<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XSOAR Trigger off reopen incident / close incident in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-trigger-off-reopen-incident-close-incident/m-p/462735#M527</link>
    <description>&lt;P&gt;Hi Boyd,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the incident is re-opened the Close Reason and Close Notes retain their values. Depending on how the incident is then closed again, may wipe the values. If you are using the Close Form, the Close Reason and Close Notes are requested. If they are removed from the form the values are set to None and these are saved when the incident is then re-closed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The best method to set these values (if they are not presented during a close form) is to use a script that has the tag "post-processing". This script (when assigned to your incident type) can then copy out the Close Reason and Close Notes from other fields and set as required.&lt;/P&gt;</description>
    <pubDate>Wed, 02 Feb 2022 09:21:35 GMT</pubDate>
    <dc:creator>ABurt</dc:creator>
    <dc:date>2022-02-02T09:21:35Z</dc:date>
    <item>
      <title>XSOAR Trigger off reopen incident / close incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-trigger-off-reopen-incident-close-incident/m-p/462651#M526</link>
      <description>&lt;P&gt;Onboarding to a new company.&lt;BR /&gt;No post processing on incident type (azure sentinel).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;When a ticket is closed on the close form, we have a custom "Azure Closure Reason" and "Classification Comment"; based on this we have a script(CloseSentinelCase) that triggers when "Azure Closure Reason" is modified.&amp;nbsp; This script sets the "Close Reason" based on the logic to "Resolved" for example.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When a ticket is reopened, the "Close Reason" is not reset, it stays "Resolved", but Active; This confuses me, if there any logic we can hang off of when a ticket is reopened to execute scripts?&amp;nbsp; What happens to an inicident when a ticket is "reopened".&amp;nbsp; I can't find any detailed documentation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Furthermore when the ticket is then re-closed, the "Close Reason" is then wiped, and is blanked out&amp;nbsp; Note, the Azure Closure Reason is not modified so the trigger script from earlier is not called.&amp;nbsp; I can not figure out what is wiping the "Close Reason".&amp;nbsp; I also can't find any documentation on the close form/close incident button to show what detailed steps are happenning.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trying to figure out specifically what's happening during re-open and close incident.&amp;nbsp; Is there any logs I can look at that spell it out.&amp;nbsp; I tried some of the server.logs but they weren't very easy to read.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help is greatly appreciated -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Boyd&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 02:06:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-trigger-off-reopen-incident-close-incident/m-p/462651#M526</guid>
      <dc:creator>jboyd98</dc:creator>
      <dc:date>2022-02-02T02:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR Trigger off reopen incident / close incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-trigger-off-reopen-incident-close-incident/m-p/462735#M527</link>
      <description>&lt;P&gt;Hi Boyd,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the incident is re-opened the Close Reason and Close Notes retain their values. Depending on how the incident is then closed again, may wipe the values. If you are using the Close Form, the Close Reason and Close Notes are requested. If they are removed from the form the values are set to None and these are saved when the incident is then re-closed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The best method to set these values (if they are not presented during a close form) is to use a script that has the tag "post-processing". This script (when assigned to your incident type) can then copy out the Close Reason and Close Notes from other fields and set as required.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 09:21:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-trigger-off-reopen-incident-close-incident/m-p/462735#M527</guid>
      <dc:creator>ABurt</dc:creator>
      <dc:date>2022-02-02T09:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR Trigger off reopen incident / close incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-trigger-off-reopen-incident-close-incident/m-p/462832#M528</link>
      <description>&lt;P&gt;Thanks Burt, working on this this morning; appreciate the response.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 15:48:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-trigger-off-reopen-incident-close-incident/m-p/462832#M528</guid>
      <dc:creator>jboyd98</dc:creator>
      <dc:date>2022-02-02T15:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR Trigger off reopen incident / close incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-trigger-off-reopen-incident-close-incident/m-p/462846#M529</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/169171"&gt;@ABurt&lt;/a&gt;,&lt;BR /&gt;I created the following post processing script:&lt;/P&gt;&lt;P&gt;------&lt;BR /&gt;closeReason = demisto.incidents()[0]["closeReason"]&lt;/P&gt;&lt;P&gt;if closeReason:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;return_results(closeReason)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;return_results("Close Reason is already set and will be re-set during this post processing")&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;demisto.executeCommand('setIncident', {'closeReason': closeReason})&lt;BR /&gt;&lt;BR /&gt;-----&lt;BR /&gt;&lt;BR /&gt;I can see if i run the script in war room while the tickets open and "Close Reason" is previously set, it returns the value and also returns a message sharing that it's already set.&amp;nbsp; It looks like the script itself is a success.&amp;nbsp; However, when I close the ticket, the end result is the "Close Reason" is blanked out again.&lt;BR /&gt;&lt;BR /&gt;Question 1.&amp;nbsp; Will post processing log out to war room; I was hoping i could see my return_results to confirm the steps,but I just see a line that shows post-processing scripts are running.&lt;BR /&gt;&lt;BR /&gt;Question 2.&amp;nbsp; How can I identify what might be happening after the "Close Incident" is clicked on the Close Form?&amp;nbsp; I looked at my fields/buttons and sorted by the column to show triggers; nothing seems to stand out.&amp;nbsp; For the incident type there is no post processing, other than what I just added.&lt;BR /&gt;&lt;BR /&gt;Any additional insight is appreciated, thanks again&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 16:33:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-trigger-off-reopen-incident-close-incident/m-p/462846#M529</guid>
      <dc:creator>jboyd98</dc:creator>
      <dc:date>2022-02-02T16:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR Trigger off reopen incident / close incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-trigger-off-reopen-incident-close-incident/m-p/462991#M531</link>
      <description>&lt;P&gt;Hello again,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By far the shortest path to a solution would be to use the "Azure Closure Reason" and "Classification Comment" in your reporting and not rely on the "Close Notes" or "Close Reason" fields at all. If you really have to use them, please read on...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem here, it seems, is that the incident (when closed) will have already accepted the values for Close Reason and Close Notes regardless of what is in the post-processing script. i.e. They cannot be set by the post-processing script. All other fields seem to be able to be set by the script. I am unsure whether this is a bug or by design.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The workaround (although a little long) is to not let the incident be closed by using the Actions -&amp;gt; Close Incident button but by providing your own button that closes the incident. So as a step by step (as an example):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1). Set the incident type to have a post processing script and use something similar to the below:&lt;/P&gt;&lt;LI-CODE lang="python"&gt;args = demisto.args()
incident = demisto.incident()
close_reason = incident.get('closeReason')
close_notes = incident.get('closeNotes')

if not close_reason or not close_notes:
    return_error("Please do not close this incident manually. Use the button provided in the 'Case Closure' tab")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2). Edit the layout of the incident and under the "Close" form settings, remove all fields and sections (this prevents the user manually adding Close Notes and Close Reason that do not match up with the Azure Closure Reason and Classification Comment)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3). Add a new tab called "Case Closure" in the incident layout.&lt;/P&gt;&lt;P&gt;4). Add a section and place a the "Azure Closure Reason" and "Classification Comment" fields. Ensure the tab has the "show empty fields" set too.&lt;/P&gt;&lt;P&gt;5). Set the script of the button to be something similar to:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;incident = demisto.incident()
incident_id = incident.get('id')
custom_fields = incident.get('CustomFields')
azure_close_reason = custom_fields.get('azureclosurereason')
classification_comment = custom_fields.get('classificationcomment')


if not azure_close_reason and not classification_comment:
    return_error("Please ensure you fill out the Azure Closure Reason and Classification Comment")
elif not azure_close_reason:
    return_error("Please ensure you fill out the Azure Closure Reason")
elif not classification_comment:
    return_error("Please ensure you fill out the Classification Comment")
else:
    demisto.executeCommand('closeInvestigation', {'closeReason': azure_close_reason, 'closeNotes': classification_comment})&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;6). The script will then close the incident if the Azure Closure Reason and Classification Comment have already been populated. It will copy these values into the Close Reason and Close Notes of the incident during closure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;7). Finally, assign a "field-change-triggered" script to both the "Azure Closure Reason" and "Classification Comment" fields that has something like the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;args = demisto.args()

field = args.get('cliName')
value = args.get('new')

if field == "azureclosurereason":
    demisto.executeCommand('setIncident', {'closeReason': value})
if field == "classificationcomment":
    demisto.executeCommand('setIncident', {'closeNotes': value})&lt;/LI-CODE&gt;&lt;P&gt;This sets the Close Reason and Close Notes based on those fields.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the above, this is what happens when a user attempt to click the Actions-&amp;gt;Close Incident:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ABurt_0-1643888346786.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38957iD976D12AE807F84A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ABurt_0-1643888346786.png" alt="ABurt_0-1643888346786.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;They then have to populate the fields before using the button:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ABurt_1-1643888403512.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38958i494D1A51F1D8F389/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ABurt_1-1643888403512.png" alt="ABurt_1-1643888403512.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once they are populated, and the button is clicked, it will copy the values into the Close information.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 12:08:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-trigger-off-reopen-incident-close-incident/m-p/462991#M531</guid>
      <dc:creator>ABurt</dc:creator>
      <dc:date>2022-02-03T12:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR Trigger off reopen incident / close incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-trigger-off-reopen-incident-close-incident/m-p/463281#M534</link>
      <description>&lt;P&gt;Thanks again&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/169171"&gt;@ABurt&lt;/a&gt;, exploring this as an option.&amp;nbsp; Will circle back and let you know the outcome.&amp;nbsp; Appreciate the help.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 22:30:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-trigger-off-reopen-incident-close-incident/m-p/463281#M534</guid>
      <dc:creator>jboyd98</dc:creator>
      <dc:date>2022-02-03T22:30:47Z</dc:date>
    </item>
  </channel>
</rss>

