PWObservationPcapDownload

Deprecated. No available replacement.

Type
python
Pack
ProtectWise

Source

import demistomock as demisto  # noqa: F401
from CommonServerPython import *  # noqa: F401
from time import sleep


res = []
dArgs = demisto.args()
burstSize = demisto.get(dArgs, 'burstsize')
burstSize = int(burstSize) if burstSize else 10
remaining = burstSize
waitSeconds = demisto.get(dArgs, 'waitms')
waitSeconds = float(waitSeconds) / 1000.0 if waitSeconds else 1.0
dArgs["using-brand"] = "ProtectWise"
obIDs = argToList(demisto.get(dArgs, 'id'))
sensorIDs = demisto.get(dArgs, 'sensorId')
sensorList = [sensorIDs] if isinstance(sensorIDs, int) else argToList(sensorIDs)
for sensorId in sensorList:
    dArgs['sensorId'] = sensorId
    for oid in obIDs:
        dArgs['id'] = oid
        dArgs['filename'] = oid + '.pcap'
        if remaining:
            remaining -= 1
        else:
            sleep(waitSeconds)  # pylint: disable=sleep-exists
            remaining = burstSize
        resCmd = demisto.executeCommand("protectwise-observation-pcap-download", dArgs)
        try:
            res += resCmd
        except Exception as ex:
            res.append({"Type": entryTypes["error"], "ContentsFormat": formats["text"],
                        "Contents": "Error occurred while parsing output from command. Exception info:\n"
                        + str(ex) + "\n\nInvalid output:\n" + str(resCmd)})
demisto.results(res)

README

Downloads PCAPs related to the specified observations. This supports rate throttling.

Script Data


Name Description
Script Type python
Tags protectwise

Dependencies


This script uses the following commands and scripts.

Inputs


Argument Name Description
id The observation ID. Can be, a comma-separated list of IDs.
sensorId The sensor ID. Can be, a comma-separated list of IDs.
filename The filename provided for the download.
burstsize The download burstsize files every time, and wait waitms milliseconds each time. The defaults are 10 files and 1 second.
waitms The download burstsize files every time, and wait waitms milliseconds each time. The defaults are 10 files and 1 second.

Outputs


There are no outputs for this script.