Search in XSOAR for Timers (active incidents)

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Search in XSOAR for Timers (active incidents)

L0 Member

Hi all
I would like to search in Cortex XSOAR for running timers that exceed a certain time. I tried it but it didn't worked out.
It should work like this that I can search for an timer (in this case detectionsla the total duration) and afterwards it should show all INC that are still running (active) where the decetion sla is over 16 hours

Bildschirmfoto 2022-02-19 um 12.27.02.png

While running the above described search I don't get any result. But there are running Incidents that are over these 16 hours. 

Bildschirmfoto 2022-02-19 um 12.32.04.png

If anyone can help I would really appreciate it.
Thank you


L3 Networker

When querying incidents by the total duration of the timer you should use a number of the total seconds, in this case 57,600 seconds,
"ago" would make sense for for a field that holds a specific date, like incidents creation date, but a duration cannot be X time ago.
You can try searching by the timer's dueDate field,
more for example please review:


  • 1 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!