Skip to main content

FindSimilarIncidentsByText

This Script is part of the Base Pack.#

Deprecated

Use DBotFindSimilarIncidents instead.

Find similar incidents by text comparison - the algorithm based on TF-IDF method. To read more about this method: https://en.wikipedia.org/wiki/Tf%E2%80%93idf

This automation runs using the default Limited User role, unless you explicitly change the permissions. For more information, see the section about permissions here: For Cortex XSOAR 6, see the https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations for Cortex XSOAR 8 Cloud, see the https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script for Cortex XSOAR 8 On-prem, see the https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script.

Script Data#


NameDescription
Script Typepython3
Tagsml, dedup, duplicate, incidents
Cortex XSOAR Version5.0.0

Used In#


This script is used in the following playbooks and scripts.

  • Dedup - Generic
  • Dedup - Generic v2
  • Dedup - Generic v3

Inputs#


Argument NameDescription
textFieldsText fields to compare. Can be label name, incident fields or custom fields. Comma separated value.
thresholdTFIDF score threshold (to consider incident as similar).
maximumNumberOfIncidentsMaximum number of incidents to check.
timeFrameHoursCheck incidents in this time frame.
ignoreClosedIncidentsIgnore close incidents.
timeFieldTime field to consider.
maxResultsMaximum number of similar candidates.
minTextLengthMinimum required text length to compare.
preProcessTextWhether to pre-process text (removing HTML, normilize words)

Outputs#


PathDescriptionType
similarIncident.rawIdSimilar incident ID.string
isSimilarIncidentFoundIs similar incident found? (true\false)boolean
similarIncidentSimilar incident.Unknown
similarIncident.nameSimilar incident name.string