Finds similar incidents based on indicators' similarity. Indicators' contribution to the final score is based on their scarcity.
|Cortex XSOAR Version
This script is used in the following playbooks and scripts.
- Dedup - Generic v4
|Incident ID to get the prediction of. If empty, predicts the current incident ID.
|The maximum number of incidents that an indicator can be associated with to be retained. This helps to filter out indicators that appear in many incidents
|The minimum number of indicators related to the incident required before running the model.
|Threshold to similarity value which is between 0 and 1.
|Type of indicators to take into account. If empty, uses all indicators types.
|Whether to show the incident you are investigating.
|The maximum number of incidents to display.
|Fields to add in the table of incident
|The start date by which we retrieve information on incidents.
|Argument for the query of similar incidents.
There are no outputs for this script.