> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/customize-your-playbook/set-and-update-incident-fields.md).

# Set and update incident fields

## Set and update incident fields

Using a playbook to create incident fields offers a structured and automated approach to defining and populating fields with relevant data during incident handling. This ensures consistency in data collection, enhances the organization of incident information, and facilitates streamlined analysis and response processes.

Creating incident fields is essential for structuring and storing specific information related to security incidents. These fields enable efficient organization and retrieval of incident data, enhancing analysis, decision-making, and automated response actions. It is an iterative process in which you create fields as you better understand your needs and the information available in the third-party integrations you use. You initially define incident fields after the planning stage, with mapping and classification for how the incidents will be ingested from third-party integrations into Cortex XSOAR.

During the investigation, you can then use the **setIncident** script in a playbook task to set and update incident fields.

![](/files/lAczxy8XakwG54yIh7ko)

{% hint style="info" %}

#### Note

* The **setIncident** script includes all available input fields. Click **+ Add input** and use the scroll bar to see all the fields.
* The `name` field has a limit of 600 characters. If there are more than 600 characters, you can shorten the `name` field to under 600 characters and then include the full information in a long text field such as the `description` field.
* There are many ﬁelds already available as part of the **Common Type** content pack. Before creating a new incident field, check if there is an existing ﬁeld that matches your needs.
  {% endhint %}

For more information on creating custom incident types and fields, see this video: [Incident Types and Fields](https://www.youtube.com/watch?v=o92rG4FPc-k).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.14/configure-cortex-xsoar/playbooks/customize-your-playbook/set-and-update-incident-fields.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
