> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/incident-investigation.md).

# Incident Investigation

An incident investigation can be opened in the following ways:

* **Automatically**: If associated with a playbook, incidents open automatically for investigation and run the associated playbook.
* **Manually**: Open an incident manually by selecting the incident in the Incidents table.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>If the incident <strong>ID</strong> hyperlink is unavailable, the incident was closed before the investigation started, usually through a preprocess rule or it was already closed when fetched. If you want to see the incident details, click <strong>Summary View</strong> at the top of the incidents table.</p><p>After an incident is created, it is assigned a <strong>Pending</strong> status in the incident table. When you start to investigate an incident the status changes automatically to <strong>Active</strong>, which starts the remediation process.</p></div>
* **CLI**: If you want to open an incident in the CLI, type **`/investigate id=`*****`<incidentID#>`***.

**Incidents Page**

When you open an incident, you see the following tabs, which assist you in the investigation:

| Tab                                                                                                                                                                             | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Incident/Case Info                                                                                                                                                              | <p>A summary of the incident, such as case details, work plan, evidence, and so on. Most of the fields are for information only, although you can add the following:</p><ul><li><strong>Evidence</strong>: A summary of data marked as evidence. You can add evidence in this tab or in the <a href="/spaces/9gZ0C5CI8Bl5Aulkp4dZ/pages/yZAC54MNvGTG7SZMQIL8">Evidence Board</a>.</li><li><p><strong>Notes</strong>: Displays any notes that have been entered. For example, understand specific actions taken by the analyst and the underlying reasons, see chats between analysts to highlight how they arrived at a certain decision, etc. You can also see the thought process behind identifying key evidence and learn about similar incidents in the future.</p><p>You can also add notes in the War Room.</p></li><li><strong>Tasks</strong>: View tasks to complete as part of an investigation. You can add tasks in this tab or <a href="/spaces/9gZ0C5CI8Bl5Aulkp4dZ/pages/vdoAkigfqTKoLhJMvCXE">Create a To-Do Task</a>.</li></ul><p>You can send a permalink to a specific Investigation Summary by copying its URL.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>You can edit the fields by <a href="/spaces/9gZ0C5CI8Bl5Aulkp4dZ/pages/0Hk1pBemZRRePNUYUWdP">Incident Customization</a>.</p></div> |
| **Investigation**                                                                                                                                                               | An overview of the information collected about the investigation, such as indicators, email information, URL screen shots and so on                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| [War Room](/xsoar-6-administrator-guide/6.12/configure-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/war-room-overview.md)                                        | A comprehensive collection of all investigation actions, artifacts, and collaboration. It is a chronological journal of the incident investigation. Each incident has a unique War Room.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| [Work Plan](/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/work-plan.md)                             | A visual representation of the running playbook that is assigned to the incident.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| [Evidence Handling](/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/evidence-handling.md)             | View any entity which has been designated as evidence. The Evidence board stores key artifacts for current and future analysis. You can reconstruct attack chains and piece together key pieces of verification for root cause discovery.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| [Related Incidents](/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/link-incidents.md)                | A visual representation of incidents that share similar characteristics, such as malicious indicators, or part of a phishing campaign.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| [Canvas](/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/investigate-an-incident-using-the-canvas.md) | <p>Visually maps an incident, its elements, correlated investigation entities, and the progression path of the incident, combining analyst intelligence with machine learning.</p><p>The <strong>Related Incidents</strong> page is orientated towards exploration and searching for similar data. The <strong>Canvas</strong> maps incidents and indicators by enabling you to decide what you want to include in a layout of your choice.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |

You can [link incidents](/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/link-incidents.md), edit the incident, add a child incident, add tasks, notes, and so on. For more information, see [incident actions](/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/incident-actions.md).

**Inline Value Fields**

By default, when editing the following inline values in an incident, the changes are not saved until you confirm your changes (clicking the checkmark icon in the value field).

* Dropdown values, such as Owner, Severity, etc.
* Text values, such as Asset ID. (You can only edit when you click the pencil in the value field).

These icons are designed to let you have an additional level of security before you make changes to the fields in incidents, indicators, and threat intel reports.

To change the default behavior set the **`inline.edit.on.blur`** server configuration to **`true`**, which enables you to make changes to inline fields without clicking the checkmark. The changes are automatically saved when clicking anywhere on the page or when navigating to another page. For text values you can also click anywhere in the value field to edit.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.12/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management/incident-investigation.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
