args: - description: The query for the Incidents that you want to export. (e.g. status:closed -category:job). You can and should generate the query from the Incidents search screen. name: query required: true - defaultValue: "7" description: Number of days you want to fetch back for (default is 7). Needs to be a number. name: fetchdays - description: 'Comma separated list of columns (fields) for the CSV. (Default is: id,name,type,severity,status,owner,roles,playbookId,occurred,created,modified,closed).' name: columns comment: This automation uses the Core REST API Integration to batch export Incidents to CSV and return the resulting CSV file to the war room. commonfields: id: ExportIncidentsToCSV version: -1 contentitemexportablefields: contentitemfields: fromServerVersion: "" dependson: must: - core-api-post - core-api-get dockerimage: demisto/python3:3.12.13.10404775 enabled: true name: ExportIncidentsToCSV runas: DBotWeakRole script: '' scripttarget: 0 subtype: python3 tags: - Utility type: python fromversion: 6.5.0 marketplaces: - xsoar - marketplacev2 - platform supportedModules: - agentix - cloud - cloud_runtime_security - cloud_posture - xsiam - edr tests: - No tests (auto formatted)