> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-lifecycle/fetch-incidents-from-an-integration-instance.md).

# Fetch Incidents From an Integration Instance

You can poll third party integration instances for events and turn them into Cortex XSOAR incidents that trigger automations (fetching). There are a number of integrations that support fetching, but not all support this feature. You can view each integration in the [Cortex XSOAR Developer Hub](https://xsoar.pan.dev/docs/reference/index).

You set the objects to be fetched and their mapping in Settings → OBJECTS SETUP → Incidents → **Classification & Mapping**.

When setting up an instance, you can configure the integration instance to fetch events. You can also set the interval for which to fetch new incidents, by configuring the **Incidents Fetch Interval** field. The fetch interval default is 1 minute. This enables you to control the interval in which an integration instance reaches out to third-party platforms to fetch incidents into Cortex XSOAR. If the integration instance, does not have the **Incidents Fetch Interval** field, you can add this field by editing the integration settings.

{% hint style="info" %}

### Note

* In some integrations the **Incidents Fetch interval** is called **Feed Fetch Interval**.
* If the integration instance does not have the **Incidents Fetch Interval** field, you need to add this field by editing the integration settings. If the integration is from a content pack, you need to create a copy of the integration. Any future updates to this integration will not be applied to the copy integration.
  {% endhint %}

You can change the default for all integration instances by setting the server configuration using the **`serversiemincidents.schedule`** key. The value is the interval in seconds (s), minutes (m) or hours (h). Setting the incident fetch interval when defining an instance overrides the server configuration settings.

Go to Settings → About → **Troubleshooting**. For example, type **`jobs.serversiemincidents.schedule`** key and **`120s`** value. It is recommended that you do not set the value to less than one minute (1m).

{% hint style="info" %}

### Note

If you turn off fetching for a period of time and then turn it on or disabled the instance and enabled it, the instance remembers the "last run" timestamp, and pulls all events that occurred while it was off.
{% endhint %}

1. Select the integration instance you want to fetch incidents by going to Settings → **INTEGRATIONS** and click the integration instance settings button.
2. Select the **Fetches incidents** checkbox.

   Once enabled, Cortex XSOAR searches for events that occurred within the time frame set for the integration, which is based on the specific integration. The default is 10 minutes prior, but can be changed in the integration script implementation.
3. (Optional) In the **Incidents Fetch Interval** field, set the number of hours or days, and the number of minutes the interval for which to fetch incidents (default 1 minute).
4. (Optional) If the **Incidents Fetch Interval** field does not appear, add it to the integration.

   Relevant for any incident fetching integration.

   1. For out-of-the-box integrations, select the duplicate integration button.

      If you have already duplicated the integration, click the Edit integration’s source button.
   2. In the **Basic** section, select the **Fetches incidents** checkbox.

      In the **Parameters** section, you can see that the **`incidentsFetchInterval`** parameter is added. Change the default value if necessary.

      ![integration-fetch.png](/files/z42H3nmQZ8q4HRgSwBTD)
   3. **Save** the integration.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.14/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-lifecycle/fetch-incidents-from-an-integration-instance.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
