OpsGenieV3
Integration with Atlassian OpsGenie. OpsGenie is a cloud-based service that enables operations teams to manage alerts generated by monitoring tools to ensure the right people are notified, and the problems are addressed in a timely manner.
Case Management · OpsGenie
Details
| ID | OpsGenieV3 |
|---|---|
| Provider | Atlassian |
| Category | Case Management |
| From Version | 6.2.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
Integration with Atlassian OpsGenie. OpsGenie is a cloud-based service that enables operations teams to manage alerts generated by monitoring tools to ensure the right people are notified, and the problems are addressed in a timely manner.
This integration was integrated and tested with OpsGenie.
Some changes have been made that might affect your existing content.
If you are upgrading from a previous of this integration, see Breaking Changes.
Configure OpsGenie v3 in Cortex
| Parameter | Description | Required |
|---|---|---|
| Server URL (e.g., https://api.opsgenie.com) | True | |
| API Token | False | |
| Fetch incidents | False | |
| First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days) | False | |
| Max Fetch | False | |
| Event types | Fetch only events with selected event types. | False |
| Status | Fetch only events with selected status. If query is used, this parameter will be overridden. | False |
| Priority | Fetch only events with selected priority. If query is used, this parameter will be overridden. | False |
| Tags | Fetch only events with selected tags. If query is used, this parameter will be overridden. | False |
| Query | Query parameters will be used as URL encoded values for “query” key. i.e. ‘https://api.opsgenie.com/v2/alerts?query=status%3Aopenor%20acknowledged%3Atrue&limit=10&sort=createdAt’ | False |
| Incident type | False | |
| Trust any certificate (not secure) | False | |
| Use system proxy settings | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
opsgenie-create-alert
Create an alert in Opsgenie.
Base Command
opsgenie-create-alert
Input
| Argument Name | Description | Required |
|---|---|---|
| message | Alert message. | Required |
| alias | Client-defined identifier of the alert. | Optional |
| description | Description field of the alert that is generally used to provide detailed information about the alert. | Optional |
| responders | Teams/users to whom the alert is routed via notifications. You need to insert it as List of triples - responder_type,value_type,value. The responder_type can be: team, user, escalation or schedule. The value_type can be: id or name. You can retrieve the value from the output of the following commands ‘!opsgenie-get-teams’, ‘!opsgenie-get-schedules’ or ‘!opsgenie-get-escalations’. For example: schedule,name,test_schedule,user,id,123,team,name,test_team. |
Optional |
| tags | Comma-separated list of tags to add. | Optional |
| priority | Incident priority. Possible values are: P1, P2, P3, P4, P5. Default is P3. | Optional |
| source | Display name of the request source. Defaults to IP address of the request sender. | Optional |
| note | Additional alert note. | Optional |
| details | Comma-separated key=value pairs to use as custom properties of the alert. JSON format is also supported when used within an automation. Examples; details=”account=pa,hostname=computer01”. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.Alert.action | String | Action of this request. |
| OpsGenie.Alert.alertId | String | ID of the created alert. |
| OpsGenie.Alert.alias | String | Alias of the created alert. |
| OpsGenie.Alert.integrationId | String | Integration ID of the created alert. |
| OpsGenie.Alert.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.Alert.processedAt | Date | When the request was processed. |
| OpsGenie.Alert.requestId | String | The ID of the request. |
| OpsGenie.Alert.status | String | The human readable result of the request. |
| OpsGenie.Alert.success | Boolean | Whether the request was successful. |
Command Example
!opsgenie-create-alert message="Example Message"
Context Example
{
"OpsGenie": {
"Alert": {
"action": "Create",
"alertId": "4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716",
"alias": "4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716",
"integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
"isSuccess": true,
"processedAt": "2021-12-01T13:48:18.757Z",
"status": "Created alert",
"success": true
}
}
}
Human Readable Output
OpsGenie
action alertId alias integrationId isSuccess processedAt status success Create 4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716 4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716 3cc69931-167f-411c-a331-768997c29d2e true 2021-12-01T13:48:18.757Z Created alert true
opsgenie-get-alerts
List the current alerts from OpsGenie.
Base Command
opsgenie-get-alerts
Input
| Argument Name | Description | Required |
|---|---|---|
| alert-id | The ID of the alert from Opsgenie. | Optional |
| sort | Name of the field that the result set will be sorted by. The options are: createdAt, updatedAt, tinyId, alias, message, status, acknowledged, isSeen snoozed, snoozedUntil, count, lastOccurredAt, source, owner, integration.name, integration.type, report.ackTime, report.closeTime, report.acknowledgedBy, report.closedBy. |
Optional |
| limit | Maximum results to return. Default is 20. | Optional |
| offset | Start index of the result set (to apply pagination). Minimum value is 0. Default is 0. | Optional |
| status | The status of the alert from Opsgenie. Possible values are: Open, Closed. | Optional |
| priority | The priority of the alert from Opsgenie. Possible values are: P1, P2, P3, P4, P5. Default is P3. | Optional |
| tags | Comma-separated list of tags. | Optional |
| query | URL encoded query parameters. | Optional |
| request_id | ID of the polling request. No need to enter a value. | Optional |
| paging | The next URL to request. No need to enter a value. | Optional |
| result | Result of the previous command. No need to enter a value. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.Alert.acknowledged | Boolean | Whether the alert was acknowledge. |
| OpsGenie.Alert.alias | String | Alert alias. |
| OpsGenie.Alert.count | Number | Number of alert occurrences. |
| OpsGenie.Alert.createdAt | Date | Time the alert was created. |
| OpsGenie.Alert.id | String | ID of the alert. |
| OpsGenie.Alert.integration.id | String | ID of the integration. |
| OpsGenie.Alert.integration.name | String | Integration name. |
| OpsGenie.Alert.integration.type | String | Type of the integration. |
| OpsGenie.Alert.isSeen | Boolean | Whether the alert was seen. |
| OpsGenie.Alert.lastOccurredAt | Date | Time the alert last occurred. |
| OpsGenie.Alert.message | String | Alert message. |
| OpsGenie.Alert.owner | String | Owner of the alert. |
| OpsGenie.Alert.ownerTeamId | String | Team ID of the owner. |
| OpsGenie.Alert.priority | String | Alert priority. |
| OpsGenie.Alert.responders.id | String | ID of the responders. |
| OpsGenie.Alert.responders.type | String | Type of the responders. |
| OpsGenie.Alert.seen | Boolean | Whether the alert was seen. |
| OpsGenie.Alert.snoozed | Boolean | Whether alert was snoozed. |
| OpsGenie.Alert.source | String | Source of the alert. |
| OpsGenie.Alert.status | String | Status of the alert. |
| OpsGenie.Alert.teams.id | String | ID of the teams associated with the alert. |
| OpsGenie.Alert.tinyId | String | Short ID for the alert. |
| OpsGenie.Alert.updatedAt | Date | Last time the alert was updated. |
| OpsGenie.Alert.report.ackTime | Number | Time the alert was acknowledged. |
| OpsGenie.Alert.report.acknowledgedBy | String | User who acknowledged the alert. |
| OpsGenie.Alert.report.closeTime | Number | Time the alert was closed. |
| OpsGenie.Alert.report.closedBy | String | User who closed the alert. |
Command Example
!opsgenie-get-alerts limit=1
Context Example
{
"OpsGenie": {
"Alert": [
{
"acknowledged": false,
"alias": "4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716",
"count": 1,
"createdAt": "2021-12-01T13:48:18.716Z",
"event_type": "Alerts",
"id": "4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716",
"integration": {
"id": "3cc69931-167f-411c-a331-768997c29d2e",
"name": "API",
"type": "API"
},
"isSeen": false,
"lastOccurredAt": "2021-12-01T13:48:18.716Z",
"message": "Example Message",
"owner": "",
"ownerTeamId": "",
"priority": "P3",
"responders": [],
"seen": false,
"snoozed": false,
"source": "192.168.x.x",
"status": "open",
"tags": [],
"teams": [],
"tinyId": "194",
"updatedAt": "2021-12-01T13:48:18.787Z"
}
]
}
}
Human Readable Output
OpsGenie
id createdAt acknowledged count status 4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716 2021-12-01T13:48:18.716Z false 1 open
opsgenie-delete-alert
Delete an alert from OpsGenie.
Base Command
opsgenie-delete-alert
Input
| Argument Name | Description | Required |
|---|---|---|
| alert-id | The ID of the alert from Opsgenie. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.DeletedAlert.action | String | Action of this request. |
| OpsGenie.DeletedAlert.alertId | String | ID of the deleted alert. |
| OpsGenie.DeletedAlert.alias | String | Alias of the deleted alert. |
| OpsGenie.DeletedAlert.integrationId | String | Integration of the deleted alert. |
| OpsGenie.DeletedAlert.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.DeletedAlert.processedAt | Date | When the request was processed. |
| OpsGenie.DeletedAlert.requestId | String | The ID of the request. |
| OpsGenie.DeletedAlert.status | String | The human readable result of the request. |
| OpsGenie.DeletedAlert.success | Boolean | Whether the request was successful. |
Command Example
!opsgenie-delete-alert alert-id=69df59c2-41c6-4866-8c03-65c1ecf5417d-1636973048286
Context Example
{
"OpsGenie": {
"DeletedAlert": {
"action": "Delete",
"alertId": "",
"alias": "",
"integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
"isSuccess": false,
"processedAt": "2021-12-01T13:48:40.911Z",
"status": "Alert does not exist",
"success": false
}
}
}
Human Readable Output
OpsGenie
action alertId alias integrationId isSuccess processedAt status success Delete 3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:40.911Z Alert does not exist false
opsgenie-ack-alert
Acknowledge an alert in OpsGenie.
Base Command
opsgenie-ack-alert
Input
| Argument Name | Description | Required |
|---|---|---|
| alert-id | The ID of the alert from Opsgenie. | Required |
| note | Additional alert note. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.AckedAlert.action | String | Action of this request. |
| OpsGenie.AckedAlert.alertId | String | ID of the acknowledged alert. |
| OpsGenie.AckedAlert.alias | String | Alias of the acknowledged alert. |
| OpsGenie.AckedAlert.integrationId | String | Integration of the acknowledged alert. |
| OpsGenie.AckedAlert.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.AckedAlert.processedAt | Date | When the request was processed. |
| OpsGenie.AckedAlert.requestId | String | The ID of the request. |
| OpsGenie.AckedAlert.status | String | The human readable result of the request. |
| OpsGenie.AckedAlert.success | Boolean | Whether the request was successful. |
Command Example
!opsgenie-ack-alert alert-id=69df59c2-41c6-4866-8c03-65c1ecf5417d-1636973048286
Context Example
{
"OpsGenie": {
"AckedAlert": {
"action": "Acknowledge",
"alertId": "",
"alias": "",
"integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
"isSuccess": false,
"processedAt": "2021-12-01T13:48:23.374Z",
"status": "Alert does not exist",
"success": false
}
}
}
Human Readable Output
OpsGenie
action alertId alias integrationId isSuccess processedAt status success Acknowledge 3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:23.374Z Alert does not exist false
opsgenie-close-alert
Close an alert in OpsGenie.
Base Command
opsgenie-close-alert
Input
| Argument Name | Description | Required |
|---|---|---|
| alert-id | The ID of the alert from Opsgenie. | Required |
| note | Additional alert note. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.ClosedAlert.action | String | Action of this request. |
| OpsGenie.ClosedAlert.alertId | String | ID of the closed alert. |
| OpsGenie.ClosedAlert.alias | String | Alias of the closed alert. |
| OpsGenie.ClosedAlert.integrationId | String | Integration ID of the acknowledged alert. |
| OpsGenie.ClosedAlert.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.ClosedAlert.processedAt | Date | When the request was processed. |
| OpsGenie.ClosedAlert.requestId | String | The ID of the request. |
| OpsGenie.ClosedAlert.status | String | The human readable result of the request. |
| OpsGenie.ClosedAlert.success | Boolean | Whether the request was successful. |
Command Example
!opsgenie-close-alert alert-id=69df59c2-41c6-4866-8c03-65c1ecf5417d-1636973048286
Context Example
{
"OpsGenie": {
"ClosedAlert": {
"action": "Close",
"alertId": "",
"alias": "",
"integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
"isSuccess": false,
"processedAt": "2021-12-01T13:48:38.491Z",
"status": "Alert does not exist",
"success": false
}
}
}
Human Readable Output
OpsGenie
action alertId alias integrationId isSuccess processedAt status success Close 3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:38.491Z Alert does not exist false
opsgenie-assign-alert
Assign an OpsGenie alert.
Base Command
opsgenie-assign-alert
Input
| Argument Name | Description | Required |
|---|---|---|
| alert-id | ID of the Opsgenie alert. | Required |
| owner_id | ID of the user to whom the alert will be assigned. Not required if owner_username is present. | Optional |
| owner_username | Display name of the request owner. Not required if owner_id is present. | Optional |
| note | Additional alert note. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.AssignAlert.action | String | Action of this request. |
| OpsGenie.AssignAlert.alertId | String | ID of assigned Alert |
| OpsGenie.AssignAlert.alias | String | Alias of the assigned alert. |
| OpsGenie.AssignAlert.integrationId | String | Integration ID of the assigned alert. |
| OpsGenie.AssignAlert.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.AssignAlert.processedAt | Date | When the request was processed. |
| OpsGenie.AssignAlert.requestId | String | The ID of the request. |
| OpsGenie.AssignAlert.status | String | The human readable result of the request. |
| OpsGenie.AssignAlert.success | Boolean | Whether the request was successful. |
Command Example
!opsgenie-assign-alert alert-id=69df59c2-41c6-4866-8c03-65c1ecf5417d-1636973048286 owner_username=b@g.com
Context Example
{
"OpsGenie": {
"AssignAlert": {
"action": "Assign",
"alertId": "",
"alias": "",
"integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
"isSuccess": false,
"processedAt": "2021-12-01T13:48:24.942Z",
"status": "Alert does not exist",
"success": false
}
}
}
Human Readable Output
OpsGenie
action alertId alias integrationId isSuccess processedAt status success Assign 3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:24.942Z Alert does not exist false
opsgenie-add-responder-alert
Add a responder to an OpsGenie alert.
Base Command
opsgenie-add-responder-alert
Input
| Argument Name | Description | Required |
|---|---|---|
| alert-id | ID of the Opsgenie alert. | Required |
| identifierType | Type of the identifier. Possible values are: id, tiny, alias. | Optional |
| responders | Team/user to whom the alert is routed via notifications. For now, it can be inserted only one responder at a time. You need to insert it as List of triple - responder_type,value_type,value. The responder_type can be: team or user. The value_type can be: id or name. You can retrieve the value from the output of the following ‘!opsgenie-get-teams’ command. For example: user,id,123 Another example: team,name,test_team. |
Required |
| note | Additional alert note. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.AddResponderAlert.action | String | Action of this request. |
| OpsGenie.AddResponderAlert.alertId | String | ID of the created alert. |
| OpsGenie.AddResponderAlert.alias | String | Alias of the created alert. |
| OpsGenie.AddResponderAlert.integrationId | String | Integration ID of the created alert. |
| OpsGenie.AddResponderAlert.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.AddResponderAlert.processedAt | Date | When the request was processed. |
| OpsGenie.AddResponderAlert.requestId | String | The ID of the request. |
| OpsGenie.AddResponderAlert.status | String | The human readable result of the request. |
| OpsGenie.AddResponderAlert.success | Boolean | Whether the request was successful. |
Command Example
!opsgenie-add-responder-alert alert-id=69df59c2-41c6-4866-8c03-65c1ecf5417d-1636973048286 responders=schedule,name,test_schedule
Context Example
{
"OpsGenie": {
"AddResponderAlert": {
"action": "Add Responder",
"alertId": "",
"alias": "",
"integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
"isSuccess": false,
"processedAt": "2021-12-01T13:48:26.82Z",
"status": "Alert does not exist",
"success": false
}
}
}
Human Readable Output
OpsGenie
action alertId alias integrationId isSuccess processedAt status success Add Responder 3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:26.82Z Alert does not exist false
opsgenie-get-escalations
Get escalations from OpsGenie.
Base Command
opsgenie-get-escalations
Input
| Argument Name | Description | Required |
|---|---|---|
| escalation_id | ID of the escalation. | Optional |
| escalation_name | Name of the escalation. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.Escalation.action | String | Action of this request. |
| OpsGenie.Escalation.Id | String | ID of the escalation. |
| OpsGenie.Escalation.name | String | Name of the escalation. |
| OpsGenie.Escalation.description | String | Description of the escalation. |
| OpsGenie.Escalation.ownerTeam | String | Owner team of the escalation. |
| OpsGenie.Escalation.rules | String | Rules of the escalation. |
| OpsGenie.Escalation.integrationId | String | Integration ID of the escalated alert. |
| OpsGenie.Escalation.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.Escalation.processedAt | Date | When the request was processed. |
| OpsGenie.Escalation.requestId | String | The ID of the request. |
| OpsGenie.Escalation.status | String | The human readable result of the request. |
| OpsGenie.Escalation.success | Boolean | Whether the request was successful. |
Command Example
#### Context Example
```json
{
"OpsGenie": {
"Escalations": [
{
"description": "",
"id": "9a441a8d-2410-43f4-9ef2-f7a265e12b74",
"name": "Engineering_escalation",
"ownerTeam": {
"id": "51d69df8-c40b-439e-9808-e1a78e54f91b",
"name": "Engineering"
},
"rules": [
{
"condition": "if-not-acked",
"delay": {
"timeAmount": 0,
"timeUnit": "minutes"
},
"notifyType": "default",
"recipient": {
"id": "7835aa84-7440-41d5-90bf-92e0045714d5",
"name": "Engineering_schedule",
"type": "schedule"
}
},
{
"condition": "if-not-acked",
"delay": {
"timeAmount": 5,
"timeUnit": "minutes"
},
"notifyType": "next",
"recipient": {
"id": "7835aa84-7440-41d5-90bf-92e0045714d5",
"name": "Engineering_schedule",
"type": "schedule"
}
},
{
"condition": "if-not-acked",
"delay": {
"timeAmount": 10,
"timeUnit": "minutes"
},
"notifyType": "all",
"recipient": {
"id": "51d69df8-c40b-439e-9808-e1a78e54f91b",
"name": "Engineering",
"type": "team"
}
}
]
},
{
"description": "",
"id": "c8a0f950-577c-4da5-894b-1fd463d9f51c",
"name": "Integration Team_escalation",
"ownerTeam": {
"id": "fbbc3f9a-12f4-4794-9938-7e0a85a06f8b",
"name": "Integration Team"
},
"rules": [
{
"condition": "if-not-acked",
"delay": {
"timeAmount": 0,
"timeUnit": "minutes"
},
"notifyType": "default",
"recipient": {
"id": "df918339-b999-4878-b69b-3c2c0d508b01",
"name": "Integration Team_schedule",
"type": "schedule"
}
},
{
"condition": "if-not-acked",
"delay": {
"timeAmount": 1,
"timeUnit": "minutes"
},
"notifyType": "default",
"recipient": {
"id": "154d6425-c120-4beb-a3e6-a66c8c44f61d",
"type": "user",
"username": "dvilenchik@example.com"
}
},
{
"condition": "if-not-acked",
"delay": {
"timeAmount": 5,
"timeUnit": "minutes"
},
"notifyType": "next",
"recipient": {
"id": "df918339-b999-4878-b69b-3c2c0d508b01",
"name": "Integration Team_schedule",
"type": "schedule"
}
},
{
"condition": "if-not-acked",
"delay": {
"timeAmount": 10,
"timeUnit": "minutes"
},
"notifyType": "all",
"recipient": {
"id": "fbbc3f9a-12f4-4794-9938-7e0a85a06f8b",
"name": "Integration Team",
"type": "team"
}
}
]
}
]
}
}
Human Readable Output
OpsGenie Escalations
description id name ownerTeam rules 9a441a8d-2410-43f4-9ef2-f7a265e12b74 Engineering_escalation id: 51d69df8-c40b-439e-9808-e1a78e54f91b
name: Engineering{‘condition’: ‘if-not-acked’, ‘notifyType’: ‘default’, ‘delay’: {‘timeAmount’: 0, ‘timeUnit’: ‘minutes’}, ‘recipient’: {‘type’: ‘schedule’, ‘id’: ‘7835aa84-7440-41d5-90bf-92e0045714d5’, ‘name’: ‘Engineering_schedule’}},
{‘condition’: ‘if-not-acked’, ‘notifyType’: ‘next’, ‘delay’: {‘timeAmount’: 5, ‘timeUnit’: ‘minutes’}, ‘recipient’: {‘type’: ‘schedule’, ‘id’: ‘7835aa84-7440-41d5-90bf-92e0045714d5’, ‘name’: ‘Engineering_schedule’}},
{‘condition’: ‘if-not-acked’, ‘notifyType’: ‘all’, ‘delay’: {‘timeAmount’: 10, ‘timeUnit’: ‘minutes’}, ‘recipient’: {‘type’: ‘team’, ‘id’: ‘51d69df8-c40b-439e-9808-e1a78e54f91b’, ‘name’: ‘Engineering’}}c8a0f950-577c-4da5-894b-1fd463d9f51c Integration Team_escalation id: fbbc3f9a-12f4-4794-9938-7e0a85a06f8b
name: Integration Team{‘condition’: ‘if-not-acked’, ‘notifyType’: ‘default’, ‘delay’: {‘timeAmount’: 0, ‘timeUnit’: ‘minutes’}, ‘recipient’: {‘type’: ‘schedule’, ‘id’: ‘df918339-b999-4878-b69b-3c2c0d508b01’, ‘name’: ‘Integration Team_schedule’}},
{‘condition’: ‘if-not-acked’, ‘notifyType’: ‘default’, ‘delay’: {‘timeAmount’: 1, ‘timeUnit’: ‘minutes’}, ‘recipient’: {‘type’: ‘user’, ‘id’: ‘154d6425-c120-4beb-a3e6-a66c8c44f61d’, ‘username’: ‘dvilenchik@example.com’}},
{‘condition’: ‘if-not-acked’, ‘notifyType’: ‘next’, ‘delay’: {‘timeAmount’: 5, ‘timeUnit’: ‘minutes’}, ‘recipient’: {‘type’: ‘schedule’, ‘id’: ‘df918339-b999-4878-b69b-3c2c0d508b01’, ‘name’: ‘Integration Team_schedule’}},
{‘condition’: ‘if-not-acked’, ‘notifyType’: ‘all’, ‘delay’: {‘timeAmount’: 10, ‘timeUnit’: ‘minutes’}, ‘recipient’: {‘type’: ‘team’, ‘id’: ‘fbbc3f9a-12f4-4794-9938-7e0a85a06f8b’, ‘name’: ‘Integration Team’}}
opsgenie-escalate-alert
Escalate an OpsGenie alert.
Base Command
opsgenie-escalate-alert
Input
| Argument Name | Description | Required |
|---|---|---|
| alert-id | ID of the Opsgenie alert. | Required |
| escalation_name | Name of the escalation to which the alert will be escalated. Provide either the ID or name of the escalation. | Optional |
| escalation_id | ID of the escalation to which the alert will be escalated. Provide either the ID or name of the escalation. | Optional |
| note | Additional alert note. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.EscalateAlert.action | String | Action of this request. |
| OpsGenie.EscalateAlert.id | String | ID of the escalation. |
| OpsGenie.EscalateAlert.name | String | Name of the escalation. |
| OpsGenie.EscalateAlert.description | String | Description of the escalation. |
| OpsGenie.EscalateAlert.integrationId | String | Integration ID of the escalated alert. |
| OpsGenie.EscalateAlert.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.EscalateAlert.processedAt | Date | When the request was processed. |
| OpsGenie.EscalateAlert.requestId | String | The ID of the request. |
| OpsGenie.EscalateAlert.status | String | The human readable result of the request. |
| OpsGenie.EscalateAlert.success | Boolean | Whether the request was successful. |
Command Example
!opsgenie-escalate-alert alert-id=69df59c2-41c6-4866-8c03-65c1ecf5417d-1636973048286 escalation_id=9a441a8d-2410-43f4-9ef2-f7a265e12b74
Context Example
{
"OpsGenie": {
"EscalateAlert": {
"action": "Escalate",
"alertId": "",
"alias": "",
"integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
"isSuccess": false,
"processedAt": "2021-12-01T13:48:31.549Z",
"status": "Alert does not exist",
"success": false
}
}
}
Human Readable Output
OpsGenie
action alertId alias integrationId isSuccess processedAt status success Escalate 3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:31.549Z Alert does not exist false
opsgenie-add-alert-tag
Add tag to the OpsGenie alert.
Base Command
opsgenie-add-alert-tag
Input
| Argument Name | Description | Required |
|---|---|---|
| alert-id | ID of the Opsgenie alert. | Required |
| tags | Comma-separated list of tags to add to the alert. | Required |
| note | Additional alert note. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.AddTagAlert.action | String | Action of this request. |
| OpsGenie.AddTagAlert.alertId | String | ID of the added alert. |
| OpsGenie.AddTagAlert.alias | String | Alias of the added alert. |
| OpsGenie.AddTagAlert.integrationId | String | Integration ID of the added alert. |
| OpsGenie.AddTagAlert.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.AddTagAlert.processedAt | Date | When the request was processed. |
| OpsGenie.AddTagAlert.requestId | String | The ID of the request. |
| OpsGenie.AddTagAlert.status | String | The human readable result of the request. |
| OpsGenie.AddTagAlert.success | Boolean | Whether the request was successful. |
Command Example
!opsgenie-add-alert-tag alert-id=69df59c2-41c6-4866-8c03-65c1ecf5417d-1636973048286 tags=1,2,3
Context Example
{
"OpsGenie": {
"AddTagAlert": {
"action": "Add Tags",
"alertId": "",
"alias": "",
"integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
"isSuccess": false,
"processedAt": "2021-12-01T13:48:33.376Z",
"status": "Alert does not exist",
"success": false
}
}
}
Human Readable Output
OpsGenie
action alertId alias integrationId isSuccess processedAt status success Add Tags 3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:33.376Z Alert does not exist false
opsgenie-remove-alert-tag
Remove a tag from the OpsGenie alert.
Base Command
opsgenie-remove-alert-tag
Input
| Argument Name | Description | Required |
|---|---|---|
| alert-id | ID of the Opsgenie alert. | Required |
| tags | Comma-separated list of tags to remove from the alert. | Required |
| note | Additional alert note. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.RemoveTagAlert.action | String | Action of this request. |
| OpsGenie.RemoveTagAlert.alertId | String | ID of the tag removed from the alert. |
| OpsGenie.RemoveTagAlert.alias | String | Alias of the removed tag alert. |
| OpsGenie.RemoveTagAlert.integrationId | String | Integration ID of the removed tag alert. |
| OpsGenie.RemoveTagAlert.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.RemoveTagAlert.processedAt | Date | When the request was processed. |
| OpsGenie.RemoveTagAlert.requestId | String | The ID of the request. |
| OpsGenie.RemoveTagAlert.status | String | The human readable result of the request. |
| OpsGenie.RemoveTagAlert.success | Boolean | Whether the request was successful. |
Command Example
!opsgenie-remove-alert-tag alert-id=69df59c2-41c6-4866-8c03-65c1ecf5417d-1636973048286 tags=1,2,3
Context Example
{
"OpsGenie": {
"RemoveTagAlert": {
"action": "Remove Tags",
"alertId": "",
"alias": "",
"integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
"isSuccess": false,
"processedAt": "2021-12-01T13:48:35.606Z",
"status": "Alert does not exist",
"success": false
}
}
}
Human Readable Output
OpsGenie
action alertId alias integrationId isSuccess processedAt status success Remove Tags 3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:35.606Z Alert does not exist false
opsgenie-get-alert-attachments
Get the attachments of the alert.
Base Command
opsgenie-get-alert-attachments
Input
| Argument Name | Description | Required |
|---|---|---|
| alert-id | ID of the Opsgenie alert. | Required |
| attachment_id | Identifier of the attachment. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.Alert.Attachment.action | String | Action of this request. |
| OpsGenie.Alert.Attachment.alertId | String | ID of the alert. |
| OpsGenie.Alert.Attachment.alias | String | Alias of the alert. |
| OpsGenie.Alert.Attachment.integrationId | String | Integration ID the alert. |
| OpsGenie.Alert.Attachment.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.Alert.Attachment.processedAt | Date | When the request was processed. |
| OpsGenie.Alert.Attachment.requestId | String | The ID of the request. |
| OpsGenie.Alert.Attachment.status | String | The human readable result of the request. |
| OpsGenie.Alert.Attachment.success | Boolean | Whether the request was successful. |
Command Example
#### Human Readable Output
### opsgenie-get-schedules
***
Get a schedule from OpsGenie.
#### Base Command
`opsgenie-get-schedules`
#### Input
| **Argument Name** | **Description** | **Required** |
| --- | --- | --- |
| schedule_id | ID of the schedule. | Optional |
| schedule_name | Name of the schedule. | Optional |
#### Context Output
| **Path** | **Type** | **Description** |
| --- | --- | --- |
| OpsGenie.Schedule.description | String | Description of the schedule. |
| OpsGenie.Schedule.enabled | Boolean | Whether the schedule was enabled. |
| OpsGenie.Schedule.id | String | ID of the schedule. |
| OpsGenie.Schedule.name | String | Name of the schedule. |
| OpsGenie.Schedule.ownerTeam.id | String | ID of the schedule owner. |
| OpsGenie.Schedule.ownerTeam.name | String | Name of the schedule owner. |
| OpsGenie.Schedule.timezone | String | Timezone of the schedule. |
#### Command Example
```!opsgenie-get-schedules```
#### Context Example
```json
{
"OpsGenie": {
"Schedule": [
{
"description": "Schedule when escalation was activated",
"enabled": true,
"id": "5892636c-6183-4788-99d6-6d93b9095194",
"name": "Escalation Schedule",
"ownerTeam": {
"id": "fbbc3f9a-12f4-4794-9938-7e0a85a06f8b",
"name": "Integration Team"
},
"rotations": [],
"timezone": "Asia/Jerusalem"
},
{
"description": "",
"enabled": true,
"id": "7835aa84-7440-41d5-90bf-92e0045714d5",
"name": "Engineering_schedule",
"ownerTeam": {
"id": "51d69df8-c40b-439e-9808-e1a78e54f91b",
"name": "Engineering"
},
"rotations": [],
"timezone": "Asia/Jerusalem"
},
{
"description": "24/7 Shift",
"enabled": true,
"id": "df918339-b999-4878-b69b-3c2c0d508b01",
"name": "Integration Team_schedule",
"ownerTeam": {
"id": "fbbc3f9a-12f4-4794-9938-7e0a85a06f8b",
"name": "Integration Team"
},
"rotations": [],
"timezone": "Asia/Jerusalem"
}
]
}
}
Human Readable Output
OpsGenie Schedule
description enabled id name ownerTeam rotations timezone Schedule when escalation was activated true 5892636c-6183-4788-99d6-6d93b9095194 Escalation Schedule id: fbbc3f9a-12f4-4794-9938-7e0a85a06f8b
name: Integration TeamAsia/Jerusalem true 7835aa84-7440-41d5-90bf-92e0045714d5 Engineering_schedule id: 51d69df8-c40b-439e-9808-e1a78e54f91b
name: EngineeringAsia/Jerusalem 24/7 Shift true df918339-b999-4878-b69b-3c2c0d508b01 Integration Team_schedule id: fbbc3f9a-12f4-4794-9938-7e0a85a06f8b
name: Integration TeamAsia/Jerusalem
opsgenie-get-schedule-overrides
Get schedule overrides.
Base Command
opsgenie-get-schedule-overrides
Input
| Argument Name | Description | Required |
|---|---|---|
| schedule_id | ID of the schedule. | Optional |
| schedule_name | Name of the schedule. | Optional |
| override_alias | Alias of the schedule override. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.Schedule.Override.action | String | Action of this request. |
| OpsGenie.Schedule.Override.alertId | String | ID of the schedule. |
| OpsGenie.Schedule.Override.alias | String | Alias of the schedule. |
| OpsGenie.Schedule.Override.integrationId | String | Integration ID of the schedule. |
| OpsGenie.Schedule.Override.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.Schedule.Override.processedAt | Date | When the request was processed. |
| OpsGenie.Schedule.Override.requestId | String | The ID of the request. |
| OpsGenie.Schedule.Override.status | String | The human readable result of the request. |
| OpsGenie.Schedule.Override.success | Boolean | Whether the request was successful. |
Command Example
!opsgenie-get-schedule-overrides schedule_id=5892636c-6183-4788-99d6-6d93b9095194
Human Readable Output
OpsGenie Schedule
No entries.
opsgenie-get-on-call
Get the on-call users for the provided schedule.
Base Command
opsgenie-get-on-call
Input
| Argument Name | Description | Required |
|---|---|---|
| schedule_id | Schedule ID from which to return on-call users. | Optional |
| schedule_name | Name of the schedule from which to return on-call users. | Optional |
| starting_date | Start date of the timeline in the following format (yyyy-MM-dd’T’HH:mm:ssZ). | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.Schedule.OnCall._parent.enabled | Boolean | Whether this on-call schedule is enabled. |
| OpsGenie.Schedule.OnCall._parent.id | String | ID Of the parent on-call schedule. |
| OpsGenie.Schedule.OnCall._parent.name | String | Name of parent on-call schedule. |
| OpsGenie.Schedule.OnCall.onCallParticipants.id | String | ID of the on-call participant. |
| OpsGenie.Schedule.OnCall.onCallParticipants.name | String | Name of the on-call participant. |
| OpsGenie.Schedule.OnCall.onCallParticipants.type | String | Type of the on-call participant. |
Command Example
!opsgenie-get-on-call schedule_id=5892636c-6183-4788-99d6-6d93b9095194
Context Example
{
"OpsGenie": {
"Schedule": {
"OnCall": {
"data": {
"_parent": {
"enabled": true,
"id": "5892636c-6183-4788-99d6-6d93b9095194",
"name": "Escalation Schedule"
},
"onCallParticipants": [
{
"id": "154d6425-c120-4beb-a3e6-a66c8c44f61d",
"name": "dvilenchik@example.com",
"type": "user"
}
]
},
"requestId": "e88ae246-5d0f-4ebf-826c-f3617e6a3d42",
"took": 0.007
}
}
}
}
Human Readable Output
OpsGenie Schedule OnCall
_parent onCallParticipants id: 5892636c-6183-4788-99d6-6d93b9095194
name: Escalation Schedule
enabled: true{‘id’: ‘154d6425-c120-4beb-a3e6-a66c8c44f61d’, ‘name’: ‘dvilenchik@example.com’, ‘type’: ‘user’}
opsgenie-create-incident
Create an incident in Opsgenie.
Base Command
opsgenie-create-incident
Input
| Argument Name | Description | Required |
|---|---|---|
| interval_in_seconds | Interval in seconds between each poll. Default is 5. | Optional |
| message | Incident message. | Required |
| description | Detailed information about the incident. | Optional |
| responders | Teams/users to whom the incident is routed via notifications. You need to insert it as List of triples - responder_type,value_type,value. The responder_type can be: team or user. The value_type can be: id or name. You can retrieve the value from the output of the ‘!opsgenie-get-teams’ command. For example: user,id,123,team,name,test_team. |
Optional |
| tags | Comma-separated list of tags to add. | Optional |
| priority | Incident Priority. Possible values are: P1, P2, P3, P4, P5. Default is P3. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.Incident.action | String | Action of this request. |
| OpsGenie.Incident.incidentId | String | ID of the created incident. |
| OpsGenie.Incident.integrationId | String | Integration ID of the created alert. |
| OpsGenie.Incident.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.Incident.processedAt | Date | When the request was processed. |
| OpsGenie.Incident.requestId | String | The ID of the request. |
| OpsGenie.Incident.status | String | The human readable result of the request. |
| OpsGenie.Incident.success | Boolean | Whether the request was successful. |
Command Example
!opsgenie-create-incident message="test" responders=team,name,test_team,team,name,test_team_1
Context Example
{
"OpsGenie": {
"Incident": {
"action": "Create",
"incidentId": "4ba53100-30dc-47a6-992a-a96df4d1ba20",
"integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
"isSuccess": true,
"processedAt": "2021-12-01T13:48:49.133Z",
"status": "Incident created successfully",
"success": true
}
}
}
Human Readable Output
OpsGenie
action incidentId integrationId isSuccess processedAt status success Create 4ba53100-30dc-47a6-992a-a96df4d1ba20 3cc69931-167f-411c-a331-768997c29d2e true 2021-12-01T13:48:49.133Z Incident created successfully true
opsgenie-delete-incident
Delete an incident from OpsGenie.
Base Command
opsgenie-delete-incident
Input
| Argument Name | Description | Required |
|---|---|---|
| incident_id | The ID of the incident from Opsgenie. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.DeletedIncident.action | String | Action of this request. |
| OpsGenie.DeletedIncident.incidentId | String | ID of the deleted incident. |
| OpsGenie.DeletedIncident.integrationId | String | Integration ID of the deleted incident. |
| OpsGenie.DeletedIncident.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.DeletedIncident.processedAt | Date | When the request was processed. |
| OpsGenie.DeletedIncident.requestId | String | The ID of the request. |
| OpsGenie.DeletedIncident.status | String | The human readable result of the request. |
| OpsGenie.DeletedIncident.success | Boolean | Whether the request was successful. |
Command Example
!opsgenie-delete-incident incident_id=c59086e0-bf2c-44e2-bdfb-ed7747cc126b
Context Example
{
"OpsGenie": {
"DeletedIncident": {
"action": "Delete",
"incidentId": "",
"integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
"isSuccess": false,
"processedAt": "2021-12-01T13:48:52.534Z",
"status": "",
"success": false
}
}
}
Human Readable Output
OpsGenie
action incidentId integrationId isSuccess processedAt status success Delete 3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:52.534Z false
opsgenie-get-incidents
List the current incidents from OpsGenie.
Base Command
opsgenie-get-incidents
Input
| Argument Name | Description | Required |
|---|---|---|
| incident_id | The ID of the incident from Opsgenie. | Optional |
| limit | Maximum number of results to return. Default is 20. | Optional |
| offset | Start index of the result set (to apply pagination). Minimum value is 0. Default is 0. | Optional |
| status | The status of the alert from Opsgenie. Possible values are: Open, Closed. | Optional |
| priority | Incident Priority. Possible values are: P1, P2, P3, P4, P5. Default is P3. | Optional |
| tags | Comma-separated list of tags to add. | Optional |
| query | URL encoded query parameters. | Optional |
| request_id | ID of the polling request. No need to enter a value. | Optional |
| paging | The next URL to request. No need to enter a value. | Optional |
| result | Result of the previous command. No need to enter a value. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.Incident.count | Number | The number of alert occurrences. |
| OpsGenie.Incident.createdAt | Date | Time the alert was created. |
| OpsGenie.Incident.incidentId | String | ID of the alert. |
| OpsGenie.Incident.integration.id | String | ID of the integration. |
| OpsGenie.Incident.integration.name | String | Integration name |
| OpsGenie.Incident.integration.type | String | Type of the integration. |
| OpsGenie.Incident.message | String | Alert message. |
| OpsGenie.Incident.ownerTeam | String | Team ID of the owner. |
| OpsGenie.Incident.priority | String | Alert priority. |
| OpsGenie.Incident.responders.id | String | ID of the responders. |
| OpsGenie.Incident.responders.type | String | Type of the responders. |
| OpsGenie.Incident.status | String | Status of the alert. |
| OpsGenie.Incident.tinyId | String | Short ID for the alert. |
| OpsGenie.Incident.updatedAt | Date | Last updated time for the alert. |
Command Example
!opsgenie-get-incidents limit=1
Context Example
{
"OpsGenie": {
"Incident": [
{
"actions": [],
"createdAt": "2021-12-01T13:48:49.006Z",
"description": "",
"event_type": "Incidents",
"extraProperties": {},
"id": "4ba53100-30dc-47a6-992a-a96df4d1ba20",
"impactStartDate": "2021-12-01T13:48:49.006Z",
"impactedServices": [],
"links": {
"api": "https://api.opsgenie.com/v1/incidents/4ba53100-30dc-47a6-992a-a96df4d1ba20",
"web": "https://demisto1.app.opsgenie.com/incident/detail/4ba53100-30dc-47a6-992a-a96df4d1ba20"
},
"message": "test",
"ownerTeam": "",
"priority": "P3",
"responders": [],
"status": "open",
"tags": [],
"tinyId": "100",
"updatedAt": "2021-12-01T13:48:49.006Z"
}
]
}
}
Human Readable Output
OpsGenie
id createdAt status 4ba53100-30dc-47a6-992a-a96df4d1ba20 2021-12-01T13:48:49.006Z open
opsgenie-close-incident
Close an incident from OpsGenie.
Base Command
opsgenie-close-incident
Input
| Argument Name | Description | Required |
|---|---|---|
| incident_id | The ID of the incident from Opsgenie. | Required |
| note | Additional incident note. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.ClosedIncident.action | String | Action of this request. |
| OpsGenie.ClosedIncident.incidentId | String | ID of the closed incident. |
| OpsGenie.ClosedIncident.integrationId | String | Integration ID of the closed incident |
| OpsGenie.ClosedIncident.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.ClosedIncident.processedAt | Date | When the request was processed. |
| OpsGenie.ClosedIncident.requestId | String | The ID of the request. |
| OpsGenie.ClosedIncident.status | String | The human readable result of the request. |
| OpsGenie.ClosedIncident.success | Boolean | Whether the request was successful. |
Command Example
!opsgenie-close-incident incident_id=c59086e0-bf2c-44e2-bdfb-ed7747cc126b
Context Example
{
"OpsGenie": {
"ClosedIncident": {
"action": "Close",
"incidentId": "",
"integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
"isSuccess": false,
"processedAt": "2021-12-01T13:48:50.974Z",
"status": "",
"success": false
}
}
}
Human Readable Output
OpsGenie
action incidentId integrationId isSuccess processedAt status success Close 3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:50.974Z false
opsgenie-resolve-incident
Resolve an incident from OpsGenie.
Base Command
opsgenie-resolve-incident
Input
| Argument Name | Description | Required |
|---|---|---|
| incident_id | The ID of the incident from Opsgenie. | Required |
| note | Additional incident note. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.ResolvedIncident.action | String | Action of this request. |
| OpsGenie.ResolvedIncident.incidentId | String | ID of the closed incident. |
| OpsGenie.ResolvedIncident.integrationId | String | Integration ID of the closed incident. |
| OpsGenie.ResolvedIncident.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.ResolvedIncident.processedAt | Date | When the request was processed. |
| OpsGenie.ResolvedIncident.requestId | String | The ID of the request. |
| OpsGenie.ResolvedIncident.status | String | The human readable result of the request. |
| OpsGenie.ResolvedIncident.success | Boolean | Whether the request was successful. |
Command Example
!opsgenie-resolve-incident incident_id=b15c7555-d685-4a96-8798-46320618004e
Context Example
{
"OpsGenie": {
"ResolvedIncident": {
"action": "Resolve",
"incidentId": "",
"integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
"isSuccess": false,
"processedAt": "2021-12-01T13:48:57.042Z",
"status": "",
"success": false
}
}
}
Human Readable Output
OpsGenie
action incidentId integrationId isSuccess processedAt status success Resolve 3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:57.042Z false
opsgenie-add-responder-incident
Add a responder to an OpsGenie incident.
Base Command
opsgenie-add-responder-incident
Input
| Argument Name | Description | Required |
|---|---|---|
| incident_id | The ID of the incident from Opsgenie. | Required |
| responders | Teams/users to whom the incident is routed via notifications. You need to insert it as list of triples - responder_type,value_type,value. The responder_type can be: team or user. The value_type can be: id or name. You can retrieve the value from the output of the ‘!opsgenie-get-teams’ command. For example: user,id,123,team,name,test_team. |
Required |
| note | Additional alert note. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.AddResponderIncident.action | String | Action of this request. |
| OpsGenie.AddResponderIncident.incidentId | String | ID of the created incident. |
| OpsGenie.AddResponderIncident.integrationId | String | Integration ID of the created incident. |
| OpsGenie.AddResponderIncident.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.AddResponderIncident.processedAt | Date | When the request was processed. |
| OpsGenie.AddResponderIncident.requestId | String | The ID of the request. |
| OpsGenie.AddResponderIncident.status | String | The human readable result of the request. |
| OpsGenie.AddResponderIncident.success | Boolean | Whether the request was successful. |
Command Example
!opsgenie-add-responder-incident incident_id=577424c1-b03c-4d23-9871-da0d395fea17 responders="team,name,Integration Team"
Context Example
{
"OpsGenie": {
"AddResponderIncident": {
"action": "Add Responder",
"incidentId": "",
"integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
"isSuccess": false,
"processedAt": "2021-12-01T13:48:59.193Z",
"status": "Given teams/users already added as responders.",
"success": false
}
}
}
Human Readable Output
OpsGenie
action incidentId integrationId isSuccess processedAt status success Add Responder 3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:59.193Z Given teams/users already added as responders. false
opsgenie-add-tag-incident
Add a tag to the OpsGenie incident.
Base Command
opsgenie-add-tag-incident
Input
| Argument Name | Description | Required |
|---|---|---|
| incident_id | The ID of the incident from Opsgenie. | Required |
| tags | Comma-separated list of tags to add to the incident. | Required |
| note | Additional incident note. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.AddTagIncident.action | String | Action of this request. |
| OpsGenie.AddTagIncident.incidentId | String | ID of the added incident. |
| OpsGenie.AddTagIncident.integrationId | String | Integration ID of the added incident. |
| OpsGenie.AddTagIncident.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.AddTagIncident.processedAt | Date | When the request was processed. |
| OpsGenie.AddTagIncident.requestId | String | The ID of the request. |
| OpsGenie.AddTagIncident.status | String | The human readable result of the request. |
| OpsGenie.AddTagIncident.success | Boolean | Whether the request was successful. |
Command Example
!opsgenie-add-tag-incident incident_id=b15c7555-d685-4a96-8798-46320618004e tags=1,2,3
Context Example
{
"OpsGenie": {
"AddTagIncident": {
"action": "Add Tags",
"incidentId": "b15c7555-d685-4a96-8798-46320618004e",
"integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
"isSuccess": true,
"processedAt": "2021-12-01T13:49:00.839Z",
"status": "Added tags",
"success": true
}
}
}
Human Readable Output
OpsGenie
action incidentId integrationId isSuccess processedAt status success Add Tags b15c7555-d685-4a96-8798-46320618004e 3cc69931-167f-411c-a331-768997c29d2e true 2021-12-01T13:49:00.839Z Added tags true
opsgenie-remove-tag-incident
Remove a tag from the OpsGenie alert.
Base Command
opsgenie-remove-tag-incident
Input
| Argument Name | Description | Required |
|---|---|---|
| incident_id | The ID of the incident from Opsgenie. | Required |
| tags | Comma-separated list of tags to add to the incident. | Required |
| note | Additional incident note. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.RemoveTagIncident.action | String | Action of this request. |
| OpsGenie.RemoveTagIncident.incidentId | String | Incident ID of the remove tag incident. |
| OpsGenie.RemoveTagIncident.integrationId | String | Integration ID of the remove tag incident. |
| OpsGenie.RemoveTagIncident.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.RemoveTagIncident.processedAt | Date | When the request was processed. |
| OpsGenie.RemoveTagIncident.requestId | String | The ID of the request. |
| OpsGenie.RemoveTagIncident.status | String | The human readable result of the request. |
| OpsGenie.RemoveTagIncident.success | Boolean | Whether the request was successful. |
Command Example
!opsgenie-remove-tag-incident incident_id=b15c7555-d685-4a96-8798-46320618004e tags=1,2
Context Example
{
"OpsGenie": {
"RemoveTagIncident": {
"action": "Remove Tags",
"incidentId": "b15c7555-d685-4a96-8798-46320618004e",
"integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
"isSuccess": true,
"processedAt": "2021-12-01T13:49:02.53Z",
"status": "Removed tags",
"success": true
}
}
}
Human Readable Output
OpsGenie
action incidentId integrationId isSuccess processedAt status success Remove Tags b15c7555-d685-4a96-8798-46320618004e 3cc69931-167f-411c-a331-768997c29d2e true 2021-12-01T13:49:02.53Z Removed tags true
opsgenie-invite-user
Invite a user to OpsGenie
Base Command
opsgenie-invite-user
Input
| Argument Name | Description | Required |
|---|---|---|
| username | E-mail address of the user. | True |
| fullName | Name of the user | True |
| role | Role of user. It may be one of admin, user or the name of a custom role you’ve created. | True |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.User.Id | String | ID of the User |
| OpsGenie.User.name | String | Username of the user |
Command Example
!opsgenie-invite-user username=test@example.com fullName="Test XSOAR" role=user
Context Example
{
"OpsGenie": {
"User": {
"id": "f14b51c9-151b-48b2-afda-e2fcc182f230-1613001837514",
"name": "test@example.com"
}
}
}
Human Readable Output
OpsGenie
Id name 3cc69931-167f-411c-a331-768997c29d2e test@example.com
opsgenie-get-teams
Get teams
Base Command
opsgenie-get-teams
Input
| Argument Name | Description | Required |
|---|---|---|
| team_id | The ID of the team from Opsgenie. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.Team.description | String | Team description. |
| OpsGenie.Team.id | String | Team ID. |
| OpsGenie.Team.links.api | String | Team API links. |
| OpsGenie.Team.links.web | String | Team web links. |
| OpsGenie.Team.name | String | Team name. |
Command Example
#### Context Example
```json
{
"OpsGenie": {
"Team": [
{
"description": "Engineering",
"id": "51d69df8-c40b-439e-9808-e1a78e54f91b",
"links": {
"api": "https://api.opsgenie.com/v2/teams/51d69df8-c40b-439e-9808-e1a78e54f91b",
"web": "https://demisto1.app.opsgenie.com/teams/dashboard/51d69df8-c40b-439e-9808-e1a78e54f91b/main"
},
"name": "Engineering"
},
{
"description": "Integration Team",
"id": "fbbc3f9a-12f4-4794-9938-7e0a85a06f8b",
"links": {
"api": "https://api.opsgenie.com/v2/teams/fbbc3f9a-12f4-4794-9938-7e0a85a06f8b",
"web": "https://demisto1.app.opsgenie.com/teams/dashboard/fbbc3f9a-12f4-4794-9938-7e0a85a06f8b/main"
},
"name": "Integration Team"
}
]
}
}
Human Readable Output
OpsGenie Team
description id links name Engineering 51d69df8-c40b-439e-9808-e1a78e54f91b web: https://demisto1.app.opsgenie.com/teams/dashboard/51d69df8-c40b-439e-9808-e1a78e54f91b/main
api: https://api.opsgenie.com/v2/teams/51d69df8-c40b-439e-9808-e1a78e54f91bEngineering Integration Team fbbc3f9a-12f4-4794-9938-7e0a85a06f8b web: https://demisto1.app.opsgenie.com/teams/dashboard/fbbc3f9a-12f4-4794-9938-7e0a85a06f8b/main
api: https://api.opsgenie.com/v2/teams/fbbc3f9a-12f4-4794-9938-7e0a85a06f8bIntegration Team
opsgenie-get-request
Get a request in Opsgenie.
Base Command
opsgenie-get-request
Input
| Argument Name | Description | Required |
|---|---|---|
| request_id | The id of the request to get | Required |
| request_type | The type of the request to get | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.Alert.action | String | Action of this request. |
| OpsGenie.Alert.alertId | String | ID of the created alert. |
| OpsGenie.Alert.alias | String | Alias of the created alert. |
| OpsGenie.Alert.integrationId | String | Integration ID of the created alert. |
| OpsGenie.Alert.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.Alert.processedAt | Date | When the request was processed. |
| OpsGenie.Alert.requestId | String | The ID of the request. |
| OpsGenie.Alert.status | String | The human readable result of the request. |
| OpsGenie.Alert.success | Boolean | Whether the request was successful. |
| OpsGenie.Incident.action | String | Action of this request. |
| OpsGenie.Incident.alertId | String | ID of the created alert. |
| OpsGenie.Incident.alias | String | Alias of the created alert. |
| OpsGenie.Incident.integrationId | String | Integration ID of the created alert. |
| OpsGenie.Incident.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.Incident.processedAt | Date | When the request was processed. |
| OpsGenie.Incident.requestId | String | The ID of the request. |
| OpsGenie.Incident.status | String | The human readable result of the request. |
| OpsGenie.Incident.success | Boolean | Whether the request was successful. |
Command Example
opsgenie-get-request request_id=b79800b2-4378-4249-8677-0bf2332b8a1f request_type=alerts"
Context Example
{
"OpsGenie": {
"Alert": {
"action": "Create",
"alertId": "4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716",
"alias": "4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716",
"integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
"isSuccess": true,
"processedAt": "2021-12-01T13:48:18.757Z",
"status": "Created alert",
"success": true
}
}
}
Human Readable Output
OpsGenie
action alertId alias integrationId isSuccess processedAt status success Create 4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716 4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716 3cc69931-167f-411c-a331-768997c29d2e true 2021-12-01T13:48:18.757Z Created alert true
Breaking changes from the previous version of this integration - OpsGenie v3
Commands
Removed the following commands in this version:
- opsgenie-list-alerts - this command was replaced by opsgenie-get-alerts.
- opsgenie-get-alert - this command was replaced by opsgenie-get-alerts.
- opsgenie-get-schedule - this command was replaced by opsgenie-get-schedules.
- opsgenie-list-schedules - this command was replaced by opsgenie-get-schedules.
Arguments
- In the opsgenie-get-on-call command, the schedule-id argument was replaced by the schedule_id and schedule_name arguments.
- In the opsgenie-create-alert command, the default value of the priority argument was changed to ‘P3’.
Outputs
- In the opsgenie-create-alert command the following outputs were replaced:
- OpsGenieV2.CreatedAlert.action - replaced by OpsGenie.Alert.action.
- OpsGenieV2.CreatedAlert.alertId - replaced by OpsGenie.Alert.alertId.
- OpsGenieV2.CreatedAlert.alias - replaced by OpsGenie.Alert.alias.
- OpsGenieV2.CreatedAlert.integrationId - replaced by OpsGenie.Alert.integrationId.
- OpsGenieV2.CreatedAlert.isSuccess - replaced by OpsGenie.Alert.isSuccess.
- OpsGenieV2.CreatedAlert.processedAt - replaced by OpsGenie.Alert.processedAt.
- OpsGenieV2.CreatedAlert.requestId - replaced by OpsGenie.Alert.requestId.
- OpsGenieV2.CreatedAlert.status - replaced by OpsGenie.Alert.status.
- OpsGenieV2.CreatedAlert.success - replaced by OpsGenie.Alert.success.
- In the opsgenie-delete-alert command the following outputs were replaced:
- OpsGenieV2.DeletedAlert.action - replaced by OpsGenie.DeletedAlert.action.
- OpsGenieV2.DeletedAlert.alertId - replaced by OpsGenie.DeletedAlert.alertId.
- OpsGenieV2.DeletedAlert.alias - replaced by OpsGenie.DeletedAlert.alias.
- OpsGenieV2.DeletedAlert.integrationId - replaced by OpsGenie.DeletedAlert.integrationId.
- OpsGenieV2.DeletedAlert.isSuccess - replaced by OpsGenie.DeletedAlert.isSuccess.
- OpsGenieV2.DeletedAlert.processedAt - replaced by OpsGenie.DeletedAlert.processedAt.
- OpsGenieV2.DeletedAlert.requestId - replaced by OpsGenie.DeletedAlert.requestId.
- OpsGenieV2.DeletedAlert.status - replaced by OpsGenie.DeletedAlert.status.
- OpsGenieV2.DeletedAlert.success - replaced by OpsGenie.DeletedAlert.success.
- In the opsgenie-ack-alert command the following outputs were replaced:
- OpsGenieV2.AckedAlert.action - replaced by OpsGenie.AckedAlert.action.
- OpsGenieV2.AckedAlert.alertId -replaced by OpsGenie.AckedAlert.alertId.
- OpsGenieV2.AckedAlert.alias -replaced by OpsGenie.AckedAlert.alias.
- OpsGenieV2.AckedAlert.integrationId - replaced by OpsGenie.AckedAlert.integrationId.
- OpsGenieV2.AckedAlert.isSuccess - replaced by OpsGenie.AckedAlert.isSuccess.
- OpsGenieV2.AckedAlert.processedAt - replaced by OpsGenie.AckedAlert.processedAt.
- OpsGenieV2.AckedAlert.requestId - replaced by OpsGenie.AckedAlert.requestId.
- OpsGenieV2.AckedAlert.status - replaced by OpsGenie.AckedAlert.status.
- OpsGenieV2.AckedAlert.success - replaced by OpsGenie.AckedAlert.success.
- In the opsgenie-get-on-call command the following outputs were replaced:
- OpsGenieV2.OnCall._parent.enabled - replaced by OpsGenie.Schedule.OnCall._parent.enabled.
- OpsGenieV2.OnCall._parent.id - replaced by OpsGenie.Schedule.OnCall._parent.id.
- OpsGenieV2.OnCall._parent.name - replaced by OpsGenie.Schedule.OnCall._parent.name.
- OpsGenieV2.OnCall.onCallParticipants.id - replaced by OpsGenie.Schedule.OnCall.onCallParticipants.id.
- OpsGenieV2.OnCall.onCallParticipants.name - replaced by OpsGenie.Schedule.OnCall.onCallParticipants.name.
- OpsGenieV2.OnCall.onCallParticipants.type - replaced by OpsGenie.Schedule.OnCall.onCallParticipants.type.
- In the opsgenie-close-alert command the following outputs were replaced:
- OpsGenieV2.CloseAlert.action - replaced by OpsGenie.ClosedAlert.action.
- OpsGenieV2.CloseAlert.alertId - replaced by OpsGenie.ClosedAlert.alertId.
- OpsGenieV2.CloseAlert.alias - replaced by OpsGenie.ClosedAlert.alias.
- OpsGenieV2.CloseAlert.integrationId - replaced by OpsGenie.ClosedAlert.integrationId.
- OpsGenieV2.CloseAlert.isSuccess - replaced by OpsGenie.ClosedAlert.isSuccess.
- OpsGenieV2.CloseAlert.processedAt - replaced by OpsGenie.ClosedAlert.processedAt.
- OpsGenieV2.CloseAlert.requestId - replaced by OpsGenie.ClosedAlert.requestId.
- OpsGenieV2.CloseAlert.status - replaced by OpsGenie.ClosedAlert.status.
- OpsGenieV2.CloseAlert.success - replaced by OpsGenie.ClosedAlert.success.
opsgenie-get-team-routing-rules
Lists team routing rules.
Base Command
opsgenie-get-team-routing-rules
Input
| Argument Name | Description | Required |
|---|---|---|
| team_id | The ID of the team from Opsgenie. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.TeamRoutingRule.name | unknown | Name of the routing rule. |
| OpsGenie.TeamRoutingRule.order | unknown | Order of the routing rule. |
| OpsGenie.TeamRoutingRule.id | unknown | ID of the routing rule. |
| OpsGenie.TeamRoutingRule.timezone | unknown | Timezone of the routing rule. |
| OpsGenie.TeamRoutingRule.teamId | unknown | Team ID of the routing rule. |
| OpsGenie.TeamRoutingRule.customerId | unknown | Customer ID of the routing rule. |
| OpsGenie.TeamRoutingRule.notify.id | unknown | Notify ID of the routing rule. |
| OpsGenie.TeamRoutingRule.notify.name | unknown | Notify name of the routing rule. |
| OpsGenie.TeamRoutingRule.notify.type | unknown | Notify type of the routing rule. |
opsgenie-get-alert-logs
Gets logs of an OpsGenie Alert.
Base Command
opsgenie-get-alert-logs
Input
| Argument Name | Description | Required |
|---|---|---|
| alert_id | Alert ID. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.AlertLogs.createdAt | String | Time the alert was created. |
| OpsGenie.AlertLogs.log | String | Log of the alert. |
| OpsGenie.AlertLogs.offset | String | Offset of the alert log. |
| OpsGenie.AlertLogs.owner | String | Owner of the alert log. |
| OpsGenie.AlertLogs.type | String | Type of the alert log. |
opsgenie-add-alert-note
Adds a note to an OpsGenie Alert.
Base Command
opsgenie-add-alert-note
Input
| Argument Name | Description | Required |
|---|---|---|
| alert_id | Alert ID to add the note to. | Required |
| note | Alert note to add. | Required |
| user | Display name of the request owner. | Optional |
| source | Display name of the request source. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.AddAlertNote.action | String | Action of this request. |
| OpsGenie.AddAlertNote.alertId | String | ID of the created alert. |
| OpsGenie.AddAlertNote.alias | String | Alias of the created alert. |
| OpsGenie.AddAlertNote.integrationId | String | Integration ID of the created alert. |
| OpsGenie.AddAlertNote.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.AddAlertNote.processedAt | Date | When the request was processed. |
| OpsGenie.AddAlertNote.requestId | String | The ID of the request. |
| OpsGenie.AddAlertNote.status | String | The human readable result of the request. |
| OpsGenie.AddAlertNote.success | Boolean | Whether the request was successful. |
opsgenie-add-alert-details
Adds details to an OpsGenie Alert.
Base Command
opsgenie-add-alert-details
Input
| Argument Name | Description | Required |
|---|---|---|
| alert_id | Alert ID to add the details to. | Required |
| details | Comma-separated key=value pairs to use as custom properties of the alert. JSON format is also supported when used within an automation. Examples; details=”account=pa,hostname=computer01”. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| OpsGenie.AddAlertDetails.action | String | Action of this request. |
| OpsGenie.AddAlertDetails.alertId | String | ID of the created alert. |
| OpsGenie.AddAlertDetails.alias | String | Alias of the created alert. |
| OpsGenie.AddAlertDetails.integrationId | String | Integration ID of the created alert. |
| OpsGenie.AddAlertDetails.isSuccess | Boolean | Whether the request was successful. |
| OpsGenie.AddAlertDetails.processedAt | Date | When the request was processed. |
| OpsGenie.AddAlertDetails.requestId | String | The ID of the request. |
| OpsGenie.AddAlertDetails.status | String | The human readable result of the request. |
| OpsGenie.AddAlertDetails.success | Boolean | Whether the request was successful. |
Configuration parameters
url— Server URL (e.g., https://api.opsgenie.com) (required)credentials— (required)isFetch— Fetch incidentsfirst_fetch— First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)max_fetch— Max Fetchevent_types— Event typesstatus— Statuspriority— Prioritytags— Tagsquery— QueryincidentType— Incident typeincidentFetchInterval— Incidents Fetch Intervalinsecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (30)
-
opsgenie-ack-alertAcknowledge an alert in OpsGenie.
-
opsgenie-add-alert-detailsAdds details to an OpsGenie Alert.
-
opsgenie-add-alert-noteAdds a note to an OpsGenie Alert.
-
opsgenie-add-alert-tagAdd tag to the OpsGenie alert.
-
opsgenie-add-responder-alertAdd a responder to an OpsGenie alert.
-
opsgenie-add-responder-incidentAdd a responder to an OpsGenie incident.
-
opsgenie-add-tag-incidentAdd a tag to the OpsGenie incident.
-
opsgenie-assign-alertAssign an OpsGenie alert.
-
opsgenie-close-alertClose an alert in OpsGenie.
-
opsgenie-close-incidentClose an incident from OpsGenie.
-
opsgenie-create-alertCreate an alert in Opsgenie.
-
opsgenie-create-incidentCreate an incident in Opsgenie.
-
opsgenie-delete-alertDelete an alert from OpsGenie.
-
opsgenie-delete-incidentDelete an incident from OpsGenie.
-
opsgenie-escalate-alertEscalate an OpsGenie alert.
-
opsgenie-get-alert-attachmentsGet the attachments of the alert.
-
opsgenie-get-alert-logsGets logs of an OpsGenie Alert.
-
opsgenie-get-alertsList the current alerts from OpsGenie.
-
opsgenie-get-escalationsGet escalations from OpsGenie.
-
opsgenie-get-incidentsList the current incidents from OpsGenie.
-
opsgenie-get-on-callGet the on-call users for the provided schedule.
-
opsgenie-get-requestGet a request in Opsgenie.
-
opsgenie-get-schedule-overridesGet schedule overrides.
-
opsgenie-get-schedulesGet a schedule from OpsGenie.
-
opsgenie-get-team-routing-rulesLists team routing rules.
-
opsgenie-get-teamsGet teams.
-
opsgenie-invite-userInvite a user to OpsGenie.
-
opsgenie-remove-alert-tagRemove a tag from the OpsGenie alert.
-
opsgenie-remove-tag-incidentRemove a tag from the OpsGenie alert.
-
opsgenie-resolve-incidentResolve an incident from OpsGenie.
from collections.abc import Callable import demistomock as demisto # noqa: F401 import urllib3 from CommonServerPython import * # noqa: F401 from requests import Response from CommonServerUserPython import * # noqa # Disable insecure warnings DEFAULT_POLL_INTERVAL = 5 urllib3.disable_warnings() """ CONSTANTS """ DEFAULT_POLL_TIMEOUT = 60 INTEGRATION_NAME = "Opsgenie" ALERTS_SUFFIX = "alerts" REQUESTS_SUFFIX = "requests" SCHEDULE_SUFFIX = "schedules" USERS_SUFFIX = "users" INCIDENTS_SUFFIX = "incidents" ESCALATION_SUFFIX = "escalations" TEAMS_SUFFIX = "teams" DATE_FORMAT = "%Y-%m-%dT%H:%M:%SZ" INCIDENT_TYPE = "Incidents" ALERT_TYPE = "Alerts" ALL_TYPE = "All" """ CLIENT CLASS """ class Client(BaseClient): """ OpsGenieV3 Client """ def get_request(self, args: dict) -> Response: url_suffix = "/v1" if args.get("request_type") == INCIDENTS_SUFFIX else "/v2" return self._http_request( method="GET", url_suffix=f"{url_suffix}/{args.get('request_type')}/{REQUESTS_SUFFIX}/{args.get('request_id')}", ok_codes=(404, 200), resp_type="response", ) def get_paged(self, args: dict): data = self._http_request(method="GET", full_url=args.get("paging")) return data @staticmethod # type: ignore def responders_to_json(responders: List, responder_key: str, one_is_dict: bool = False) -> Dict[str, Union[List, Dict]]: """ :param responders: the responders list which we get from demisto.args() :param responder_key: Some of the api calls need "responder" and others "responders" as a key in the responders jason :param one_is_dict: Some of the api calls need when there is one responder it as a dict and others as a list :return json_responders: reformatted respondres dict """ if not responders: return {} if len(responders) % 3 != 0: raise DemistoException("responders must be list of: responder_type, value_type, value") responders_triple = list(zip(responders[::3], responders[1::3], responders[2::3])) json_responders = {responder_key: []} # type: ignore for responder_type, value_type, value in responders_triple: if responder_type == "user" and value_type == "name": value_type = "username" json_responders[responder_key].append({value_type: value, "type": responder_type}) response = json_responders if len(responders_triple) == 1 and one_is_dict: response = {responder_key: json_responders[responder_key][0]} return response # type: ignore def create_alert(self, args: dict): args["responders"] = argToList(args.get("responders")) args["tags"] = argToList(args.get("tags")) if args.get("details") and not isinstance(args.get("details"), dict): args["details"] = {key_value.split("=")[0]: key_value.split("=")[1] for key_value in argToList(args.get("details"))} args.update(Client.responders_to_json(args.get("responders", []), "responders")) return self._http_request(method="POST", url_suffix=f"/v2/{ALERTS_SUFFIX}", json_data=args) def get_alert(self, alert_id: int): return self._http_request(method="GET", url_suffix=f"/v2/{ALERTS_SUFFIX}/{alert_id}") def list_alerts(self, args: dict): args["tags"] = argToList(args.get("tags")) params = {"limit": args.get("limit"), "offset": args.get("offset"), "query": Client.build_query(args)} res = self._http_request(method="GET", url_suffix=f"/v2/{ALERTS_SUFFIX}", params=params) if len(res.get("data", [])) > 0: for result in res.get("data"): result["event_type"] = ALERT_TYPE return res def delete_alert(self, args: dict): return self._http_request(method="DELETE", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert-id')}", json_data=args) def ack_alert(self, args: dict): return self._http_request( method="POST", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert-id')}/acknowledge", json_data=args ) def close_alert(self, args: dict): return self._http_request(method="POST", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert-id')}/close", json_data=args) def assign_alert(self, args: dict): return self._http_request(method="POST", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert-id')}/assign", json_data=args) def add_responder_alert(self, args: dict): alert_id = args.get("alert-id") identifier = args.get("identifierType", "id") args["responders"] = argToList(args.get("responders")) args.update(Client.responders_to_json(responders=args.get("responders", []), responder_key="responder", one_is_dict=True)) return self._http_request( method="POST", url_suffix=f"/v2/{ALERTS_SUFFIX}/{alert_id}/responders", params={"identifierType": identifier}, json_data=args, ) def get_escalation(self, args: dict): if args.get("escalation_id") and args.get("escalation_name"): raise DemistoException("Either escalation_id or escalation_name should be provided.") identifier_type = "id" if args.get("escalation_id") else "name" escalation = args.get("escalation_id", None) or args.get("escalation_name", None) return self._http_request( method="GET", url_suffix=f"/v2/{ESCALATION_SUFFIX}/{escalation}", params={"identifierType": identifier_type} ) def get_escalations(self): return self._http_request(method="GET", url_suffix=f"/v2/{ESCALATION_SUFFIX}") def escalate_alert(self, args: dict): return self._http_request( method="POST", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert-id')}/escalate", json_data=args ) def add_alert_tag(self, args: dict): args["tags"] = argToList(args.get("tags")) return self._http_request(method="POST", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert-id')}/tags", json_data=args) def add_alert_note(self, args: dict): return self._http_request(method="POST", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert_id')}/notes", json_data=args) def add_alert_details(self, args: dict): if not isinstance(args.get("details"), dict): args["details"] = {key_value.split("=")[0]: key_value.split("=")[1] for key_value in argToList(args.get("details"))} return self._http_request(method="POST", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert_id')}/details", json_data=args) def remove_alert_tag(self, args: dict): args["tags"] = argToList(args.get("tags")) return self._http_request( method="DELETE", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert-id')}/tags", params={"tags": args.get("tags")}, json_data=args, ) def get_alert_attachments(self, args: dict): attachment_id = args.get("attachment_id") if attachment_id: return self._http_request(method="GET", url_suffix=f"/v2/{ALERTS_SUFFIX}/attachments/{attachment_id}") return self._http_request(method="GET", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert-id')}/attachments") def get_alert_logs(self, args: dict): alert_id = args.get("alert_id") return self._http_request(method="GET", url_suffix=f"/v2/{ALERTS_SUFFIX}/{alert_id}/logs") def get_schedule(self, args: dict): if not is_one_argument_given(args.get("schedule_id"), args.get("schedule_name")): raise DemistoException("Either schedule_id or schedule_name should be provided.") identifier_type = "id" if args.get("schedule_id") else "name" schedule = args.get("schedule_id", None) or args.get("schedule_name", None) return self._http_request( method="GET", url_suffix=f"/v2/{SCHEDULE_SUFFIX}/{schedule}", params={"identifierType": identifier_type} ) def list_schedules(self): return self._http_request(method="GET", url_suffix=f"/v2/{SCHEDULE_SUFFIX}") def get_schedule_override(self, args: dict): identifier_type = "id" if args.get("schedule_id") else "name" schedule = args.get("schedule_id", None) or args.get("schedule_name", None) return self._http_request( method="GET", url_suffix=f"/v2/{SCHEDULE_SUFFIX}/{schedule}/overrides/{args.get('override_alias')}", params={"scheduleIdentifierType": identifier_type}, ) def list_schedule_overrides(self, args: dict): identifier_type = "id" if args.get("schedule_id") else "name" schedule = args.get("schedule_id", None) or args.get("schedule_name", None) return self._http_request( method="GET", url_suffix=f"/v2/{SCHEDULE_SUFFIX}/{schedule}/overrides", params={"scheduleIdentifierType": identifier_type}, ) def get_on_call(self, args: dict): return self._http_request( method="GET", url_suffix=f"/v2/{SCHEDULE_SUFFIX}/{args.get('schedule')}/on-calls", params={"scheduleIdentifierType": args.get("scheduleIdentifierType"), "date": args.get("date")}, ) def create_incident(self, args: dict): args["responders"] = argToList(args.get("responders")) args.update(Client.responders_to_json(args.get("responders", []), "responders")) return self._http_request(method="POST", url_suffix=f"/v1/{INCIDENTS_SUFFIX}/create", json_data=args) def delete_incident(self, args: dict): return self._http_request(method="DELETE", url_suffix=f"/v1/{INCIDENTS_SUFFIX}/{args.get('incident_id')}", json_data=args) def get_incident(self, args: dict): return self._http_request( method="GET", url_suffix=f"/v1/{INCIDENTS_SUFFIX}/{args.get('incident_id')}", ) @staticmethod def build_query(args: dict) -> str: query = "" if args.get("query", ""): query = args.get("query", "") if args.get("is_fetch_query", False) or not args.get("query", ""): status = args.get("status", ALL_TYPE) if status != ALL_TYPE: query += " AND " if query else "" query += f"status={status.lower()}" priority = argToList(args.get("priority", [ALL_TYPE])) if ALL_TYPE not in priority: query += " AND " if query else "" priority_parsed = " OR ".join(list(priority)) query += f"priority: ({priority_parsed})" tags = argToList(args.get("tags", [])) if tags: query += " AND " if query else "" tag_parsed = " OR ".join(list(tags)) query += f"tag: ({tag_parsed})" return query def list_incidents(self, args: dict): args["tags"] = argToList(args.get("tags")) params = {"limit": args.get("limit"), "offset": args.get("offset"), "query": Client.build_query(args)} res = self._http_request(method="GET", url_suffix=f"/v1/{INCIDENTS_SUFFIX}", params=params) if len(res.get("data", [])) > 0: for result in res.get("data"): result["event_type"] = INCIDENT_TYPE return res def close_incident(self, args: dict): return self._http_request( method="POST", url_suffix=f"/v1/{INCIDENTS_SUFFIX}/{args.get('incident_id')}/close", json_data=args ) def resolve_incident(self, args: dict): return self._http_request( method="POST", url_suffix=f"/v1/{INCIDENTS_SUFFIX}/{args.get('incident_id')}/resolve", json_data=args ) def add_responder_incident(self, args: dict): args["responders"] = argToList(args.get("responders")) args.update(Client.responders_to_json(args.get("responders", []), "responder")) return self._http_request( method="POST", url_suffix=f"/v1/{INCIDENTS_SUFFIX}/{args.get('incident_id')}/responders", json_data=args ) def add_tag_incident(self, args: dict): args["tags"] = argToList(args.get("tags")) return self._http_request( method="POST", url_suffix=f"/v1/{INCIDENTS_SUFFIX}/{args.get('incident_id')}/tags", json_data=args ) def remove_tag_incident(self, args: dict): args["tags"] = argToList(args.get("tags")) return self._http_request( method="DELETE", url_suffix=f"/v1/{INCIDENTS_SUFFIX}/{args.get('incident_id')}/tags", params={"tags": args.get("tags")}, json_data=args, ) def invite_user(self, args): return self._http_request(method="POST", url_suffix=f"/v2/{USERS_SUFFIX}", json_data=args) def get_team(self, args: dict): return self._http_request(method="GET", url_suffix=f"/v2/{TEAMS_SUFFIX}/{args.get('team_id')}") def get_team_routing_rules(self, args: dict): return self._http_request(method="GET", url_suffix=f"/v2/{TEAMS_SUFFIX}/{args.get('team_id')}/routing-rules") def list_teams(self): return self._http_request(method="GET", url_suffix=f"/v2/{TEAMS_SUFFIX}") """ HELPER FUNCTIONS """ def is_one_argument_given(arg1, arg2): """ checks that out of two arguments only one argument is set. :param arg1: first argument :param arg2: second argument :return: True if only one argument is set else False """ return bool(arg1) ^ bool(arg2) """ COMMAND FUNCTIONS """ def run_polling_paging_command( args: dict, cmd: str, results_function: Callable, action_function: Optional[Callable] = None ) -> CommandResults: ScheduledCommand.raise_error_if_not_supported() interval_in_secs = int(args.get("interval_in_seconds", DEFAULT_POLL_INTERVAL)) result = args.get("result", []) limit = int(args.get("limit", 20)) if "request_id" not in args and action_function: # starting new flow results = action_function(args) request_id = results.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {results}") next_paging = results.get("paging", {}).get("next") result = result + results.get("data") if not next_paging or len(result) >= limit: # If not a paged request, simply return return CommandResults( outputs_prefix=args.get("output_prefix", "OpsGenie"), outputs=results.get("data"), readable_output=tableToMarkdown( "OpsGenie", results.get("data"), headers=["id", "createdAt", "acknowledged", "count", "status", "tags"], removeNull=True, ), raw_response=results, ) else: # If a paged request, return scheduled_command args["request_id"] = request_id args["result"] = result args["paging"] = next_paging polling_args = {"interval_in_seconds": interval_in_secs, "polling": True, **args} scheduled_command = ScheduledCommand( command=cmd, next_run_in_seconds=int(args.get("interval_in_seconds", DEFAULT_POLL_INTERVAL)), args=polling_args, timeout_in_seconds=int(args.get("timeout_in_seconds", DEFAULT_POLL_TIMEOUT)), ) return CommandResults( scheduled_command=scheduled_command, readable_output=f"Waiting for request_id={request_id}", outputs_prefix=args.get("output_prefix", "OpsGenie"), outputs={"requestId": request_id}, ) results = results_function(args) result = result + results.get("data") results["data"] = result next_paging = results.get("paging", {}).get("next") if not next_paging or len(result) >= limit: # If not a paged request, simply return return CommandResults( outputs_prefix=args.get("output_prefix", "OpsGenie"), outputs=results.get("data"), readable_output=tableToMarkdown( "OpsGenie", results.get("data"), headers=["id", "createdAt", "acknowledged", "count", "status", "tags"], removeNull=True, ), raw_response=results, ) if len(result) < limit: # schedule next poll args["request_id"] = results.get("request_id") args["result"] = result args["paging"] = next_paging polling_args = {"interval_in_seconds": interval_in_secs, "polling": True, **args} scheduled_command = ScheduledCommand( command=cmd, next_run_in_seconds=int(args.get("interval_in_seconds", DEFAULT_POLL_INTERVAL)), args=polling_args, timeout_in_seconds=int(args.get("timeout_in_seconds", DEFAULT_POLL_TIMEOUT)), ) # result with scheduled_command only - no update to the war room command_results = CommandResults( scheduled_command=scheduled_command, readable_output=f"Waiting for request_id={args.get('request_id')}", outputs_prefix=args.get("output_prefix", "OpsGenie"), outputs={"requestId": args.get("request_id")}, ) return command_results return CommandResults( outputs_prefix=args.get("output_prefix", "OpsGenie"), outputs=results.get("data"), readable_output=tableToMarkdown( "OpsGenie", results.get("data"), headers=["id", "createdAt", "acknowledged", "count", "status", "tags"], removeNull=True, ), raw_response=results, ) def test_module(client: Client, params: dict) -> str: """ Tries to run list_alerts, returning OK if integration is working. """ result_list = client.list_alerts({"sort": "createdAt", "limit": 5}) result_fetch = [{"ok": "ok"}] if params.get("isFetch"): result_fetch, last_run = fetch_incidents_command(client, params) if result_list and result_fetch: return "ok" return "Failed." def create_alert(client: Client, args: Dict[str, Any]) -> CommandResults: args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.Alert", **args} data = client.create_alert(args) request_id = data.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {data}") args["request_id"] = request_id return get_request_command(client, args) def get_alerts(client: Client, args: Dict[str, Any]) -> CommandResults: alert_id = args.get("alert-id", None) result = client.get_alert(alert_id) if alert_id else list_alerts(client, args) if isinstance(result, CommandResults): return result return CommandResults( outputs_prefix="OpsGenie.Alert", outputs=result.get("data"), readable_output=tableToMarkdown( "OpsGenie Alert", result.get("data"), headers=["id", "createdAt", "acknowledged", "count", "status", "tags"], removeNull=True, ), raw_response=result, ) def list_alerts(client: Client, args: Dict[str, Any]) -> CommandResults: polling_args = { "url_suffix": f"/v2/{ALERTS_SUFFIX}", "output_prefix": "OpsGenie.Alert", "request_type": ALERTS_SUFFIX, **args, } polling_result = run_polling_paging_command( args=polling_args, cmd="opsgenie-get-alerts", action_function=client.list_alerts, results_function=client.get_paged ) return polling_result def delete_alert(client: Client, args: Dict[str, Any]) -> CommandResults: args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.DeletedAlert", **args} data = client.delete_alert(args) request_id = data.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {data}") args["request_id"] = request_id return get_request_command(client, args) def ack_alert(client: Client, args: Dict[str, Any]) -> CommandResults: args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.AckedAlert", **args} data = client.ack_alert(args) request_id = data.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {data}") args["request_id"] = request_id return get_request_command(client, args) def close_alert(client: Client, args: Dict[str, Any]) -> CommandResults: args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.ClosedAlert", **args} data = client.close_alert(args) request_id = data.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {data}") args["request_id"] = request_id return get_request_command(client, args) def assign_alert(client: Client, args: Dict[str, Any]) -> CommandResults: if args.get("owner_id"): owner = {"id": args.get("owner_id")} elif args.get("owner_username"): owner = {"username": args.get("owner_username")} else: # not args.get("owner_id") and not args.get("owner_username") raise DemistoException("Either owner_id or owner_username should be provided.") args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.AssignAlert", "owner": owner, **args} data = client.assign_alert(args) request_id = data.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {data}") args["request_id"] = request_id return get_request_command(client, args) def add_responder_alert(client: Client, args: Dict[str, Any]) -> CommandResults: args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.AddResponderAlert", **args} data = client.add_responder_alert(args) request_id = data.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {data}") args["request_id"] = request_id return get_request_command(client, args) def get_escalations(client: Client, args: Dict[str, Any]) -> CommandResults: escalation = args.get("escalation_id", None) or args.get("escalation_name", None) result = client.get_escalation(args) if escalation else client.get_escalations() return CommandResults( outputs_prefix="OpsGenie.Escalations", outputs=result.get("data"), readable_output=tableToMarkdown("OpsGenie Escalations", result.get("data")), raw_response=result, ) def escalate_alert(client: Client, args: Dict[str, Any]) -> CommandResults: if args.get("escalation_id"): escalation = {"id": args.get("escalation_id")} elif args.get("escalation_name"): escalation = {"name": args.get("escalation_name")} else: # not args.get("owner_id") and not args.get("owner_username") raise DemistoException("Either escalation_id or escalation_name should be provided.") args = {"request_type": ALERTS_SUFFIX, "escalation": escalation, "output_prefix": "OpsGenie.EscalateAlert", **args} data = client.escalate_alert(args) request_id = data.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {data}") args["request_id"] = request_id return get_request_command(client, args) def add_alert_tag(client: Client, args: Dict[str, Any]) -> CommandResults: args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.AddTagAlert", **args} data = client.add_alert_tag(args) request_id = data.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {data}") args["request_id"] = request_id return get_request_command(client, args) def add_alert_note(client: Client, args: Dict[str, Any]) -> CommandResults: args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.AddAlertNote", **args} data = client.add_alert_note(args) request_id = data.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {data}") args["request_id"] = request_id return get_request_command(client, args) def add_alert_details(client: Client, args: Dict[str, Any]) -> CommandResults: args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.AddAlertDetails", **args} data = client.add_alert_details(args) request_id = data.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {data}") args["request_id"] = request_id return get_request_command(client, args) def remove_alert_tag(client: Client, args: Dict[str, Any]) -> CommandResults: args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.RemoveTagAlert", **args} data = client.remove_alert_tag(args) request_id = data.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {data}") args["request_id"] = request_id return get_request_command(client, args) def get_alert_attachments(client: Client, args: Dict[str, Any]) -> CommandResults: result = client.get_alert_attachments(args) return CommandResults( outputs_prefix="OpsGenie.Alert.Attachment", outputs=result.get("data"), readable_output=tableToMarkdown("OpsGenie Attachment", result.get("data")), raw_response=result, ) def get_alert_logs(client: Client, args: Dict[str, Any]) -> CommandResults: result = client.get_alert_logs(args) data = result.get("data") return CommandResults( outputs_prefix="OpsGenie.AlertLogs", outputs=result.get("data"), readable_output=tableToMarkdown("OpsGenie Logs", data), raw_response=result, ) def get_schedules(client: Client, args: Dict[str, Any]) -> CommandResults: schedule = args.get("schedule_id", None) or args.get("schedule_name", None) result = client.get_schedule(args) if schedule else client.list_schedules() return CommandResults( outputs_prefix="OpsGenie.Schedule", outputs=result.get("data"), readable_output=tableToMarkdown("OpsGenie Schedule", result.get("data")), raw_response=result, ) def get_schedule_overrides(client: Client, args: Dict[str, Any]) -> CommandResults: if not args.get("schedule_id") and not args.get("schedule_name"): raise DemistoException("Either schedule_id or schedule_name should be provided.") result = client.get_schedule_override(args) if args.get("override_alias") else client.list_schedule_overrides(args) return CommandResults( outputs_prefix="OpsGenie.Schedule", outputs=result.get("data"), readable_output=tableToMarkdown("OpsGenie Schedule", result.get("data")), raw_response=result, ) def get_on_call(client: Client, args: Dict[str, Any]) -> CommandResults: if args.get("schedule_id"): schedule = args.get("schedule_id") schedule_identifier_type = "id" elif args.get("schedule_name"): schedule = args.get("schedule_name") schedule_identifier_type = "name" else: # not args.get("schedule_id") and not args.get("schedule_name") raise DemistoException("Either schedule_id or schedule_name should be provided.") date = arg_to_datetime(args.get("starting_date")) on_call_args = { "request_type": SCHEDULE_SUFFIX, "scheduleIdentifierType": schedule_identifier_type, "schedule": schedule, **args, } if date: on_call_args["date"] = date.isoformat() demisto.debug(f"get on call with date: {date}") result = client.get_on_call(on_call_args) command_result = CommandResults( outputs_prefix="OpsGenie.Schedule.OnCall", outputs=result, readable_output=tableToMarkdown("OpsGenie Schedule OnCall", result.get("data")), raw_response=result, ) return command_result def create_incident(client: Client, args: Dict[str, Any]) -> CommandResults: args = {"request_type": INCIDENTS_SUFFIX, "output_prefix": "OpsGenie.Incident", **args} data = client.create_incident(args) request_id = data.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {data}") args["request_id"] = request_id return get_request_command(client, args) def delete_incident(client: Client, args: Dict[str, Any]) -> CommandResults: args = {"request_type": INCIDENTS_SUFFIX, "output_prefix": "OpsGenie.DeletedIncident", **args} data = client.delete_incident(args) request_id = data.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {data}") args["request_id"] = request_id return get_request_command(client, args) def get_incidents(client: Client, args: Dict[str, Any]) -> CommandResults: incident_id = args.get("incident_id", None) result = client.get_incident(args) if incident_id else list_incidents(client, args) if isinstance(result, CommandResults): return result return CommandResults( outputs_prefix="OpsGenie.Incident", outputs=result.get("data"), readable_output=tableToMarkdown( "OpsGenie Incident", result.get("data"), headers=["id", "createdAt", "acknowledged", "count", "status", "tags"], removeNull=True, ), raw_response=result, ) def list_incidents(client: Client, args: Dict[str, Any]) -> CommandResults: polling_args = {"url_suffix": f"/v1/{INCIDENTS_SUFFIX}", "output_prefix": "OpsGenie.Incident", **args} polling_result = run_polling_paging_command( args=polling_args, cmd="opsgenie-get-incidents", action_function=client.list_incidents, results_function=client.get_paged ) return polling_result def close_incident(client: Client, args: Dict[str, Any]) -> CommandResults: args = {"request_type": INCIDENTS_SUFFIX, "output_prefix": "OpsGenie.ClosedIncident", **args} data = client.close_incident(args) request_id = data.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {data}") args["request_id"] = request_id return get_request_command(client, args) def resolve_incident(client: Client, args: Dict[str, Any]) -> CommandResults: args = {"request_type": INCIDENTS_SUFFIX, "output_prefix": "OpsGenie.ResolvedIncident", **args} data = client.resolve_incident(args) request_id = data.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {data}") args["request_id"] = request_id return get_request_command(client, args) def add_responder_incident(client: Client, args: Dict[str, Any]) -> CommandResults: args = {"request_type": INCIDENTS_SUFFIX, "output_prefix": "OpsGenie.AddResponderIncident", **args} data = client.add_responder_incident(args) request_id = data.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {data}") args["request_id"] = request_id return get_request_command(client, args) def add_tag_incident(client: Client, args: Dict[str, Any]) -> CommandResults: args = {"request_type": INCIDENTS_SUFFIX, "output_prefix": "OpsGenie.AddTagIncident", **args} data = client.add_tag_incident(args) request_id = data.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {data}") args["request_id"] = request_id return get_request_command(client, args) def remove_tag_incident(client: Client, args: Dict[str, Any]) -> CommandResults: args = {"request_type": INCIDENTS_SUFFIX, "output_prefix": "OpsGenie.RemoveTagIncident", **args} data = client.remove_tag_incident(args) request_id = data.get("requestId") if not request_id: raise ConnectionError(f"Failed to send request - {data}") args["request_id"] = request_id return get_request_command(client, args) def get_request_command(client: Client, args: Dict[str, Any]) -> CommandResults: request_type = str(args.get("request_type")) results: Response = client.get_request(args) if results.status_code == 404: ScheduledCommand.raise_error_if_not_supported() request_id = args.get("request_id") raw_res = {} if results.content: try: raw_res = json.loads(results.content) except ValueError: demisto.error(f"Failed to parse the response content : {results.content!s}") return CommandResults( raw_response=raw_res, readable_output=None if args.get("polled_once") else f"Waiting for request_id={request_id}", outputs_prefix=args.get("output_prefix", "OpsGenie.Request"), outputs=None if args.get("polled_once") else {"requestId": request_id}, scheduled_command=ScheduledCommand( command="opsgenie-get-request", next_run_in_seconds=int(args.get("interval_in_seconds", DEFAULT_POLL_INTERVAL)), args={**args, "polled_once": True}, timeout_in_seconds=int(args.get("timeout_in_seconds", DEFAULT_POLL_TIMEOUT)), ), ) else: results_dict = results.json() outputs_prefix = args.get("output_prefix", f"OpsGenie.{request_type.capitalize()[:-1]}") return CommandResults( outputs_prefix=outputs_prefix, outputs=results_dict.get("data"), readable_output=tableToMarkdown( f"OpsGenie - {pascalToSpace(outputs_prefix.split('.')[-1])}", results_dict.get("data") ), raw_response=results_dict, ) def invite_user(client, args) -> CommandResults: args["role"] = {"name": args.get("role")} result = client.invite_user(args) return CommandResults( outputs_prefix="OpsGenie.Users", outputs=result.get("data"), readable_output=tableToMarkdown("OpsGenie Users", result.get("data")), raw_response=result, ) def get_teams(client: Client, args: Dict[str, Any]) -> CommandResults: result = client.get_team(args) if args.get("team_id") else client.list_teams() return CommandResults( outputs_prefix="OpsGenie.Team", outputs=result.get("data"), readable_output=tableToMarkdown("OpsGenie Team", result.get("data")), raw_response=result, ) def get_team_routing_rules(client: Client, args: Dict[str, Any]) -> CommandResults: result = client.get_team_routing_rules(args) data = result.get("data") return CommandResults( outputs_prefix="OpsGenie.TeamRoutingRule", outputs=data, readable_output=tableToMarkdown("OpsGenie Team Routing Rules", data), raw_response=result, ) def _parse_fetch_time(fetch_time: str): fetch_time_date = dateparser.parse(date_string=f"{fetch_time} UTC") assert fetch_time_date is not None, f"could not parse {fetch_time} UTC" return fetch_time_date.strftime(DATE_FORMAT) def fetch_incidents_by_type( client: Client, query: Optional[str], limit: Optional[int], fetch_time: str, status: Optional[str], priority: Optional[str], tags: Optional[str], incident_fetching_func: Callable, now: datetime, last_run_dict: Optional[dict] = None, ): params: Dict[str, Any] = {} if not last_run_dict: new_last_run = _parse_fetch_time(fetch_time) last_run_dict = {"lastRun": new_last_run, "next_page": None} if last_run_dict.get("next_page"): raw_response = client.get_paged({"paging": last_run_dict.get("next_page")}) else: timestamp_now = int(now.timestamp()) last_run = last_run_dict.get("lastRun") last_run_date = dateparser.parse(last_run) # type: ignore assert last_run_date is not None, f"could not parse {last_run}" timestamp_last_run = int(last_run_date.timestamp()) time_query = f"createdAt>{timestamp_last_run} AND createdAt<={timestamp_now}" params["query"] = f"{query} AND {time_query}" if query else f"{time_query}" params["limit"] = limit params["is_fetch_query"] = bool(query) params["status"] = status params["priority"] = priority params["tags"] = tags raw_response = incident_fetching_func(params) last_run_dict["lastRun"] = now.strftime(DATE_FORMAT) data = raw_response.get("data") incidents = [] if data: for event in data: incidents.append({"name": event.get("message"), "occurred": event.get("createdAt"), "rawJSON": json.dumps(event)}) if last_run_dict.get("lastRun") < event.get("createdAt"): last_run_dict["lastRun"] = event.get("createdAt") return incidents, raw_response.get("paging", {}).get("next"), last_run_dict.get("lastRun") def _get_utc_now(): return datetime.utcnow() def fetch_incidents_command( client: Client, params: Dict[str, Any], last_run: Optional[Dict] = None ) -> tuple[List[Dict[str, Any]], Dict]: """Uses to fetch incidents into Demisto Documentation: https://github.com/demisto/content/tree/master/docs/fetching_incidents Args: client: Client object with request last_run: Last fetch object occurs params: demisto params Returns: incidents, new last_run """ demisto.debug(f"Got incidentType={params.get('event_types')}") event_type = params.get("event_types", [ALL_TYPE]) demisto.debug(f"Got event_type={event_type}") now = _get_utc_now() incidents = [] alerts = [] last_run_alerts = demisto.get(last_run, f"{ALERT_TYPE}.lastRun") next_page_alerts = demisto.get(last_run, f"{ALERT_TYPE}.next_page") last_run_incidents = demisto.get(last_run, f"{INCIDENT_TYPE}.lastRun") next_page_incidents = demisto.get(last_run, f"{INCIDENT_TYPE}.next_page") query = params.get("query") limit = int(params.get("max_fetch", 50)) fetch_time = params.get("first_fetch", "3 days").strip() status = params.get("status") priority = params.get("priority") tags = params.get("tags") if ALERT_TYPE in event_type or ALL_TYPE in event_type: alerts, next_page_alerts, last_run_alerts = fetch_incidents_by_type( client, query, limit, fetch_time, status, priority, tags, client.list_alerts, now, demisto.get(last_run, f"{ALERT_TYPE}"), ) if INCIDENT_TYPE in event_type or ALL_TYPE in event_type: incidents, next_page_incidents, last_run_incidents = fetch_incidents_by_type( client, query, limit, fetch_time, status, priority, tags, client.list_incidents, now, demisto.get(last_run, f"{INCIDENT_TYPE}"), ) return incidents + alerts, { ALERT_TYPE: {"lastRun": last_run_alerts, "next_page": next_page_alerts}, INCIDENT_TYPE: {"lastRun": last_run_incidents, "next_page": next_page_incidents}, } """ MAIN FUNCTION """ def main() -> None: api_key = demisto.params().get("credentials", {}).get("password") base_url = demisto.params().get("url") verify_certificate = not demisto.params().get("insecure", False) proxy = demisto.params().get("proxy", False) demisto.debug(f"Command being called is {demisto.command()}") try: client = Client( base_url=base_url, verify=verify_certificate, proxy=proxy, headers={ "Authorization": f"GenieKey {api_key}", }, ) commands = { "opsgenie-create-alert": create_alert, "opsgenie-invite-user": invite_user, "opsgenie-get-alerts": get_alerts, "opsgenie-delete-alert": delete_alert, "opsgenie-ack-alert": ack_alert, "opsgenie-close-alert": close_alert, "opsgenie-assign-alert": assign_alert, "opsgenie-add-responder-alert": add_responder_alert, "opsgenie-get-escalations": get_escalations, "opsgenie-escalate-alert": escalate_alert, "opsgenie-add-alert-tag": add_alert_tag, "opsgenie-add-alert-note": add_alert_note, "opsgenie-add-alert-details": add_alert_details, "opsgenie-remove-alert-tag": remove_alert_tag, "opsgenie-get-alert-attachments": get_alert_attachments, "opsgenie-get-alert-logs": get_alert_logs, "opsgenie-get-schedules": get_schedules, "opsgenie-get-schedule-overrides": get_schedule_overrides, "opsgenie-get-on-call": get_on_call, "opsgenie-create-incident": create_incident, "opsgenie-delete-incident": delete_incident, "opsgenie-get-incidents": get_incidents, "opsgenie-close-incident": close_incident, "opsgenie-resolve-incident": resolve_incident, "opsgenie-add-responder-incident": add_responder_incident, "opsgenie-add-tag-incident": add_tag_incident, "opsgenie-remove-tag-incident": remove_tag_incident, "opsgenie-get-teams": get_teams, "opsgenie-get-team-routing-rules": get_team_routing_rules, "opsgenie-get-request": get_request_command, } command = demisto.command() if command == "test-module": # This is the call made when pressing the integration Test button. return_results(test_module(client, demisto.params())) elif command == "fetch-incidents": incidents, new_run_date = fetch_incidents_command( client=client, params=demisto.params(), last_run=demisto.getLastRun().get("lastRun") ) demisto.setLastRun(new_run_date) demisto.incidents(incidents) elif command in commands: return_results(commands[command](client, demisto.args())) else: raise NotImplementedError(f'Command "{command}" was not implemented.') # Log exceptions and return errors except Exception as e: demisto.error(traceback.format_exc()) # print the traceback return_error(f"Failed to execute {demisto.command()} command.\nError:\n{e!s}") if __name__ in ("__main__", "__builtin__", "builtins"): main()