> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-using-the-widget-builder.md).

# Create a widget using the widget builder

In the **Widgets Library**, you create a widget using the widget builder, which enables you to define and configure data, and preview how that widget appears. The widget builder allows you to create complex widgets, eliminating the need to write scripts or upload JSON files (although you have the option to do this). These complex widgets have the same capabilities as if you were creating a script-based widget.

<details>

<summary>Task 1. Create a new widget</summary>

In the **Widgets Library** of the report or dashboard you are creating or editing, click ![new-widget.png](/files/if6pWuGQ3RIEapQyDnTt) and select the widget type as follows.

| Widget type          | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| -------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Incidents            | Use incident data to create widgets related to incidents, for example timestamps, duration, incident types, and any incident field.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Indicators           | Use indicator data to create widgets related to indicators, for example timestamps, indicator types, and any indicator field.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| SOAR Metrics         | Use SOAR metrics data to create widgets related to scripts, playbooks, and integrations, for example executions, durations, and errors.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Tasks                | <p>Use tasks data to create widgets related to investigation tasks, for example assignee, playbook name, and duration (manual or automated).</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>When creating a widget based on the results of an investigation task, only the following task types are supported for widget aggregation:</p><ul><li>Manual tasks</li><li>Tasks that have an assignee</li><li>Tasks that have a due date</li><li>Tasks that are in an error state</li><li>Oversized tasks</li></ul></div>                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Scripts              | <p>Use a script to create a widget. Although you can create complex widgets using the widget builder, you can also create dynamic widgets using scripts, such as calculating the percentage of incidents that DBot closed. The script can also pull information from the Cortex XSOAR API.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Before creating a script based widget, you need to create a script in the <strong>Scripts</strong> page and then select the script in the widget builder. The script must have the <strong><code>widget</code></strong> tag assigned, otherwise it does not appear when selecting the script in the widget builder.</p></div><p>In the widget builder, you cannot manipulate data (no data appears in the <strong>Operations</strong> tab). However, you can define script arguments and change the color, layout, and legends.</p><p>For more information, see <a href="/pages/REwPZkK3VdjNepcAlzhr">Create a custom widget using a script</a>.</p> |
| Threat Intel Reports | Use threat intel data to create widgets related to threat intel reports that have been created, for example reports by type and status.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Upload               | Upload a JSON file to create a static widget which displays basic information, such as grouping incidents severity by type and active incidents by type.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |

</details>

<details>

<summary>Task 2. Define the widget data</summary>

In the **Query** step, set the following information:

**Widget display format**

Select one of the widget format icons. You can see a preview of how the widget appears.

| Widget format                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | Description                                                                                                                                                                            |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| ![widget-timer.png](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABUAAAAWCAYAAAAvg9c4AAAACXBIWXMAABYlAAAWJQFJUiTwAAAAB3RJTUUH5QUECRc1kT5DjAAAAAd0RVh0QXV0aG9yAKmuzEgAAAAMdEVYdERlc2NyaXB0aW9uABMJISMAAAAKdEVYdENvcHlyaWdodACsD8w6AAAADnRFWHRDcmVhdGlvbiB0aW1lADX3DwkAAAAJdEVYdFNvZnR3YXJlAF1w/zoAAAALdEVYdERpc2NsYWltZXIAt8C0jwAAAAh0RVh0V2FybmluZwDAG+aHAAAAB3RFWHRTb3VyY2UA9f+D6wAAAAh0RVh0Q29tbWVudAD2zJa/AAAABnRFWHRUaXRsZQCo7tInAAACTUlEQVQ4jdWVwUobURSGvxk7ScgkTOJEMcLUTYx1axeKYMA8gI1gBZf2CewD1boTqWDqA1iMIlKXLqwxGzvFCcRkHIYZaiZmuigJTWNioemi//ZyvnPv+c85V/B932fAEgcN/GfQZ/0OPc+jWCxyenrKV13H8zwkSeK5pjE3N0c6nUaSpK44oVdNr6+v+bi/T7lc7pl0bGyMV0tLTExMPA39cnnJ9vY2nucRjUbJLCwwPT1NIBCgXq9zcXFB4egI27YJhUKsrq7yYmqqN7RcLvN+awvbtkmn07xeWUGWZQAajQaNhwdCwSCO4/Bhd5disUgsFuPN+jqJRAL4zahms8nJyQm2bTOeTLKcy7WBAJ/PztjZ2aFeryPLMsu5HOPJJHd3dxQKBZrNZjfUNE2uSiUEQWAxm0VRlJ71BFAUhcVsFkEQuCqVME2zG1qr1bAsC1VV0TStL7AlTdNQVRXLsqjVat3Qyu0tAKqqEgoG/wgaCgZRVbUjvm+fAhiGwbvNTVzXBWDqF5d7qQM6PDwMQLVa5fv9PYFAgNHRUd5ubNBqElEUOxrecV0qlQoAI4+5P5JIoCgK1WoVXdcBGBoaQpZlIpEIkUiEcDiMIAjtmG+6jmmaKIrSvlQHNB6PM5lK4fs+nw4OsCyr7zMty+Lw8BDf95lMpYjH491QURSZn58nGo1yYxjs5fM4jvMo0HEc9vJ5bgyDWCxGJpNBFH/inhzTcDjM7OwsL2dm2mN6fn7O0fExrusiSRJra2v9x7SlgS+Ulga++v5G/8938gOlYhKSi5x3EQAAAABJRU5ErkJggg==)                                                                                                              | View data in a timer format. For example, mean time to assignment. In the Visuals tab, you can select the threshold color.                                                             |
| ![widget\_number.png](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABoAAAAYCAYAAADkgu3FAAAACXBIWXMAAA7EAAAOxAGVKw4bAAAAB3RJTUUH4wsMBxUv+CmA7QAAAAd0RVh0QXV0aG9yAKmuzEgAAAAMdEVYdERlc2NyaXB0aW9uABMJISMAAAAKdEVYdENvcHlyaWdodACsD8w6AAAADnRFWHRDcmVhdGlvbiB0aW1lADX3DwkAAAAJdEVYdFNvZnR3YXJlAF1w/zoAAAALdEVYdERpc2NsYWltZXIAt8C0jwAAAAh0RVh0V2FybmluZwDAG+aHAAAAB3RFWHRTb3VyY2UA9f+D6wAAAAh0RVh0Q29tbWVudAD2zJa/AAAABnRFWHRUaXRsZQCo7tInAAABsElEQVRIie3Wv6oaQRiH4deY4SBbuLXgDeiC2NlqYWMhCMJ6B1YWtjbegZ2FomChaKPdNuIVCIKgIOgWYqH4v1FYwd10khyiazzhJMX5VcN8MA/zDTOMw7Isi0/It89AvqAP5fvvJsvlMt1u96UFc7kcgUDgOQhAkiRCoRBvb29PAZvNhn6/f7d+F5JlGVVVcbvdT0HD4fAh9G/P6H2WyyXFYhHTNEmn00ynU+r1OufzmVgsRiqV+jh0vV7pdDqsVitM08QwDHa7HZlMhv1+T7VaRVEUHA7Hw3VsWzcYDJhMJsTjcQCEECSTSQKBAIqiIMsy6/XadkcPof1+T7vdJhaL4fV6f6lZlkW/3+dyueD3+22hh62bz+fouo6u67e5RqNBNptlNBrRarVQVRWPx8N2u30dUhSFcrkMwHg8plKpkEgkWCwWlEolwuEw0WjU9nxsISHE7R5JkgSAYRjUajUOhwOapqFpGsFgkEgk8jr0c3w+H4VCAZfLRT6fxzTNW83pdDKbzf4OJIRACHEbv49d++5Cx+ORZrP5R2/dS9DpdKLX6z2FPBPH15/hv4d+AD6MokEweGtjAAAAAElFTkSuQmCC)                                                                                                                                                                                                                                                                                                                                | View data in a number format. In the Visuals tab, you can select the threshold color.                                                                                                  |
| ![widget\_bar.png](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAfCAYAAACGVs+MAAAACXBIWXMAAA7EAAAOxAGVKw4bAAAAB3RJTUUH4wsMBjcDbIHAGQAAAAd0RVh0QXV0aG9yAKmuzEgAAAAMdEVYdERlc2NyaXB0aW9uABMJISMAAAAKdEVYdENvcHlyaWdodACsD8w6AAAADnRFWHRDcmVhdGlvbiB0aW1lADX3DwkAAAAJdEVYdFNvZnR3YXJlAF1w/zoAAAALdEVYdERpc2NsYWltZXIAt8C0jwAAAAh0RVh0V2FybmluZwDAG+aHAAAAB3RFWHRTb3VyY2UA9f+D6wAAAAh0RVh0Q29tbWVudAD2zJa/AAAABnRFWHRUaXRsZQCo7tInAAAByklEQVRIie2XMaviQBSFz0ycEIQUQpBARMRC8QeYQrTwT1vZiWIh9kI6m4CiBpNAJnHmFY9ddvdtEicvrFt4upB77/ngzhwSIqWUeKHoK83fAP8FQKPoZRRF8DwPt9sN/X4fjuOA0nqZC6dFUYT9fo/lconj8QghRK3mpQBCCIRhiCAIkCRJ7eZAyQr+lJQSnHNwzgvrNE0DYwyNRvl4JYA0TbHb7bBerxFFUW5dp9PBfD7HcDisF0AIgcvlAs/zcL/fc+uyLCsErAyg6zqm0ylGoxEej0dunWEYaLfb9QNQSmFZFizLUmmrD4Bzju12i81mgziOn+ppNpuYTCZwXRe6rn8PQAiB8/mMw+FQeAZ+lWmaGAwGuRmiBMAYg+u66Ha7SNP06R7btsEY+z6ApmmwbfvpA/ZDlNLcCFcOoizLcoNIJYAqAZQFkUoAVQIoCyKVAKoEUBZEKgGkBCClRJIkiOMYhmHAcZzC+jAMf3smhIAxBsYYCCHqANfrFYvFAqvV6suAZ8QYw3g8xmw2g2ma6gCcc/i+D9/3lc2Bz9X1er2/ro0U/RdwznE6nRAEQSXjnyaEoNVqwbKsL1e0EOBf6OVfxW+AN8AHJdPNPzUjnfkAAAAASUVORK5CYII=)                                                                                                                                                                                                                                                                                               | View data in a bar format.                                                                                                                                                             |
| ![widget\_barchart.png](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACQAAAAbCAYAAAAULC3gAAAACXBIWXMAAA7EAAAOxAGVKw4bAAAAB3RJTUUH4wsMBjgqqatEugAAAAd0RVh0QXV0aG9yAKmuzEgAAAAMdEVYdERlc2NyaXB0aW9uABMJISMAAAAKdEVYdENvcHlyaWdodACsD8w6AAAADnRFWHRDcmVhdGlvbiB0aW1lADX3DwkAAAAJdEVYdFNvZnR3YXJlAF1w/zoAAAALdEVYdERpc2NsYWltZXIAt8C0jwAAAAh0RVh0V2FybmluZwDAG+aHAAAAB3RFWHRTb3VyY2UA9f+D6wAAAAh0RVh0Q29tbWVudAD2zJa/AAAABnRFWHRUaXRsZQCo7tInAAAA1klEQVRIie2WIQ6EMBBFP5ulnho4AhaNIrh6uAfn4QqcAEtQCFrHNVAkmMHvhpYFsrtp+mz/TF7+mHpERPgjHr8WeMUJmXBCJuwQUkqhLEsopd7euq5D0zRYluV7QjqmaULf91jX9dS8HSc7iu60e9jX0DzPqKoKdV3f4WNhQ3fjhEw8ry5gjCFNU4RhCACI4xhBEIAxBs45hBDgnB9fSCeQUlJRFCSlPDOu5VJDbdtiHMfD+SiKkOc5fN/fzVwSGobho3ySJMiyTJvxiNwnX4sTMuGETGxlRMHI9QUntAAAAABJRU5ErkJggg==)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | View data in a column format.                                                                                                                                                          |
| ![widget\_pie.png](/files/PCbkIlhKTiU5nF94gEsy)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | View data in a pie format.                                                                                                                                                             |
| ![widget\_graph.png](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABUAAAAaCAYAAABYQRdDAAAACXBIWXMAAA7EAAAOxAGVKw4bAAAAB3RJTUUH4wsMBjIsuicJBQAAAAd0RVh0QXV0aG9yAKmuzEgAAAAMdEVYdERlc2NyaXB0aW9uABMJISMAAAAKdEVYdENvcHlyaWdodACsD8w6AAAADnRFWHRDcmVhdGlvbiB0aW1lADX3DwkAAAAJdEVYdFNvZnR3YXJlAF1w/zoAAAALdEVYdERpc2NsYWltZXIAt8C0jwAAAAh0RVh0V2FybmluZwDAG+aHAAAAB3RFWHRTb3VyY2UA9f+D6wAAAAh0RVh0Q29tbWVudAD2zJa/AAAABnRFWHRUaXRsZQCo7tInAAACIElEQVRIieXVu0srQRTH8e/MZnbjSkg2LoKIIIpoJVikMQRdCOny7wYLEYJgqSJYGQliioBF3ou7y87cSr258RUf1f3VZz5zZuDMCGOM4Ycjfxr8NTQzmUxotVr0+302NjZYXV1Fyu/tJSeTCefn5xwfH3N/f4/W+tudSq014/GYwWBAFEXfBuG37vQri4wxJElCkiQ8Pj4yGo1wHIelpSVs2/4aqrXm5uaGZrNJp9MhSRL29vao1Wr4vv85NE1TwjBESsni4iJSSgqFAsYY7u7u0FqztbX1XP8hmqYprVaLZrOJ53kcHh7iui7X19fc3t6SpimZTAbHcbAs62P0CWw0GlxeXpLNZun3+7iuy8XFBaPRiIODA3zfZ3l5Gdu230f/Bq+urlBKkSQJZ2dnWJaFZVmUy2Wq1Sq5XA6AhYWFt9F/wc3NTYIgoNfrcXJywnA4ZH9/n2q1ysrKyswEzqBaa9rt9hRYr9fZ3t4mjmNyuRxhGLK7u/sqOIMaY2i32xwdHU2BOzs7OI5DNpulVCqhtcZ13TffiClUCEGxWGRtbQ2lFOVy+Rl8iuu6r0LvHj+fzxMEAXEcUygUpsDPZgaVUuJ53tzQq6gxhiiKGI/HZDLzT68QAqUUSqkXtNfr0Wg0OD09RQgxN6qUolQqUalUXtA4jul2u3S73blBANu2WV9fJ01TRBRF5uHhgcFg8CXsKUIIPM/D933E//1F/wHIpfKhawTmmwAAAABJRU5ErkJggg==)                                                                                                                                                                         | View data in a line graph format.                                                                                                                                                      |
| ![widget\_table.png](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAB0AAAAfCAYAAAAbW8YEAAAACXBIWXMAAA7EAAAOxAGVKw4bAAAAB3RJTUUH4wsMBjIF+JWRaQAAAAd0RVh0QXV0aG9yAKmuzEgAAAAMdEVYdERlc2NyaXB0aW9uABMJISMAAAAKdEVYdENvcHlyaWdodACsD8w6AAAADnRFWHRDcmVhdGlvbiB0aW1lADX3DwkAAAAJdEVYdFNvZnR3YXJlAF1w/zoAAAALdEVYdERpc2NsYWltZXIAt8C0jwAAAAh0RVh0V2FybmluZwDAG+aHAAAAB3RFWHRTb3VyY2UA9f+D6wAAAAh0RVh0Q29tbWVudAD2zJa/AAAABnRFWHRUaXRsZQCo7tInAAACn0lEQVRIie2WzUvjQBjGf/kCUWr9oloQDypGehDEeqie/Cf8Ez150Ys3oQdRNIoXRbBBVEqpksRWa/oxnXiQdrcmutV1ZVn3vWXeh/nlmXlmGCUIgoAvLvWrgf+h/yZUfzlQqVQ4ODjAsiweHh4+NKmiKCSTSZaXlzFNE13vxHR8SSk5Oztje3ubXC6HEOJDUADbtpFSEo/HGR8f7+h1LK8QgmKxyM3NzW8BAarVKvl8Hs/zQr2Q03q9DkAmk2FpaYlYLMb19TXZbJZKpcLKygozMzMA1Go19vf3sSyLVCoV0gshaDQab0NbpSgKQ0NDmKbJwMAAhmFweHiIlJKJiQlSqVTbzeXlJbquR+rL5XLkKvwd6YXnvd3b2+P8/Bxd1/F9n9vbW4QQrK2tsbm5CTxvh+u6lMvlSH0ikegeKqXEcRwcxwn1rq6uIieK0r8LahgG6XSaxcVFent7KRQK7O7u4vs+mUyGycnJ9oocHR1xfHyMaZoh/Wv1apASiQRzc3PE43FyuRwnJycATE9PMz8/Dzynt1gscnp6Gqm/v7/vHtoCa5qGrutomoaiKB1jLaeqqr6qf5dTgEajwePjYzsYzWYTKSW+77evx1qt1j7XUfp3QYUQWJaFbdtomka1WsVxHJrNJuvr62xtbQEQBAGe51EqlSL1o6Oj3UOllJRKJVzXDfXy+XzkRK7rRuq7hhqG8SnXoJSye+ifvgb1lzBVVVFV9VOC1Ep8yNTPT1AhBNlslo2NDer1OoODg6EgDQ8P09fXB/wI0t3dHf39/SH91NQUq6ur7e2IdKppGrOzs1xcXLCzs4Nt26G/7CZIiqIwNjbGwsICyWTybactt57n4brum2ftV9XT08PIyAixWCy0xCHoV9T3eYJ+H+gTKh3cp1A4NN4AAAAASUVORK5CYII=) | View data in a table format. Click the gear icon to edit columns.                                                                                                                      |
| ![widget\_text.png](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAB8AAAAdCAYAAABSZrcyAAAACXBIWXMAAA7EAAAOxAGVKw4bAAAAB3RJTUUH4wsMBjEkn9HS9AAAAAd0RVh0QXV0aG9yAKmuzEgAAAAMdEVYdERlc2NyaXB0aW9uABMJISMAAAAKdEVYdENvcHlyaWdodACsD8w6AAAADnRFWHRDcmVhdGlvbiB0aW1lADX3DwkAAAAJdEVYdFNvZnR3YXJlAF1w/zoAAAALdEVYdERpc2NsYWltZXIAt8C0jwAAAAh0RVh0V2FybmluZwDAG+aHAAAAB3RFWHRTb3VyY2UA9f+D6wAAAAh0RVh0Q29tbWVudAD2zJa/AAAABnRFWHRUaXRsZQCo7tInAAABe0lEQVRIie2WQYrCMBiFXyZRpKUqdlUVXLhwI8QTCF7BtXftJdyIVAsqLlQQSlolpp3NWBgYYyuKDPZblf8l7yMQQkmSJAnexNe7xIX8M+VMF14uF0gpoZR6qJxSilKpBMb+1mjlnufBdV2s1+uH5O12G6PRCL1eL79cCAHf93E8HtHv99FqtdJsv99jOp3ifD7fzHzfhxDiZr9WfsWyLAwGA3DO09liscB2u0UQBDezMAy1vZnklFIYhgHLstKZYRhgjGmze2hXMMZQq9XS76wwxlCtVkEI0e7TNna7XUwmEwBAo9HILHccB+PxGEop7T6t3DRNmKaZWXqlUqmg2WzeXfe5L1whL+R3kVIiDENEUQSlFOI4RhRFEEJASpmri+T9gZzNZnBdF/P5HIfDAXEcw7ZtdDodDIdDcM5BKc3Ulf3N/EEIgeVyidVqlc42mw2UUuCcI89Zcp88CALsdjucTqdf83K5DNu2Ua/XQQh5jfyZ/K/bXsifwTewzZrYlGF9DgAAAABJRU5ErkJggg==)                                                                                                                                                                                                                                                                                                                                                                                                      | View data in a text format, which can be used as a text summary of the displayed data. You can use {0} to display a query value and {date} to display the date. Markdown is supported. |

**Data Source**

Select the source data to query.

Cortex XSOAR retrieves data relevant for that data source. For example, for Incidents, in the Group by field all data relating to incidents is retrieved, such as type, owner, and created by.

| Widget data source   | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| -------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Incidents            | Use incident data to create widgets related to incidents, for example timestamps, duration, incident types, and any incident field.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Indicators           | Use indicator data to create widgets related to indicators, for example timestamps, indicator types, and any indicator field.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| SOAR Metrics         | Use SOAR metrics data to create widgets related to scripts, playbooks, and integrations, for example executions, durations, and errors.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| War Room Entries     | Use War Room entry data to create widgets, for example number of entries according to owner.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Tasks                | <p>Use tasks data to create widgets related to investigation tasks, for example assignee, playbook name, and duration (manual or automated).</p><p>When creating a widget based on the results of an investigation task, only the following task types are supported for widget aggregation:</p><ul><li>Manual tasks</li><li>Tasks that have an assignee</li><li>Tasks that have a due date</li><li>Tasks that are in an error state</li><li>Oversized tasks</li></ul>                                                                                                                                                                                                                                                                                                                       |
| Scripts              | <p>Use a script to create a widget. Although you can create complex widgets using the widget builder, you can also create dynamic widgets using scripts, such as calculating the percentage of incidents that DBot closed. The script can also pull information from the Cortex XSOAR API.</p><p>Before creating a script based widget, you need to create a script in the Scripts page and then select the script in the widget builder. The script must have the <strong><code>widget</code></strong> tag assigned, otherwise it does not appear when selecting the script in the widget builder.</p><p>In the widget builder, you cannot manipulate data (no data appears in the Operations tab). However, you can define script arguments and change the color, layout, and legends.</p> |
| Threat Intel Reports | Use threat intel data to create widgets related to threat intel reports that have been created, for example reports by type and status.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |

**Query**

Queries data in the Lucene query syntax form relating to the data source.

For example when the data source is incidents and the query is: **`-status:closed and owner:""`**, it queries all incidents that are not closed which do not have an owner.

Or to see all incidents that are not closed, not archived, and are not jobs, use the query: **`-status:closed and -status:archived and -category:job`**.

**Date range**

The time frame to retrieve data.

**Widget name**

Type a meaningful name for the widget.

</details>

<details>

<summary>Task 3. Configure the widget data</summary>

This step enables data manipulation, similar to scripting. You can configure the data according to groups and fields (including custom calculations on fields).

1. (Not relevant for tables or text) Click the **Operations** step, and in the **Values** section select one of the following calculations to perform on the data (not relevant for Script and War Room Entries data sources).

   | Calculation | Description                                                                                                                                                                                                        |
   | ----------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
   | **Count**   | Counts the total value of the field. For example, display the total number of incidents in your system. You can then group by type and severity.                                                                   |
   | **Average** | Calculates the average value of the field. For example, display the average number of incidents in your system over the selected time frame. You can then group by type and severity.                              |
   | **Sum**     | Counts the value of the field according to a specific value. For example, when you define a metrics widget type, select the execution count, total duration, errors count, or create your own custom calculations. |
   | **Min**     | Calculates the minimum numeric value of the data. For example, you may want to see the minimum number of fetched events.                                                                                           |
   | **Max**     | Calculates the maximum numeric value of the data. For example, you may want to see the maximum number of fetched events.                                                                                           |
2. (Not relevant for **Count**) Select one of the fields from the dropdown or create your own custom calculations by selecting **Custom calculations on fields**.
3. If adding custom calculations, type the calculation as required.

   The custom calculation modal suggests incident fields based on the widget data type, which are automatically validated. You can add your own fields (provided these fields exist), according to the widget data type, by using the CLI name. These fields are not validated.

   You can add mathematical operators (such as **`+, -, /, *`**) between fields. Variables using **`{}`** are also supported. For example:

   * To see the average time that incidents are late, type **`{now}-remediationsla.dueDate`**.
   * To calculate the average time between detection and remediation for phishing incidents (in the phishing generic playbook we set the time detection and remediation SLA timers), type **`remidationsla.startDate-detectionsla.startDate`**.
   * To see remediations (less 10 minutes), type **`remdiationsla.dueDate-10`**.
4. In the **Axis and grouping** section **Group by** field, from the dropdown, select the group you want to add.

   By default, the results are limited to the top 10 most popular results. If you want to change the top most popular to the least popular, change the number, or you want to see the remaining results that are not covered in one group (the **Show ‘Others’** checkbox), click the edit button and update as required.

   If you want to add a custom field, ensure the **Make data available for search** incident type field is checked when editing or creating a new field.

   Example 26. Limit the number of results

   You can limit the amount of results to return, view the most or least popular, and for some fields select the time format. For example, you may want to see the top 10 most popular active incidents active incidents by month.

   ![widget-pop.png](/files/u4fkmDOqF33vTjInorVK)
5. (Optional) Define custom groups (for example, define specific owners in the owner group).

   1. Click **Custom ‘Group by’**.
   2. In the **Create Custom groups** window, click **Equals (String)** to change the operator.
   3. Select a value from the dropdown.
   4. Change the name as required.
   5. If you want to create a second group, click **Add custom group**.
   6. If you want to add a group for all other values that have not been defined, click the **Create and display a group for all remaining values** checkbox.

   Example 27. Group data into two teams

   You can manipulate data according to one or two groups (two groups are useful for vertical bars and line charts). Within each group, you can group by a bucket. For example, for two teams - Team A and Team B, each one is made up with different team members. You only want to see Team A and Team B and not the individual team members.

   ![widget-group.png](/files/ZJmfBSI9nWZrrtqn4M6C)
6. In the **Second group by** field, add the group as required. For example, to see data filtered by owner and severity, select **Group By** Owner and **Second Group by** Severity.

</details>

<details>

<summary>Task 4. Define the widget display</summary>

1. Click the **Visuals** step and define how the widget appears.

   | Parameter                | Description                                                                                                                                                                                                                                                                                                                          |
   | ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
   | Axis name                | The name of the axis for both horizontal and vertical.                                                                                                                                                                                                                                                                               |
   | Format                   | Select the format of the table for both horizontal and vertical axis. For example, hours, minutes, days, weeks, etc.                                                                                                                                                                                                                 |
   | Reference Line           | Whether you want a line showing the average, minimum, maximum, or custom line.                                                                                                                                                                                                                                                       |
   | Show Legend              | Whether you want to see the legend in your widget.                                                                                                                                                                                                                                                                                   |
   | Show also percentage     | Displays the percentage when selecting a pie chart.                                                                                                                                                                                                                                                                                  |
   | Show values on the graph | Add the values on the chart widget.                                                                                                                                                                                                                                                                                                  |
   | Display trend            | Compares dates for a particular period in a number widget. For example, this week vs. last week, this year vs. last year, and so on. To change the comparison period, in the **Time frame** field from the dropdown, select the relevant date.                                                                                       |
   | Widget color threshold   | Select the **Widget color threshold** in a number or duration widget to highlight the threshold data and define the threshold by selecting the Widget color threshold checkbox. For example, if less than 150 red, 100 yellow, 50 green. To add more thresholds, click **Add new threshold**. You can change the colors as required. |
2. To change the color, in the preview section, hover next to the legend, click the ellipsis and then click **Edit color**.

</details>

<details>

<summary>Task 5. Save and add the widget to a dashboard or report</summary>

1. Click **Save**.

   The widget is added to the widgets library.
2. Add the widget to the dashboard or report.

   When you add the widget, it automatically uses the date range of the dashboard or report. You can change it by clicking the settings icon and selecting Use widget’s date range. To revert, click the settings icon again and select **Use dashboard’s date range**.

</details>

**Create a widget using the widget builder examples**

<details>

<summary>Average time to close incidents</summary>

In this example we want to create a bar chart widget that shows the following:

* The average time it takes to close incidents per day
* Classified according to incident types
* Incidents that occurred during the previous seven days

1. Click the add **+** button from the **Widgets Library**.
2. Select **Incidents**.
3. Enter a name in the **Widget name** field.
4. Click the Bar graph icon.
5. In the **Query** tab, define the following:

   Data source: **Incidents**

   Query: **`-category:job and -status:Closed`**

   Date range: **Last 7 days**
6. In the **Operations** tab:

   Change **Count** to **Average**.

   From the dropdown list, select **Custom calculations on fields**.

   Type **`remediationsla.startDate-detectionsla.startDate`**

   Group by: **Date Occurred**

   Second Group by: **Type**

   ![widget-example.png](/files/vtuKih35jMtwB1eQVOoW)

</details>

<details>

<summary>How many incidents over the last seven days</summary>

In this example, we want to view the following data:

* How many incidents occurred in the last 7 days
* Closed vs not closed (pending or active)
* Line chart

1. Click the add **+** button from the **Widgets Library**.
2. Select **Incidents**.
3. Enter a name in the **Widget name** field.
4. Click the Line graph icon.
5. In the **Query** tab, define the following:

   Data source: **Incidents**

   Query: **`-category:job`**

   Date range: **Last 30 days**
6. In the **Operations** tab, the first group is **`Date Occurred`**.
7. In the second group, from the dropdown list, select **`status`**.
8. Click **Custom Group by** to add the following data:

   ![widget-eg.png](/files/Bl7jhYMyEiuIgwIyIGbZ)

</details>

<details>

<summary>Average time for open incidents that are late</summary>

In this example, we want to create the following incident type widget:

* The average time for open incidents that are late
* Grouped by 2 groups (group A and group B) and by type
* In a bar chart

1. Click the add **+** button from the **Widgets Library**.
2. Select **Incidents**.
3. Enter a name in the **Widget name** field.
4. Click the Bar graph icon.
5. In the **Query** tab, define the following:

   Data source: **Incidents**

   Query: **`-status:Closed and category:job`**

   Date range: **Last 30 days**
6. In the **Operations** tab, add the following information:
   1. In the **Values** section, select **Average**.
   2. From the dropdown list, click **Custom calculations on fields**.
   3. Type **`{now}-remediationsla.dueDate`**.

      We want to see the average time that incidents are late (from today’s date). We add a variable **`{now}`**, so that we do not have to change the date.
   4. In the **Group by** field, select **Owner** and then click **Custom Group by**.
   5. Add the following, using users from your organization.

      ![widget-group.png](/files/ZJmfBSI9nWZrrtqn4M6C)
   6. In the **Second group by** field, from the dropdown list, select **Type**.
   7. Select the checkbox for **Create and display a group for all remaining values** and then click Save.
7. In the **Visuals** tab, select the following:
   1. Horizontal options - Axis name: **`TEAM`**.
   2. Vertical options - Axis name: **`REMEDIATION TIME`**.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/dashboards-and-reports/widgets/create-a-widget-using-the-widget-builder.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
