XSOAR 8 (SaaS)
Export Cortex XSOAR incidents to cloud storage
Export Cortex XSOAR 8 SaaS incidents as JSON files to Amazon S3, S3-compatible storage, or Azure Blob Storage.
Export Cortex XSOAR 8 SaaS incidents to external cloud storage. Exports support Amazon S3, S3-compatible storage, and Azure Blob Storage.
Exported incident data
Incidents are exported as JSON files containing:
Incident data, including all incident fields
Context data
Investigation data
War Room entries
You can also export incident attachments.
Configure cloud storage exports
Before exporting, configure egress to your storage solution in Cortex Gateway. Then configure External Storage settings in Cortex XSOAR.
You can schedule incident exports or export incidents on demand.
Last updated
Was this helpful?
