Cortex XSOAR 8 (SaaS)
Customize incident close reasons
Customize incident close reasons in Cortex XSOAR 8 SaaS.
The default incident close reason values are:
False Positive
Resolved
Duplicate
Other
To customize the incident close reason, you need to add a new server configuration.
Select Settings & Info → Settings → System → Server Settings → Server Configuration → Add Server Configuration.
Add the following key and value:
KeyValueincident.closereasonsA comma-separated list. For example,
False Positive,Resolved,Duplicate,Low Priority,Invalid,Other.
Last updated
Was this helpful?
