AnyMatch
Returns all elements from the left side that have a substring that is equal to an element from the right side. Note: This filter is case-insensitive. E.g -AnyMatch left=baby right=A will return baby. For more examples see the filter's Readme.
python · Filters And Transformers
Details
| ID | AnyMatch |
|---|---|
| Language | python |
| From Version | 6.9.0 |
| Docker Image | demisto/python3:3.12.13.10404775 |
| Tags | filter general |
README
This filter accepts two inputs, left and right, each of which can be either a single element of any type (e.g., string, int, etc.) or a list of elements. The filter iterates over each element in the left input and returns all elements that have a substring that is equal to an element from the right side. The matching process is case-insensitive, meaning it disregards letter case during the comparison.
All inputs are treated either as a string or as a list of strings, if it contains a comma.
A JSON is always treated as a string.
Since the comparison treats all inputs as strings, integers and strings are considered equal during the evaluation.
Script Data
| Name | Description |
|---|---|
| Script Type | python3 |
| Tags | filter |
| Cortex XSOAR Version | 6.9.0 |
Inputs
| Argument Name | Description |
|---|---|
| left | Value to check if it has a substring that is equal to an element in the right side. Can be a single value or a comma-separated list. |
| right | Value to check if it is equal to an element or to a substring of an element from the left. Can be a single value or a comma-separated list. |
Outputs
There are no outputs for this script.
Table of examples
| Left | Right | Result | Explanation |
|---|---|---|---|
| 1,2,3 | “1” | 1 | Integers are treated as strings. |
| 1,2,250 | 25,10 | 250 | A part of 250 exists in the right side. |
| 1 | 21 | None | |
| 5,1,6,9,65,8 | 1,6 | 1,6,65 | |
| a | holla | None | |
| bca | A | bca | The filter is case-insensitive. |
| {‘alert’ {‘data’: ‘x’}} | x | {‘alert’ {‘data’: ‘x’}} | |
| {‘a’:1},{‘b’:2} | {‘a’:1,’c’:2} | None | {'a':1,'c':2} is nat a part of a value from the left. |
| {‘a’:1},{‘b’:2} | {a:1} | None | {a:1} is not a part of any value from the left. |
| {key1:value1, key2:value2} | 1 | {key1:value1, key2:value2} | A json is treated as a single string, even when there is a comma in it. |
| ’’,’ | {‘a’:1,’c’:2} | ’ | '' is not a part of {'a':1,'c':2}, but ' is. |
import demistomock as demisto import pytest from AnyMatch import main # Note: left and right can be all types, and in order to test list as an input we use a string that looks like a list, # a comma separated string that will be converted to a list in the script. # Note: When executing the filter within playbooks, a JSON on the left will be treated as a single long string, as designed. # There is an example for that in the TestPlaybook. # However, during testing, I encountered difficulty reproducing that behavior. In the test environment, # a JSON containing a comma will be separated into two strings. @pytest.mark.parametrize( "left,right, call_count,expected_result", [ (123, 1, 1, [True]), ("2", "25,10", 1, [False]), ("1, '2'", "1,2,3", 2, [True, True]), # a part of '2' is in '1,2,3' ('"abc", "ahah", "a"', "A", 3, [True, True, True]), ( "5,1,6,9,65,8,b", "1,'6'", 7, [False, True, False, False, False, False, False], ), # no part of 6 or 65 is in the list: 1,'6' ("a", "kfjua", 1, [False]), (1, "1", 1, [True]), # int and str are equal ("bca", "A", 1, [True]), # case insensitive ("ABC", "a", 1, [True]), # case insensitive ({"alert": {"data": "x"}}, "x", 1, [True]), ("{'a':1,'c':2}", "{'a': 1}, {'b': 2}", 2, [False, False]), # {'a':1} is not a part of {'a':1, or 'c':2} ("{'a': 1}, {'b': 2}", "{a:1}", 2, [False, False]), # {a:1} is not a part of {'a': 1} or {'b': 2} # although '' is not a part of {'a':1,'c':2}, but ' is in {'a': 1 and in 'c': 2} ("{'a':1,'c':2}", "'', '", 2, [True, True]), (None, "A", 1, [False]), ], ) def test_main(mocker, left, right, call_count, expected_result): """ Given: left and right arguments. When: Running AnyMatch script. Then: Validate the results are as expected. """ mocker.patch.object(demisto, "args", return_value={"left": left, "right": right}) mocker.patch.object(demisto, "results") main() assert demisto.results.call_count == call_count for i in range(len(expected_result)): results = demisto.results.call_args_list[i][0][0] assert results == expected_result[i]