IncidentWrapper

Cortex XSOAR API

IncidentWrapper is an extension of the Incident entity, which includes an additional field of changed-status for the web client
ShardID
optional
format: int64
account
optional
Account holds the tenant name so that slicing and dicing on the master can leverage bleve
activated
optional
When was this activated format: date-time
activatingingUserId
optional
The user that activated this investigation
allRead
optional
allReadWrite
optional
attachment
optional
array[Attachment] Attachments
autime
optional
AlmostUniqueTime is an attempt to have a unique sortable ID for an incident format: int64
cacheVersn
optional
format: int64
canvases
optional
Canvases of the incident
category
optional
Category
changeStatus
optional
closeNotes
optional
Notes for closing the incident
closeReason
optional
The reason for closing the incident (select from existing predefined values)
closed
optional
When was this closed format: date-time
closingUserId
optional
The user ID that closed this investigation
created
optional
format: date-time
dbotCreatedBy
optional
Who has created this event - relevant only for manual incidents
dbotCurrentDirtyFields
optional
For mirroring, manage a list of current dirty fields so that we can send delta to outgoing integration
dbotDirtyFields
optional
For mirroring, manage a list of dirty fields to not override them from the source of the incident
dbotMirrorDirection
optional
DBotMirrorDirection of how to mirror the incident (in/out/both)
dbotMirrorId
optional
DBotMirrorID of a remote system we are syncing with
dbotMirrorInstance
optional
DBotMirrorInstance name of a mirror integration instance
dbotMirrorLastSync
optional
The last time we synced this incident even if we did not update anything format: date-time
dbotMirrorTags
optional
The entry tags I want to sync to remote system
details
optional
The details of the incident - reason, etc.
droppedCount
optional
DroppedCount ... format: int64
dueDate
optional
SLA format: date-time
feedBased
optional
If this incident was triggered by a feed job
hasRole
optional
Internal field to make queries on role faster
highlight
optional
id
optional
indexName
optional
insights
optional
format: uint64
investigationId
optional
Investigation that was opened as a result of the incoming event
isDebug
optional
IsDebug ...
isPlayground
optional
IsPlayGround
labels
optional
array[Label] Labels related to incident - each label is composed of a type and value
lastJobRunTime
optional
If this incident was triggered by a job, this would be the time the previous job started format: date-time
lastOpen
optional
format: date-time
linkedCount
optional
LinkedCount ... format: int64
linkedIncidents
optional
LinkedIncidents incidents that were marked as linked by user
modified
optional
format: date-time
name
optional
Incident Name - given by user
notifyTime
optional
Incdicates when last this field was changed with a value that supposed to send a notification format: date-time
numericId
optional
format: int64
occurred
optional
When this incident has really occurred format: date-time
openDuration
optional
Duration incident was open format: int64
owner
optional
The user who owns this incident
parent
optional
Parent
phase
optional
Phase
playbookId
optional
The associated playbook for this incident
previousAllRead
optional
previousAllReadWrite
optional
previousRoles
optional
Do not change this field manually
primaryTerm
optional
format: int64
rawCategory
optional
rawCloseReason
optional
The reason for closing the incident (select from existing predefined values)
rawJSON
optional
rawName
optional
Incident RawName
rawPhase
optional
RawPhase
rawType
optional
Incident raw type
reason
optional
The reason for the resolve
reminder
optional
When if at all to send a reminder format: date-time
roles
optional
The role assigned to this investigation
runStatus
optional
RunStatus of a job
sequenceNumber
optional
format: int64
severity
optional
Severity is the incident severity format: double
sizeInBytes
optional
format: int64
sla
optional
SLAState is the incident sla at closure time format: double
sortValues
optional
sourceBrand
optional
SourceBrand ...
sourceInstance
optional
SourceInstance ...
status
optional
IncidentStatus is the status of the incident format: double
syncHash
optional
todoTaskIds
optional
ToDoTaskIDs list of to do task ids
type
optional
Incident type
version
optional
format: int64
xsoarHasReadOnlyRole
optional
xsoarPreviousReadOnlyRoles
optional
xsoarReadOnlyRoles
optional