ExportIncidentsToCSV

This automation uses the Core REST API Integration to batch export Incidents to CSV and return the resulting CSV file to the war room.

python · Common Scripts

Details

IDExportIncidentsToCSV
Languagepython
From Version6.5.0
Docker Imagedemisto/python3:3.12.13.10404775
TagsUtility

README

This automation uses the Core REST API Integration to batch export Incidents to CSV and return the resulting CSV file to the war room.

Script Data


Name Description
Script Type python3
Tags Utility

Dependencies


This script uses the following commands and scripts.

  • core-api-get
  • core-api-post

Inputs


Argument Name Description
query The query for the Incidents that you want to export. (e.g. status:closed -category:job). You can and should generate the query from the Incidents search screen.
fetchdays The number of days back to fetch incidents. This argument acts as the primary time filter and is always applied, even when using the query argument. The command first filters for all incidents created in the last fetchdays and then applies the query argument to that subset of incidents. Warning: If the query argument contains a created: time range (for example, created:>=now-90d), you must set fetchdays to a value equal to or larger than that range. If fetchdays is smaller that the window in the query, the results will be truncated. (default is 7). Must be a number.
columns Comma separated list of columns (fields) for the CSV. (Default is: id,name,type,severity,status,owner,roles,playbookId,occurred,created,modified,closed)

Outputs


There are no outputs for this script.

args:
- description: The query for the Incidents that you want to export. (e.g. status:closed -category:job). You can and should generate the query from the Incidents search screen.
  name: query
  required: true
- defaultValue: "7"
  description: Number of days you want to fetch back for (default is 7).  Needs to be a number.
  name: fetchdays
- description: 'Comma separated list of columns (fields) for the CSV.  (Default is: id,name,type,severity,status,owner,roles,playbookId,occurred,created,modified,closed).'
  name: columns
comment: This automation uses the Core REST API Integration to batch export Incidents to CSV and return the resulting CSV file to the war room.
commonfields:
  id: ExportIncidentsToCSV
  version: -1
contentitemexportablefields:
  contentitemfields:
    fromServerVersion: ""
dependson:
  must:
  - core-api-post
  - core-api-get
dockerimage: demisto/python3:3.12.13.10404775
enabled: true
name: ExportIncidentsToCSV
runas: DBotWeakRole
script: ''
scripttarget: 0
subtype: python3
tags:
- Utility
type: python
fromversion: 6.5.0
marketplaces:
- xsoar
- marketplacev2
- platform
supportedModules:
- agentix
- cloud
- cloud_runtime_security
- cloud_posture
- xsiam
- edr
tests:
- No tests (auto formatted)