> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management.md).

# Incident management

On the **Incidents** page, you can view all of the incidents in Cortex XSOAR and do the following:

{% hint style="info" %}

### Note

If you are unable to perform a specific action or view data, you may not have sufficient user role permissions. Contact your Cortex XSOAR administrator for more details.
{% endhint %}

| Action                                | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| ------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Search for incidents                  | <p>You can search for incidents by doing the following:</p><ul><li>Search query: The <strong>Incidents</strong> page displays all open incidents from the last 7 days by default. For more information about search queries and to create a query and save it for future use, see <a href="/pages/cWZd7PsRXpI4xGT2KUBk">Search for incidents</a>.</li><li>Search incidents globally using the search box. For more information, see <a href="/spaces/M6t3x619iLxkOSWNFxz0/pages/cWZd7PsRXpI4xGT2KUBk#use-the-search-box">Use the search box</a>.</li></ul> |
| Filter incidents using the Bar Charts | <p>Bar charts display important incident information, such as the incident type, severity, and owner. You can change the criteria in each bar chart.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Incidents sorted using an SLA/Timer field are sorted by the due date of the SLA field.</p></div>                                                                                                                                                                                 |
| Create a new incident                 | Create an incident manually. For more information, see [Create an incident](/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/create-an-incident.md).                                                                                                                                                                                                                                                                                                                             |
| Create a widget                       | Create a widget based on the search criteria and add it to a dashboard or report. For more information, see [Create a widget from an incident](/cortex-xsoar-8-on-prem/8.10/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-from-an-incident.md).                                                                                                                                                                                                                                                                                    |

{% hint style="info" %}

### Note

You can change how the top half of the incident page appears by hiding the chart panel, query panel, and switching to a detailed view.
{% endhint %}

#### Manage incidents from the incidents table

In the incidents table, view general information about each incident, such as the type, the severity, and when it occurred. The status of the incident is classified as follows:

| Status  | Description                                                                                                                             |
| ------- | --------------------------------------------------------------------------------------------------------------------------------------- |
| Active  | The investigation has started. The War Room is activated, and the playbook starts, if assigned. Users can be assigned to this incident. |
| Pending | The investigation has not started, and no War Room has been activated. As soon as you open the incident, it becomes active.             |
| Closed  | The investigation has been closed.                                                                                                      |

Incidents can be assigned a severity at incident creation when running a playbook, or after creation through the CLI or in the incident layout. Incident severity levels are:

* Critical (4)
* High (3)
* Medium (2)
* Low (1)
* Informational (0.5)
* Unknown (0)

You can do the following actions:

| Action                  | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ----------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Investigate an incident | View, investigate, and take remedial action on the incident by clicking the incident **ID** hyperlink. For more information, see [Investigate an incident](/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Assign                  | Assign incidents to any user who has been added to Cortex XSOAR, including users who are marked as away. You can assign users to many incidents at one time.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Edit                    | <p>Edit the incident parameters and then rerun a playbook on the incident, which is useful while developing playbooks. You can process an incident multiple times during playbook development, without creating new incidents every time.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>When batch editing multiple incidents, uploading files is currently not supported.</p></div>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Mark as Duplicate       | <p>Deduplicate an incident. Closing an incident as a duplicate enables you to investigate one rather than multiple incidents. When selected, you need to add the ID you want to retain. When validated, and the other is closed as a duplicate, the duplicated incident is removed from the table.</p><p>If you want to link an incident with or without closing, you can use the <code>!linkIncidents</code> command. For more information, see <a href="/pages/4YwFq9Z9OEpa9hyAtCrO">Link incidents</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Run Command             | You can select multiple incidents and run a command across all of them.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Retention               | You can mark multiple incidents for permanent retention, including incidents that have been deleted manually, or by API call.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Export                  | Export incidents to an Excel or a CSV file. For more information, see [Export incidents](/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management/export-incidents.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Close                   | <p>You can select multiple incidents and close all of them. If required, add the close reason and details. The investigation will be closed.</p><p>When you close an incident, the close reason is set to whatever value you last entered. For example, when closing an incident, if you initially selected <strong>False Positive</strong> as the <strong>Close Reason</strong>, reopened it, and closed it again, leaving the <strong>Close Reason</strong> empty, the empty <strong>Close Reason</strong> will overwrite the previous <strong>Close Reason</strong>. To keep the close reason that was entered previously on the incident, add the previous value in the <strong>Close Reason</strong> argument.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>The close reasons are customizable by server configurations. Provided you have administrator permission, you can change the reasons. For more information, see <a href="/pages/gcEVBybbljC2siZlchDR">Customize incident close reasons</a>.</p></div><p>You can also close the incident when investigating the incident.</p> |
| Delete                  | <p>You can select multiple incidents and delete all of them.</p><p>You can also delete the incident when investigating the incident.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Star an incident        | To help you focus on the most important incidents, you can mark an incident as a favorite. Starring incidents enables you to narrow down the scope of incidents on the **Incidents** page. Incidents remain in your favorites until they are closed or you manually change the starred status.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |

{% hint style="info" %}

### Tip

Any incidents assigned to yourself, starred incidents, and incidents you are participating in can easily be accessed in the **My Incidents** section.
{% endhint %}

#### Further information

To see how to manage incidents, watch the following video in Live Community:

[Working an Incident](https://live.paloaltonetworks.com/t5/cortex-xsoar-how-to-videos/cortex-xsoar-8-analyst-training-part-2-working-an-incident/ta-p/577388)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.10/investigate-and-respond-to-threats/incidents-and-indicators-investigation/incident-management.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
