> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/post-processing-for-incidents.md).

# Post Processing for Incidents

After you remediate an incident, you may want to perform additional actions on the incident, such as closing a ticket in a ticketing system or sending out an email. You can create a post-processing script to cover these scenarios.

{% hint style="info" %}

### Note

If a post-processing script returns an error, the incident does not close.
{% endhint %}

You need to [Create a Post-Processing Script](#UUID-6f8ac586-334d-cf7a-e81d-19fdcc6f4b3e) and then [Add a Post-Processing Script to the Incident Type](#UUID-0ebf4d17-c5bf-5798-732c-8ddd1cf219ab).

**Arguments Available in a Post-Processing Script**

These arguments are available for use in a post-processing script:

* **`closed`** - The incident closed time.
* **`status`**
* **`openDuration`**
* **`closeNotes`**
* **`closingUserId`** - The username of the user who closed the incident, or **`DBot`** if the incident was closed by DBot (for example, through a playbook).
* **`closeReason`**
* Any other field values passed in at closure, whether through the incident close form, the CLI, or a playbook task.

### **Create a Post-Processing Script**

This procedure describes how to create a post-processing script after an incident has been remedied.

1. Select Automation → **New Automation**.
2. Type a name for the post-processing script and click **Save**.
3. In the **Tags** field, from the dropdown list select **Post-processing**.
4. Add fields as required.
5. Click **Save**.
6. [Add a Post-Processing Script to the Incident Type](#UUID-0ebf4d17-c5bf-5798-732c-8ddd1cf219ab).

The following script example requires the user to verify all To Do tasks before closing an incident. Before you start, you need to [configure and enable a Cortex XSOAR REST API instance](https://xsoar.pan.dev/docs/reference/integrations/core-rest-api).

```programlisting
inc_id = demisto.incidents()[0].get('id')
tasks = list(demisto.executeCommand("core-api-get", {"uri": "/todo/{}".format(inc_id)})[0]['Contents']['response'])

if tasks:

    for task in tasks:

        if not task.get("completedBy"):
            return_error("Please complete all ToDo tasks before closing the incident")
            break
```

In this example, we create post processing script for Service Now incidents using a SNOW instance, where there are required fields to resolve and close (such as Resolution Code, Resolution Notes, etc.).

This script works with the defaults from Service Now and resolves and closes the mirrored ticket in Service Now.

```programlisting
commonfields:
  id: c8eeeb6c-3622-4bcb-897a-d183625609fd
  version: 20
vcShouldKeepItemLegacyProdMachine: false
name: ServiceNowCloseIncidentTicket
script: |-
  # return the args and incident details to the war room, useful for seeing what you have available to you
  # args can be called with demisto.args().get('argname')

  # debugging
  # demisto.results(demisto.args())
  # demisto.results(demisto.incident())

  # get the close notes and reason from the XSOAR Incident
  close_reason = demisto.args().get('closeReason')
  close_notes = demisto.args().get('closeNotes','No close notes provided')
  servicenow_sysid = demisto.incident().get("dbotMirrorId", False)

  # map XSOAR close reasons to Service Now close codes
  close_code_map = {
      "False Positive":"Not Solved (Not Reproducible)",
      "Resolved":"Solved (Permanently)",
      "Other":"Solved (Work Around)",
      "Duplicate":"Solved (Work Around)"
  }

  close_code = close_code_map.get(close_reason,"Solved (Work Arounnd")

  # handle if there is no service now sys_id, resolve and close snow ticket
  if servicenow_sysid:
      demisto.results(demisto.executeCommand("servicenow-update-ticket", {"id":servicenow_sysid,"close_code":close_code,"state":6,"close_notes":close_notes}))
      demisto.results(demisto.executeCommand("servicenow-update-ticket", {"id":servicenow_sysid,"state":7}))

  else:
      demisto.results("No ServiceNow sys_id found, doing nothing...")
type: python
tags:
- post-processing
- training
comment: Post processing script to resolve and close Service Now tickets if the XSOAR
  Incident is closed.
enabled: true
scripttarget: 0
subtype: python3
timeout: 80ns
pswd: ""
runonce: false
dockerimage: demisto/python:1.3-alpine
runas: Administrator
```

{% hint style="info" %}

### Note

If there is an additional custom argument defined for a post-processing script, the arguments **`closeNotes`**, **`closeReason`**, **`closed`**, **`openDuration`**, etc. are not available in the demisto.args() dictionary. In this case, there are two options:

1. Remove the additional custom argument from **Script settings** and instead add it as a field on the **Close Form** for the incident type. This results in the additional argument being passed to the post-processing script.
2. Manually add the default system arguments of **`closeNotes`**, **`closeReason`**, **`closed`**, **`openDuration`**, etc. to the **Script settings**, in addition to the custom argument. If not added, the code example above `close_notes = demisto.args().get('closeNotes','No close notes provided')` always returns "No close notes provided".
   {% endhint %}

### **Add a Post-Processing Script to the Incident Type**

Before you start you need to [Create a Post-Processing Script](#UUID-6f8ac586-334d-cf7a-e81d-19fdcc6f4b3e). After you add a post-processing script to the incident type, all incident types will use the post-processing script.

1. Go to Settings → OBJECTS SETUP → Incidents → **Types** .
2. Select the incident type you want to add the post processing script.
3. Click **Edit**.
4. In the **Post process using** field, from the dropdown list, select the script.

   ![post-process.png](/files/QsewSpcNqoinHn6IXnRL)
5. Click **Save**.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/post-processing-for-incidents.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
