<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extract Incident context data using 'set' script in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/extract-incident-context-data-using-set-script/m-p/1226432#M176</link>
    <description>&lt;P&gt;do you try execute playbook task directly from alert in the incident or from the 'editor'?&amp;nbsp;&lt;BR /&gt;Debug/edit can have error during returning values from the incident. But it should work when you directly run the playbook from the alert.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Apr 2025 13:08:55 GMT</pubDate>
    <dc:creator>MDovirak</dc:creator>
    <dc:date>2025-04-14T13:08:55Z</dc:date>
    <item>
      <title>Extract Incident context data using 'set' script</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/extract-incident-context-data-using-set-script/m-p/1226211#M175</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;very simple task running the 'set' script in a very basic playbook in xsiam&lt;/P&gt;
&lt;P&gt;i am trying to pull the 'xsiam url link to the incident' from the incident context data&amp;nbsp;${parentIncidentFields.xdr_url} into a set task.. but it keeps showing as empty.&lt;/P&gt;
&lt;P&gt;any idea how i can pull an incident field into the playbook task?&lt;/P&gt;
&lt;P&gt;if i do ${alert.name} for example, it works fine but i cannot seem to pull anything from the incident context data, only the alert context data. is it even possible? should be. in my 'transformer and alerts' toolset, it works if i do a test run against an alert with&amp;nbsp;${parentIncidentFields.xdr_url} and it shows the desired URL. but soon as i run it from the playbook it just shows nothing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to add: from the warroom inside an alert, it works if i do this command &lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; !set key=xsiamurl value=${parentIncidentFields.xdr_url}&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks in adv&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 12:19:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/extract-incident-context-data-using-set-script/m-p/1226211#M175</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2025-04-10T12:19:55Z</dc:date>
    </item>
    <item>
      <title>Re: Extract Incident context data using 'set' script</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/extract-incident-context-data-using-set-script/m-p/1226432#M176</link>
      <description>&lt;P&gt;do you try execute playbook task directly from alert in the incident or from the 'editor'?&amp;nbsp;&lt;BR /&gt;Debug/edit can have error during returning values from the incident. But it should work when you directly run the playbook from the alert.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 13:08:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/extract-incident-context-data-using-set-script/m-p/1226432#M176</guid>
      <dc:creator>MDovirak</dc:creator>
      <dc:date>2025-04-14T13:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Extract Incident context data using 'set' script</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/extract-incident-context-data-using-set-script/m-p/1226439#M177</link>
      <description>&lt;P&gt;Hi Thanks..&lt;/P&gt;
&lt;P&gt;yes managed to figure it out.. i think.&lt;/P&gt;
&lt;P&gt;so when I use the debugger panel it does not seem to be able to pull the incident field data from the incident as I suspect it cannot link the incident to the alert.&lt;/P&gt;
&lt;P&gt;then if i run the playbook in the alert's warroom then it works fine as expected..&lt;/P&gt;
&lt;P&gt;so will make sure not to to rely on the debugger panel too much next time :- )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 15:14:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/extract-incident-context-data-using-set-script/m-p/1226439#M177</guid>
      <dc:creator>PA_nts</dc:creator>
      <dc:date>2025-04-14T15:14:08Z</dc:date>
    </item>
  </channel>
</rss>

