Skip to main content

Update Incident

Update the details of an existing incident.

External Documentation

To learn more, visit the Cortex XDR documentation.

Parameters

ParameterDescription
Assigned Pretty NameUpdated full name of the incident assignee.
To supply a new value in this field, you must also supply a value for Assigned User Mail in the same action.
Assigned User MailUpdated email address of the incident assignee.
CommentThe text of the comment to add.
Incident IDThe ID of the incident to update. Can be retrieved from the 'Get All Incidents' action.
Resolve CommentDescriptive comment explaining the incident change. This can be set only for resolved incidents.
SeverityAdministrator-defined severity.
StatusUpdated incident status.

Workflow Library Example

Update Incident with Cortex Xdr and Send Results Via Email

Workflow LibraryPreview this Workflow on desktop