QRadarFetchedEventsSum
This display the amount of fetched events vs the total amount of events in the offense.
- Type
- python
- Pack
- QRadar
Source
import demistomock as demisto # noqa: F401
from CommonServerPython import * # noqa: F401
HTML_TEMPLATE = (
"</br>"
"<div style='line-height:36px; color:#404142; text-align:center; font-size:20px; line-height:36px;'>"
"{fetched}/{total}"
"</div>"
"<div class='editable-field-wrapper' style='text-align:center; padding-top:10px;'>"
"Fetched Events / Total"
"</div>"
"<div class='editable-field-wrapper' style='text-align:center;'>"
"{message}"
"</div>"
)
def main():
try:
incident = demisto.incident()
custom_fields = incident.get("CustomFields", {})
fetched = custom_fields.get("numberoffetchedevents", 0) # define which incident field to use
total = custom_fields.get("numberofeventsinoffense", 0) # define which incident field to use
if fetched == 0:
message = (
"The offense contains Events but non were fetched. "
"Event fetching can be configured in the integration instance settings."
)
else:
message = "Events details on this page are based on the fetched events."
html = HTML_TEMPLATE.format(fetched=fetched, total=total, message=message)
return {"ContentsFormat": "html", "Type": entryTypes["note"], "Contents": html}
except Exception as exp:
return_error("could not parse QRadar offense", error=exp)
if __name__ in ("__main__", "__builtin__", "builtins"):
return_results(main())
README
This script displays the amount of fetched events vs the total number of events in the offense.
Script Data
| Name | Description |
|---|---|
| Script Type | python3 |
| Tags | dynamic-section |
| Cortex XSOAR Version | 6.0.0 |
Inputs
There are no inputs for this script.
Outputs
There are no outputs for this script.