<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Filter out incidents having email communications associated with it in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/filter-out-incidents-having-email-communications-associated-with/m-p/528315#M1697</link>
    <description>&lt;P&gt;From all the incidents I have, I want to filter out the incidents having email communications associated with them.&lt;BR /&gt;There are several fields in the context and in the incident of the context that identifies an incident as email communications associated.&lt;BR /&gt;Can anybody help me with this ? maybe using any specific field from context or incident.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jan 2023 09:54:20 GMT</pubDate>
    <dc:creator>bhargav_11</dc:creator>
    <dc:date>2023-01-24T09:54:20Z</dc:date>
    <item>
      <title>Filter out incidents having email communications associated with it</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/filter-out-incidents-having-email-communications-associated-with/m-p/528315#M1697</link>
      <description>&lt;P&gt;From all the incidents I have, I want to filter out the incidents having email communications associated with them.&lt;BR /&gt;There are several fields in the context and in the incident of the context that identifies an incident as email communications associated.&lt;BR /&gt;Can anybody help me with this ? maybe using any specific field from context or incident.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 09:54:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/filter-out-incidents-having-email-communications-associated-with/m-p/528315#M1697</guid>
      <dc:creator>bhargav_11</dc:creator>
      <dc:date>2023-01-24T09:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: Filter out incidents having email communications associated with it</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/filter-out-incidents-having-email-communications-associated-with/m-p/528373#M1701</link>
      <description>&lt;P&gt;If you are filtering via the UI, you can use the query &amp;lt;FieldName&amp;gt;="" to retrieve incidents that have an empty field. So if the field was called emailcommunications it would look like this: emailcommunications="". If there are multiple fields you need to filter by you can use and/or operators to logically filter for the subset of incidents you are trying to retrieve. If this is being done via playbook, you can use the SearchIncidentsV2 automation. You would choose the query input and then use the same query as in the UI.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 16:54:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/filter-out-incidents-having-email-communications-associated-with/m-p/528373#M1701</guid>
      <dc:creator>amontminy</dc:creator>
      <dc:date>2023-01-24T16:54:26Z</dc:date>
    </item>
  </channel>
</rss>

