Restrict an Investigation - Administrator Guide - 6.10 - Cortex XSOAR - Cortex - Security Operations

Cortex XSOAR Administrator Guide

Cortex XSOAR
Creation date
Last date published
Administrator Guide

You can restrict an investigation to the incident owner and the team associated with the investigation.

  1. Do one of the following:

    • Open the incident and select ActionsRestrict incident.

      To remove the restriction select ActionsPermit incident.

    • In the CLI, type /investigation_restrict id= id_ number

  2. (Optional) For Automation do the following:

    • Use the restrictInvestigation command in a playbook.

    • Specify the incident ID of the incident for which you want to restrict access.

    • Set the Restrict argument to True to restrict the incident.

    • Set the Restrict argument to False to remove restricted from the incident.