Use the Work Plan in an investigation
Use Work Plans in Cortex XSOAR 8 SaaS investigations.
The Work Plan is a visual representation of the running playbook assigned to the incident. Playbooks enable you to automate many security processes, such as managing your investigations and handling tickets. Work Plans enable you to monitor and manage a playbook workflow, and add new tasks to tailor the playbook to a specific investigation.
In an investigation, when you open the Work Plan tab you can see the playbook, the playbook name, and navigation tools.
By default, the Follow checkbox is checked, which allows you to see the playbook executing in real-time. The playbook moves when a task is completed.
In the Work Plan you can do the following:
Change the default playbook
On the left-hand side of the window, select the playbook you want to run.
When changing the playbook, all completed tasks are removed and the new playbook will run. If you select playbooks several times you can view the history of which playbooks ran.
Rerun the playbook
When changing the playbook, select the current playbook to run again.
View inputs and outputs
View the inputs and outputs of each task that has run. You can't view inputs and outputs of any task that hasn't run.
Manage tasks
View, create, and edit a playbook task. For each task, you can do the following:
Designate tasks as complete either manually or by running a script.
Assign an owner
Set a due date
Add comments and completed notes, as required.
You can manage these tasks in the CLI by using the /task command. For more information about tasks, see Incident Tasks.
Export to a PNG
Export the Work plan to a PNG format for easy analysis.
The color coding and symbols in the Work Plan help you to easily troubleshoot errors or respond to manual steps. The following table displays the playbook tasks and icons in the Work Plan.
A playbook will not continue its execution path if a prior task has failed; you must resolve the failed task before subsequent tasks can run.
Last updated
Was this helpful?














