<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unclassified incident management: incidents remain in active status in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/unclassified-incident-management-incidents-remain-in-active/m-p/1233024#M4093</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/282687"&gt;@CMarletta Livi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Firstly it is recommended to work with a more recent version of XSOAR, 6.8 is pretty legacy. In regards to your question;&lt;/P&gt;
&lt;P&gt;On the Incident Type settings you can mark the "Run Playbook Automatically" checkbox and for all new incidents created the playbook will run automatically.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See the picture below for the checkbox. Ensure you have a playbook attached to this type and that the incidents are being opened as expected. If this setting is &lt;U&gt;not&lt;/U&gt; checked the incidents are opened in a "pending" status (white/grey clickable incident ID on the Incidents Page). I didn't fully understand what you meant by "&lt;SPAN&gt;The problem involves an overload of active workers and consequently the blocking of the management of all incidents.&lt;/SPAN&gt;". Perhaps you are creating too many incidents too quickly. There is an operational limit regarding this.&lt;/P&gt;
&lt;P&gt;Let me know if this helps.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks,&lt;/P&gt;
&lt;P&gt;MichaelSysec&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="michaelsysec242_0-1751456965471.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68271i3279BA226C3E215E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="michaelsysec242_0-1751456965471.png" alt="michaelsysec242_0-1751456965471.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Jul 2025 11:50:50 GMT</pubDate>
    <dc:creator>michaelsysec242</dc:creator>
    <dc:date>2025-07-02T11:50:50Z</dc:date>
    <item>
      <title>Unclassified incident management: incidents remain in active status</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/unclassified-incident-management-incidents-remain-in-active/m-p/1233021#M4092</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in XSOAR 6.8 I created a custom incident type to automatically handle the closure of unclassified incidents. In 'Incidents Classification Editor' I set this type to 'Direct unclassified events to:'. The type is correctly associated with the unclassified incidents and also the playbook but the playbook is not automatically executed and the incident remains in Active state. Why?&amp;nbsp;How can I solve it? The problem involves an overload of active workers and consequently the blocking of the management of all incidents.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 09:44:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/unclassified-incident-management-incidents-remain-in-active/m-p/1233021#M4092</guid>
      <dc:creator>CMarletta Livi</dc:creator>
      <dc:date>2025-07-02T09:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: Unclassified incident management: incidents remain in active status</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/unclassified-incident-management-incidents-remain-in-active/m-p/1233024#M4093</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/282687"&gt;@CMarletta Livi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Firstly it is recommended to work with a more recent version of XSOAR, 6.8 is pretty legacy. In regards to your question;&lt;/P&gt;
&lt;P&gt;On the Incident Type settings you can mark the "Run Playbook Automatically" checkbox and for all new incidents created the playbook will run automatically.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See the picture below for the checkbox. Ensure you have a playbook attached to this type and that the incidents are being opened as expected. If this setting is &lt;U&gt;not&lt;/U&gt; checked the incidents are opened in a "pending" status (white/grey clickable incident ID on the Incidents Page). I didn't fully understand what you meant by "&lt;SPAN&gt;The problem involves an overload of active workers and consequently the blocking of the management of all incidents.&lt;/SPAN&gt;". Perhaps you are creating too many incidents too quickly. There is an operational limit regarding this.&lt;/P&gt;
&lt;P&gt;Let me know if this helps.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks,&lt;/P&gt;
&lt;P&gt;MichaelSysec&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="michaelsysec242_0-1751456965471.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68271i3279BA226C3E215E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="michaelsysec242_0-1751456965471.png" alt="michaelsysec242_0-1751456965471.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 11:50:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/unclassified-incident-management-incidents-remain-in-active/m-p/1233024#M4093</guid>
      <dc:creator>michaelsysec242</dc:creator>
      <dc:date>2025-07-02T11:50:50Z</dc:date>
    </item>
  </channel>
</rss>

