Abstract
Use a playbook, script, or command to update incident fields.
Sometimes you need to update incident fields based on a change in an alert. For example, after starting an investigation an analyst might want to change the name of an incident, star an incident, or change the status of an incident.
You can update the following incident fields through a playbook, script, or command:
manual_severity
starred
assigned_user_email
status
score
incident_name
description
The following sections explain how to update incident fields by running a command in the CLI, and running a script, and running a playbook.