For the complete documentation index, see llms.txt. This page is also available as Markdown.
XSOAR 8 (SaaS)

Retain incidents

Retain incidents in Cortex XSOAR 8 SaaS.

By default, Cortex XSOAR keeps incidents for 6 months. The retention period is calculated from when the incident was created in Cortex XSOAR. For more information about the retention policy and how to extend retention, see Cortex XSOAR 8 Retention Policy FAQs.

Note

Up to 1,000 incidents per tenant can be excluded from the incident retention policy. Retained incidents are not deleted. If you reach 1000 retained incidents, you won't be able to exclude additional incidents from the retention policy unless you disable incident retention for some or all of your existing retained incidents.

Only user roles that have retain incident permissions can retain or undo incident retention. For more information, see The Components tab.

Retain an incident
  1. On the Incidents page, click the incident you want to retain.

  2. From the Actions dropdown button in the selected incident's page, select Retain Incident.

To disable retention for an incident, select Undo Retain Incident from the Actions menu.

Bulk retain incidents
  1. From the Incidents page, select the incidents to retain.

  2. Click RetentionRetain.

To disable retention for a group of incidents, select the incidents in the Incidents page and click RetentionUndo Retain.

Search for retained incidents

To search for retained incidents in the Incidents search bar, use the retained field, with T (True) or F (False). You can also add the Retain Incident field to the Incidents table to easily view which incidents are retained.

Last updated

Was this helpful?