Create a featured field

To help you to track issues involving specific hosts, users, and IP addresses, you can label specific issue attributes as featured fields. Issues that contain a matching featured field value are identified with a ![featured-alert-field-flag.png](/docs/images/38b94e8ae030319c.png) flag in the **Name** field of the **Issues** table. After setting up featured fields, you can use them filter the **Issues** table and to create case scoring rules.

Featured Active Directory values are displayed in the **User** and **Host** fields accordingly.

### How to create a featured field in Cortex XSIAM

1. Go to **Cases & Issues → Case Configuration →** **Featured Fields** and select a type of featured field.
2. Click **Add featured \<field-type>** and select one of the following options:
 * **Create New**

 To create a new featured field from scratch, enter one or more field-type values and click **Add**.
 * **Upload from File**

 To upload field values from a CSV file, upload your file and click **Import**. Click **Download example file** to ensure you are using the correct format.
3. Find issues containing featured fields.

 In the **Issues** table, use the **Contains Featured** filters.
4. (Optional) Create a case scoring rule using the **Contains Featured** fields to further highlight and prioritize issues containing the Host, User, and IP address attributes.