> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/reference/server-configurations/incident-server-configurations.md).

# Incident Server Configurations

| Key                                                             | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | Default                                                                                                     |
| --------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| **`canvas.suggestions.IncidentIndicatorSuggestions.max`**       | The maximum number of suggestions for malicious suggestions in the investigation canvas. For more information, see [Edit Dbot Incident and Indicator Suggestions](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/day-to-day-tasks-in-cortex-xsoar/incident-management/investigate-an-incident-using-the-canvas.md#UUID-8ec00606-56cd-868f-7183-b59c2793eb39).                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | **`5`**                                                                                                     |
| **`canvas.suggestions.IncidentMutualIndicatorSuggestions.max`** | The maximum number of suggestions for common indicators between incidents in the investigation canvas. For more information, see [Edit Dbot Incident and Indicator Suggestions](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/day-to-day-tasks-in-cortex-xsoar/incident-management/investigate-an-incident-using-the-canvas.md#UUID-8ec00606-56cd-868f-7183-b59c2793eb39).                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | **`5`**                                                                                                     |
| **`canvas.suggestions.IndicatorIndicatorSuggestions.max`**      | The maximum number of suggestions for indicators in the investigation canvas. For more information, see [Edit Dbot Incident and Indicator Suggestions](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/day-to-day-tasks-in-cortex-xsoar/incident-management/investigate-an-incident-using-the-canvas.md#UUID-8ec00606-56cd-868f-7183-b59c2793eb39).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | **`5`**                                                                                                     |
| **`create.incidents.limit.by.time.range`**                      | Whether any fetching limits are imposed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | **`false`**                                                                                                 |
| **`create.incidents.limit.by.time.range.hours`**                | The period of time (hours) within which to limit incidents that can be fetched.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | **`24`**                                                                                                    |
| **`create.incidents.limit.by.time.range.max.allowed`**          | The maximum number of incidents that can be fetched within the time period defined in the **`create.incidents.limit.by.time.range.hours`** server configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | **`1000`**                                                                                                  |
| **`Export.utf8bom`**                                            | Whether to [export an incident to CSV using the UTF-BOM format](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/day-to-day-tasks-in-cortex-xsoar/incident-management/export-an-incident-to-csv-using-the-utf8-bom-format.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | **`true`**                                                                                                  |
| **`incident.closereasons`**                                     | [Customizes incident close reasons](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/customize-incident-close-reasons.md) in a comma separated list. For example, **`false positive, resolved, duplicate, low priority, invalid, other`**.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | **`false positive, resolved, duplicate, other`**                                                            |
| **`incident.batch.close.fields`**                               | When attempting to close an incident as duplicate, if the incident has mandatory fields that must be populated before closing, the close action fails by default. With this server configuration, you can change the default from **`fail`** to **`allow`** or **`populate`**. Allow closes the duplicate incident. Populate closes the duplicate incident after populating the missing values of the mandatory fields. The values are copied from the original incident that this incident duplicates.                                                                                                                                                                                                                                                                                                                                                 | **`fail`**                                                                                                  |
| **`incident.html.style.attributes`**                            | <p><a href="/pages/o6cA159kB9OhkDwT1k66#UUID-e8d5accb-b5ad-8550-54ca-32b3705c8eb3">Configures the HTML field</a>, if missing HTML styles. Add the following settings to the allowed list the attributes used in your HTML code. Supports the following styles:</p><p><strong><code>text-align,font-size,font-family,font-weight,color,line-height,border-style,border,page-break-inside,tablelayout,padding,background-size,display,padding-top,padding-right,padding-bottom,padding-left,text-size-adjust,break-inside,word-break,width,height,-ms-text-size-adjust,-webkit-text-size-adjust</code></strong></p>                                                                                                                                                                                                                                       | N/a                                                                                                         |
| **`incident.metadata.ignore.list`**                             | Configures an ignored list for which incident fields to use for related incidents. A comma-separated list. For more information, see [Configure Incident Fields for Related Incidents](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/day-to-day-tasks-in-cortex-xsoar/incident-management/configure-incident-fields-for-related-incidents.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | N/a                                                                                                         |
| **`incident.metadata.whitelist`**                               | Configures an allowed list for which incident fields to use for related incidents. A comma-separated list. For more information, see [Configure Incident Fields for Related Incidents](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/day-to-day-tasks-in-cortex-xsoar/incident-management/configure-incident-fields-for-related-incidents.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | N/a                                                                                                         |
| **`incident.prevent.modify.closed`**                            | <p>Prevents modifying incident fields after an incident is closed.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Admin users can still modify incident fields after an incident is closed.</p></div>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | **`false`**                                                                                                 |
| **`incident.restrict.default.admin`**                           | Prevents the default administrator from viewing restricted incidents.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | **`false`**                                                                                                 |
| **`incident.stuck.notification.status`**                        | <p>This is required in order to use <strong><code>playbook.stuck.notification.users</code></strong>, and if you want it to only send error emails then it needs to be set to:</p><p><strong><code>incident.stuck.notification.status = error</code></strong></p><p>In addition, if you set the configuration for this, you MUST NOT set <strong><code>message.ignore.incidentstatuschanged = true</code></strong>, or you will receive no notifications.</p>                                                                                                                                                                                                                                                                                                                                                                                            | N/a                                                                                                         |
| **`ingestion.samples.save-mapped`**                             | <p>Indicates whether to save the raw JSON for fetched incidents (fetched from SIEM) in ALL incidents. Values: <strong><code>true/false</code></strong>.</p><p>In some cases, it is useful to record the raw JSON for debugging issues with fetched incidents.</p><div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Caution</strong></p><p>By default, this feature is not enabled. Enabling this feature might drastically impact disk size due to data duplication. We recommend that you only enable this feature when creating playbooks in Cortex XSOAR development instances.</p></div>                                                                                                                                                                                                          | **`false`**                                                                                                 |
| **`inline.edit.on.blur`**                                       | <p>By default, when editing the following inline values in an incident/indicator/threat intel reports, the changes are not saved until you confirm your changes (clicking the checkmark icon in the value field).</p><ul><li>Dropdown values, such as Owner, Severity, etc.</li><li>Text values, such as Asset ID. (You can only edit when you click the pencil in the value field).</li></ul><p>These icons are designed to let you have an additional level of security before you make changes to the fields in incidents/indicators.</p><p>Set this configuration to true, to enable you to make changes to the inline fields without clicking the checkmark. The changes are automatically saved when clicking anywhere on the page or when navigating to another page. For text values you can also click anywhere in the value field to edit</p> | **`false`**                                                                                                 |
| **`investigation.prevent.modify.closed`**                       | Whether to add chats and notes to closed investigation (set to **`false`** to allow).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | **`true`**                                                                                                  |
| **`investigation.task.partial.index`**                          | <p>Whether to index all the tasks or a subset of them. Indexing all can take a lot of memory and affect performance.</p><p>Values:</p><ul><li><strong><code>1</code></strong>: Manual tasks</li><li><strong><code>2</code></strong>: Tasks that have an assignee</li><li><strong><code>4</code></strong>: Tasks that have a due date</li><li><strong><code>8</code></strong>: Tasks that are in an error state</li><li><strong><code>16</code></strong>: Oversized tasks</li></ul><p>Default is the total sum of the above values: <strong><code>31</code></strong>.</p>                                                                                                                                                                                                                                                                                | **`31`**                                                                                                    |
| **`labels.type.user`**                                          | Add a new label field so that it is available at all times, when creating an incident. Use comma separated labels for multiple values.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | N/a                                                                                                         |
| **`linked.inc.retry.limit`**                                    | Sets the number of times to retry linking an incident upon failure. When dealing with linking hundreds of incidents, start with a value of 100 and go up if there are still some failures.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | **`100`**                                                                                                   |
| **`message.ignore.failedFetchIncidents`**                       | Whether to ignore failed fetched incidents. For more information, see [Receive Notification on an Incident Fetch Error](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-lifecycle.md#UUID-aa8e347e-1f53-53fa-d925-c87b827c3a2f).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | **`false`**                                                                                                 |
| **`ml.suggestions.canvas.leftpane.incidents.limit`**            | The maximum number of incidents in the Quick View window. For more information, see [Edit Dbot Incident and Indicator Suggestions](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/day-to-day-tasks-in-cortex-xsoar/incident-management/investigate-an-incident-using-the-canvas.md#UUID-8ec00606-56cd-868f-7183-b59c2793eb39).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | **`10`**                                                                                                    |
| **`module.health.notification.users`**                          | List of names in CSV format to receive notifications when an integration experiences a fetch error. For more information, see [Receive Notification on an Incident Fetch Error](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-lifecycle.md#UUID-aa8e347e-1f53-53fa-d925-c87b827c3a2f).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | N/a                                                                                                         |
| **`serverSiemIncidents.schedule`**                              | <p>The interval in minutes, for fetching incidents. Set by the following configuration:</p><p><strong><code>recent.integration.siem.fetch.incidents.delay</code></strong></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | **`1`**                                                                                                     |
| **`ui.incidents.page.size`**                                    | Increases the number of incidents per page.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | <p><strong><code>50</code></strong></p><p>(Multi-tenant) <strong><code>200</code></strong> Main Account</p> |
| **`UI.term.incident`**                                          | Changes the display name of security incidents. For a list of values, see [Change the Display Name of Security Incidents](/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/change-the-display-name-of-security-incidents.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | N/a                                                                                                         |
| **`attachment.file.unique.name`**                               | When set to true, a timestamp is automatically appended to the file name for files uploaded as attachments.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | **`false`**                                                                                                 |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.13/learn-about-cortex-xsoar/reference/server-configurations/incident-server-configurations.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
