Incident Tasks
Add and manage Playbook and to-do tasks in Cortex XSOAR 6.13 incidents.
Incident tasks are tasks for users to complete as part of an investigation, which are split according to the following:
Playbook Tasks: you can view, assign an owner, complete, and set a due date for playbook tasks that require attention.
To-Do Tasks: create tasks for users to complete as part of an investigation, and which are not attached to the incident's playbook. A playbook can finish running and an incident can be closed even if the incident contains open To-Do tasks.
You can Create a To-Do Task directly from the incident Case (incident) info tab or in the To-Do Task section.
Alternatively, you can create To-Do tasks from the command line.
Create a To-Do Task
You can create To-Do tasks directly in the incident from either the Case (Incident) Info tab or the Incident Tasks window. You can also create To-Do Tasks using the command line.
From the incident, click
and then click Incident Task.In the Incident Tasks window, click the To-Do Tasks tab.
You can also add To-Do Tasks from the Case (Incident) Info tab if you have customized the incident to include To-Do tasks.
Click Add a task.
Add the Task Details as required:
ParameterDescriptionTask Name
A meaningful name for the task (mandatory).
Task Description
A meaningful description for the task that provides sufficient information for the assignee to complete the task.
Assignee
The user to assign to the task. You can only assign a single user per task.
Set due date
The due date for the task. If the task is not completed by this date, it is marked as overdue but is not a roadblock for the investigation.
Tag the result with
Tags to apply to the To-Do task.
Click Save.
If you have customize the incident, you can see the To Do Tasks from the Case (Incident) Info tab.
Last updated
Was this helpful?
