria. For example, search for issues from a specific issue source.
4. Click Create.
5. Repeat as needed to create multiple rules.
6. Click Save.

### Scope-Based Access Control for issue layout rules

Issue layout rules support Scope-Based Access Control (SBAC). The following parameters apply to editing access.

* If Scope-Based Access Control (SBAC) is enabled and Endpoint Scoping Mode is set to restrictive mode, you can edit a rule if you are scoped to all tags in the rule.
* If Scope-Based Access Control (SBAC) is enabled and Endpoint Scoping Mode is set to permissive mode, you can edit a rule if you are scoped to at least one tag listed in the rule.
* As a scoped user who has editing permissions to a rule, you can change the order among other rules that are locked.
* If a rule was added when set to restrictive mode, and then changed to permissive (or vice versa), you will only have view permissions.