> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.15/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-inputs-and-outputs.md).

# Playbook Inputs and Outputs

Configure Cortex XSOAR 6.15 playbook inputs and outputs for task data flow.

Playbooks and tasks have inputs, which are data pieces that are present in the playbook or task. The inputs are often manipulated or enriched and they produce outputs. The inputs might come from the incident itself, such as the role to whom to assign the incident, or an input can be provided by an integration. For example, when an Active Directory integration is used in a task to extract a user's credentials.

You can add playbook inputs from context data and from indicators. Some playbooks such as Threat Intel Management playbooks use indicators as the playbook input.

<details>

<summary>Playbook input and output examples</summary>

The following example uses incident context data as the playbook input.

![](https://content.gitbook.com/content/8xEMUKpU65o1wagTHaO3/blobs/TlWqlD9SiZSCQfoypc22/dfca7f2a917b5bb1b98d1fd01d8f563b9d5d20691d3656e834265cbfba26e2a2.png)

In the image above, we see a playbook that is triggered based on context data, meaning an incident. The first two inputs are the **`SrcIP`**, which comes from the **`incident.src`** key, and **`DstIP`**, which is retrieved from **`incident.dst`**.

In addition, the playbook itself creates an output object whose entries serve the tasks throughout the playbook.

![](https://content.gitbook.com/content/8xEMUKpU65o1wagTHaO3/blobs/mHYu2cWvsqrjkTFVVul6/048dde3860f2215b6d54a2039562cb0b15077d8511242bbd3913d8e35dc955ec.png)

For example, we create a list of endpoint IP addresses which can later be enriched by an IP enrichment task, or a list of endpoint MAC addresses, which can be used to possibly get information about the hosts that were affected by the incident.

Outputs can also be data that was extracted or derived from the inputs. For example, in the following image we received the user's credentials from Active Directory, and used those credentials to retrieve the user's email address, manager, and any groups to which they belong.

![](https://content.gitbook.com/content/8xEMUKpU65o1wagTHaO3/blobs/2cWfMPiAcpRYR08eDApl/38318950ba594c4ae4ac2a47a6c197cdea40d067f1eb976dd2ec4b985536d955.png)

An output can then serve as input for a subsequent task. For example, the user's manager who was returned as an output in the image above, can be used as an input to retrieve information from Active Directory.

![](https://content.gitbook.com/content/8xEMUKpU65o1wagTHaO3/blobs/uiXHq3ttU0nQlkyhwTCg/64ced44a3543964541d4e7fc7206c7d962848ad093868a4c595c545565de8e70.png)

Notice that the input for this task is Account. Manager, which is the output we highlighted in the playbooks inputs.

</details>

For information on enabling sub-playbooks to access to main playbook data as inputs, see [Incident Context Data](/xsoar-6-administrator-guide/6.15/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents/incident-context-data.md).

### Group playbook inputs and outputs

Playbook input and output fields are collected into groups. This organizes the inputs and outputs, providing clarity and context to understand which inputs are relevant to which playbook flow.

#### Playbook group permissions

Users with permission to edit playbooks can add, edit, and delete groups and input and output fields. Users without this permission can only view groups, inputs, and outputs.

#### Work with playbook groups

You can do the following with groups:

* Add or delete a group. Deleting a group deletes all the fields defined in the group.
* Change the name and/or description of the group.
* Change the order groups appear by dragging.
* Collapse and expand a group.

#### How to add a new group

1. Click **+ Add Input Group** or **+ Add Output Group**.
2. Enter a group name and description and click the check mark.
3. Add fields to the group.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>If you do not add any fields, the group will be deleted when you click <strong>Save</strong>.</p></div>

#### Manage input or output fields within a group

You can do the following with input or output fields within a group:

* Add, edit, or delete fields within a group. Input or output fields are always part of a group.
* Move fields between groups by dragging.
* Change field order within a group by dragging.

**How to add an input or output field in a group**

Inputs:

1. Within a group, click **+ Add Input** at the bottom of the list of input fields. You may need to scroll down to see it.
2. Enter the input field **Name** (required), **Value**, and **Description**.
3. When you are done adding fields, click **Save**.

Outputs:

1. Within a group, click **+ Add Output** or **+ Add Manually** at the bottom of the list of output fields. You may need to scroll down to see these options.
   * If you click **+ Add Output**, select from the outputs from previous tasks.
   * If you click **+ Add Manually**, enter the context path and description for the output.
2. When you are done adding fields, click **Save**.

#### &#xD;&#x20;&#xD;<br>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.15/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks/playbook-inputs-and-outputs.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
