VectraRUXLinkTicketDetections
Link the Detections which have the same External Reference ID.
- Type
- python
- Pack
- VectraRUX
Source
import demistomock as demisto # noqa: F401
from CommonServerPython import * # noqa: F401
def main():
try:
args = demisto.args()
incident_external_reference_id = args.get("incident_external_reference_id")
incident_detection_id = args.get("incident_detection_id")
query = (
f'-status:closed -category:job vectraruxexternalreferenceid:"{incident_external_reference_id}" '
f'-vectraruxdetectionid:="{incident_detection_id}"'
)
res = demisto.executeCommand("SearchIncidentsV2", {"query": query})
if isError(res[0]):
return_error(f"Error searching incidents: {get_error(res[0])}")
content = res[0]["Contents"]
data = []
if content:
data = content[0].get("Contents", {}).get("data", [])
incident_ids = []
for item in data:
detection_id = item.get("id")
incident_ids.append(str(detection_id))
if incident_ids:
res = demisto.executeCommand("linkIncidents", {"linkedIncidentIDs": ",".join(incident_ids)})
return_results(res)
except Exception as e:
return_error(f"Failed to execute VectraRUXLinkTicketDetections script. Error: {str(e)}")
""" ENTRY POINT """
if __name__ in ("__main__", "__builtin__", "builtins"):
main()
README
Link the Detections which have the same External Reference ID.
Script Data
| Name | Description |
|---|---|
| Script Type | python3 |
| Tags | incident-action-button |
| Cortex XSOAR Version | 6.10.0 |
Inputs
| Argument Name | Description |
|---|---|
| incident_external_reference_id | Incident External Reference ID. |
| incident_detection_id | Incident Detection ID. |
Outputs
There are no outputs for this script.