Customize incident close reasons
Customize close reasons for incidents by adding a server configuration in Cortex XSOAR.
Last updated
Was this helpful?
Customize close reasons for incidents by adding a server configuration in Cortex XSOAR.
The default incident close reason values are:
False Positive
Resolved
Duplicate
Other
To customize the incident close reason, you need to add a new server configuration.
Select Settings & Info → Settings → System → Server Settings → Server Configuration → Add Server Configuration.
Add the following key and value:
Key
Value
incident.closereasons
A comma-separated list. For example, False Positive,Resolved,Duplicate,Low Priority,Invalid,Other.
Last updated
Was this helpful?
Was this helpful?
