Close an investigation - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR Pro Administrator Guide

Product
Cortex XDR
License
Pro
Creation date
2024-07-16
Last date published
2024-11-11
Category
Administrator Guide
Retire_Doc
Retiring
Link_to_new_Doc
/r/Cortex-XDR/Cortex-XDR-Documentation
Abstract

Close an existing investigation from the Forensic Investigations page.

From the list of ongoing investigations, you can close an investigation. You might want to close an investigation if resolved, or if you want to cancel the investigation.

Note

When you close an investigation, Palo Alto Networks has a grace period of 24 hours before deleting any collections associated with the investigation. During this timeframe, you have the option to cancel the close investigation action.

  1. From the Forensic Investigations table, right-click an investigation and select Close.

  2. In the Close Investigation widget, you can view all evidence collections exported for the investigation.

  3. In the Forensic Investigation table, the status of the investigation changes to Close Pending, and the timestamp displays the time the investigation expires and the investigation data is deleted.

  4. Right-click an investigation pending closure to display the following options::

    • Edit: Update the investigation name, description, or adjust user permissions.

    • Open: Cancel the close request.

    • Permanently delete: Delete the investigation and all associated data immediately. This action can't be canceled.