<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Update an incident via API XSOAR in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/update-an-incident-via-api-xsoar/m-p/420446#M271</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need help about How get via API an incident update. I don't see this option (sorry), I can set a new incident but I don't update an incident. This way must be API, I use this route "/incident".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you help me, plase?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Mon, 19 Jul 2021 17:39:34 GMT</pubDate>
    <dc:creator>sanaya</dc:creator>
    <dc:date>2021-07-19T17:39:34Z</dc:date>
    <item>
      <title>Update an incident via API XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/update-an-incident-via-api-xsoar/m-p/420446#M271</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need help about How get via API an incident update. I don't see this option (sorry), I can set a new incident but I don't update an incident. This way must be API, I use this route "/incident".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you help me, plase?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 17:39:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/update-an-incident-via-api-xsoar/m-p/420446#M271</guid>
      <dc:creator>sanaya</dc:creator>
      <dc:date>2021-07-19T17:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: Update an incident via API XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/update-an-incident-via-api-xsoar/m-p/423572#M290</link>
      <description>&lt;P&gt;Sanaya,&lt;/P&gt;&lt;P&gt;&amp;nbsp;To learn more about XSOAR's API endpoints, you can download the &lt;EM&gt;&lt;STRONG&gt;Cortex XSOAR API Guide&lt;/STRONG&gt;&lt;/EM&gt; right from XSOAR itself: &lt;EM&gt;Settings &amp;gt; Integrations &amp;gt; API Keys &amp;gt; Download Cortex XSOAR API Guide&lt;/EM&gt; (also see the screenshot below).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An alternative method for determining the API endpoint and POST body syntax would be to make the desired request in a browser and use its 'Developer Tools' to view the request (see screenshot below for an example)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if this answers your question.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="atullo_0-1627678715044.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35380iAAADCBD5501500D5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="atullo_0-1627678715044.png" alt="atullo_0-1627678715044.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="atullo_1-1627680612200.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35382i4AF4B29DFC41EA73/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="atullo_1-1627680612200.png" alt="atullo_1-1627680612200.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 21:32:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/update-an-incident-via-api-xsoar/m-p/423572#M290</guid>
      <dc:creator>atullo</dc:creator>
      <dc:date>2021-07-30T21:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: Update an incident via API XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/update-an-incident-via-api-xsoar/m-p/436038#M361</link>
      <description>&lt;P&gt;This answer is insufficient. The poster asked for the API endpoint that can be used to update an incident. That information is not provided anywhere in the reply. Instead, the responder refers the poster to the&amp;nbsp;Cortex XSOAR API Guide which, while being quite lengthy, lacks far more helpful information than it provides. For instance, every definition example in that guide (except for numerical and boolean values, which really don't need examples) is completely useless.&lt;/P&gt;&lt;P&gt;A better solution reply would identify the endpoint and provide a detailed example of a typical request message body that modifies an incident's required, optional, and custom fields. Bonus points for some explanations on how to avoid common "bad request" errors for that endpoint.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 23:32:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/update-an-incident-via-api-xsoar/m-p/436038#M361</guid>
      <dc:creator>Snader</dc:creator>
      <dc:date>2021-09-22T23:32:48Z</dc:date>
    </item>
    <item>
      <title>Re: Update an incident via API XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/update-an-incident-via-api-xsoar/m-p/436126#M363</link>
      <description>&lt;P&gt;Use the endpoint "&lt;STRONG&gt;/incident&lt;/STRONG&gt;" with &lt;STRONG&gt;POST&lt;/STRONG&gt; data. There are some details that are worth going through though:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The POST data must contain &lt;STRONG&gt;all&lt;/STRONG&gt;&amp;nbsp;the investigation data. If you do not provide the field data for a specific field, it will be wiped from the investigation.&lt;/LI&gt;&lt;LI&gt;You must match up the "version" at which the current incident is at.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To satisfy the above, the easiest method would be:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Use the "/investigation/&lt;STRONG&gt;&amp;lt;incident-id&amp;gt;&lt;/STRONG&gt;" in a POST request to obtain the latest information of the investigation&lt;OL&gt;&lt;LI&gt;This requires the headers to include the API token in the "Authorization" key and "Content-Type" to be "application/json"&lt;/LI&gt;&lt;LI&gt;This will return a JSON of the current state of the investigation. You make changes to this JSON data.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Send the changed JSON data back using the POST method to the "&lt;STRONG&gt;/incident&lt;/STRONG&gt;" endpoint&lt;OL&gt;&lt;LI&gt;Use the modified JSON in the payload&lt;/LI&gt;&lt;LI&gt;Headers are the same as the previous POST request&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The result should be instant.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reasoning behind the "version" match is that changes should be made to latest version of the incident to prevent race-conditions. If you specify a version number that is not the latest (i.e. someone else made a change just before you did) then the call will fail with the error:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;{
    "id": "errOptimisticLock",
    "status": 400,
    "title": "Optimistic lock error",
    "detail": "Optimistic lock error",
    "error": "DB Version '4' and Insert version '10' do not match for id: 97 on bucket [] [incidents] (15)",
    "encrypted": false,
    "multires": null
}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;The DB version will show which version you sent the change for and the version that the incident is currently at.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;I hope this helps.&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 23 Sep 2021 12:11:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/update-an-incident-via-api-xsoar/m-p/436126#M363</guid>
      <dc:creator>ABurt</dc:creator>
      <dc:date>2021-09-23T12:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: Update an incident via API XSOAR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/update-an-incident-via-api-xsoar/m-p/436414#M364</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/128606"&gt;@sanaya&lt;/a&gt;&amp;nbsp;Please let me know if this helps in your situation.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2021 09:44:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/update-an-incident-via-api-xsoar/m-p/436414#M364</guid>
      <dc:creator>ABurt</dc:creator>
      <dc:date>2021-09-24T09:44:24Z</dc:date>
    </item>
  </channel>
</rss>

