<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XSOAR Incident Workflow implementation in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-incident-workflow-implementation/m-p/560571#M2691</link>
    <description>&lt;P&gt;You might want to consider using a post processing script. The example in the docs (required fields to close incident) sounds similar to your needs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Administrator-Guide/Create-a-Post-Processing-Script" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Administrator-Guide/Create-a-Post-Processing-Script&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Oct 2023 18:08:22 GMT</pubDate>
    <dc:creator>NMasse</dc:creator>
    <dc:date>2023-10-04T18:08:22Z</dc:date>
    <item>
      <title>XSOAR Incident Workflow implementation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-incident-workflow-implementation/m-p/560332#M2675</link>
      <description>&lt;P&gt;hi,&lt;BR /&gt;is there a possibility in xsoar to prevent an incident from being closed if certain conditions are not met? I would like to implement in incident workflow where one part is executed automatically and the other by the analyst, then if certain fields are not valorised prevent the closure of the incident.&lt;BR /&gt;Thank you very much&lt;BR /&gt;regards&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 08:03:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-incident-workflow-implementation/m-p/560332#M2675</guid>
      <dc:creator>FrancescoBarducci</dc:creator>
      <dc:date>2023-10-03T08:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR Incident Workflow implementation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-incident-workflow-implementation/m-p/560361#M2680</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/318526"&gt;@FrancescoBarducci&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This would be possible by adding a conditional task at the very end of the playbook. The conditional task can have two conditions:&lt;/P&gt;
&lt;P&gt;1. A condition that will be used to automate the closure of the incident automatically by adding a standard task using the "closeinvestigation" automation for this branch.&lt;/P&gt;
&lt;P&gt;2. The condition that will be used for a manual incident closure.&amp;nbsp; A standard tasks can be added to this branch (with not automation) that can include details of the manual review that needs to be performed and details explaining that the incident will need to be closed manually.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 13:57:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-incident-workflow-implementation/m-p/560361#M2680</guid>
      <dc:creator>albmartinez</dc:creator>
      <dc:date>2023-10-03T13:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR Incident Workflow implementation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-incident-workflow-implementation/m-p/560489#M2688</link>
      <description>&lt;P&gt;hello,&lt;BR /&gt;I tried but could not implement the functionality in the way I would like.&lt;BR /&gt;Basically, what I would like to implement is a sort of control as happens in ticketing platforms, i.e. if the analyst for example, in the Incidents tab, selects one or more incidents and clicks on "Close", at the moment he is able to close them while I would like it not to be possible to do so in the absence of certain fields valued within the incident. Is it possible to implement this type of control?&lt;BR /&gt;Thank you very much&lt;BR /&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2023 08:38:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-incident-workflow-implementation/m-p/560489#M2688</guid>
      <dc:creator>FrancescoBarducci</dc:creator>
      <dc:date>2023-10-04T08:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR Incident Workflow implementation</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-incident-workflow-implementation/m-p/560571#M2691</link>
      <description>&lt;P&gt;You might want to consider using a post processing script. The example in the docs (required fields to close incident) sounds similar to your needs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Administrator-Guide/Create-a-Post-Processing-Script" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Administrator-Guide/Create-a-Post-Processing-Script&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2023 18:08:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-incident-workflow-implementation/m-p/560571#M2691</guid>
      <dc:creator>NMasse</dc:creator>
      <dc:date>2023-10-04T18:08:22Z</dc:date>
    </item>
  </channel>
</rss>

