For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XSOAR 8 (SaaS)

Schedule incident export

Schedule automated incident exports to Amazon S3, Azure Blob Storage, or S3-compatible cloud storage in Cortex XSOAR 8 SaaS.

How scheduled incident export works

Scheduled exports use your incident retention policy. By default, Cortex XSOAR exports incidents older than six months (from the date of incident creation) once a day. If you purchase additional retention, it exports incidents older than your total retention period. For example, with an additional three months of retention, incidents older than nine months are exported daily.

Enable scheduled incident exports

  1. Go to Settings & InfoSettingsSystemExport Incidents.

  2. Select an existing external storage option from the dropdown.

  3. Enter the relative path where the data is stored. For example, if the data is stored in the export_incidents top-level folder in an Amazon S3 bucket, the relative path is export_incidents.

  4. Under Export frequency, toggle the button to Enable scheduled exports.

  5. Select whether to Include incident attachments.

  6. Save.

Monitor scheduled exports

After you enable scheduled exports, the Export Incidents page shows the next scheduled export. After an export completes, it shows the last successful export. During an active export, it shows the current status.

  • The first time incidents are exported, the process may take multiple days or weeks, depending on the number of incidents and the amount of data. The previous export must be completed before the system begins another export.

  • To stop an existing export process, click the Abort button. The Abort button only appears when an export is in process.

  • If an export fails, the Instance Admin receives an email notification. To enable or disable notification settings, click on your username and select User PreferencesNotificationsOther NotificationsScheduled export and delete failure.

  • Once an incident has been exported, it is not exported again, even if it remains in the system and is modified after the export.

Last updated

Was this helpful?