> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-war-room-in-an-investigation.md).

# Use the War Room in an investigation

The War Room contains an audit trail of all automatic or manual actions that take place in an incident. A War Room is where you can review and interact with your incidents. Cortex XSOAR provides machine learning insights to suggest the most effective analysts and command-sets. Each incident has a unique War Room.

![war-room-overview.png](/files/D9kjeIMkVWdh9MWhnKW3)

Within Cortex XSOAR, real-time investigation is facilitated through the War Room, which is powered by ChatOps and helps you to do the following:

* Run real-time security actions through the CLI, without switching consoles
* Run security playbooks, scripts, and commands
* Collaborate and execute remote actions across integrated products
* Capture incident context from different sources
* Document all actions in one source
* Converse with others for joint investigations

Every Incident has a War Room, but every user has access, subject to permissions, to a private War Room called the Playground.

**The Playground**

The Playground is a non-production environment where you can safely develop and test data, such as scripts, APIs, and commands. It is an investigation area that is not connected to a live (active) investigation.

To access the playground you can do the following:

* Type any command in the CLI (not in the incident).

  If you type a command in the incident, the results are returned to the incident War Room, not the Playground.
* If you have an Admin role, in **My Incidents** on the sidebar, click **Playground**.
* Type **`ctrl + k`** and then select the **`War Room`**
* In any browser, type: `https://<tenant>/WarRoom/playground/`

{% hint style="info" %}

### Note

In the Playground, you can clear the context data, if needed, which deletes everything in the Playground context data, but does not affect the actual incident. To clear the context, run `!DeleteContext all=yes'` from the CLI or click **Clear Context Data** while viewing the context data.

If you want to erase an existing playground and create a new one, run the `/playground_create` command.
{% endhint %}

**The War Room**

When you open the War Room, you can see all the actions taken on an incident, such as commands, notes, and evidence in several formats such as Markdown, and HTML When Markdown, HTML, or geographical information is received the content is displayed in the relevant format. You can schedule a command in the War Room to run at a specific time. For more information, see [Schedule a command in the War Room](/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/schedule-a-command-in-the-war-room.md).

To view specific data entries, you can filter entries by selecting the relevant checkbox, such as:

* **Chats**: Shows communication between team members.
* **Notes**: Any entries marked as notes.
* **Files**: Anything uploaded to the War Room in a playbook, script, or by the analyst

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Important</h3><p>Make sure files uploaded as attachments to the War Room are smaller than 250 MB. Uploading larger files can affect performance.</p></div>
* **Incident History**: Any incident field or SLA Timer field that was modified
* **Commands and playbook tasks**: Any actions taken by playbook tasks or run manually by the analyst
* **Tags**: Any tags that have been added

You can also highlight any command thread for tracking commands.

{% hint style="info" %}

### Note

Cortex XSOAR does not index notes, chats, and pinned as evidence entries.
{% endhint %}

In each War Room entry, you can take the following actions:

| Action                   | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Edit                     | You can edit, format, or delete your entries. If an entry has been changed, a History link will appear where you can view all changes to the entry.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Mark as Evidence         | Opens the Mark as evidence window where you specify the evidence details to be saved in the Evidence Board. The Evidence Board stores key artifacts for current and future analysis. You can also add evidence in the **Case Info** tab or the **Evidence Board** tab. For more information, see [Evidence Handling](/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/evidence-handling.md),                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Mark as note             | <p>Marks the entry as a note, which can help you understand why certain action was taken and assist future decisions.</p><p>You can also add a note by doing the following:</p><ul><li>Upload a file to the War Room by selecting <strong>Mark as Note</strong>.</li><li>If the <strong>Case Info</strong> tab includes a <strong>NOTES</strong> section, add it to the section.</li><li><p>In a playbook task (Advanced tab)</p><p>Tasks can be automatically added from script outputs as notes.</p></li><li><p>In the CLI by running the <code>!markAsNote entryIDs=<\`\`ID of the war room entry></code> command.</p><p>In the relevant War Room entry, click <strong>Copy to CLI</strong> to retrieve the <code>ID of the War Room entry</code>.</p></li></ul><p>When marked as a note, it is highlighted, so you can easily find them in the War Room or the <strong>Case Info</strong> tab.</p> |
| View artifact in new tab | Opens a new tab for the artifact.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Detach from task         | Removes a task from the artifact.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Attach to a task         | Adds a task to the artifact.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Download artifact        | Downloads an artifact according to the entry type, such txt files for text, json for a JSON entry, etc.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Add tags                 | Add any relevant tags to use that help you find relevant information.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Copy to CLI              | <ul><li>ID: Entry IDs are used to uniquely identify War Room entries and take the format <code>\<ENTRY\_IDENTIFER>@\<INCIDENT\_ID></code>, for example, <code>54925dc3-a972-4489-8bef-793331fa6c77\@1</code>. Many out-of-the-box commands and scripts use entry IDs arguments to pass in files as inputs.</li><li>URL: Copy the URL which is a direct link to the War Room entry</li></ul><p>To find the entry ID or URL of an entry in the War Room, click on the vertical ellipsis icon at the upper right of the entry, then copy the value.</p>                                                                                                                                                                                                                                                                                                                                                   |

You can also upload files to the War Room by selecting the paperclip icon next to the CLI. Any files that have been uploaded can also be downloaded from the War Room entry.

{% hint style="warning" %}

### Caution

You are not protected from malicious content when downloading files from the War Room.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.5/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-war-room-in-an-investigation.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
