Automate changes to incident fields using SLA scripts - Administrator Guide - 8 - Cortex XSOAR - Cortex - Security Operations

Cortex XSOAR Administrator Guide

Product
Cortex XSOAR
Version
8
Creation date
2024-09-18
Last date published
2024-09-26
Category
Administrator Guide
Solution
Cloud
Retire_Doc
Retiring
Link_to_new_Doc
/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation
Abstract

Create scripts to perform specific actions in Cortex XSOAR when the SLA is breached. Properties in the SLA timer field value.

Scripts in Cortex XSOAR enable you to automate processes. In the context of SLA, you can create scripts that will perform specific actions when the SLA is breached. Each SLA script must include the SLA tag.

You can use an out-of-the-box script and attach it to an incident field.

Send an email when the SLA is overdue

Cortex XSOAR comes with an out-of-the-box script, called SendEmailOnSLABreach, that sends an email to specific users when the script is triggered. You can add this to any incident field as required. For example, add the script to the Remediation SLA incident, so that when an SLA/Timer is breached, an email is sent automatically. By default, the script sends an email to the incident assignee, but you can manually edit the script to add additional recipients..

Stop and start different timers in an incident field

In the following example, you want to stop the Time To Assignment timer when an owner is assigned and start the Remediation SLA timer.

If you have not done so already, download the CaseManagement-Generic content pack. This content pack includes the TimersOnOwnerChange script.

  1. Go to Settings & InfoSettingsObject SetupIncidentsIncident Fields

  2. Edit the Owner field.

  3. In the Script to run when field value changes field, add the TimersOnOwnerChange script.

  4. Save the field.

  5. (Optional) Test the field change.

    1. Open an unassigned incident and in the CLI type !startTimer timeField=timetoassignment.

      In the War Room, the field returns the new value from idle to running.

    2. Go to the Incident Info tab and add an owner.

    3. In the War Room, you should see that the Time to Assignment has ended and the Remediation SLA has started:

      sla-warroom.png