PreProcessAsimilyDedup

Asimily Preprocessing Rule for Deduplication of incoming incident. The script will be used for creating Pre-Process Rules for Incidents to avoid creating duplicate incidents. Comparison is based on incident type and dbotMirrorId.

python · Asimily Insight

Details

IDPreProcessAsimilyDedup
Languagepython
From Version6.10.0
Docker Imagedemisto/python3:3.12.13.10116658
TagspreProcessing

README

The script will be used for creating Pre-Process Rules for Incidents to avoid creating duplicate incidents. Comparison is based on incident type and dbotMirrorId.

Permissions


This automation runs using the default Limited User role, unless you explicitly change the permissions.
For more information, see the section about permissions here:
For Cortex XSOAR 6, see the https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations.
For Cortex XSOAR 8 Cloud, see the https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script.
For Cortex XSOAR 8 On-prem, see the https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script.

Script Data


Name Description
Script Type python
Tags preProcessing

Inputs


There are no inputs for this script.

Outputs


Returns False if incident already exists to Drop incoming incident. Otherwise return True.

import demistomock as demisto  # noqa: F401
from CommonServerPython import *


def main():  # pragma: no cover
    try:
        incident = demisto.incidents()[0]
        incident_type = incident.get("type")
        mirror_id = incident.get("dbotMirrorId")

        if not incident_type or not mirror_id:
            return_results(True)  # Keep it if missing either value
            return

        if incident_type not in ["Asimily Anomaly", "Asimily CVE"]:
            return_results(True)
            return

        query = f'dbotMirrorId:"{mirror_id}" and type:"{incident_type}"'
        result = demisto.executeCommand("getIncidents", {"query": query, "size": 1})

        incidents = result[0].get("Contents", {}).get("data", []) if result and isinstance(result, list) else []

        if incidents:
            return_results(False)  # Drop
        else:
            return_results(True)  # Keep
    except Exception as ex:
        return_error(f"Failed to execute AsimilyPreProcessDedup. Error: {str(ex)}")


if __name__ in ("__main__", "__builtin__", "builtins"):  # pragma: no cover
    main()