args: - description: Additional text by which to query incidents. name: query - description: A comma-separated list of incident types by which to filter. name: incidentTypes - description: 'The start date by which to filter incidents. Date format will be the same as in the incidents query page, for example: "3 days ago", ""2019-01-01T00:00:00 +0200").' name: fromDate - description: 'The end date by which to filter incidents. Date format will be the same as in the incidents query page, for example: "3 days ago", ""2019-01-01T00:00:00 +0200").' name: toDate - defaultValue: '500' description: The maximum number of incidents to fetch. name: limit - auto: PREDEFINED defaultValue: 'false' deprecated: true description: Deprecated due to performance considerations. Rather than using this argument, it is recommended to retrieve the context of the incidents separately, preferably for a limited number of incidents. name: includeContext predefined: - 'true' - 'false' - auto: PREDEFINED defaultValue: created description: The incident field to specify for the date range. Can be "created" or "modified". The default is "created". Due to performance considerations, you should only use "modified" if you have a large number of incidents. name: timeField predefined: - created - modified - description: A comma-separated list of non-empty value incident field names by which to filter incidents. name: NonEmptyFields - auto: PREDEFINED defaultValue: pickle description: The output file format. name: outputFormat predefined: - json - pickle - description: A comma-separated list of fields in the object to poplulate. name: populateFields - defaultValue: '100' description: Incidents query batch size. name: pageSize comment: |- Gets a list of incident objects and the associated incident outputs that match the specified query and filters. The results are returned in a structured data file. This automation runs using the default Limited User role, unless you explicitly change the permissions. For more information, see the section about permissions here: - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script commonfields: id: GetIncidentsByQuery version: -1 name: GetIncidentsByQuery outputs: - contextPath: GetIncidentsByQuery.Filename description: The output file name. type: String - contextPath: GetIncidentsByQuery.FileFormat description: The output file format. type: String script: '-' subtype: python3 tags: - ml timeout: 60µs type: python dockerimage: demisto/python3:3.12.13.10404775 tests: - Create Phishing Classifier V2 ML Test fromversion: 5.0.0