> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-investigation-actions/update-issue-fields.md).

# Update issue fields

You can update issue fields by running the `setIssue` and `setIssueStatus` commands in the CLI, in a script, or a playbook task.

* **`setIssue`:** Sets values for specific issue fields. The supported fields are presented in the list of arguments.

  #### Examples of the setIssue command in the CLI

  The following examples show how to run the `setIssue` command in the CLI. You can run CLI commands in the **War Room**. When you start typing the CLI provides the available options and if you select an enum field, the CLI provides the available values.

  * To change the issue severity to `high`, run

    ```programlisting
    !setIssue severity=high
    ```
  * To change the issue severity to `high` and star the issue, run

    ```programlisting
    !setIssue severity=high starred=true
    ```
* **`setIssueStatus`:** Sets the status or resolution value for an issue. This command supports the `status` argument, which presents a list of status and resolution type values. The selected status is set in the `custom_status` field.

  If you specify a resolution status, the issue is closed and the `resolution_status` and `closeReason` fields are updated to the same value as the `custom_status` field. If you specify a New, Reopened, or Under Investigation status, the issue remains open and the `resolution_status` and `closeReason` fields are empty.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Tip</p><p>You can create custom issue statuses and resolution reasons, and use the <code>setIssueStatus</code> command to set these custom statuses for issues.</p><p>For example, when a user starts investigating an issue, the issue status is automatically changed from <strong>New</strong> to <strong>Under Investigation</strong>. In some cases, it is useful to create an interim status, such as <strong>Triage</strong>. After you create the custom status, the new status will be available for selection. To create a custom status, follow the instructions in Create custom case statuses and resolution reasons.</p></div>

  #### Examples of using the setIssueStatus command in the CLI

  The following examples show how to run the `setIssueStatus` command in the CLI. You can run CLI commands in the **War Room**. When you start typing, the CLI provides the available options and if you select an enum field, the CLI provides the available values.

  * To change the issue status to `Resolved - Known Issue`, run

    ```programlisting
    !setIssueStatus status="Resolved - Known Issue"
    ```
  * To change the issue status to custom status `Triage`, run

    ```programlisting
    !setIssueStatus status=Triage
    ```

    <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Note</p><p>You must create a custom status before you can select it.</p></div>

  #### Example of using the setIssueStatus command in a playbook

  The following example shows how the `setIssueStatus` command can be used in a playbook task. In this example, the task sets a custom issue status (Triage). The custom issue status was created before setting up the playbook.

  ![setAlertStatus\_playbook\_example.png](/files/XfffHjucSOOEtJRrv7KX)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-investigation-actions/update-issue-fields.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
