<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Auto Incidnet closure in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/auto-incidnet-closure/m-p/567540#M2867</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/337895"&gt;@Mohamad_1221&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can run a job with 2 tasks. The first one will be SearchIncidentsV2 or SearchIncidentsSummary where you can define a query for the incidents to be closed. The output of those tasks might be huge, you can use ExtendContext and ignore the output option.ExtendContext would be something like&amp;nbsp;FoundIncidents=Contents.data={"name":&amp;nbsp;val.name, "id":&amp;nbsp;val.id}. As a second task you can use closeInvestigation automation and define&amp;nbsp;&lt;STRONG&gt;id&amp;nbsp;&lt;/STRONG&gt;field as a ${FoundIncidents.id} and other fields like close reason.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this solves your problem.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 29 Nov 2023 09:51:40 GMT</pubDate>
    <dc:creator>gyldz</dc:creator>
    <dc:date>2023-11-29T09:51:40Z</dc:date>
    <item>
      <title>Auto Incidnet closure</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/auto-incidnet-closure/m-p/567154#M2864</link>
      <description>&lt;P&gt;Dear Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm looking for a way to daily automatically close all incidents with specific criteria.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to archive that using jobs , I'm trying to create a playbook the query incidents (with specific criteria) and whatever the query outcome I need to close those incidents.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any suggestions on achieving that , I'm open for all suggestion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 07:50:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/auto-incidnet-closure/m-p/567154#M2864</guid>
      <dc:creator>Mohamad_1221</dc:creator>
      <dc:date>2023-11-27T07:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Incidnet closure</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/auto-incidnet-closure/m-p/567540#M2867</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/337895"&gt;@Mohamad_1221&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can run a job with 2 tasks. The first one will be SearchIncidentsV2 or SearchIncidentsSummary where you can define a query for the incidents to be closed. The output of those tasks might be huge, you can use ExtendContext and ignore the output option.ExtendContext would be something like&amp;nbsp;FoundIncidents=Contents.data={"name":&amp;nbsp;val.name, "id":&amp;nbsp;val.id}. As a second task you can use closeInvestigation automation and define&amp;nbsp;&lt;STRONG&gt;id&amp;nbsp;&lt;/STRONG&gt;field as a ${FoundIncidents.id} and other fields like close reason.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this solves your problem.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 09:51:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/auto-incidnet-closure/m-p/567540#M2867</guid>
      <dc:creator>gyldz</dc:creator>
      <dc:date>2023-11-29T09:51:40Z</dc:date>
    </item>
  </channel>
</rss>

