args: - auto: PREDEFINED defaultValue: scatter description: The type of the widget to return. name: returnWidgetType predefined: - scatter - summary - incidents - defaultValue: 1 months ago description: 'The start date by which to filter incidents. Date format will be the same as in the incidents query page, for example: "3 days ago", ""2019-01-01T00:00:00 +0200").' name: fromDate - defaultValue: '500' description: The maximum number of incidents to fetch. name: limit - defaultValue: Cortex XDR Incident description: The Cortex XDR incident type. name: incidentType - description: Input search query from the dashboard. name: searchQuery - defaultValue: '24' description: Period of time (in hours) before retraining the model. Default is "24". name: modelExpiration predefined: - '' - auto: PREDEFINED defaultValue: 'False' description: Determines whether to force the model to re-train. Default is "False". name: forceRetrain predefined: - 'True' - 'False' - defaultValue: xdralerts.osactorprocesscommandline,xdralerts.actionprocessimagecommandline,xdralerts.causalityactorprocesscommandline,xdralerts.actorprocesscommandline,xdralerts.description description: Comma-separated list of additional incident fields to display, but which will not be taken into account when computing similarity. name: fieldsToDisplay comment: Train clustering model on Cortex XDR incident type. commonfields: id: DBotGroupXDRIncidents version: -1 name: DBotGroupXDRIncidents script: '-' subtype: python3 tags: - widget timeout: 3.6µs type: python tests: - No tests (auto formatted) fromversion: 6.2.0 dockerimage: demisto/python3:3.12.13.10116658 marketplaces: - xsoar - xsoar_on_prem