> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident.md).

# Investigate an incident

You can open an incident investigation:

* Automatically: If associated with a playbook, incidents open automatically for investigation and run the associated playbook.
* Manually: Open an incident manually by selecting the incident in the Incidents table.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>If the incident <strong>ID</strong> hyperlink is unavailable, the incident was closed before the investigation started, usually through a preprocess rule or it was already closed when fetched. If you want to see the incident details, click the <strong>Switch to detailed view</strong> icon at the top of the incidents page.</p><p><img src="/files/X2XR7GKSKI9Qc7FTpbx5" alt="switch-to-detailed-view.png" data-size="original"></p><p>After an incident is created, it is assigned a <strong>Pending</strong> status. When you start to investigate an incident the status changes automatically to <strong>Active</strong>, which starts the remediation process.</p></div>
* In the CLI: If you want to open an incident in the CLI, type **`/investigate id=`*****`<incidentID#>`***.

You can limit access to investigations and restrict investigations according to your requirements, as described in [Limit access to investigations using access control](/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/limit-access-to-investigations-using-access-control.md).

{% hint style="info" %}

### Note

If you cannot perform a specific action or view data, you may not have sufficient user role permissions. Contact your Cortex XSOAR for more details.
{% endhint %}

<details>

<summary>Start the investigation</summary>

When you open an incident, you can see various tabs that assist you in the investigation. The following tabs are common to most incident types:

{% hint style="info" %}

### Note

Tabs, tab names, sections, and fields vary according to the incident layout.

In an investigation, images from external links don't appear, as they are restricted due to security issues. To use an image, either upload the image using base64 or upload it using markdown in the War Room.
{% endhint %}

| Tab            | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| -------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Case Info      | <p>A summary of the incident, such as case details, outstanding tasks, linked incidents, and evidence. Some fields are informational and some are editable. Includes the following sections (depending on the layout):</p><ul><li><strong>CASE DETAILS</strong>: A summary of the incident, such as type, severity, and when the incident occurred. Update these fields as required.</li><li><p><strong>WORK PLAN</strong> When you click on the section, you can view or take action on the following:</p><ul><li><strong>Playbook tasks</strong>: When a playbook runs, any outstanding tasks appear. You can take various actions here or in the <strong>Work Plan</strong> tab.</li><li><p><strong>To-Do Tasks</strong> View or create To-Do tasks.</p><p>You can also create To-Do Tasks from the <strong>Actions</strong> tab. See <a href="/pages/IYolQgyjUib4Nc1142CY">Incident Tasks</a>.</p></li></ul></li><li><p><strong>NOTES</strong>: If added to the layout, notes help you understand specific actions taken, and allow you to view conversations between analysts to see how they arrived at a certain decision. You can see the thought process behind identifying key evidence and identifying similar incidents.</p><p>You can add notes in this section or in the War Room. Notes are searchable when using the incidents search bar.</p></li><li><strong>EVIDENCE</strong>: A summary of data marked as evidence. You can add evidence in this tab, the <strong>NOTES</strong> field, or the <strong>Evidence Board</strong> tab.</li><li><strong>LINKED INCIDENTS</strong>: Add or remove linked incidents. For more information, see <a href="/pages/M5EDpu9q5GyA1cxjDhPX">Link incidents</a>.</li></ul> |
| Investigation  | Provides an overview of the information collected about the investigation, such as indicators, email information, and URL screenshots.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| War Room       | A comprehensive collection of all investigation actions, artifacts, and collaboration. It is a chronological journal of the incident investigation. Each incident has a unique War Room. For information, see [Use the War Room in an investigation](/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-war-room-in-an-investigation.md)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Work Plan      | A visual representation of the running playbook that is assigned to the incident. For more information, see [Use the Work Plan in an investigation](/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-work-plan-in-an-investigation.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Evidence Board | View any entity that has been designated as evidence. The Evidence board stores key artifacts for current and future analysis. You can reconstruct attack chains and piece together key pieces of verification for root cause discovery. For more information, see [Evidence Handling](/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/evidence-handling.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |

</details>

<details>

<summary>Incident actions</summary>

You can do several actions when investigating an incident, such as adding members, creating a report, and restricting incidents.

When viewing an incident, from the Side panels dropdown, you can do the following:

| Action         | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Quick View     | A summary of the incident, timeline information, labels, and indicators.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Incident tasks | Add tasks for users to complete as part of an investigation. For more information, see [Incident Tasks](/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/incident-tasks.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Team           | <p>Add or delete incident team members.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>When you mention team members in the CLI, they are automatically added as team members.</p></div>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Context data   | <p>View context data to see what information was returned. The context is a map (dictionary) created for each incident and is used to store structured results from the integration commands and scripts. Context keys are strings and the values can be strings, numbers, objects, and arrays.</p><p>Context data acts as an incident data dump from which data is mapped into incident fields. When an incident is generated in Cortex XSOAR and a playbook or analyst begins investigating it, context data will be written to the incident to assist with the investigation and remediation process.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>All incident data stored in incident fields are also stored in the context data. In most cases, not all context data is stored in incident fields. Incident fields represent a subset of the total incident data.</p></div><p>When an incident is created, the incident data is stored in the context data, under the <strong><code>incident</code></strong> key. When an investigation is opened and integration commands are run, data returned from those commands is also stored outside of the main <strong><code>incident</code></strong> key.</p><p>For more information, see <a href="/pages/DQVc2lym5Q19vGw7SDvG">Use incident context data</a>.</p> |

When viewing an incident, from the **Actions** dropdown, you can do the following:

| Action                         | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| ------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Edit                           | Edit the incident, as required.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Report                         | Create a report to capture investigation-specific data and share it with team members. For more information, see [Create an incident summary report](/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/create-an-incident-summary-report.md).                                                                                                                                                                                                                                                                                                                                                 |
| Add a child incident           | <p>Child investigations are used to compartmentalize sensitive War Room activity. You can create child investigations to collaborate discreetly with a select group of people on a specific topic of investigation. Child investigations are also used where a secondary investigation is needed and its content may add too much "noise" to the original investigation.</p><p>Select the <strong>Restricted</strong> checkbox to turn the child investigation into a discrete investigation.</p>                                                                                                                                                                          |
| Restrict/Permit an incident    | Restrict an investigation for the incident owner and team. If restricted, select permit to open the incident to all users. For more information, see [Limit access to investigations using access control](/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/limit-access-to-investigations-using-access-control.md).                                                                                                                                                                                                                                                                         |
| Close/Reopen an incident       | <p>Mark the incident as closed. If closed, you can select <strong>Reopen</strong> the incident.</p><p>When you close an incident, the close reason is set to whatever value you last entered. For example, when closing an incident, if you initially selected <strong>False Positive</strong> as the <strong>Close Reason</strong>, reopened it, and closed it again, leaving the <strong>Close Reason</strong> empty, the empty <strong>Close Reason</strong> will overwrite the previous <strong>Close Reason</strong>. To keep the close reason that was entered previously on the incident, add the previous value in the <strong>Close Reason</strong> argument.</p> |
| Retain/Undo Retain an incident | Mark the incident for retention or disable retention for the incident. For more information, see [Retain incidents](/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/retain-incidents.md).                                                                                                                                                                                                                                                                                                                                                                                                   |
| Delete                         | Delete the incident from the database.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |

</details>

<details>

<summary>Incident navigation</summary>

You can navigate directly to a specific incident via the incident ID or incident name, using Ctrl+ K for Windows or Command-K for macOS.

When investigating an incident opened from **My Incidents** or the main **Incidents** page, you can navigate to the next/previous incident from within the incident, without returning to the original list. The navigation buttons appear next to the **Action** button. The total number of incidents from the list of incidents is shown (depending on your search criteria) and where you are in the list. For example, in the last 30 days, there were 7000 incidents. When opening an incident, you can investigate 7000 incidents using the navigation buttons without returning to the **Incidents** page.

Only users with permission to edit incidents can view the navigation buttons.

The navigation buttons are only available if the incident is opened from **My Incidents** or the **Incidents** page. If you navigate directly to an incident, without going through the **Incidents** page or **My Incidents** list, no navigation buttons appear.

{% hint style="info" %}

### Note

In a multi-tenant environment, the incident navigation buttons are available when directly viewing a child tenant or if the child tenant is selected in the main account.
{% endhint %}

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.13/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
