ba68d19e51
"fetch" said nothing next to a list of commands that all start with "get". The command sits beside cortex-xdr-get-incidents in the picker, and the only thing an operator needs to read there is which of the two carries everything — so the name says it: get-incidents-full. The id moves with it (fetch_incidents -> get_incidents_full), since the script and the bundled mapper are bound to a command by filename. Anyone who created a rule against the old id in the few minutes 1.3.0 was up has to point it at the new command; the changelog says so. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>