<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search incidents by context value in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/search-incidents-by-context-value/m-p/515047#M1205</link>
    <description>&lt;P&gt;Thanks for the reply. I understand, search for the context of all the incidents is too much for the XSOAR. So the point is to find the similiar incidents and then look inside their context.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 16 Sep 2022 05:59:32 GMT</pubDate>
    <dc:creator>Josep</dc:creator>
    <dc:date>2022-09-16T05:59:32Z</dc:date>
    <item>
      <title>Search incidents by context value</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/search-incidents-by-context-value/m-p/514954#M1200</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;There are incidents with a context value "content : exception"&lt;/P&gt;
&lt;P&gt;Which query command on "Search in incidents" could find all incidents with this context value?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2022 11:57:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/search-incidents-by-context-value/m-p/514954#M1200</guid>
      <dc:creator>Josep</dc:creator>
      <dc:date>2022-09-15T11:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: Search incidents by context value</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/search-incidents-by-context-value/m-p/515030#M1203</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/226640"&gt;@Josep&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We do not index context items outside the incident key. If you want to filter incidents based on that data I would suggest implementing a new field.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this is a one-time thing, you could try the&amp;nbsp;FindSimilarIncidents automation. The automation searches for similar incident using indexed fields first, by using the&amp;nbsp;similarIncidentFields and similarIncidentKeys parameters. After the first level of filtering, the automation then searches for incidents that have similar context keys using the&amp;nbsp;similarContextKeys parameter. You can use this as a way of searching.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 00:23:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/search-incidents-by-context-value/m-p/515030#M1203</guid>
      <dc:creator>jfernandes1</dc:creator>
      <dc:date>2022-09-16T00:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: Search incidents by context value</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/search-incidents-by-context-value/m-p/515047#M1205</link>
      <description>&lt;P&gt;Thanks for the reply. I understand, search for the context of all the incidents is too much for the XSOAR. So the point is to find the similiar incidents and then look inside their context.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 05:59:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/search-incidents-by-context-value/m-p/515047#M1205</guid>
      <dc:creator>Josep</dc:creator>
      <dc:date>2022-09-16T05:59:32Z</dc:date>
    </item>
  </channel>
</rss>

