> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/incident-handling/understanding-the-incidents-page/incidents-table-view-reference-information.md).

# Incidents table view reference information

The following table describes the fields in the Incidents page table view.

| Field                                    | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Alert Categories                         | Alert categories that were triggered by the incident's alerts                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Alerts Grouping Status                   | Whether Alert Grouping is currently enabled                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Alerts Breakdown                         | Total number of alerts, broken down by severity                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Assignee Email                           | Email address of the incident assignee                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Assigned To                              | Incident assignee                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Creation Time                            | Date and time that the incident was created                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Critical/High/Medium/Low Severity Alerts | Number of critical, high, medium, or low severity alerts included in the incident                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Hosts                                    | Hosts affected by the incident                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Incident Description                     | Description generated from the alert name of the first alert that was added to the incident, the host and user affected, or number of users and hosts affected                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Incident ID                              | ID assigned to the incident                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Incident Name                            | User-defined incident name                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Incident Sources                         | List of sources that raised high and medium severity alerts in the incident                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Last Updated                             | Last time that a user took an action on the incident, or an alert was added to the incident                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| MITRE ATT\&CK Tactic                     | Types of MITRE ATT\&CK tactics that were triggered by the alerts in the incident                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| MITRE ATT\&CK Technique                  | Types of MITRE ATT\&CK techniques and sub-techniques that were triggered by the alerts in the incident                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Resolve Comment                          | User-added comment when setting the incident status to Resolved                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Resolved Timestamp                       | Date and time that the incident status was set to Resolved                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Severity                                 | Highest severity of the alerts in the incident, or the user-defined severity                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Starred                                  | <p>Whether the incident is starred.</p><p>Incidents are automatically starred if they include alerts that match your incident prioritization policy.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Status                                   | When incidents are generated they have the status set to **New**. To begin investigating an incident, set the status to **Under Investigation**. When the incident is resolved, set the status to **Resolved** and select a resolution reason. For a description of each resolution reason, see [Resolution reasons for incidents and alerts](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/incident-handling/manage-incidents/resolution-reasons-for-incidents-and-alerts.md).                                                                                                                                                                                                      |
| Tags                                     | <p>Tag family and the corresponding tags. If SBAC is enabled, you can view and manage the incident according your scope settings.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>When you view incidents as a scoped user and the tenant is set to <em>permissive</em> mode, you can view the incident but you do not have access to entities outside of your scope.</p><p>When you view incidents as a scoped user and the tenant is set to <em>restrictive</em> mode, the incident content is not visible. You can send the incident ID to your administrator and request an updated user scope that enables you to view the incident.</p></div> |
| Total Alerts                             | Total number of alerts in the incident                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Users                                    | Users affected by the alerts in the incident                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| WildFire Hits                            | Number of Malware, Phishing, and Grayware artifacts that are part of the incident                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/incident-handling/understanding-the-incidents-page/incidents-table-view-reference-information.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
