Schedule incident export
Schedule automated incident exports to Amazon S3, Azure Blob Storage, or S3-compatible cloud storage in Cortex XSOAR 8 SaaS.
How scheduled incident export works
Scheduled exports use your incident retention policy. By default, Cortex XSOAR exports incidents older than six months (from the date of incident creation) once a day. If you purchase additional retention, it exports incidents older than your total retention period. For example, with an additional three months of retention, incidents older than nine months are exported daily.
Before exporting incidents, you must configure an external cloud storage solution. For more information, see Configure access to external storage
Enable scheduled incident exports
Go to Settings & Info → Settings → System → Export Incidents.
Select an existing external storage option from the dropdown.
Enter the relative path where the data is stored. For example, if the data is stored in the
export_incidentstop-level folder in an Amazon S3 bucket, the relative path isexport_incidents.Under Export frequency, toggle the button to Enable scheduled exports.
Select whether to Include incident attachments.
Save.
Monitor scheduled exports
After you enable scheduled exports, the Export Incidents page shows the next scheduled export. After an export completes, it shows the last successful export. During an active export, it shows the current status.
Last updated
Was this helpful?
