<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex  XDR Incident Report in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-report/m-p/559416#M5206</link>
    <description>&lt;P&gt;Looking for a way to create a report that shows how long it is taking our analyst to close an incident. I have read elsewhere it is not possible since the data is not exposed to xql.&amp;nbsp; Does anyone know how to create something that would show how long an incident is open before closing?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have looked at the widgets in the report library but nothing shows this data.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Sep 2023 22:12:21 GMT</pubDate>
    <dc:creator>mehrleytim</dc:creator>
    <dc:date>2023-09-25T22:12:21Z</dc:date>
    <item>
      <title>Cortex  XDR Incident Report</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-report/m-p/559416#M5206</link>
      <description>&lt;P&gt;Looking for a way to create a report that shows how long it is taking our analyst to close an incident. I have read elsewhere it is not possible since the data is not exposed to xql.&amp;nbsp; Does anyone know how to create something that would show how long an incident is open before closing?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have looked at the widgets in the report library but nothing shows this data.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 22:12:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-report/m-p/559416#M5206</guid>
      <dc:creator>mehrleytim</dc:creator>
      <dc:date>2023-09-25T22:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex  XDR Incident Report</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-report/m-p/559478#M5210</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203199"&gt;@mehrleytim&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for reaching out to Palo Alto Live community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With respect to your query, if we can create a widget or report that shows how long it is taking our analyst to close an incident, unfortunately we do not have that option available as the alert or incidents are not the part of the data sets.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, there are few existing widgets that you can refer and can be useful with respect to your query or feature that you are looking for. Below are the list of widgets I can recommend you that you can refer:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;My MTTR (Will show you the MTTR of resolved incidents assigned to the logged in user).&lt;/LI&gt;
&lt;LI&gt;Resolved Incidents MTTR (Will show the MTTR of the resolved incidents by severity).&lt;/LI&gt;
&lt;LI&gt;Resolved Incidents by Assignee.&lt;/LI&gt;
&lt;LI&gt;Incidents Over Time.&lt;/LI&gt;
&lt;LI&gt;Total Incidents.&lt;/LI&gt;
&lt;LI&gt;Incidents By Status (Last 30 days).&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 08:43:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-incident-report/m-p/559478#M5210</guid>
      <dc:creator>dbahuguna</dc:creator>
      <dc:date>2023-09-26T08:43:11Z</dc:date>
    </item>
  </channel>
</rss>

