Export incidents from the Incidents table
Export selected Cortex XSOAR 8 SaaS incidents to CSV or Excel files.
Export selected Cortex XSOAR incidents from the Incidents table to a CSV or Excel file. Use exports to share incident data outside Cortex XSOAR.
If you want to export an incident as a JSON file, run the !js script="return ${.}" command in the War Room.
Exported data does not include files, attachments, or artifacts. All exported text is plain text.
Before you begin
Enable pop-ups from your Cortex XSOAR 8 SaaS tenant.
Select which data appears in your exported file by adding columns to the incidents table. If a column is hidden, the data is not exported. You can hide, show, or reorder the columns in the table by using the settings icon on the Incidents page.
Export incidents to Excel or CSV
On the Incidents page, at the top of the incidents table, click the settings wheel to configure the columns to include for export.
Select the incidents to export, and click Export.
Select one of the following:
Summary Report (CSV file)
Detailed Report (Excel file)
Incident export limits
Export up to 1,000 incidents at once. Exports fail when selected incidents exceed 10,000 combined entries. Downloaded files cannot exceed 100 MB.
Last updated
Was this helpful?
