<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using SearchIncidentsV2 or GetIncidentsByQuery in automations in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/using-searchincidentsv2-or-getincidentsbyquery-in-automations/m-p/551740#M2428</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/306384"&gt;@sdes&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;If you check&amp;nbsp;&lt;SPAN&gt;SearchIncidentsV2 is also calling&amp;nbsp;GetIncidentsByQuery script and you already made it work with&amp;nbsp;GetIncidentsByQuery. We would advise to return only the required fields to save some resources. You can use populateFields option for this purpose. You can see the use of it below.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="python"&gt;populate_fields = ["id", "labels"]
res = demisto.executeCommand('GetIncidentsByQuery', {
        'incidentTypes': "Cortex XDR Incident",
        'populateFields': ' , '.join(populate_fields)
    })

if is_error(res):
   return_error(res)
incidents = json.loads(res[0]['Contents'])
demisto.results(incidents)&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;I hope this answers your question.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 31 Jul 2023 09:49:42 GMT</pubDate>
    <dc:creator>gyldz</dc:creator>
    <dc:date>2023-07-31T09:49:42Z</dc:date>
    <item>
      <title>Using SearchIncidentsV2 or GetIncidentsByQuery in automations</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/using-searchincidentsv2-or-getincidentsbyquery-in-automations/m-p/551664#M2426</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First of all, we are using a lot of automations searching for incidents using queries often with more than 100 results.&lt;/P&gt;
&lt;P&gt;The scripts line looks like this:&lt;/P&gt;
&lt;P&gt;res = demisto.executeCommand('SearchIncidentsV2', {'query': query, 'limit': 5000})[0].get('Contents')&lt;/P&gt;
&lt;P&gt;It seems however the "Content" only contains 100 results even though it shows the right number of incidents&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="01.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52353i9F75E81F84159803/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="01.jpg" alt="01.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="02.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52354i8660986F4E7D2452/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="02.jpg" alt="02.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;To have access to the datas you have to add something like this too:&lt;/P&gt;
&lt;P&gt;inc_data = res[0].get('Contents').get('data')&lt;/P&gt;
&lt;P&gt;Still 100 results even with the limit higher&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I, however, found that not using "Contents" but "EntryContext" provides everything, the script lines are a little bit more complex:&lt;/P&gt;
&lt;P&gt;res = demisto.executeCommand('SearchIncidentsV2', {'query': query, 'limit': 5000})[0].get('EntryContext')&lt;/P&gt;
&lt;P&gt;inc_data = res.get('foundIncidents(val.id &amp;amp;&amp;amp; val.id == obj.id)'&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="03.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52355iD5CF51298C0BAD5A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="03.jpg" alt="03.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="04.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52356iD608A57DB9A6DF22/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="04.jpg" alt="04.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;This is not very clean.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only solution we have so far is by using GetIncidentsByQuery as below:&lt;/P&gt;
&lt;P&gt;res = json.loads(demisto.executeCommand('GetIncidentsByQuery', {'query': query, 'limit': 5000})[0].get('Contents'))&lt;/P&gt;
&lt;P&gt;This is working perfectly&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any better solution out there?&lt;/P&gt;
&lt;P&gt;In this specific case we want to get similar open incidents using "name" returning incidents ID and Labels.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks in advance.&lt;/P&gt;
&lt;P&gt;Sebastien&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jul 2023 09:40:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/using-searchincidentsv2-or-getincidentsbyquery-in-automations/m-p/551664#M2426</guid>
      <dc:creator>sdes</dc:creator>
      <dc:date>2023-07-29T09:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: Using SearchIncidentsV2 or GetIncidentsByQuery in automations</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/using-searchincidentsv2-or-getincidentsbyquery-in-automations/m-p/551740#M2428</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/306384"&gt;@sdes&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;If you check&amp;nbsp;&lt;SPAN&gt;SearchIncidentsV2 is also calling&amp;nbsp;GetIncidentsByQuery script and you already made it work with&amp;nbsp;GetIncidentsByQuery. We would advise to return only the required fields to save some resources. You can use populateFields option for this purpose. You can see the use of it below.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="python"&gt;populate_fields = ["id", "labels"]
res = demisto.executeCommand('GetIncidentsByQuery', {
        'incidentTypes': "Cortex XDR Incident",
        'populateFields': ' , '.join(populate_fields)
    })

if is_error(res):
   return_error(res)
incidents = json.loads(res[0]['Contents'])
demisto.results(incidents)&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;I hope this answers your question.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 09:49:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/using-searchincidentsv2-or-getincidentsbyquery-in-automations/m-p/551740#M2428</guid>
      <dc:creator>gyldz</dc:creator>
      <dc:date>2023-07-31T09:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: Using SearchIncidentsV2 or GetIncidentsByQuery in automations</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/using-searchincidentsv2-or-getincidentsbyquery-in-automations/m-p/551741#M2429</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/287891"&gt;@gyldz&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your swift reply. I suppose GetIncidentByQuery is the "go to" solution.&lt;/P&gt;
&lt;P&gt;I will take note of the improvements you suggested.&lt;/P&gt;
&lt;P&gt;Thanks again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Sebastien&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 10:04:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/using-searchincidentsv2-or-getincidentsbyquery-in-automations/m-p/551741#M2429</guid>
      <dc:creator>sdes</dc:creator>
      <dc:date>2023-07-31T10:04:47Z</dc:date>
    </item>
  </channel>
</rss>

