<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Transitioning Events/Incidents Across Analysts in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/transitioning-events-incidents-across-analysts/m-p/588453#M3357</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/139011807"&gt;@Mcballew&lt;/a&gt;&amp;nbsp;, I think this is a complicated question. It depends on the level of maturity of your automation journey.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Simple&lt;/STRONG&gt;: Modify incident&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;owner&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to new analyst. You can also invite the analyst to join the incident by adding a warroom entry like &lt;CODE&gt;"@user This is why the incident was assigned to you"&lt;/CODE&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Moderate&lt;/STRONG&gt;: There are multiple choices available. The below steps will also add entries to the user&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;My Task&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;dashboard.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; - Assign a workplan task to an analyst&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; - Create an ad-hoc task assigned to the new analyst&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; - If you've implemented a queuing system. You can choose to remove yourself as the incident&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;owner&lt;/STRONG&gt;. Change the incident&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;role&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to the new analyst's role (ex "IR L2"). The incident will then show in their queue which will then be picked up by the next available analyst.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- We also have an automation called &lt;CODE&gt;!AssignAnalystToIncident&lt;/CODE&gt; which can be used if the new analyst should be chosen based on some logic like online only, least workload or special SME (machine learning).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Complex&lt;/STRONG&gt;: We have a shift management pack that includes a more involved process of analysts creating shift handover incidents. The process is detailed here -&amp;nbsp;&lt;A href="https://xsoar.pan.dev/docs/reference/packs/Shift_management" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/packs/Shift_management&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Depending on your use case you might consider a combination of the above recommendations. I hope you find this helpful.&lt;/P&gt;</description>
    <pubDate>Fri, 31 May 2024 04:53:21 GMT</pubDate>
    <dc:creator>jfernandes1</dc:creator>
    <dc:date>2024-05-31T04:53:21Z</dc:date>
    <item>
      <title>Transitioning Events/Incidents Across Analysts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/transitioning-events-incidents-across-analysts/m-p/588250#M3353</link>
      <description>&lt;P&gt;Does anyone mind sharing any resources or practical examples of how they're using XSOAR to transition events/incidents across multiple analysts or shifts?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2024 11:01:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/transitioning-events-incidents-across-analysts/m-p/588250#M3353</guid>
      <dc:creator>Mcballew</dc:creator>
      <dc:date>2024-05-29T11:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Transitioning Events/Incidents Across Analysts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/transitioning-events-incidents-across-analysts/m-p/588453#M3357</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/139011807"&gt;@Mcballew&lt;/a&gt;&amp;nbsp;, I think this is a complicated question. It depends on the level of maturity of your automation journey.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Simple&lt;/STRONG&gt;: Modify incident&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;owner&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to new analyst. You can also invite the analyst to join the incident by adding a warroom entry like &lt;CODE&gt;"@user This is why the incident was assigned to you"&lt;/CODE&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Moderate&lt;/STRONG&gt;: There are multiple choices available. The below steps will also add entries to the user&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;My Task&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;dashboard.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; - Assign a workplan task to an analyst&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; - Create an ad-hoc task assigned to the new analyst&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; - If you've implemented a queuing system. You can choose to remove yourself as the incident&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;owner&lt;/STRONG&gt;. Change the incident&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;role&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to the new analyst's role (ex "IR L2"). The incident will then show in their queue which will then be picked up by the next available analyst.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- We also have an automation called &lt;CODE&gt;!AssignAnalystToIncident&lt;/CODE&gt; which can be used if the new analyst should be chosen based on some logic like online only, least workload or special SME (machine learning).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Complex&lt;/STRONG&gt;: We have a shift management pack that includes a more involved process of analysts creating shift handover incidents. The process is detailed here -&amp;nbsp;&lt;A href="https://xsoar.pan.dev/docs/reference/packs/Shift_management" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/packs/Shift_management&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Depending on your use case you might consider a combination of the above recommendations. I hope you find this helpful.&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 04:53:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/transitioning-events-incidents-across-analysts/m-p/588453#M3357</guid>
      <dc:creator>jfernandes1</dc:creator>
      <dc:date>2024-05-31T04:53:21Z</dc:date>
    </item>
  </channel>
</rss>

