Set the indicator extraction mode for a playbook task

By default, system-wide indicator extraction is disabled. You can set the indicator extraction mode for specific playbook tasks.

1. Select the playbook where you want to add indicator extraction to a task, and click **Edit**.
2. In the playbook, click a task to open the **Edit Task** window.
3. Click the **Advanced** tab.
4. In the indicator extraction drop-down menu, select the mode you want to use.
5. Click **OK**.