OpsGenieV3

Integration with Atlassian OpsGenie. OpsGenie is a cloud-based service that enables operations teams to manage alerts generated by monitoring tools to ensure the right people are notified, and the problems are addressed in a timely manner.

Case Management · OpsGenie

Details

IDOpsGenieV3
ProviderAtlassian
CategoryCase Management
From Version6.2.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesAgentix XSIAM

README

Integration with Atlassian OpsGenie. OpsGenie is a cloud-based service that enables operations teams to manage alerts generated by monitoring tools to ensure the right people are notified, and the problems are addressed in a timely manner.
This integration was integrated and tested with OpsGenie.

Some changes have been made that might affect your existing content.
If you are upgrading from a previous of this integration, see Breaking Changes.

Configure OpsGenie v3 in Cortex

Parameter Description Required
Server URL (e.g., https://api.opsgenie.com)   True
API Token   False
Fetch incidents   False
First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)   False
Max Fetch   False
Event types Fetch only events with selected event types. False
Status Fetch only events with selected status. If query is used, this parameter will be overridden. False
Priority Fetch only events with selected priority. If query is used, this parameter will be overridden. False
Tags Fetch only events with selected tags. If query is used, this parameter will be overridden. False
Query Query parameters will be used as URL encoded values for “query” key. i.e. ‘https://api.opsgenie.com/v2/alerts?query=status%3Aopenor%20acknowledged%3Atrue&amp;limit=10&amp;sort=createdAt’ False
Incident type   False
Trust any certificate (not secure)   False
Use system proxy settings   False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

opsgenie-create-alert


Create an alert in Opsgenie.

Base Command

opsgenie-create-alert

Input

Argument Name Description Required
message Alert message. Required
alias Client-defined identifier of the alert. Optional
description Description field of the alert that is generally used to provide detailed information about the alert. Optional
responders Teams/users to whom the alert is routed via notifications.
You need to insert it as List of triples - responder_type,value_type,value.
The responder_type can be: team, user, escalation or schedule.
The value_type can be: id or name.
You can retrieve the value from the output of the following commands ‘!opsgenie-get-teams’, ‘!opsgenie-get-schedules’ or ‘!opsgenie-get-escalations’.
For example: schedule,name,test_schedule,user,id,123,team,name,test_team.
Optional
tags Comma-separated list of tags to add. Optional
priority Incident priority. Possible values are: P1, P2, P3, P4, P5. Default is P3. Optional
source Display name of the request source. Defaults to IP address of the request sender. Optional
note Additional alert note. Optional
details Comma-separated key=value pairs to use as custom properties of the alert. JSON format is also supported when used within an automation. Examples; details=”account=pa,hostname=computer01”. Optional

Context Output

Path Type Description
OpsGenie.Alert.action String Action of this request.
OpsGenie.Alert.alertId String ID of the created alert.
OpsGenie.Alert.alias String Alias of the created alert.
OpsGenie.Alert.integrationId String Integration ID of the created alert.
OpsGenie.Alert.isSuccess Boolean Whether the request was successful.
OpsGenie.Alert.processedAt Date When the request was processed.
OpsGenie.Alert.requestId String The ID of the request.
OpsGenie.Alert.status String The human readable result of the request.
OpsGenie.Alert.success Boolean Whether the request was successful.

Command Example

!opsgenie-create-alert message="Example Message"

Context Example

{
    "OpsGenie": {
        "Alert": {
            "action": "Create",
            "alertId": "4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716",
            "alias": "4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716",
            "integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
            "isSuccess": true,
            "processedAt": "2021-12-01T13:48:18.757Z",
            "status": "Created alert",
            "success": true
        }
    }
}

Human Readable Output

OpsGenie

action alertId alias integrationId isSuccess processedAt status success
Create 4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716 4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716 3cc69931-167f-411c-a331-768997c29d2e true 2021-12-01T13:48:18.757Z Created alert true

opsgenie-get-alerts


List the current alerts from OpsGenie.

Base Command

opsgenie-get-alerts

Input

Argument Name Description Required
alert-id The ID of the alert from Opsgenie. Optional
sort Name of the field that the result set will be sorted by.
The options are: createdAt, updatedAt, tinyId, alias, message, status, acknowledged, isSeen snoozed, snoozedUntil, count, lastOccurredAt, source, owner, integration.name, integration.type, report.ackTime, report.closeTime, report.acknowledgedBy, report.closedBy.
Optional
limit Maximum results to return. Default is 20. Optional
offset Start index of the result set (to apply pagination). Minimum value is 0. Default is 0. Optional
status The status of the alert from Opsgenie. Possible values are: Open, Closed. Optional
priority The priority of the alert from Opsgenie. Possible values are: P1, P2, P3, P4, P5. Default is P3. Optional
tags Comma-separated list of tags. Optional
query URL encoded query parameters. Optional
request_id ID of the polling request. No need to enter a value. Optional
paging The next URL to request. No need to enter a value. Optional
result Result of the previous command. No need to enter a value. Optional

Context Output

Path Type Description
OpsGenie.Alert.acknowledged Boolean Whether the alert was acknowledge.
OpsGenie.Alert.alias String Alert alias.
OpsGenie.Alert.count Number Number of alert occurrences.
OpsGenie.Alert.createdAt Date Time the alert was created.
OpsGenie.Alert.id String ID of the alert.
OpsGenie.Alert.integration.id String ID of the integration.
OpsGenie.Alert.integration.name String Integration name.
OpsGenie.Alert.integration.type String Type of the integration.
OpsGenie.Alert.isSeen Boolean Whether the alert was seen.
OpsGenie.Alert.lastOccurredAt Date Time the alert last occurred.
OpsGenie.Alert.message String Alert message.
OpsGenie.Alert.owner String Owner of the alert.
OpsGenie.Alert.ownerTeamId String Team ID of the owner.
OpsGenie.Alert.priority String Alert priority.
OpsGenie.Alert.responders.id String ID of the responders.
OpsGenie.Alert.responders.type String Type of the responders.
OpsGenie.Alert.seen Boolean Whether the alert was seen.
OpsGenie.Alert.snoozed Boolean Whether alert was snoozed.
OpsGenie.Alert.source String Source of the alert.
OpsGenie.Alert.status String Status of the alert.
OpsGenie.Alert.teams.id String ID of the teams associated with the alert.
OpsGenie.Alert.tinyId String Short ID for the alert.
OpsGenie.Alert.updatedAt Date Last time the alert was updated.
OpsGenie.Alert.report.ackTime Number Time the alert was acknowledged.
OpsGenie.Alert.report.acknowledgedBy String User who acknowledged the alert.
OpsGenie.Alert.report.closeTime Number Time the alert was closed.
OpsGenie.Alert.report.closedBy String User who closed the alert.

Command Example

!opsgenie-get-alerts limit=1

Context Example

{
    "OpsGenie": {
        "Alert": [
            {
                "acknowledged": false,
                "alias": "4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716",
                "count": 1,
                "createdAt": "2021-12-01T13:48:18.716Z",
                "event_type": "Alerts",
                "id": "4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716",
                "integration": {
                    "id": "3cc69931-167f-411c-a331-768997c29d2e",
                    "name": "API",
                    "type": "API"
                },
                "isSeen": false,
                "lastOccurredAt": "2021-12-01T13:48:18.716Z",
                "message": "Example Message",
                "owner": "",
                "ownerTeamId": "",
                "priority": "P3",
                "responders": [],
                "seen": false,
                "snoozed": false,
                "source": "192.168.x.x",
                "status": "open",
                "tags": [],
                "teams": [],
                "tinyId": "194",
                "updatedAt": "2021-12-01T13:48:18.787Z"
            }
        ]
    }
}

Human Readable Output

OpsGenie

id createdAt acknowledged count status
4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716 2021-12-01T13:48:18.716Z false 1 open

opsgenie-delete-alert


Delete an alert from OpsGenie.

Base Command

opsgenie-delete-alert

Input

Argument Name Description Required
alert-id The ID of the alert from Opsgenie. Required

Context Output

Path Type Description
OpsGenie.DeletedAlert.action String Action of this request.
OpsGenie.DeletedAlert.alertId String ID of the deleted alert.
OpsGenie.DeletedAlert.alias String Alias of the deleted alert.
OpsGenie.DeletedAlert.integrationId String Integration of the deleted alert.
OpsGenie.DeletedAlert.isSuccess Boolean Whether the request was successful.
OpsGenie.DeletedAlert.processedAt Date When the request was processed.
OpsGenie.DeletedAlert.requestId String The ID of the request.
OpsGenie.DeletedAlert.status String The human readable result of the request.
OpsGenie.DeletedAlert.success Boolean Whether the request was successful.

Command Example

!opsgenie-delete-alert alert-id=69df59c2-41c6-4866-8c03-65c1ecf5417d-1636973048286

Context Example

{
    "OpsGenie": {
        "DeletedAlert": {
            "action": "Delete",
            "alertId": "",
            "alias": "",
            "integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
            "isSuccess": false,
            "processedAt": "2021-12-01T13:48:40.911Z",
            "status": "Alert does not exist",
            "success": false
        }
    }
}

Human Readable Output

OpsGenie

action alertId alias integrationId isSuccess processedAt status success
Delete     3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:40.911Z Alert does not exist false

opsgenie-ack-alert


Acknowledge an alert in OpsGenie.

Base Command

opsgenie-ack-alert

Input

Argument Name Description Required
alert-id The ID of the alert from Opsgenie. Required
note Additional alert note. Optional

Context Output

Path Type Description
OpsGenie.AckedAlert.action String Action of this request.
OpsGenie.AckedAlert.alertId String ID of the acknowledged alert.
OpsGenie.AckedAlert.alias String Alias of the acknowledged alert.
OpsGenie.AckedAlert.integrationId String Integration of the acknowledged alert.
OpsGenie.AckedAlert.isSuccess Boolean Whether the request was successful.
OpsGenie.AckedAlert.processedAt Date When the request was processed.
OpsGenie.AckedAlert.requestId String The ID of the request.
OpsGenie.AckedAlert.status String The human readable result of the request.
OpsGenie.AckedAlert.success Boolean Whether the request was successful.

Command Example

!opsgenie-ack-alert alert-id=69df59c2-41c6-4866-8c03-65c1ecf5417d-1636973048286

Context Example

{
    "OpsGenie": {
        "AckedAlert": {
            "action": "Acknowledge",
            "alertId": "",
            "alias": "",
            "integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
            "isSuccess": false,
            "processedAt": "2021-12-01T13:48:23.374Z",
            "status": "Alert does not exist",
            "success": false
        }
    }
}

Human Readable Output

OpsGenie

action alertId alias integrationId isSuccess processedAt status success
Acknowledge     3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:23.374Z Alert does not exist false

opsgenie-close-alert


Close an alert in OpsGenie.

Base Command

opsgenie-close-alert

Input

Argument Name Description Required
alert-id The ID of the alert from Opsgenie. Required
note Additional alert note. Optional

Context Output

Path Type Description
OpsGenie.ClosedAlert.action String Action of this request.
OpsGenie.ClosedAlert.alertId String ID of the closed alert.
OpsGenie.ClosedAlert.alias String Alias of the closed alert.
OpsGenie.ClosedAlert.integrationId String Integration ID of the acknowledged alert.
OpsGenie.ClosedAlert.isSuccess Boolean Whether the request was successful.
OpsGenie.ClosedAlert.processedAt Date When the request was processed.
OpsGenie.ClosedAlert.requestId String The ID of the request.
OpsGenie.ClosedAlert.status String The human readable result of the request.
OpsGenie.ClosedAlert.success Boolean Whether the request was successful.

Command Example

!opsgenie-close-alert alert-id=69df59c2-41c6-4866-8c03-65c1ecf5417d-1636973048286

Context Example

{
    "OpsGenie": {
        "ClosedAlert": {
            "action": "Close",
            "alertId": "",
            "alias": "",
            "integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
            "isSuccess": false,
            "processedAt": "2021-12-01T13:48:38.491Z",
            "status": "Alert does not exist",
            "success": false
        }
    }
}

Human Readable Output

OpsGenie

action alertId alias integrationId isSuccess processedAt status success
Close     3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:38.491Z Alert does not exist false

opsgenie-assign-alert


Assign an OpsGenie alert.

Base Command

opsgenie-assign-alert

Input

Argument Name Description Required
alert-id ID of the Opsgenie alert. Required
owner_id ID of the user to whom the alert will be assigned. Not required if owner_username is present. Optional
owner_username Display name of the request owner. Not required if owner_id is present. Optional
note Additional alert note. Optional

Context Output

Path Type Description
OpsGenie.AssignAlert.action String Action of this request.
OpsGenie.AssignAlert.alertId String ID of assigned Alert
OpsGenie.AssignAlert.alias String Alias of the assigned alert.
OpsGenie.AssignAlert.integrationId String Integration ID of the assigned alert.
OpsGenie.AssignAlert.isSuccess Boolean Whether the request was successful.
OpsGenie.AssignAlert.processedAt Date When the request was processed.
OpsGenie.AssignAlert.requestId String The ID of the request.
OpsGenie.AssignAlert.status String The human readable result of the request.
OpsGenie.AssignAlert.success Boolean Whether the request was successful.

Command Example

!opsgenie-assign-alert alert-id=69df59c2-41c6-4866-8c03-65c1ecf5417d-1636973048286 owner_username=b@g.com

Context Example

{
    "OpsGenie": {
        "AssignAlert": {
            "action": "Assign",
            "alertId": "",
            "alias": "",
            "integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
            "isSuccess": false,
            "processedAt": "2021-12-01T13:48:24.942Z",
            "status": "Alert does not exist",
            "success": false
        }
    }
}

Human Readable Output

OpsGenie

action alertId alias integrationId isSuccess processedAt status success
Assign     3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:24.942Z Alert does not exist false

opsgenie-add-responder-alert


Add a responder to an OpsGenie alert.

Base Command

opsgenie-add-responder-alert

Input

Argument Name Description Required
alert-id ID of the Opsgenie alert. Required
identifierType Type of the identifier. Possible values are: id, tiny, alias. Optional
responders Team/user to whom the alert is routed via notifications.
For now, it can be inserted only one responder at a time.
You need to insert it as List of triple - responder_type,value_type,value.
The responder_type can be: team or user.
The value_type can be: id or name.
You can retrieve the value from the output of the following ‘!opsgenie-get-teams’ command.
For example: user,id,123 Another example: team,name,test_team.
Required
note Additional alert note. Optional

Context Output

Path Type Description
OpsGenie.AddResponderAlert.action String Action of this request.
OpsGenie.AddResponderAlert.alertId String ID of the created alert.
OpsGenie.AddResponderAlert.alias String Alias of the created alert.
OpsGenie.AddResponderAlert.integrationId String Integration ID of the created alert.
OpsGenie.AddResponderAlert.isSuccess Boolean Whether the request was successful.
OpsGenie.AddResponderAlert.processedAt Date When the request was processed.
OpsGenie.AddResponderAlert.requestId String The ID of the request.
OpsGenie.AddResponderAlert.status String The human readable result of the request.
OpsGenie.AddResponderAlert.success Boolean Whether the request was successful.

Command Example

!opsgenie-add-responder-alert alert-id=69df59c2-41c6-4866-8c03-65c1ecf5417d-1636973048286 responders=schedule,name,test_schedule

Context Example

{
    "OpsGenie": {
        "AddResponderAlert": {
            "action": "Add Responder",
            "alertId": "",
            "alias": "",
            "integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
            "isSuccess": false,
            "processedAt": "2021-12-01T13:48:26.82Z",
            "status": "Alert does not exist",
            "success": false
        }
    }
}

Human Readable Output

OpsGenie

action alertId alias integrationId isSuccess processedAt status success
Add Responder     3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:26.82Z Alert does not exist false

opsgenie-get-escalations


Get escalations from OpsGenie.

Base Command

opsgenie-get-escalations

Input

Argument Name Description Required
escalation_id ID of the escalation. Optional
escalation_name Name of the escalation. Optional

Context Output

Path Type Description
OpsGenie.Escalation.action String Action of this request.
OpsGenie.Escalation.Id String ID of the escalation.
OpsGenie.Escalation.name String Name of the escalation.
OpsGenie.Escalation.description String Description of the escalation.
OpsGenie.Escalation.ownerTeam String Owner team of the escalation.
OpsGenie.Escalation.rules String Rules of the escalation.
OpsGenie.Escalation.integrationId String Integration ID of the escalated alert.
OpsGenie.Escalation.isSuccess Boolean Whether the request was successful.
OpsGenie.Escalation.processedAt Date When the request was processed.
OpsGenie.Escalation.requestId String The ID of the request.
OpsGenie.Escalation.status String The human readable result of the request.
OpsGenie.Escalation.success Boolean Whether the request was successful.

Command Example


#### Context Example

```json
{
    "OpsGenie": {
        "Escalations": [
            {
                "description": "",
                "id": "9a441a8d-2410-43f4-9ef2-f7a265e12b74",
                "name": "Engineering_escalation",
                "ownerTeam": {
                    "id": "51d69df8-c40b-439e-9808-e1a78e54f91b",
                    "name": "Engineering"
                },
                "rules": [
                    {
                        "condition": "if-not-acked",
                        "delay": {
                            "timeAmount": 0,
                            "timeUnit": "minutes"
                        },
                        "notifyType": "default",
                        "recipient": {
                            "id": "7835aa84-7440-41d5-90bf-92e0045714d5",
                            "name": "Engineering_schedule",
                            "type": "schedule"
                        }
                    },
                    {
                        "condition": "if-not-acked",
                        "delay": {
                            "timeAmount": 5,
                            "timeUnit": "minutes"
                        },
                        "notifyType": "next",
                        "recipient": {
                            "id": "7835aa84-7440-41d5-90bf-92e0045714d5",
                            "name": "Engineering_schedule",
                            "type": "schedule"
                        }
                    },
                    {
                        "condition": "if-not-acked",
                        "delay": {
                            "timeAmount": 10,
                            "timeUnit": "minutes"
                        },
                        "notifyType": "all",
                        "recipient": {
                            "id": "51d69df8-c40b-439e-9808-e1a78e54f91b",
                            "name": "Engineering",
                            "type": "team"
                        }
                    }
                ]
            },
            {
                "description": "",
                "id": "c8a0f950-577c-4da5-894b-1fd463d9f51c",
                "name": "Integration Team_escalation",
                "ownerTeam": {
                    "id": "fbbc3f9a-12f4-4794-9938-7e0a85a06f8b",
                    "name": "Integration Team"
                },
                "rules": [
                    {
                        "condition": "if-not-acked",
                        "delay": {
                            "timeAmount": 0,
                            "timeUnit": "minutes"
                        },
                        "notifyType": "default",
                        "recipient": {
                            "id": "df918339-b999-4878-b69b-3c2c0d508b01",
                            "name": "Integration Team_schedule",
                            "type": "schedule"
                        }
                    },
                    {
                        "condition": "if-not-acked",
                        "delay": {
                            "timeAmount": 1,
                            "timeUnit": "minutes"
                        },
                        "notifyType": "default",
                        "recipient": {
                            "id": "154d6425-c120-4beb-a3e6-a66c8c44f61d",
                            "type": "user",
                            "username": "dvilenchik@example.com"
                        }
                    },
                    {
                        "condition": "if-not-acked",
                        "delay": {
                            "timeAmount": 5,
                            "timeUnit": "minutes"
                        },
                        "notifyType": "next",
                        "recipient": {
                            "id": "df918339-b999-4878-b69b-3c2c0d508b01",
                            "name": "Integration Team_schedule",
                            "type": "schedule"
                        }
                    },
                    {
                        "condition": "if-not-acked",
                        "delay": {
                            "timeAmount": 10,
                            "timeUnit": "minutes"
                        },
                        "notifyType": "all",
                        "recipient": {
                            "id": "fbbc3f9a-12f4-4794-9938-7e0a85a06f8b",
                            "name": "Integration Team",
                            "type": "team"
                        }
                    }
                ]
            }
        ]
    }
}

Human Readable Output

OpsGenie Escalations

description id name ownerTeam rules
  9a441a8d-2410-43f4-9ef2-f7a265e12b74 Engineering_escalation id: 51d69df8-c40b-439e-9808-e1a78e54f91b
name: Engineering
{‘condition’: ‘if-not-acked’, ‘notifyType’: ‘default’, ‘delay’: {‘timeAmount’: 0, ‘timeUnit’: ‘minutes’}, ‘recipient’: {‘type’: ‘schedule’, ‘id’: ‘7835aa84-7440-41d5-90bf-92e0045714d5’, ‘name’: ‘Engineering_schedule’}},
{‘condition’: ‘if-not-acked’, ‘notifyType’: ‘next’, ‘delay’: {‘timeAmount’: 5, ‘timeUnit’: ‘minutes’}, ‘recipient’: {‘type’: ‘schedule’, ‘id’: ‘7835aa84-7440-41d5-90bf-92e0045714d5’, ‘name’: ‘Engineering_schedule’}},
{‘condition’: ‘if-not-acked’, ‘notifyType’: ‘all’, ‘delay’: {‘timeAmount’: 10, ‘timeUnit’: ‘minutes’}, ‘recipient’: {‘type’: ‘team’, ‘id’: ‘51d69df8-c40b-439e-9808-e1a78e54f91b’, ‘name’: ‘Engineering’}}
  c8a0f950-577c-4da5-894b-1fd463d9f51c Integration Team_escalation id: fbbc3f9a-12f4-4794-9938-7e0a85a06f8b
name: Integration Team
{‘condition’: ‘if-not-acked’, ‘notifyType’: ‘default’, ‘delay’: {‘timeAmount’: 0, ‘timeUnit’: ‘minutes’}, ‘recipient’: {‘type’: ‘schedule’, ‘id’: ‘df918339-b999-4878-b69b-3c2c0d508b01’, ‘name’: ‘Integration Team_schedule’}},
{‘condition’: ‘if-not-acked’, ‘notifyType’: ‘default’, ‘delay’: {‘timeAmount’: 1, ‘timeUnit’: ‘minutes’}, ‘recipient’: {‘type’: ‘user’, ‘id’: ‘154d6425-c120-4beb-a3e6-a66c8c44f61d’, ‘username’: ‘dvilenchik@example.com’}},
{‘condition’: ‘if-not-acked’, ‘notifyType’: ‘next’, ‘delay’: {‘timeAmount’: 5, ‘timeUnit’: ‘minutes’}, ‘recipient’: {‘type’: ‘schedule’, ‘id’: ‘df918339-b999-4878-b69b-3c2c0d508b01’, ‘name’: ‘Integration Team_schedule’}},
{‘condition’: ‘if-not-acked’, ‘notifyType’: ‘all’, ‘delay’: {‘timeAmount’: 10, ‘timeUnit’: ‘minutes’}, ‘recipient’: {‘type’: ‘team’, ‘id’: ‘fbbc3f9a-12f4-4794-9938-7e0a85a06f8b’, ‘name’: ‘Integration Team’}}

opsgenie-escalate-alert


Escalate an OpsGenie alert.

Base Command

opsgenie-escalate-alert

Input

Argument Name Description Required
alert-id ID of the Opsgenie alert. Required
escalation_name Name of the escalation to which the alert will be escalated. Provide either the ID or name of the escalation. Optional
escalation_id ID of the escalation to which the alert will be escalated. Provide either the ID or name of the escalation. Optional
note Additional alert note. Optional

Context Output

Path Type Description
OpsGenie.EscalateAlert.action String Action of this request.
OpsGenie.EscalateAlert.id String ID of the escalation.
OpsGenie.EscalateAlert.name String Name of the escalation.
OpsGenie.EscalateAlert.description String Description of the escalation.
OpsGenie.EscalateAlert.integrationId String Integration ID of the escalated alert.
OpsGenie.EscalateAlert.isSuccess Boolean Whether the request was successful.
OpsGenie.EscalateAlert.processedAt Date When the request was processed.
OpsGenie.EscalateAlert.requestId String The ID of the request.
OpsGenie.EscalateAlert.status String The human readable result of the request.
OpsGenie.EscalateAlert.success Boolean Whether the request was successful.

Command Example

!opsgenie-escalate-alert alert-id=69df59c2-41c6-4866-8c03-65c1ecf5417d-1636973048286 escalation_id=9a441a8d-2410-43f4-9ef2-f7a265e12b74

Context Example

{
    "OpsGenie": {
        "EscalateAlert": {
            "action": "Escalate",
            "alertId": "",
            "alias": "",
            "integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
            "isSuccess": false,
            "processedAt": "2021-12-01T13:48:31.549Z",
            "status": "Alert does not exist",
            "success": false
        }
    }
}

Human Readable Output

OpsGenie

action alertId alias integrationId isSuccess processedAt status success
Escalate     3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:31.549Z Alert does not exist false

opsgenie-add-alert-tag


Add tag to the OpsGenie alert.

Base Command

opsgenie-add-alert-tag

Input

Argument Name Description Required
alert-id ID of the Opsgenie alert. Required
tags Comma-separated list of tags to add to the alert. Required
note Additional alert note. Optional

Context Output

Path Type Description
OpsGenie.AddTagAlert.action String Action of this request.
OpsGenie.AddTagAlert.alertId String ID of the added alert.
OpsGenie.AddTagAlert.alias String Alias of the added alert.
OpsGenie.AddTagAlert.integrationId String Integration ID of the added alert.
OpsGenie.AddTagAlert.isSuccess Boolean Whether the request was successful.
OpsGenie.AddTagAlert.processedAt Date When the request was processed.
OpsGenie.AddTagAlert.requestId String The ID of the request.
OpsGenie.AddTagAlert.status String The human readable result of the request.
OpsGenie.AddTagAlert.success Boolean Whether the request was successful.

Command Example

!opsgenie-add-alert-tag alert-id=69df59c2-41c6-4866-8c03-65c1ecf5417d-1636973048286 tags=1,2,3

Context Example

{
    "OpsGenie": {
        "AddTagAlert": {
            "action": "Add Tags",
            "alertId": "",
            "alias": "",
            "integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
            "isSuccess": false,
            "processedAt": "2021-12-01T13:48:33.376Z",
            "status": "Alert does not exist",
            "success": false
        }
    }
}

Human Readable Output

OpsGenie

action alertId alias integrationId isSuccess processedAt status success
Add Tags     3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:33.376Z Alert does not exist false

opsgenie-remove-alert-tag


Remove a tag from the OpsGenie alert.

Base Command

opsgenie-remove-alert-tag

Input

Argument Name Description Required
alert-id ID of the Opsgenie alert. Required
tags Comma-separated list of tags to remove from the alert. Required
note Additional alert note. Optional

Context Output

Path Type Description
OpsGenie.RemoveTagAlert.action String Action of this request.
OpsGenie.RemoveTagAlert.alertId String ID of the tag removed from the alert.
OpsGenie.RemoveTagAlert.alias String Alias of the removed tag alert.
OpsGenie.RemoveTagAlert.integrationId String Integration ID of the removed tag alert.
OpsGenie.RemoveTagAlert.isSuccess Boolean Whether the request was successful.
OpsGenie.RemoveTagAlert.processedAt Date When the request was processed.
OpsGenie.RemoveTagAlert.requestId String The ID of the request.
OpsGenie.RemoveTagAlert.status String The human readable result of the request.
OpsGenie.RemoveTagAlert.success Boolean Whether the request was successful.

Command Example

!opsgenie-remove-alert-tag alert-id=69df59c2-41c6-4866-8c03-65c1ecf5417d-1636973048286 tags=1,2,3

Context Example

{
    "OpsGenie": {
        "RemoveTagAlert": {
            "action": "Remove Tags",
            "alertId": "",
            "alias": "",
            "integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
            "isSuccess": false,
            "processedAt": "2021-12-01T13:48:35.606Z",
            "status": "Alert does not exist",
            "success": false
        }
    }
}

Human Readable Output

OpsGenie

action alertId alias integrationId isSuccess processedAt status success
Remove Tags     3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:35.606Z Alert does not exist false

opsgenie-get-alert-attachments


Get the attachments of the alert.

Base Command

opsgenie-get-alert-attachments

Input

Argument Name Description Required
alert-id ID of the Opsgenie alert. Required
attachment_id Identifier of the attachment. Optional

Context Output

Path Type Description
OpsGenie.Alert.Attachment.action String Action of this request.
OpsGenie.Alert.Attachment.alertId String ID of the alert.
OpsGenie.Alert.Attachment.alias String Alias of the alert.
OpsGenie.Alert.Attachment.integrationId String Integration ID the alert.
OpsGenie.Alert.Attachment.isSuccess Boolean Whether the request was successful.
OpsGenie.Alert.Attachment.processedAt Date When the request was processed.
OpsGenie.Alert.Attachment.requestId String The ID of the request.
OpsGenie.Alert.Attachment.status String The human readable result of the request.
OpsGenie.Alert.Attachment.success Boolean Whether the request was successful.

Command Example


#### Human Readable Output

### opsgenie-get-schedules

***
Get a schedule from OpsGenie.

#### Base Command

`opsgenie-get-schedules`

#### Input

| **Argument Name** | **Description** | **Required** |
| --- | --- | --- |
| schedule_id | ID of the schedule. | Optional |
| schedule_name | Name of the schedule. | Optional |

#### Context Output

| **Path** | **Type** | **Description** |
| --- | --- | --- |
| OpsGenie.Schedule.description | String | Description of the schedule. |
| OpsGenie.Schedule.enabled | Boolean | Whether the schedule was enabled. |
| OpsGenie.Schedule.id | String | ID of the schedule. |
| OpsGenie.Schedule.name | String | Name of the schedule. |
| OpsGenie.Schedule.ownerTeam.id | String | ID of the schedule owner. |
| OpsGenie.Schedule.ownerTeam.name | String | Name of the schedule owner. |
| OpsGenie.Schedule.timezone | String | Timezone of the schedule. |

#### Command Example

```!opsgenie-get-schedules```

#### Context Example

```json
{
    "OpsGenie": {
        "Schedule": [
            {
                "description": "Schedule when escalation was activated",
                "enabled": true,
                "id": "5892636c-6183-4788-99d6-6d93b9095194",
                "name": "Escalation Schedule",
                "ownerTeam": {
                    "id": "fbbc3f9a-12f4-4794-9938-7e0a85a06f8b",
                    "name": "Integration Team"
                },
                "rotations": [],
                "timezone": "Asia/Jerusalem"
            },
            {
                "description": "",
                "enabled": true,
                "id": "7835aa84-7440-41d5-90bf-92e0045714d5",
                "name": "Engineering_schedule",
                "ownerTeam": {
                    "id": "51d69df8-c40b-439e-9808-e1a78e54f91b",
                    "name": "Engineering"
                },
                "rotations": [],
                "timezone": "Asia/Jerusalem"
            },
            {
                "description": "24/7 Shift",
                "enabled": true,
                "id": "df918339-b999-4878-b69b-3c2c0d508b01",
                "name": "Integration Team_schedule",
                "ownerTeam": {
                    "id": "fbbc3f9a-12f4-4794-9938-7e0a85a06f8b",
                    "name": "Integration Team"
                },
                "rotations": [],
                "timezone": "Asia/Jerusalem"
            }
        ]
    }
}

Human Readable Output

OpsGenie Schedule

description enabled id name ownerTeam rotations timezone
Schedule when escalation was activated true 5892636c-6183-4788-99d6-6d93b9095194 Escalation Schedule id: fbbc3f9a-12f4-4794-9938-7e0a85a06f8b
name: Integration Team
  Asia/Jerusalem
  true 7835aa84-7440-41d5-90bf-92e0045714d5 Engineering_schedule id: 51d69df8-c40b-439e-9808-e1a78e54f91b
name: Engineering
  Asia/Jerusalem
24/7 Shift true df918339-b999-4878-b69b-3c2c0d508b01 Integration Team_schedule id: fbbc3f9a-12f4-4794-9938-7e0a85a06f8b
name: Integration Team
  Asia/Jerusalem

opsgenie-get-schedule-overrides


Get schedule overrides.

Base Command

opsgenie-get-schedule-overrides

Input

Argument Name Description Required
schedule_id ID of the schedule. Optional
schedule_name Name of the schedule. Optional
override_alias Alias of the schedule override. Optional

Context Output

Path Type Description
OpsGenie.Schedule.Override.action String Action of this request.
OpsGenie.Schedule.Override.alertId String ID of the schedule.
OpsGenie.Schedule.Override.alias String Alias of the schedule.
OpsGenie.Schedule.Override.integrationId String Integration ID of the schedule.
OpsGenie.Schedule.Override.isSuccess Boolean Whether the request was successful.
OpsGenie.Schedule.Override.processedAt Date When the request was processed.
OpsGenie.Schedule.Override.requestId String The ID of the request.
OpsGenie.Schedule.Override.status String The human readable result of the request.
OpsGenie.Schedule.Override.success Boolean Whether the request was successful.

Command Example

!opsgenie-get-schedule-overrides schedule_id=5892636c-6183-4788-99d6-6d93b9095194

Human Readable Output

OpsGenie Schedule

No entries.

opsgenie-get-on-call


Get the on-call users for the provided schedule.

Base Command

opsgenie-get-on-call

Input

Argument Name Description Required
schedule_id Schedule ID from which to return on-call users. Optional
schedule_name Name of the schedule from which to return on-call users. Optional
starting_date Start date of the timeline in the following format (yyyy-MM-dd’T’HH:mm:ssZ). Optional

Context Output

Path Type Description
OpsGenie.Schedule.OnCall._parent.enabled Boolean Whether this on-call schedule is enabled.
OpsGenie.Schedule.OnCall._parent.id String ID Of the parent on-call schedule.
OpsGenie.Schedule.OnCall._parent.name String Name of parent on-call schedule.
OpsGenie.Schedule.OnCall.onCallParticipants.id String ID of the on-call participant.
OpsGenie.Schedule.OnCall.onCallParticipants.name String Name of the on-call participant.
OpsGenie.Schedule.OnCall.onCallParticipants.type String Type of the on-call participant.

Command Example

!opsgenie-get-on-call schedule_id=5892636c-6183-4788-99d6-6d93b9095194

Context Example

{
    "OpsGenie": {
        "Schedule": {
            "OnCall": {
                "data": {
                    "_parent": {
                        "enabled": true,
                        "id": "5892636c-6183-4788-99d6-6d93b9095194",
                        "name": "Escalation Schedule"
                    },
                    "onCallParticipants": [
                        {
                            "id": "154d6425-c120-4beb-a3e6-a66c8c44f61d",
                            "name": "dvilenchik@example.com",
                            "type": "user"
                        }
                    ]
                },
                "requestId": "e88ae246-5d0f-4ebf-826c-f3617e6a3d42",
                "took": 0.007
            }
        }
    }
}

Human Readable Output

OpsGenie Schedule OnCall

_parent onCallParticipants
id: 5892636c-6183-4788-99d6-6d93b9095194
name: Escalation Schedule
enabled: true
{‘id’: ‘154d6425-c120-4beb-a3e6-a66c8c44f61d’, ‘name’: ‘dvilenchik@example.com’, ‘type’: ‘user’}

opsgenie-create-incident


Create an incident in Opsgenie.

Base Command

opsgenie-create-incident

Input

Argument Name Description Required
interval_in_seconds Interval in seconds between each poll. Default is 5. Optional
message Incident message. Required
description Detailed information about the incident. Optional
responders Teams/users to whom the incident is routed via notifications.
You need to insert it as List of triples - responder_type,value_type,value.
The responder_type can be: team or user.
The value_type can be: id or name.
You can retrieve the value from the output of the ‘!opsgenie-get-teams’ command.
For example: user,id,123,team,name,test_team.
Optional
tags Comma-separated list of tags to add. Optional
priority Incident Priority. Possible values are: P1, P2, P3, P4, P5. Default is P3. Optional

Context Output

Path Type Description
OpsGenie.Incident.action String Action of this request.
OpsGenie.Incident.incidentId String ID of the created incident.
OpsGenie.Incident.integrationId String Integration ID of the created alert.
OpsGenie.Incident.isSuccess Boolean Whether the request was successful.
OpsGenie.Incident.processedAt Date When the request was processed.
OpsGenie.Incident.requestId String The ID of the request.
OpsGenie.Incident.status String The human readable result of the request.
OpsGenie.Incident.success Boolean Whether the request was successful.

Command Example

!opsgenie-create-incident message="test" responders=team,name,test_team,team,name,test_team_1

Context Example

{
    "OpsGenie": {
        "Incident": {
            "action": "Create",
            "incidentId": "4ba53100-30dc-47a6-992a-a96df4d1ba20",
            "integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
            "isSuccess": true,
            "processedAt": "2021-12-01T13:48:49.133Z",
            "status": "Incident created successfully",
            "success": true
        }
    }
}

Human Readable Output

OpsGenie

action incidentId integrationId isSuccess processedAt status success
Create 4ba53100-30dc-47a6-992a-a96df4d1ba20 3cc69931-167f-411c-a331-768997c29d2e true 2021-12-01T13:48:49.133Z Incident created successfully true

opsgenie-delete-incident


Delete an incident from OpsGenie.

Base Command

opsgenie-delete-incident

Input

Argument Name Description Required
incident_id The ID of the incident from Opsgenie. Required

Context Output

Path Type Description
OpsGenie.DeletedIncident.action String Action of this request.
OpsGenie.DeletedIncident.incidentId String ID of the deleted incident.
OpsGenie.DeletedIncident.integrationId String Integration ID of the deleted incident.
OpsGenie.DeletedIncident.isSuccess Boolean Whether the request was successful.
OpsGenie.DeletedIncident.processedAt Date When the request was processed.
OpsGenie.DeletedIncident.requestId String The ID of the request.
OpsGenie.DeletedIncident.status String The human readable result of the request.
OpsGenie.DeletedIncident.success Boolean Whether the request was successful.

Command Example

!opsgenie-delete-incident incident_id=c59086e0-bf2c-44e2-bdfb-ed7747cc126b

Context Example

{
    "OpsGenie": {
        "DeletedIncident": {
            "action": "Delete",
            "incidentId": "",
            "integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
            "isSuccess": false,
            "processedAt": "2021-12-01T13:48:52.534Z",
            "status": "",
            "success": false
        }
    }
}

Human Readable Output

OpsGenie

action incidentId integrationId isSuccess processedAt status success
Delete   3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:52.534Z   false

opsgenie-get-incidents


List the current incidents from OpsGenie.

Base Command

opsgenie-get-incidents

Input

Argument Name Description Required
incident_id The ID of the incident from Opsgenie. Optional
limit Maximum number of results to return. Default is 20. Optional
offset Start index of the result set (to apply pagination). Minimum value is 0. Default is 0. Optional
status The status of the alert from Opsgenie. Possible values are: Open, Closed. Optional
priority Incident Priority. Possible values are: P1, P2, P3, P4, P5. Default is P3. Optional
tags Comma-separated list of tags to add. Optional
query URL encoded query parameters. Optional
request_id ID of the polling request. No need to enter a value. Optional
paging The next URL to request. No need to enter a value. Optional
result Result of the previous command. No need to enter a value. Optional

Context Output

Path Type Description
OpsGenie.Incident.count Number The number of alert occurrences.
OpsGenie.Incident.createdAt Date Time the alert was created.
OpsGenie.Incident.incidentId String ID of the alert.
OpsGenie.Incident.integration.id String ID of the integration.
OpsGenie.Incident.integration.name String Integration name
OpsGenie.Incident.integration.type String Type of the integration.
OpsGenie.Incident.message String Alert message.
OpsGenie.Incident.ownerTeam String Team ID of the owner.
OpsGenie.Incident.priority String Alert priority.
OpsGenie.Incident.responders.id String ID of the responders.
OpsGenie.Incident.responders.type String Type of the responders.
OpsGenie.Incident.status String Status of the alert.
OpsGenie.Incident.tinyId String Short ID for the alert.
OpsGenie.Incident.updatedAt Date Last updated time for the alert.

Command Example

!opsgenie-get-incidents limit=1

Context Example

{
    "OpsGenie": {
        "Incident": [
            {
                "actions": [],
                "createdAt": "2021-12-01T13:48:49.006Z",
                "description": "",
                "event_type": "Incidents",
                "extraProperties": {},
                "id": "4ba53100-30dc-47a6-992a-a96df4d1ba20",
                "impactStartDate": "2021-12-01T13:48:49.006Z",
                "impactedServices": [],
                "links": {
                    "api": "https://api.opsgenie.com/v1/incidents/4ba53100-30dc-47a6-992a-a96df4d1ba20",
                    "web": "https://demisto1.app.opsgenie.com/incident/detail/4ba53100-30dc-47a6-992a-a96df4d1ba20"
                },
                "message": "test",
                "ownerTeam": "",
                "priority": "P3",
                "responders": [],
                "status": "open",
                "tags": [],
                "tinyId": "100",
                "updatedAt": "2021-12-01T13:48:49.006Z"
            }
        ]
    }
}

Human Readable Output

OpsGenie

id createdAt status
4ba53100-30dc-47a6-992a-a96df4d1ba20 2021-12-01T13:48:49.006Z open

opsgenie-close-incident


Close an incident from OpsGenie.

Base Command

opsgenie-close-incident

Input

Argument Name Description Required
incident_id The ID of the incident from Opsgenie. Required
note Additional incident note. Optional

Context Output

Path Type Description
OpsGenie.ClosedIncident.action String Action of this request.
OpsGenie.ClosedIncident.incidentId String ID of the closed incident.
OpsGenie.ClosedIncident.integrationId String Integration ID of the closed incident
OpsGenie.ClosedIncident.isSuccess Boolean Whether the request was successful.
OpsGenie.ClosedIncident.processedAt Date When the request was processed.
OpsGenie.ClosedIncident.requestId String The ID of the request.
OpsGenie.ClosedIncident.status String The human readable result of the request.
OpsGenie.ClosedIncident.success Boolean Whether the request was successful.

Command Example

!opsgenie-close-incident incident_id=c59086e0-bf2c-44e2-bdfb-ed7747cc126b

Context Example

{
    "OpsGenie": {
        "ClosedIncident": {
            "action": "Close",
            "incidentId": "",
            "integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
            "isSuccess": false,
            "processedAt": "2021-12-01T13:48:50.974Z",
            "status": "",
            "success": false
        }
    }
}

Human Readable Output

OpsGenie

action incidentId integrationId isSuccess processedAt status success
Close   3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:50.974Z   false

opsgenie-resolve-incident


Resolve an incident from OpsGenie.

Base Command

opsgenie-resolve-incident

Input

Argument Name Description Required
incident_id The ID of the incident from Opsgenie. Required
note Additional incident note. Optional

Context Output

Path Type Description
OpsGenie.ResolvedIncident.action String Action of this request.
OpsGenie.ResolvedIncident.incidentId String ID of the closed incident.
OpsGenie.ResolvedIncident.integrationId String Integration ID of the closed incident.
OpsGenie.ResolvedIncident.isSuccess Boolean Whether the request was successful.
OpsGenie.ResolvedIncident.processedAt Date When the request was processed.
OpsGenie.ResolvedIncident.requestId String The ID of the request.
OpsGenie.ResolvedIncident.status String The human readable result of the request.
OpsGenie.ResolvedIncident.success Boolean Whether the request was successful.

Command Example

!opsgenie-resolve-incident incident_id=b15c7555-d685-4a96-8798-46320618004e

Context Example

{
    "OpsGenie": {
        "ResolvedIncident": {
            "action": "Resolve",
            "incidentId": "",
            "integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
            "isSuccess": false,
            "processedAt": "2021-12-01T13:48:57.042Z",
            "status": "",
            "success": false
        }
    }
}

Human Readable Output

OpsGenie

action incidentId integrationId isSuccess processedAt status success
Resolve   3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:57.042Z   false

opsgenie-add-responder-incident


Add a responder to an OpsGenie incident.

Base Command

opsgenie-add-responder-incident

Input

Argument Name Description Required
incident_id The ID of the incident from Opsgenie. Required
responders Teams/users to whom the incident is routed via notifications.
You need to insert it as list of triples - responder_type,value_type,value.
The responder_type can be: team or user.
The value_type can be: id or name.
You can retrieve the value from the output of the ‘!opsgenie-get-teams’ command.
For example: user,id,123,team,name,test_team.
Required
note Additional alert note. Optional

Context Output

Path Type Description
OpsGenie.AddResponderIncident.action String Action of this request.
OpsGenie.AddResponderIncident.incidentId String ID of the created incident.
OpsGenie.AddResponderIncident.integrationId String Integration ID of the created incident.
OpsGenie.AddResponderIncident.isSuccess Boolean Whether the request was successful.
OpsGenie.AddResponderIncident.processedAt Date When the request was processed.
OpsGenie.AddResponderIncident.requestId String The ID of the request.
OpsGenie.AddResponderIncident.status String The human readable result of the request.
OpsGenie.AddResponderIncident.success Boolean Whether the request was successful.

Command Example

!opsgenie-add-responder-incident incident_id=577424c1-b03c-4d23-9871-da0d395fea17 responders="team,name,Integration Team"

Context Example

{
    "OpsGenie": {
        "AddResponderIncident": {
            "action": "Add Responder",
            "incidentId": "",
            "integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
            "isSuccess": false,
            "processedAt": "2021-12-01T13:48:59.193Z",
            "status": "Given teams/users already added as responders.",
            "success": false
        }
    }
}

Human Readable Output

OpsGenie

action incidentId integrationId isSuccess processedAt status success
Add Responder   3cc69931-167f-411c-a331-768997c29d2e false 2021-12-01T13:48:59.193Z Given teams/users already added as responders. false

opsgenie-add-tag-incident


Add a tag to the OpsGenie incident.

Base Command

opsgenie-add-tag-incident

Input

Argument Name Description Required
incident_id The ID of the incident from Opsgenie. Required
tags Comma-separated list of tags to add to the incident. Required
note Additional incident note. Optional

Context Output

Path Type Description
OpsGenie.AddTagIncident.action String Action of this request.
OpsGenie.AddTagIncident.incidentId String ID of the added incident.
OpsGenie.AddTagIncident.integrationId String Integration ID of the added incident.
OpsGenie.AddTagIncident.isSuccess Boolean Whether the request was successful.
OpsGenie.AddTagIncident.processedAt Date When the request was processed.
OpsGenie.AddTagIncident.requestId String The ID of the request.
OpsGenie.AddTagIncident.status String The human readable result of the request.
OpsGenie.AddTagIncident.success Boolean Whether the request was successful.

Command Example

!opsgenie-add-tag-incident incident_id=b15c7555-d685-4a96-8798-46320618004e tags=1,2,3

Context Example

{
    "OpsGenie": {
        "AddTagIncident": {
            "action": "Add Tags",
            "incidentId": "b15c7555-d685-4a96-8798-46320618004e",
            "integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
            "isSuccess": true,
            "processedAt": "2021-12-01T13:49:00.839Z",
            "status": "Added tags",
            "success": true
        }
    }
}

Human Readable Output

OpsGenie

action incidentId integrationId isSuccess processedAt status success
Add Tags b15c7555-d685-4a96-8798-46320618004e 3cc69931-167f-411c-a331-768997c29d2e true 2021-12-01T13:49:00.839Z Added tags true

opsgenie-remove-tag-incident


Remove a tag from the OpsGenie alert.

Base Command

opsgenie-remove-tag-incident

Input

Argument Name Description Required
incident_id The ID of the incident from Opsgenie. Required
tags Comma-separated list of tags to add to the incident. Required
note Additional incident note. Optional

Context Output

Path Type Description
OpsGenie.RemoveTagIncident.action String Action of this request.
OpsGenie.RemoveTagIncident.incidentId String Incident ID of the remove tag incident.
OpsGenie.RemoveTagIncident.integrationId String Integration ID of the remove tag incident.
OpsGenie.RemoveTagIncident.isSuccess Boolean Whether the request was successful.
OpsGenie.RemoveTagIncident.processedAt Date When the request was processed.
OpsGenie.RemoveTagIncident.requestId String The ID of the request.
OpsGenie.RemoveTagIncident.status String The human readable result of the request.
OpsGenie.RemoveTagIncident.success Boolean Whether the request was successful.

Command Example

!opsgenie-remove-tag-incident incident_id=b15c7555-d685-4a96-8798-46320618004e tags=1,2

Context Example

{
    "OpsGenie": {
        "RemoveTagIncident": {
            "action": "Remove Tags",
            "incidentId": "b15c7555-d685-4a96-8798-46320618004e",
            "integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
            "isSuccess": true,
            "processedAt": "2021-12-01T13:49:02.53Z",
            "status": "Removed tags",
            "success": true
        }
    }
}

Human Readable Output

OpsGenie

action incidentId integrationId isSuccess processedAt status success
Remove Tags b15c7555-d685-4a96-8798-46320618004e 3cc69931-167f-411c-a331-768997c29d2e true 2021-12-01T13:49:02.53Z Removed tags true

opsgenie-invite-user


Invite a user to OpsGenie

Base Command

opsgenie-invite-user

Input

Argument Name Description Required
username E-mail address of the user. True
fullName Name of the user True
role Role of user. It may be one of admin, user or the name of a custom role you’ve created. True

Context Output

Path Type Description
OpsGenie.User.Id String ID of the User
OpsGenie.User.name String Username of the user

Command Example

!opsgenie-invite-user username=test@example.com fullName="Test XSOAR" role=user

Context Example

{
    "OpsGenie": {
        "User": {
            "id": "f14b51c9-151b-48b2-afda-e2fcc182f230-1613001837514",
            "name": "test@example.com"
        }
    }
}

Human Readable Output

OpsGenie

Id name
3cc69931-167f-411c-a331-768997c29d2e test@example.com

opsgenie-get-teams


Get teams

Base Command

opsgenie-get-teams

Input

Argument Name Description Required
team_id The ID of the team from Opsgenie. Optional

Context Output

Path Type Description
OpsGenie.Team.description String Team description.
OpsGenie.Team.id String Team ID.
OpsGenie.Team.links.api String Team API links.
OpsGenie.Team.links.web String Team web links.
OpsGenie.Team.name String Team name.

Command Example


#### Context Example

```json
{
    "OpsGenie": {
        "Team": [
            {
                "description": "Engineering",
                "id": "51d69df8-c40b-439e-9808-e1a78e54f91b",
                "links": {
                    "api": "https://api.opsgenie.com/v2/teams/51d69df8-c40b-439e-9808-e1a78e54f91b",
                    "web": "https://demisto1.app.opsgenie.com/teams/dashboard/51d69df8-c40b-439e-9808-e1a78e54f91b/main"
                },
                "name": "Engineering"
            },
            {
                "description": "Integration Team",
                "id": "fbbc3f9a-12f4-4794-9938-7e0a85a06f8b",
                "links": {
                    "api": "https://api.opsgenie.com/v2/teams/fbbc3f9a-12f4-4794-9938-7e0a85a06f8b",
                    "web": "https://demisto1.app.opsgenie.com/teams/dashboard/fbbc3f9a-12f4-4794-9938-7e0a85a06f8b/main"
                },
                "name": "Integration Team"
            }
        ]
    }
}

Human Readable Output

OpsGenie Team

description id links name
Engineering 51d69df8-c40b-439e-9808-e1a78e54f91b web: https://demisto1.app.opsgenie.com/teams/dashboard/51d69df8-c40b-439e-9808-e1a78e54f91b/main
api: https://api.opsgenie.com/v2/teams/51d69df8-c40b-439e-9808-e1a78e54f91b
Engineering
Integration Team fbbc3f9a-12f4-4794-9938-7e0a85a06f8b web: https://demisto1.app.opsgenie.com/teams/dashboard/fbbc3f9a-12f4-4794-9938-7e0a85a06f8b/main
api: https://api.opsgenie.com/v2/teams/fbbc3f9a-12f4-4794-9938-7e0a85a06f8b
Integration Team

opsgenie-get-request


Get a request in Opsgenie.

Base Command

opsgenie-get-request

Input

Argument Name Description Required
request_id The id of the request to get Required
request_type The type of the request to get Required

Context Output

Path Type Description
OpsGenie.Alert.action String Action of this request.
OpsGenie.Alert.alertId String ID of the created alert.
OpsGenie.Alert.alias String Alias of the created alert.
OpsGenie.Alert.integrationId String Integration ID of the created alert.
OpsGenie.Alert.isSuccess Boolean Whether the request was successful.
OpsGenie.Alert.processedAt Date When the request was processed.
OpsGenie.Alert.requestId String The ID of the request.
OpsGenie.Alert.status String The human readable result of the request.
OpsGenie.Alert.success Boolean Whether the request was successful.
OpsGenie.Incident.action String Action of this request.
OpsGenie.Incident.alertId String ID of the created alert.
OpsGenie.Incident.alias String Alias of the created alert.
OpsGenie.Incident.integrationId String Integration ID of the created alert.
OpsGenie.Incident.isSuccess Boolean Whether the request was successful.
OpsGenie.Incident.processedAt Date When the request was processed.
OpsGenie.Incident.requestId String The ID of the request.
OpsGenie.Incident.status String The human readable result of the request.
OpsGenie.Incident.success Boolean Whether the request was successful.

Command Example

opsgenie-get-request request_id=b79800b2-4378-4249-8677-0bf2332b8a1f request_type=alerts"

Context Example

{
    "OpsGenie": {
        "Alert": {
            "action": "Create",
            "alertId": "4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716",
            "alias": "4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716",
            "integrationId": "3cc69931-167f-411c-a331-768997c29d2e",
            "isSuccess": true,
            "processedAt": "2021-12-01T13:48:18.757Z",
            "status": "Created alert",
            "success": true
        }
    }
}

Human Readable Output

OpsGenie

action alertId alias integrationId isSuccess processedAt status success
Create 4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716 4c4623e3-0b3f-47b7-becd-907d3e51d129-1638366498716 3cc69931-167f-411c-a331-768997c29d2e true 2021-12-01T13:48:18.757Z Created alert true

Breaking changes from the previous version of this integration - OpsGenie v3

Commands

Removed the following commands in this version:

  • opsgenie-list-alerts - this command was replaced by opsgenie-get-alerts.
  • opsgenie-get-alert - this command was replaced by opsgenie-get-alerts.
  • opsgenie-get-schedule - this command was replaced by opsgenie-get-schedules.
  • opsgenie-list-schedules - this command was replaced by opsgenie-get-schedules.

Arguments

  • In the opsgenie-get-on-call command, the schedule-id argument was replaced by the schedule_id and schedule_name arguments.
  • In the opsgenie-create-alert command, the default value of the priority argument was changed to ‘P3’.

Outputs

  • In the opsgenie-create-alert command the following outputs were replaced:
    • OpsGenieV2.CreatedAlert.action - replaced by OpsGenie.Alert.action.
    • OpsGenieV2.CreatedAlert.alertId - replaced by OpsGenie.Alert.alertId.
    • OpsGenieV2.CreatedAlert.alias - replaced by OpsGenie.Alert.alias.
    • OpsGenieV2.CreatedAlert.integrationId - replaced by OpsGenie.Alert.integrationId.
    • OpsGenieV2.CreatedAlert.isSuccess - replaced by OpsGenie.Alert.isSuccess.
    • OpsGenieV2.CreatedAlert.processedAt - replaced by OpsGenie.Alert.processedAt.
    • OpsGenieV2.CreatedAlert.requestId - replaced by OpsGenie.Alert.requestId.
    • OpsGenieV2.CreatedAlert.status - replaced by OpsGenie.Alert.status.
    • OpsGenieV2.CreatedAlert.success - replaced by OpsGenie.Alert.success.
  • In the opsgenie-delete-alert command the following outputs were replaced:
    • OpsGenieV2.DeletedAlert.action - replaced by OpsGenie.DeletedAlert.action.
    • OpsGenieV2.DeletedAlert.alertId - replaced by OpsGenie.DeletedAlert.alertId.
    • OpsGenieV2.DeletedAlert.alias - replaced by OpsGenie.DeletedAlert.alias.
    • OpsGenieV2.DeletedAlert.integrationId - replaced by OpsGenie.DeletedAlert.integrationId.
    • OpsGenieV2.DeletedAlert.isSuccess - replaced by OpsGenie.DeletedAlert.isSuccess.
    • OpsGenieV2.DeletedAlert.processedAt - replaced by OpsGenie.DeletedAlert.processedAt.
    • OpsGenieV2.DeletedAlert.requestId - replaced by OpsGenie.DeletedAlert.requestId.
    • OpsGenieV2.DeletedAlert.status - replaced by OpsGenie.DeletedAlert.status.
    • OpsGenieV2.DeletedAlert.success - replaced by OpsGenie.DeletedAlert.success.
  • In the opsgenie-ack-alert command the following outputs were replaced:
    • OpsGenieV2.AckedAlert.action - replaced by OpsGenie.AckedAlert.action.
    • OpsGenieV2.AckedAlert.alertId -replaced by OpsGenie.AckedAlert.alertId.
    • OpsGenieV2.AckedAlert.alias -replaced by OpsGenie.AckedAlert.alias.
    • OpsGenieV2.AckedAlert.integrationId - replaced by OpsGenie.AckedAlert.integrationId.
    • OpsGenieV2.AckedAlert.isSuccess - replaced by OpsGenie.AckedAlert.isSuccess.
    • OpsGenieV2.AckedAlert.processedAt - replaced by OpsGenie.AckedAlert.processedAt.
    • OpsGenieV2.AckedAlert.requestId - replaced by OpsGenie.AckedAlert.requestId.
    • OpsGenieV2.AckedAlert.status - replaced by OpsGenie.AckedAlert.status.
    • OpsGenieV2.AckedAlert.success - replaced by OpsGenie.AckedAlert.success.
  • In the opsgenie-get-on-call command the following outputs were replaced:
    • OpsGenieV2.OnCall._parent.enabled - replaced by OpsGenie.Schedule.OnCall._parent.enabled.
    • OpsGenieV2.OnCall._parent.id - replaced by OpsGenie.Schedule.OnCall._parent.id.
    • OpsGenieV2.OnCall._parent.name - replaced by OpsGenie.Schedule.OnCall._parent.name.
    • OpsGenieV2.OnCall.onCallParticipants.id - replaced by OpsGenie.Schedule.OnCall.onCallParticipants.id.
    • OpsGenieV2.OnCall.onCallParticipants.name - replaced by OpsGenie.Schedule.OnCall.onCallParticipants.name.
    • OpsGenieV2.OnCall.onCallParticipants.type - replaced by OpsGenie.Schedule.OnCall.onCallParticipants.type.
  • In the opsgenie-close-alert command the following outputs were replaced:
    • OpsGenieV2.CloseAlert.action - replaced by OpsGenie.ClosedAlert.action.
    • OpsGenieV2.CloseAlert.alertId - replaced by OpsGenie.ClosedAlert.alertId.
    • OpsGenieV2.CloseAlert.alias - replaced by OpsGenie.ClosedAlert.alias.
    • OpsGenieV2.CloseAlert.integrationId - replaced by OpsGenie.ClosedAlert.integrationId.
    • OpsGenieV2.CloseAlert.isSuccess - replaced by OpsGenie.ClosedAlert.isSuccess.
    • OpsGenieV2.CloseAlert.processedAt - replaced by OpsGenie.ClosedAlert.processedAt.
    • OpsGenieV2.CloseAlert.requestId - replaced by OpsGenie.ClosedAlert.requestId.
    • OpsGenieV2.CloseAlert.status - replaced by OpsGenie.ClosedAlert.status.
    • OpsGenieV2.CloseAlert.success - replaced by OpsGenie.ClosedAlert.success.

opsgenie-get-team-routing-rules


Lists team routing rules.

Base Command

opsgenie-get-team-routing-rules

Input

Argument Name Description Required
team_id The ID of the team from Opsgenie. Required

Context Output

Path Type Description
OpsGenie.TeamRoutingRule.name unknown Name of the routing rule.
OpsGenie.TeamRoutingRule.order unknown Order of the routing rule.
OpsGenie.TeamRoutingRule.id unknown ID of the routing rule.
OpsGenie.TeamRoutingRule.timezone unknown Timezone of the routing rule.
OpsGenie.TeamRoutingRule.teamId unknown Team ID of the routing rule.
OpsGenie.TeamRoutingRule.customerId unknown Customer ID of the routing rule.
OpsGenie.TeamRoutingRule.notify.id unknown Notify ID of the routing rule.
OpsGenie.TeamRoutingRule.notify.name unknown Notify name of the routing rule.
OpsGenie.TeamRoutingRule.notify.type unknown Notify type of the routing rule.

opsgenie-get-alert-logs


Gets logs of an OpsGenie Alert.

Base Command

opsgenie-get-alert-logs

Input

Argument Name Description Required
alert_id Alert ID. Required

Context Output

Path Type Description
OpsGenie.AlertLogs.createdAt String Time the alert was created.
OpsGenie.AlertLogs.log String Log of the alert.
OpsGenie.AlertLogs.offset String Offset of the alert log.
OpsGenie.AlertLogs.owner String Owner of the alert log.
OpsGenie.AlertLogs.type String Type of the alert log.

opsgenie-add-alert-note


Adds a note to an OpsGenie Alert.

Base Command

opsgenie-add-alert-note

Input

Argument Name Description Required
alert_id Alert ID to add the note to. Required
note Alert note to add. Required
user Display name of the request owner. Optional
source Display name of the request source. Optional

Context Output

Path Type Description
OpsGenie.AddAlertNote.action String Action of this request.
OpsGenie.AddAlertNote.alertId String ID of the created alert.
OpsGenie.AddAlertNote.alias String Alias of the created alert.
OpsGenie.AddAlertNote.integrationId String Integration ID of the created alert.
OpsGenie.AddAlertNote.isSuccess Boolean Whether the request was successful.
OpsGenie.AddAlertNote.processedAt Date When the request was processed.
OpsGenie.AddAlertNote.requestId String The ID of the request.
OpsGenie.AddAlertNote.status String The human readable result of the request.
OpsGenie.AddAlertNote.success Boolean Whether the request was successful.

opsgenie-add-alert-details


Adds details to an OpsGenie Alert.

Base Command

opsgenie-add-alert-details

Input

Argument Name Description Required
alert_id Alert ID to add the details to. Required
details Comma-separated key=value pairs to use as custom properties of the alert. JSON format is also supported when used within an automation. Examples; details=”account=pa,hostname=computer01”. Required

Context Output

Path Type Description
OpsGenie.AddAlertDetails.action String Action of this request.
OpsGenie.AddAlertDetails.alertId String ID of the created alert.
OpsGenie.AddAlertDetails.alias String Alias of the created alert.
OpsGenie.AddAlertDetails.integrationId String Integration ID of the created alert.
OpsGenie.AddAlertDetails.isSuccess Boolean Whether the request was successful.
OpsGenie.AddAlertDetails.processedAt Date When the request was processed.
OpsGenie.AddAlertDetails.requestId String The ID of the request.
OpsGenie.AddAlertDetails.status String The human readable result of the request.
OpsGenie.AddAlertDetails.success Boolean Whether the request was successful.

Configuration parameters

  • url — Server URL (e.g., https://api.opsgenie.com) (required)
  • credentials — (required)
  • isFetch — Fetch incidents
  • first_fetch — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
  • max_fetch — Max Fetch
  • event_types — Event types
  • status — Status
  • priority — Priority
  • tags — Tags
  • query — Query
  • incidentType — Incident type
  • incidentFetchInterval — Incidents Fetch Interval
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings

Commands (30)

  • opsgenie-ack-alert

    Acknowledge an alert in OpsGenie.

  • opsgenie-add-alert-details

    Adds details to an OpsGenie Alert.

  • opsgenie-add-alert-note

    Adds a note to an OpsGenie Alert.

  • opsgenie-add-alert-tag

    Add tag to the OpsGenie alert.

  • opsgenie-add-responder-alert

    Add a responder to an OpsGenie alert.

  • opsgenie-add-responder-incident

    Add a responder to an OpsGenie incident.

  • opsgenie-add-tag-incident

    Add a tag to the OpsGenie incident.

  • opsgenie-assign-alert

    Assign an OpsGenie alert.

  • opsgenie-close-alert

    Close an alert in OpsGenie.

  • opsgenie-close-incident

    Close an incident from OpsGenie.

  • opsgenie-create-alert

    Create an alert in Opsgenie.

  • opsgenie-create-incident

    Create an incident in Opsgenie.

  • opsgenie-delete-alert

    Delete an alert from OpsGenie.

  • opsgenie-delete-incident

    Delete an incident from OpsGenie.

  • opsgenie-escalate-alert

    Escalate an OpsGenie alert.

  • opsgenie-get-alert-attachments

    Get the attachments of the alert.

  • opsgenie-get-alert-logs

    Gets logs of an OpsGenie Alert.

  • opsgenie-get-alerts

    List the current alerts from OpsGenie.

  • opsgenie-get-escalations

    Get escalations from OpsGenie.

  • opsgenie-get-incidents

    List the current incidents from OpsGenie.

  • opsgenie-get-on-call

    Get the on-call users for the provided schedule.

  • opsgenie-get-request

    Get a request in Opsgenie.

  • opsgenie-get-schedule-overrides

    Get schedule overrides.

  • opsgenie-get-schedules

    Get a schedule from OpsGenie.

  • opsgenie-get-team-routing-rules

    Lists team routing rules.

  • opsgenie-get-teams

    Get teams.

  • opsgenie-invite-user

    Invite a user to OpsGenie.

  • opsgenie-remove-alert-tag

    Remove a tag from the OpsGenie alert.

  • opsgenie-remove-tag-incident

    Remove a tag from the OpsGenie alert.

  • opsgenie-resolve-incident

    Resolve an incident from OpsGenie.

from collections.abc import Callable

import demistomock as demisto  # noqa: F401
import urllib3
from CommonServerPython import *  # noqa: F401
from requests import Response

from CommonServerUserPython import *  # noqa

# Disable insecure warnings
DEFAULT_POLL_INTERVAL = 5
urllib3.disable_warnings()

""" CONSTANTS """
DEFAULT_POLL_TIMEOUT = 60
INTEGRATION_NAME = "Opsgenie"
ALERTS_SUFFIX = "alerts"
REQUESTS_SUFFIX = "requests"
SCHEDULE_SUFFIX = "schedules"
USERS_SUFFIX = "users"
INCIDENTS_SUFFIX = "incidents"
ESCALATION_SUFFIX = "escalations"
TEAMS_SUFFIX = "teams"
DATE_FORMAT = "%Y-%m-%dT%H:%M:%SZ"
INCIDENT_TYPE = "Incidents"
ALERT_TYPE = "Alerts"
ALL_TYPE = "All"

""" CLIENT CLASS """


class Client(BaseClient):
    """
    OpsGenieV3 Client
    """

    def get_request(self, args: dict) -> Response:
        url_suffix = "/v1" if args.get("request_type") == INCIDENTS_SUFFIX else "/v2"

        return self._http_request(
            method="GET",
            url_suffix=f"{url_suffix}/{args.get('request_type')}/{REQUESTS_SUFFIX}/{args.get('request_id')}",
            ok_codes=(404, 200),
            resp_type="response",
        )

    def get_paged(self, args: dict):
        data = self._http_request(method="GET", full_url=args.get("paging"))
        return data

    @staticmethod
    # type: ignore
    def responders_to_json(responders: List, responder_key: str, one_is_dict: bool = False) -> Dict[str, Union[List, Dict]]:
        """
        :param responders: the responders list which we get from demisto.args()
        :param responder_key: Some of the api calls need "responder" and others "responders" as a
        key in the responders jason
        :param one_is_dict: Some of the api calls need when there is one responder it as a dict
        and others as a list
        :return json_responders: reformatted respondres dict
        """
        if not responders:
            return {}
        if len(responders) % 3 != 0:
            raise DemistoException("responders must be list of: responder_type, value_type, value")
        responders_triple = list(zip(responders[::3], responders[1::3], responders[2::3]))
        json_responders = {responder_key: []}  # type: ignore
        for responder_type, value_type, value in responders_triple:
            if responder_type == "user" and value_type == "name":
                value_type = "username"
            json_responders[responder_key].append({value_type: value, "type": responder_type})
        response = json_responders
        if len(responders_triple) == 1 and one_is_dict:
            response = {responder_key: json_responders[responder_key][0]}
        return response  # type: ignore

    def create_alert(self, args: dict):
        args["responders"] = argToList(args.get("responders"))
        args["tags"] = argToList(args.get("tags"))
        if args.get("details") and not isinstance(args.get("details"), dict):
            args["details"] = {key_value.split("=")[0]: key_value.split("=")[1] for key_value in argToList(args.get("details"))}

        args.update(Client.responders_to_json(args.get("responders", []), "responders"))
        return self._http_request(method="POST", url_suffix=f"/v2/{ALERTS_SUFFIX}", json_data=args)

    def get_alert(self, alert_id: int):
        return self._http_request(method="GET", url_suffix=f"/v2/{ALERTS_SUFFIX}/{alert_id}")

    def list_alerts(self, args: dict):
        args["tags"] = argToList(args.get("tags"))
        params = {"limit": args.get("limit"), "offset": args.get("offset"), "query": Client.build_query(args)}
        res = self._http_request(method="GET", url_suffix=f"/v2/{ALERTS_SUFFIX}", params=params)
        if len(res.get("data", [])) > 0:
            for result in res.get("data"):
                result["event_type"] = ALERT_TYPE
        return res

    def delete_alert(self, args: dict):
        return self._http_request(method="DELETE", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert-id')}", json_data=args)

    def ack_alert(self, args: dict):
        return self._http_request(
            method="POST", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert-id')}/acknowledge", json_data=args
        )

    def close_alert(self, args: dict):
        return self._http_request(method="POST", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert-id')}/close", json_data=args)

    def assign_alert(self, args: dict):
        return self._http_request(method="POST", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert-id')}/assign", json_data=args)

    def add_responder_alert(self, args: dict):
        alert_id = args.get("alert-id")
        identifier = args.get("identifierType", "id")
        args["responders"] = argToList(args.get("responders"))
        args.update(Client.responders_to_json(responders=args.get("responders", []), responder_key="responder", one_is_dict=True))
        return self._http_request(
            method="POST",
            url_suffix=f"/v2/{ALERTS_SUFFIX}/{alert_id}/responders",
            params={"identifierType": identifier},
            json_data=args,
        )

    def get_escalation(self, args: dict):
        if args.get("escalation_id") and args.get("escalation_name"):
            raise DemistoException("Either escalation_id or escalation_name should be provided.")
        identifier_type = "id" if args.get("escalation_id") else "name"
        escalation = args.get("escalation_id", None) or args.get("escalation_name", None)
        return self._http_request(
            method="GET", url_suffix=f"/v2/{ESCALATION_SUFFIX}/{escalation}", params={"identifierType": identifier_type}
        )

    def get_escalations(self):
        return self._http_request(method="GET", url_suffix=f"/v2/{ESCALATION_SUFFIX}")

    def escalate_alert(self, args: dict):
        return self._http_request(
            method="POST", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert-id')}/escalate", json_data=args
        )

    def add_alert_tag(self, args: dict):
        args["tags"] = argToList(args.get("tags"))
        return self._http_request(method="POST", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert-id')}/tags", json_data=args)

    def add_alert_note(self, args: dict):
        return self._http_request(method="POST", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert_id')}/notes", json_data=args)

    def add_alert_details(self, args: dict):
        if not isinstance(args.get("details"), dict):
            args["details"] = {key_value.split("=")[0]: key_value.split("=")[1] for key_value in argToList(args.get("details"))}
        return self._http_request(method="POST", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert_id')}/details", json_data=args)

    def remove_alert_tag(self, args: dict):
        args["tags"] = argToList(args.get("tags"))
        return self._http_request(
            method="DELETE",
            url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert-id')}/tags",
            params={"tags": args.get("tags")},
            json_data=args,
        )

    def get_alert_attachments(self, args: dict):
        attachment_id = args.get("attachment_id")
        if attachment_id:
            return self._http_request(method="GET", url_suffix=f"/v2/{ALERTS_SUFFIX}/attachments/{attachment_id}")
        return self._http_request(method="GET", url_suffix=f"/v2/{ALERTS_SUFFIX}/{args.get('alert-id')}/attachments")

    def get_alert_logs(self, args: dict):
        alert_id = args.get("alert_id")
        return self._http_request(method="GET", url_suffix=f"/v2/{ALERTS_SUFFIX}/{alert_id}/logs")

    def get_schedule(self, args: dict):
        if not is_one_argument_given(args.get("schedule_id"), args.get("schedule_name")):
            raise DemistoException("Either schedule_id or schedule_name should be provided.")
        identifier_type = "id" if args.get("schedule_id") else "name"
        schedule = args.get("schedule_id", None) or args.get("schedule_name", None)
        return self._http_request(
            method="GET", url_suffix=f"/v2/{SCHEDULE_SUFFIX}/{schedule}", params={"identifierType": identifier_type}
        )

    def list_schedules(self):
        return self._http_request(method="GET", url_suffix=f"/v2/{SCHEDULE_SUFFIX}")

    def get_schedule_override(self, args: dict):
        identifier_type = "id" if args.get("schedule_id") else "name"
        schedule = args.get("schedule_id", None) or args.get("schedule_name", None)
        return self._http_request(
            method="GET",
            url_suffix=f"/v2/{SCHEDULE_SUFFIX}/{schedule}/overrides/{args.get('override_alias')}",
            params={"scheduleIdentifierType": identifier_type},
        )

    def list_schedule_overrides(self, args: dict):
        identifier_type = "id" if args.get("schedule_id") else "name"
        schedule = args.get("schedule_id", None) or args.get("schedule_name", None)
        return self._http_request(
            method="GET",
            url_suffix=f"/v2/{SCHEDULE_SUFFIX}/{schedule}/overrides",
            params={"scheduleIdentifierType": identifier_type},
        )

    def get_on_call(self, args: dict):
        return self._http_request(
            method="GET",
            url_suffix=f"/v2/{SCHEDULE_SUFFIX}/{args.get('schedule')}/on-calls",
            params={"scheduleIdentifierType": args.get("scheduleIdentifierType"), "date": args.get("date")},
        )

    def create_incident(self, args: dict):
        args["responders"] = argToList(args.get("responders"))
        args.update(Client.responders_to_json(args.get("responders", []), "responders"))
        return self._http_request(method="POST", url_suffix=f"/v1/{INCIDENTS_SUFFIX}/create", json_data=args)

    def delete_incident(self, args: dict):
        return self._http_request(method="DELETE", url_suffix=f"/v1/{INCIDENTS_SUFFIX}/{args.get('incident_id')}", json_data=args)

    def get_incident(self, args: dict):
        return self._http_request(
            method="GET",
            url_suffix=f"/v1/{INCIDENTS_SUFFIX}/{args.get('incident_id')}",
        )

    @staticmethod
    def build_query(args: dict) -> str:
        query = ""
        if args.get("query", ""):
            query = args.get("query", "")
        if args.get("is_fetch_query", False) or not args.get("query", ""):
            status = args.get("status", ALL_TYPE)
            if status != ALL_TYPE:
                query += " AND " if query else ""
                query += f"status={status.lower()}"
            priority = argToList(args.get("priority", [ALL_TYPE]))
            if ALL_TYPE not in priority:
                query += " AND " if query else ""
                priority_parsed = " OR ".join(list(priority))
                query += f"priority: ({priority_parsed})"
            tags = argToList(args.get("tags", []))
            if tags:
                query += " AND " if query else ""
                tag_parsed = " OR ".join(list(tags))
                query += f"tag: ({tag_parsed})"
        return query

    def list_incidents(self, args: dict):
        args["tags"] = argToList(args.get("tags"))
        params = {"limit": args.get("limit"), "offset": args.get("offset"), "query": Client.build_query(args)}
        res = self._http_request(method="GET", url_suffix=f"/v1/{INCIDENTS_SUFFIX}", params=params)
        if len(res.get("data", [])) > 0:
            for result in res.get("data"):
                result["event_type"] = INCIDENT_TYPE
        return res

    def close_incident(self, args: dict):
        return self._http_request(
            method="POST", url_suffix=f"/v1/{INCIDENTS_SUFFIX}/{args.get('incident_id')}/close", json_data=args
        )

    def resolve_incident(self, args: dict):
        return self._http_request(
            method="POST", url_suffix=f"/v1/{INCIDENTS_SUFFIX}/{args.get('incident_id')}/resolve", json_data=args
        )

    def add_responder_incident(self, args: dict):
        args["responders"] = argToList(args.get("responders"))
        args.update(Client.responders_to_json(args.get("responders", []), "responder"))
        return self._http_request(
            method="POST", url_suffix=f"/v1/{INCIDENTS_SUFFIX}/{args.get('incident_id')}/responders", json_data=args
        )

    def add_tag_incident(self, args: dict):
        args["tags"] = argToList(args.get("tags"))
        return self._http_request(
            method="POST", url_suffix=f"/v1/{INCIDENTS_SUFFIX}/{args.get('incident_id')}/tags", json_data=args
        )

    def remove_tag_incident(self, args: dict):
        args["tags"] = argToList(args.get("tags"))
        return self._http_request(
            method="DELETE",
            url_suffix=f"/v1/{INCIDENTS_SUFFIX}/{args.get('incident_id')}/tags",
            params={"tags": args.get("tags")},
            json_data=args,
        )

    def invite_user(self, args):
        return self._http_request(method="POST", url_suffix=f"/v2/{USERS_SUFFIX}", json_data=args)

    def get_team(self, args: dict):
        return self._http_request(method="GET", url_suffix=f"/v2/{TEAMS_SUFFIX}/{args.get('team_id')}")

    def get_team_routing_rules(self, args: dict):
        return self._http_request(method="GET", url_suffix=f"/v2/{TEAMS_SUFFIX}/{args.get('team_id')}/routing-rules")

    def list_teams(self):
        return self._http_request(method="GET", url_suffix=f"/v2/{TEAMS_SUFFIX}")


""" HELPER FUNCTIONS """


def is_one_argument_given(arg1, arg2):
    """
    checks that out of two arguments only one argument is set.
    :param arg1: first argument
    :param arg2: second argument
    :return: True if only one argument is set else False
    """

    return bool(arg1) ^ bool(arg2)


""" COMMAND FUNCTIONS """


def run_polling_paging_command(
    args: dict, cmd: str, results_function: Callable, action_function: Optional[Callable] = None
) -> CommandResults:
    ScheduledCommand.raise_error_if_not_supported()

    interval_in_secs = int(args.get("interval_in_seconds", DEFAULT_POLL_INTERVAL))
    result = args.get("result", [])
    limit = int(args.get("limit", 20))

    if "request_id" not in args and action_function:
        # starting new flow
        results = action_function(args)
        request_id = results.get("requestId")
        if not request_id:
            raise ConnectionError(f"Failed to send request - {results}")
        next_paging = results.get("paging", {}).get("next")
        result = result + results.get("data")
        if not next_paging or len(result) >= limit:
            # If not a paged request, simply return
            return CommandResults(
                outputs_prefix=args.get("output_prefix", "OpsGenie"),
                outputs=results.get("data"),
                readable_output=tableToMarkdown(
                    "OpsGenie",
                    results.get("data"),
                    headers=["id", "createdAt", "acknowledged", "count", "status", "tags"],
                    removeNull=True,
                ),
                raw_response=results,
            )
        else:
            # If a paged request, return scheduled_command
            args["request_id"] = request_id
            args["result"] = result
            args["paging"] = next_paging
            polling_args = {"interval_in_seconds": interval_in_secs, "polling": True, **args}
            scheduled_command = ScheduledCommand(
                command=cmd,
                next_run_in_seconds=int(args.get("interval_in_seconds", DEFAULT_POLL_INTERVAL)),
                args=polling_args,
                timeout_in_seconds=int(args.get("timeout_in_seconds", DEFAULT_POLL_TIMEOUT)),
            )
            return CommandResults(
                scheduled_command=scheduled_command,
                readable_output=f"Waiting for request_id={request_id}",
                outputs_prefix=args.get("output_prefix", "OpsGenie"),
                outputs={"requestId": request_id},
            )

    results = results_function(args)
    result = result + results.get("data")
    results["data"] = result
    next_paging = results.get("paging", {}).get("next")
    if not next_paging or len(result) >= limit:
        # If not a paged request, simply return
        return CommandResults(
            outputs_prefix=args.get("output_prefix", "OpsGenie"),
            outputs=results.get("data"),
            readable_output=tableToMarkdown(
                "OpsGenie",
                results.get("data"),
                headers=["id", "createdAt", "acknowledged", "count", "status", "tags"],
                removeNull=True,
            ),
            raw_response=results,
        )

    if len(result) < limit:
        # schedule next poll
        args["request_id"] = results.get("request_id")
        args["result"] = result
        args["paging"] = next_paging
        polling_args = {"interval_in_seconds": interval_in_secs, "polling": True, **args}
        scheduled_command = ScheduledCommand(
            command=cmd,
            next_run_in_seconds=int(args.get("interval_in_seconds", DEFAULT_POLL_INTERVAL)),
            args=polling_args,
            timeout_in_seconds=int(args.get("timeout_in_seconds", DEFAULT_POLL_TIMEOUT)),
        )
        # result with scheduled_command only - no update to the war room
        command_results = CommandResults(
            scheduled_command=scheduled_command,
            readable_output=f"Waiting for request_id={args.get('request_id')}",
            outputs_prefix=args.get("output_prefix", "OpsGenie"),
            outputs={"requestId": args.get("request_id")},
        )
        return command_results
    return CommandResults(
        outputs_prefix=args.get("output_prefix", "OpsGenie"),
        outputs=results.get("data"),
        readable_output=tableToMarkdown(
            "OpsGenie",
            results.get("data"),
            headers=["id", "createdAt", "acknowledged", "count", "status", "tags"],
            removeNull=True,
        ),
        raw_response=results,
    )


def test_module(client: Client, params: dict) -> str:
    """
    Tries to run list_alerts, returning OK if integration is working.
    """
    result_list = client.list_alerts({"sort": "createdAt", "limit": 5})
    result_fetch = [{"ok": "ok"}]
    if params.get("isFetch"):
        result_fetch, last_run = fetch_incidents_command(client, params)
    if result_list and result_fetch:
        return "ok"
    return "Failed."


def create_alert(client: Client, args: Dict[str, Any]) -> CommandResults:
    args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.Alert", **args}
    data = client.create_alert(args)
    request_id = data.get("requestId")
    if not request_id:
        raise ConnectionError(f"Failed to send request - {data}")
    args["request_id"] = request_id
    return get_request_command(client, args)


def get_alerts(client: Client, args: Dict[str, Any]) -> CommandResults:
    alert_id = args.get("alert-id", None)
    result = client.get_alert(alert_id) if alert_id else list_alerts(client, args)
    if isinstance(result, CommandResults):
        return result
    return CommandResults(
        outputs_prefix="OpsGenie.Alert",
        outputs=result.get("data"),
        readable_output=tableToMarkdown(
            "OpsGenie Alert",
            result.get("data"),
            headers=["id", "createdAt", "acknowledged", "count", "status", "tags"],
            removeNull=True,
        ),
        raw_response=result,
    )


def list_alerts(client: Client, args: Dict[str, Any]) -> CommandResults:
    polling_args = {
        "url_suffix": f"/v2/{ALERTS_SUFFIX}",
        "output_prefix": "OpsGenie.Alert",
        "request_type": ALERTS_SUFFIX,
        **args,
    }
    polling_result = run_polling_paging_command(
        args=polling_args, cmd="opsgenie-get-alerts", action_function=client.list_alerts, results_function=client.get_paged
    )
    return polling_result


def delete_alert(client: Client, args: Dict[str, Any]) -> CommandResults:
    args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.DeletedAlert", **args}
    data = client.delete_alert(args)
    request_id = data.get("requestId")
    if not request_id:
        raise ConnectionError(f"Failed to send request - {data}")
    args["request_id"] = request_id
    return get_request_command(client, args)


def ack_alert(client: Client, args: Dict[str, Any]) -> CommandResults:
    args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.AckedAlert", **args}
    data = client.ack_alert(args)
    request_id = data.get("requestId")
    if not request_id:
        raise ConnectionError(f"Failed to send request - {data}")
    args["request_id"] = request_id
    return get_request_command(client, args)


def close_alert(client: Client, args: Dict[str, Any]) -> CommandResults:
    args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.ClosedAlert", **args}
    data = client.close_alert(args)
    request_id = data.get("requestId")
    if not request_id:
        raise ConnectionError(f"Failed to send request - {data}")
    args["request_id"] = request_id
    return get_request_command(client, args)


def assign_alert(client: Client, args: Dict[str, Any]) -> CommandResults:
    if args.get("owner_id"):
        owner = {"id": args.get("owner_id")}
    elif args.get("owner_username"):
        owner = {"username": args.get("owner_username")}
    else:  # not args.get("owner_id") and not args.get("owner_username")
        raise DemistoException("Either owner_id or owner_username should be provided.")

    args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.AssignAlert", "owner": owner, **args}
    data = client.assign_alert(args)
    request_id = data.get("requestId")
    if not request_id:
        raise ConnectionError(f"Failed to send request - {data}")
    args["request_id"] = request_id
    return get_request_command(client, args)


def add_responder_alert(client: Client, args: Dict[str, Any]) -> CommandResults:
    args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.AddResponderAlert", **args}
    data = client.add_responder_alert(args)
    request_id = data.get("requestId")
    if not request_id:
        raise ConnectionError(f"Failed to send request - {data}")
    args["request_id"] = request_id
    return get_request_command(client, args)


def get_escalations(client: Client, args: Dict[str, Any]) -> CommandResults:
    escalation = args.get("escalation_id", None) or args.get("escalation_name", None)
    result = client.get_escalation(args) if escalation else client.get_escalations()
    return CommandResults(
        outputs_prefix="OpsGenie.Escalations",
        outputs=result.get("data"),
        readable_output=tableToMarkdown("OpsGenie Escalations", result.get("data")),
        raw_response=result,
    )


def escalate_alert(client: Client, args: Dict[str, Any]) -> CommandResults:
    if args.get("escalation_id"):
        escalation = {"id": args.get("escalation_id")}
    elif args.get("escalation_name"):
        escalation = {"name": args.get("escalation_name")}
    else:  # not args.get("owner_id") and not args.get("owner_username")
        raise DemistoException("Either escalation_id or escalation_name should be provided.")
    args = {"request_type": ALERTS_SUFFIX, "escalation": escalation, "output_prefix": "OpsGenie.EscalateAlert", **args}
    data = client.escalate_alert(args)
    request_id = data.get("requestId")
    if not request_id:
        raise ConnectionError(f"Failed to send request - {data}")
    args["request_id"] = request_id
    return get_request_command(client, args)


def add_alert_tag(client: Client, args: Dict[str, Any]) -> CommandResults:
    args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.AddTagAlert", **args}
    data = client.add_alert_tag(args)
    request_id = data.get("requestId")
    if not request_id:
        raise ConnectionError(f"Failed to send request - {data}")
    args["request_id"] = request_id
    return get_request_command(client, args)


def add_alert_note(client: Client, args: Dict[str, Any]) -> CommandResults:
    args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.AddAlertNote", **args}
    data = client.add_alert_note(args)
    request_id = data.get("requestId")
    if not request_id:
        raise ConnectionError(f"Failed to send request - {data}")
    args["request_id"] = request_id
    return get_request_command(client, args)


def add_alert_details(client: Client, args: Dict[str, Any]) -> CommandResults:
    args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.AddAlertDetails", **args}
    data = client.add_alert_details(args)
    request_id = data.get("requestId")
    if not request_id:
        raise ConnectionError(f"Failed to send request - {data}")
    args["request_id"] = request_id
    return get_request_command(client, args)


def remove_alert_tag(client: Client, args: Dict[str, Any]) -> CommandResults:
    args = {"request_type": ALERTS_SUFFIX, "output_prefix": "OpsGenie.RemoveTagAlert", **args}
    data = client.remove_alert_tag(args)
    request_id = data.get("requestId")
    if not request_id:
        raise ConnectionError(f"Failed to send request - {data}")
    args["request_id"] = request_id
    return get_request_command(client, args)


def get_alert_attachments(client: Client, args: Dict[str, Any]) -> CommandResults:
    result = client.get_alert_attachments(args)
    return CommandResults(
        outputs_prefix="OpsGenie.Alert.Attachment",
        outputs=result.get("data"),
        readable_output=tableToMarkdown("OpsGenie Attachment", result.get("data")),
        raw_response=result,
    )


def get_alert_logs(client: Client, args: Dict[str, Any]) -> CommandResults:
    result = client.get_alert_logs(args)
    data = result.get("data")
    return CommandResults(
        outputs_prefix="OpsGenie.AlertLogs",
        outputs=result.get("data"),
        readable_output=tableToMarkdown("OpsGenie Logs", data),
        raw_response=result,
    )


def get_schedules(client: Client, args: Dict[str, Any]) -> CommandResults:
    schedule = args.get("schedule_id", None) or args.get("schedule_name", None)
    result = client.get_schedule(args) if schedule else client.list_schedules()
    return CommandResults(
        outputs_prefix="OpsGenie.Schedule",
        outputs=result.get("data"),
        readable_output=tableToMarkdown("OpsGenie Schedule", result.get("data")),
        raw_response=result,
    )


def get_schedule_overrides(client: Client, args: Dict[str, Any]) -> CommandResults:
    if not args.get("schedule_id") and not args.get("schedule_name"):
        raise DemistoException("Either schedule_id or schedule_name should be provided.")
    result = client.get_schedule_override(args) if args.get("override_alias") else client.list_schedule_overrides(args)
    return CommandResults(
        outputs_prefix="OpsGenie.Schedule",
        outputs=result.get("data"),
        readable_output=tableToMarkdown("OpsGenie Schedule", result.get("data")),
        raw_response=result,
    )


def get_on_call(client: Client, args: Dict[str, Any]) -> CommandResults:
    if args.get("schedule_id"):
        schedule = args.get("schedule_id")
        schedule_identifier_type = "id"
    elif args.get("schedule_name"):
        schedule = args.get("schedule_name")
        schedule_identifier_type = "name"
    else:  # not args.get("schedule_id") and not args.get("schedule_name")
        raise DemistoException("Either schedule_id or schedule_name should be provided.")
    date = arg_to_datetime(args.get("starting_date"))
    on_call_args = {
        "request_type": SCHEDULE_SUFFIX,
        "scheduleIdentifierType": schedule_identifier_type,
        "schedule": schedule,
        **args,
    }
    if date:
        on_call_args["date"] = date.isoformat()
        demisto.debug(f"get on call with date: {date}")
    result = client.get_on_call(on_call_args)
    command_result = CommandResults(
        outputs_prefix="OpsGenie.Schedule.OnCall",
        outputs=result,
        readable_output=tableToMarkdown("OpsGenie Schedule OnCall", result.get("data")),
        raw_response=result,
    )
    return command_result


def create_incident(client: Client, args: Dict[str, Any]) -> CommandResults:
    args = {"request_type": INCIDENTS_SUFFIX, "output_prefix": "OpsGenie.Incident", **args}
    data = client.create_incident(args)
    request_id = data.get("requestId")
    if not request_id:
        raise ConnectionError(f"Failed to send request - {data}")
    args["request_id"] = request_id
    return get_request_command(client, args)


def delete_incident(client: Client, args: Dict[str, Any]) -> CommandResults:
    args = {"request_type": INCIDENTS_SUFFIX, "output_prefix": "OpsGenie.DeletedIncident", **args}
    data = client.delete_incident(args)
    request_id = data.get("requestId")
    if not request_id:
        raise ConnectionError(f"Failed to send request - {data}")
    args["request_id"] = request_id
    return get_request_command(client, args)


def get_incidents(client: Client, args: Dict[str, Any]) -> CommandResults:
    incident_id = args.get("incident_id", None)
    result = client.get_incident(args) if incident_id else list_incidents(client, args)
    if isinstance(result, CommandResults):
        return result
    return CommandResults(
        outputs_prefix="OpsGenie.Incident",
        outputs=result.get("data"),
        readable_output=tableToMarkdown(
            "OpsGenie Incident",
            result.get("data"),
            headers=["id", "createdAt", "acknowledged", "count", "status", "tags"],
            removeNull=True,
        ),
        raw_response=result,
    )


def list_incidents(client: Client, args: Dict[str, Any]) -> CommandResults:
    polling_args = {"url_suffix": f"/v1/{INCIDENTS_SUFFIX}", "output_prefix": "OpsGenie.Incident", **args}
    polling_result = run_polling_paging_command(
        args=polling_args, cmd="opsgenie-get-incidents", action_function=client.list_incidents, results_function=client.get_paged
    )
    return polling_result


def close_incident(client: Client, args: Dict[str, Any]) -> CommandResults:
    args = {"request_type": INCIDENTS_SUFFIX, "output_prefix": "OpsGenie.ClosedIncident", **args}
    data = client.close_incident(args)
    request_id = data.get("requestId")
    if not request_id:
        raise ConnectionError(f"Failed to send request - {data}")
    args["request_id"] = request_id
    return get_request_command(client, args)


def resolve_incident(client: Client, args: Dict[str, Any]) -> CommandResults:
    args = {"request_type": INCIDENTS_SUFFIX, "output_prefix": "OpsGenie.ResolvedIncident", **args}
    data = client.resolve_incident(args)
    request_id = data.get("requestId")
    if not request_id:
        raise ConnectionError(f"Failed to send request - {data}")
    args["request_id"] = request_id
    return get_request_command(client, args)


def add_responder_incident(client: Client, args: Dict[str, Any]) -> CommandResults:
    args = {"request_type": INCIDENTS_SUFFIX, "output_prefix": "OpsGenie.AddResponderIncident", **args}
    data = client.add_responder_incident(args)
    request_id = data.get("requestId")
    if not request_id:
        raise ConnectionError(f"Failed to send request - {data}")
    args["request_id"] = request_id
    return get_request_command(client, args)


def add_tag_incident(client: Client, args: Dict[str, Any]) -> CommandResults:
    args = {"request_type": INCIDENTS_SUFFIX, "output_prefix": "OpsGenie.AddTagIncident", **args}
    data = client.add_tag_incident(args)
    request_id = data.get("requestId")
    if not request_id:
        raise ConnectionError(f"Failed to send request - {data}")
    args["request_id"] = request_id
    return get_request_command(client, args)


def remove_tag_incident(client: Client, args: Dict[str, Any]) -> CommandResults:
    args = {"request_type": INCIDENTS_SUFFIX, "output_prefix": "OpsGenie.RemoveTagIncident", **args}
    data = client.remove_tag_incident(args)
    request_id = data.get("requestId")
    if not request_id:
        raise ConnectionError(f"Failed to send request - {data}")
    args["request_id"] = request_id
    return get_request_command(client, args)


def get_request_command(client: Client, args: Dict[str, Any]) -> CommandResults:
    request_type = str(args.get("request_type"))
    results: Response = client.get_request(args)

    if results.status_code == 404:
        ScheduledCommand.raise_error_if_not_supported()
        request_id = args.get("request_id")

        raw_res = {}
        if results.content:
            try:
                raw_res = json.loads(results.content)
            except ValueError:
                demisto.error(f"Failed to parse the response content : {results.content!s}")

        return CommandResults(
            raw_response=raw_res,
            readable_output=None if args.get("polled_once") else f"Waiting for request_id={request_id}",
            outputs_prefix=args.get("output_prefix", "OpsGenie.Request"),
            outputs=None if args.get("polled_once") else {"requestId": request_id},
            scheduled_command=ScheduledCommand(
                command="opsgenie-get-request",
                next_run_in_seconds=int(args.get("interval_in_seconds", DEFAULT_POLL_INTERVAL)),
                args={**args, "polled_once": True},
                timeout_in_seconds=int(args.get("timeout_in_seconds", DEFAULT_POLL_TIMEOUT)),
            ),
        )
    else:
        results_dict = results.json()
        outputs_prefix = args.get("output_prefix", f"OpsGenie.{request_type.capitalize()[:-1]}")
        return CommandResults(
            outputs_prefix=outputs_prefix,
            outputs=results_dict.get("data"),
            readable_output=tableToMarkdown(
                f"OpsGenie - {pascalToSpace(outputs_prefix.split('.')[-1])}", results_dict.get("data")
            ),
            raw_response=results_dict,
        )


def invite_user(client, args) -> CommandResults:
    args["role"] = {"name": args.get("role")}
    result = client.invite_user(args)
    return CommandResults(
        outputs_prefix="OpsGenie.Users",
        outputs=result.get("data"),
        readable_output=tableToMarkdown("OpsGenie Users", result.get("data")),
        raw_response=result,
    )


def get_teams(client: Client, args: Dict[str, Any]) -> CommandResults:
    result = client.get_team(args) if args.get("team_id") else client.list_teams()
    return CommandResults(
        outputs_prefix="OpsGenie.Team",
        outputs=result.get("data"),
        readable_output=tableToMarkdown("OpsGenie Team", result.get("data")),
        raw_response=result,
    )


def get_team_routing_rules(client: Client, args: Dict[str, Any]) -> CommandResults:
    result = client.get_team_routing_rules(args)
    data = result.get("data")
    return CommandResults(
        outputs_prefix="OpsGenie.TeamRoutingRule",
        outputs=data,
        readable_output=tableToMarkdown("OpsGenie Team Routing Rules", data),
        raw_response=result,
    )


def _parse_fetch_time(fetch_time: str):
    fetch_time_date = dateparser.parse(date_string=f"{fetch_time} UTC")
    assert fetch_time_date is not None, f"could not parse {fetch_time} UTC"
    return fetch_time_date.strftime(DATE_FORMAT)


def fetch_incidents_by_type(
    client: Client,
    query: Optional[str],
    limit: Optional[int],
    fetch_time: str,
    status: Optional[str],
    priority: Optional[str],
    tags: Optional[str],
    incident_fetching_func: Callable,
    now: datetime,
    last_run_dict: Optional[dict] = None,
):
    params: Dict[str, Any] = {}
    if not last_run_dict:
        new_last_run = _parse_fetch_time(fetch_time)
        last_run_dict = {"lastRun": new_last_run, "next_page": None}

    if last_run_dict.get("next_page"):
        raw_response = client.get_paged({"paging": last_run_dict.get("next_page")})
    else:
        timestamp_now = int(now.timestamp())
        last_run = last_run_dict.get("lastRun")
        last_run_date = dateparser.parse(last_run)  # type: ignore
        assert last_run_date is not None, f"could not parse {last_run}"
        timestamp_last_run = int(last_run_date.timestamp())
        time_query = f"createdAt>{timestamp_last_run} AND createdAt<={timestamp_now}"
        params["query"] = f"{query} AND {time_query}" if query else f"{time_query}"
        params["limit"] = limit
        params["is_fetch_query"] = bool(query)
        params["status"] = status
        params["priority"] = priority
        params["tags"] = tags
        raw_response = incident_fetching_func(params)
        last_run_dict["lastRun"] = now.strftime(DATE_FORMAT)

    data = raw_response.get("data")
    incidents = []
    if data:
        for event in data:
            incidents.append({"name": event.get("message"), "occurred": event.get("createdAt"), "rawJSON": json.dumps(event)})
            if last_run_dict.get("lastRun") < event.get("createdAt"):
                last_run_dict["lastRun"] = event.get("createdAt")

    return incidents, raw_response.get("paging", {}).get("next"), last_run_dict.get("lastRun")


def _get_utc_now():
    return datetime.utcnow()


def fetch_incidents_command(
    client: Client, params: Dict[str, Any], last_run: Optional[Dict] = None
) -> tuple[List[Dict[str, Any]], Dict]:
    """Uses to fetch incidents into Demisto
    Documentation: https://github.com/demisto/content/tree/master/docs/fetching_incidents

    Args:
        client: Client object with request
        last_run: Last fetch object occurs
        params: demisto params

    Returns:
        incidents, new last_run
    """
    demisto.debug(f"Got incidentType={params.get('event_types')}")
    event_type = params.get("event_types", [ALL_TYPE])
    demisto.debug(f"Got event_type={event_type}")
    now = _get_utc_now()
    incidents = []
    alerts = []
    last_run_alerts = demisto.get(last_run, f"{ALERT_TYPE}.lastRun")
    next_page_alerts = demisto.get(last_run, f"{ALERT_TYPE}.next_page")
    last_run_incidents = demisto.get(last_run, f"{INCIDENT_TYPE}.lastRun")
    next_page_incidents = demisto.get(last_run, f"{INCIDENT_TYPE}.next_page")
    query = params.get("query")
    limit = int(params.get("max_fetch", 50))
    fetch_time = params.get("first_fetch", "3 days").strip()
    status = params.get("status")
    priority = params.get("priority")
    tags = params.get("tags")
    if ALERT_TYPE in event_type or ALL_TYPE in event_type:
        alerts, next_page_alerts, last_run_alerts = fetch_incidents_by_type(
            client,
            query,
            limit,
            fetch_time,
            status,
            priority,
            tags,
            client.list_alerts,
            now,
            demisto.get(last_run, f"{ALERT_TYPE}"),
        )
    if INCIDENT_TYPE in event_type or ALL_TYPE in event_type:
        incidents, next_page_incidents, last_run_incidents = fetch_incidents_by_type(
            client,
            query,
            limit,
            fetch_time,
            status,
            priority,
            tags,
            client.list_incidents,
            now,
            demisto.get(last_run, f"{INCIDENT_TYPE}"),
        )
    return incidents + alerts, {
        ALERT_TYPE: {"lastRun": last_run_alerts, "next_page": next_page_alerts},
        INCIDENT_TYPE: {"lastRun": last_run_incidents, "next_page": next_page_incidents},
    }


""" MAIN FUNCTION """


def main() -> None:
    api_key = demisto.params().get("credentials", {}).get("password")
    base_url = demisto.params().get("url")
    verify_certificate = not demisto.params().get("insecure", False)
    proxy = demisto.params().get("proxy", False)

    demisto.debug(f"Command being called is {demisto.command()}")
    try:
        client = Client(
            base_url=base_url,
            verify=verify_certificate,
            proxy=proxy,
            headers={
                "Authorization": f"GenieKey {api_key}",
            },
        )

        commands = {
            "opsgenie-create-alert": create_alert,
            "opsgenie-invite-user": invite_user,
            "opsgenie-get-alerts": get_alerts,
            "opsgenie-delete-alert": delete_alert,
            "opsgenie-ack-alert": ack_alert,
            "opsgenie-close-alert": close_alert,
            "opsgenie-assign-alert": assign_alert,
            "opsgenie-add-responder-alert": add_responder_alert,
            "opsgenie-get-escalations": get_escalations,
            "opsgenie-escalate-alert": escalate_alert,
            "opsgenie-add-alert-tag": add_alert_tag,
            "opsgenie-add-alert-note": add_alert_note,
            "opsgenie-add-alert-details": add_alert_details,
            "opsgenie-remove-alert-tag": remove_alert_tag,
            "opsgenie-get-alert-attachments": get_alert_attachments,
            "opsgenie-get-alert-logs": get_alert_logs,
            "opsgenie-get-schedules": get_schedules,
            "opsgenie-get-schedule-overrides": get_schedule_overrides,
            "opsgenie-get-on-call": get_on_call,
            "opsgenie-create-incident": create_incident,
            "opsgenie-delete-incident": delete_incident,
            "opsgenie-get-incidents": get_incidents,
            "opsgenie-close-incident": close_incident,
            "opsgenie-resolve-incident": resolve_incident,
            "opsgenie-add-responder-incident": add_responder_incident,
            "opsgenie-add-tag-incident": add_tag_incident,
            "opsgenie-remove-tag-incident": remove_tag_incident,
            "opsgenie-get-teams": get_teams,
            "opsgenie-get-team-routing-rules": get_team_routing_rules,
            "opsgenie-get-request": get_request_command,
        }
        command = demisto.command()
        if command == "test-module":
            # This is the call made when pressing the integration Test button.
            return_results(test_module(client, demisto.params()))
        elif command == "fetch-incidents":
            incidents, new_run_date = fetch_incidents_command(
                client=client, params=demisto.params(), last_run=demisto.getLastRun().get("lastRun")
            )
            demisto.setLastRun(new_run_date)
            demisto.incidents(incidents)

        elif command in commands:
            return_results(commands[command](client, demisto.args()))
        else:
            raise NotImplementedError(f'Command "{command}" was not implemented.')

    # Log exceptions and return errors
    except Exception as e:
        demisto.error(traceback.format_exc())  # print the traceback
        return_error(f"Failed to execute {demisto.command()} command.\nError:\n{e!s}")


if __name__ in ("__main__", "__builtin__", "builtins"):
    main()