IBM Security QRadar SOAR

 View Only
Expand all | Collapse all

Reopen Closed Incident using Inbound Email

  • 1.  Reopen Closed Incident using Inbound Email

    Posted Mon August 29, 2022 08:36 AM

    Hi,
    I am working on a scenario, where we need to reopen a closed incident based on inbound email. I am able to find that specific closed incident using "Email Message" Script, and I can add Note to the closed incident, however the "plan_status" is not being changed from "C" to "A".

    Did you guys handle such situation? Please share your thoughts.


    Thanks,
    Shahzad Ahmed



    ------------------------------
    Shahzad Ahmed
    ------------------------------


  • 2.  RE: Reopen Closed Incident using Inbound Email

    Posted Sun September 04, 2022 06:00 AM
    are you getting any errors.
    if yes , please share them.

    regards , 
    mohamd islam

    ------------------------------
    mohamad islam hamadieh
    ------------------------------



  • 3.  RE: Reopen Closed Incident using Inbound Email

    Posted Sun September 04, 2022 07:17 AM

    The script works fine if we just associate the email to the closed incident. 

    If we change the "plan_status" of the found incident from "helper.findIncidents(xyz)" as "A". The incident does not reopen and there is no error etc.

    Previously we were able to add Note the closed incident, however we are getting following error while adding Note the incident:

    "Error Running Script: The Script was unable to complete. Please contact the Resilient Administrator and report this issue."


    Thanks



    ------------------------------
    Shahzad Ahmed
    ------------------------------