AnyMatch

Returns all elements from the left side that have a substring that is equal to an element from the right side. Note: This filter is case-insensitive. E.g -AnyMatch left=baby right=A will return baby. For more examples see the filter's Readme.

python · Filters And Transformers

Details

IDAnyMatch
Languagepython
From Version6.9.0
Docker Imagedemisto/python3:3.12.13.10404775
Tagsfilter general

README

This filter accepts two inputs, left and right, each of which can be either a single element of any type (e.g., string, int, etc.) or a list of elements. The filter iterates over each element in the left input and returns all elements that have a substring that is equal to an element from the right side. The matching process is case-insensitive, meaning it disregards letter case during the comparison.

All inputs are treated either as a string or as a list of strings, if it contains a comma.
A JSON is always treated as a string.

Since the comparison treats all inputs as strings, integers and strings are considered equal during the evaluation.

Script Data


Name Description
Script Type python3
Tags filter
Cortex XSOAR Version 6.9.0

Inputs


Argument Name Description
left Value to check if it has a substring that is equal to an element in the right side. Can be a single value or a comma-separated list.
right Value to check if it is equal to an element or to a substring of an element from the left. Can be a single value or a comma-separated list.

Outputs


There are no outputs for this script.

Table of examples

Left Right Result Explanation
1,2,3 “1” 1 Integers are treated as strings.
1,2,250 25,10 250 A part of 250 exists in the right side.
1 21 None  
5,1,6,9,65,8 1,6 1,6,65  
a holla None  
bca A bca The filter is case-insensitive.
{‘alert’ {‘data’: ‘x’}} x {‘alert’ {‘data’: ‘x’}}  
{‘a’:1},{‘b’:2} {‘a’:1,’c’:2} None {'a':1,'c':2} is nat a part of a value from the left.
{‘a’:1},{‘b’:2} {a:1} None {a:1} is not a part of any value from the left.
{key1:value1, key2:value2} 1 {key1:value1, key2:value2} A json is treated as a single string, even when there is a comma in it.
’’,’ {‘a’:1,’c’:2} '' is not a part of {'a':1,'c':2}, but ' is.
import demistomock as demisto
import pytest
from AnyMatch import main

# Note: left and right can be all types, and in order to test list as an input we use a string that looks like a list,
# a comma separated string that will be converted to a list in the script.

# Note: When executing the filter within playbooks, a JSON on the left will be treated as a single long string, as designed.
# There is an example for that in the TestPlaybook.
# However, during testing, I encountered difficulty reproducing that behavior. In the test environment,
# a JSON containing a comma will be separated into two strings.


@pytest.mark.parametrize(
    "left,right, call_count,expected_result",
    [
        (123, 1, 1, [True]),
        ("2", "25,10", 1, [False]),
        ("1, '2'", "1,2,3", 2, [True, True]),  # a part of '2' is in '1,2,3'
        ('"abc", "ahah", "a"', "A", 3, [True, True, True]),
        (
            "5,1,6,9,65,8,b",
            "1,'6'",
            7,
            [False, True, False, False, False, False, False],
        ),  # no part of 6 or 65 is in the list: 1,'6'
        ("a", "kfjua", 1, [False]),
        (1, "1", 1, [True]),  # int and str are equal
        ("bca", "A", 1, [True]),  # case insensitive
        ("ABC", "a", 1, [True]),  # case insensitive
        ({"alert": {"data": "x"}}, "x", 1, [True]),
        ("{'a':1,'c':2}", "{'a': 1}, {'b': 2}", 2, [False, False]),  # {'a':1} is not a part of {'a':1, or 'c':2}
        ("{'a': 1}, {'b': 2}", "{a:1}", 2, [False, False]),  # {a:1} is not a part of {'a': 1} or {'b': 2}
        # although '' is not a part of {'a':1,'c':2}, but ' is in {'a': 1 and in  'c': 2}
        ("{'a':1,'c':2}", "'', '", 2, [True, True]),
        (None, "A", 1, [False]),
    ],
)
def test_main(mocker, left, right, call_count, expected_result):
    """
    Given:
        left and right arguments.
    When:
        Running AnyMatch script.
    Then:
        Validate the results are as expected.
    """
    mocker.patch.object(demisto, "args", return_value={"left": left, "right": right})
    mocker.patch.object(demisto, "results")
    main()
    assert demisto.results.call_count == call_count
    for i in range(len(expected_result)):
        results = demisto.results.call_args_list[i][0][0]
        assert results == expected_result[i]