SplunkAddComment
Use this script to add a comment with a tag (the "Comment tag to Splunk" defined in the instance configuration) as an entry in Cortex XSOAR, which will then be mirrored as a comment to a Splunk issue. This script should be run within an incident.
- Type
- python
- Pack
- SplunkPy
Source
import demistomock as demisto # noqa: F401
from CommonServerPython import * # noqa: F401
def add_comment(args: Dict[str, Any]) -> CommandResults:
demisto.debug("adding comment")
tags = argToList(args.get("tags", "FROM XSOAR"))
comment_body = args.get("comment", "")
return CommandResults(readable_output=comment_body, mark_as_note=True, tags=tags)
def main(): # pragma: no cover
try:
demisto.debug("SplunkAddComment is being called")
res = add_comment(demisto.args())
return_results(res)
except Exception as ex:
return_error(f"Failed to execute SplunkAddComment. Error: {ex!s}")
if __name__ in ["__builtin__", "builtins", "__main__"]:
main()
README
Use this script to add a comment with a tag (the “Comment tag to Splunk” defined in the instance configuration) as an entry in Cortex XSOAR, which will then be mirrored as a comment to a Splunk issue. This script should be run within an incident.
Script Data
| Name | Description |
|---|---|
| Script Type | python3 |
| Cortex XSOAR Version | 6.0.0 |
Inputs
| Argument Name | Description |
|---|---|
| comment | Comment to be added to the Splunk issue. |
| tag | The comment tag. Use the comment entry tag (defined in your instance configuration) to mirror the comment to splunk. |
Outputs
There are no outputs for this script.