For the complete documentation index, see llms.txt. This page is also available as Markdown.
XSOAR 8 (SaaS)

Export Cortex XSOAR incidents to cloud storage

Export Cortex XSOAR 8 SaaS incidents as JSON files to Amazon S3, S3-compatible storage, or Azure Blob Storage.

Export Cortex XSOAR 8 SaaS incidents to external cloud storage. Exports support Amazon S3, S3-compatible storage, and Azure Blob Storage.

Exported incident data

Incidents are exported as JSON files containing:

  • Incident data, including all incident fields

  • Context data

  • Investigation data

  • War Room entries

You can also export incident attachments.

Configure cloud storage exports

Before exporting, configure egress to your storage solution in Cortex Gateway. Then configure External Storage settings in Cortex XSOAR.

You can schedule incident exports or export incidents on demand.

  • The Azure Blob Storage option is disabled by default; contact Customer Support if you would like to enable.

  • The first time incidents are exported, the process may take multiple days or weeks, depending on the number of incidents and the amount of data. The previous export must be completed before the system begins another export.

  • Once an incident has been exported, it is not exported again, even if it remains in the system and is modified after the export.

  • Exported incidents cannot be imported back into Cortex XSOAR.

  • Retained incidents are not exported.

Last updated

Was this helpful?