For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XSOAR 6.13

Incident Tasks

Add and manage Playbook and to-do tasks in Cortex XSOAR 6.13 incidents.

Incident tasks are tasks for users to complete as part of an investigation, which are split according to the following:

  • Playbook Tasks: you can view, assign an owner, complete, and set a due date for playbook tasks that require attention.

  • To-Do Tasks: create tasks for users to complete as part of an investigation, and which are not attached to the incident's playbook. A playbook can finish running and an incident can be closed even if the incident contains open To-Do tasks.

    You can Create a To-Do Task directly from the incident Case (incident) info tab or in the To-Do Task section.

    Alternatively, you can create To-Do tasks from the command line.

Create a To-Do Task

You can create To-Do tasks directly in the incident from either the Case (Incident) Info tab or the Incident Tasks window. You can also create To-Do Tasks using the command line.

  1. From the incident, click i_icon.png and then click Incident Task.

  2. In the Incident Tasks window, click the To-Do Tasks tab.

    You can also add To-Do Tasks from the Case (Incident) Info tab if you have customized the incident to include To-Do tasks.

  3. Click Add a task.

  4. Add the Task Details as required:

    Parameter
    Description

    Task Name

    A meaningful name for the task (mandatory).

    Task Description

    A meaningful description for the task that provides sufficient information for the assignee to complete the task.

    Assignee

    The user to assign to the task. You can only assign a single user per task.

    Set due date

    The due date for the task. If the task is not completed by this date, it is marked as overdue but is not a roadblock for the investigation.

    Tag the result with

    Tags to apply to the To-Do task.

  5. Click Save.

    If you have customize the incident, you can see the To Do Tasks from the Case (Incident) Info tab.

Last updated

Was this helpful?