GetIncidentsByQuery
Gets a list of incident objects and the associated incident outputs that match the specified query and filters. The results are returned in a structured data file. This automation runs using the default Limited User role, unless you explicitly change the permissions. For more information, see the section about permissions here: - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
python · Base
Details
| ID | GetIncidentsByQuery |
|---|---|
| Language | python |
| From Version | 5.0.0 |
| Docker Image | demisto/python3:3.12.13.10404775 |
| Tags | ml |
README
Gets a list of incident objects and the associated incident outputs that
match the specified query and filters. The results are returned in a structured data file.
This automation runs using the default Limited User role, unless you explicitly change the permissions.
For more information, see the section about permissions here: For Cortex XSOAR 6, see the https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations for Cortex XSOAR 8 Cloud, see the https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script for Cortex XSOAR 8 On-prem, see the https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script.
Script Data
| Name | Description |
|---|---|
| Script Type | python3 |
| Tags | ml |
| Cortex XSOAR Version | 5.0.0 |
Used In
This script is used in the following playbooks and scripts.
- DBot Create Phishing Classifier V2
Inputs
| Argument Name | Description |
|---|---|
| query | Additional text by which to query incidents. |
| incidentTypes | A comma-separated list of incident types by which to filter. |
| fromDate | The start date by which to filter incidents. Date format will be the same as in the incidents query page, for example: “3 days ago”, ““2019-01-01T00:00:00 +0200”). |
| toDate | The end date by which to filter incidents. Date format will be the same as in the incidents query page, for example: “3 days ago”, ““2019-01-01T00:00:00 +0200”). |
| limit | The maximum number of incidents to fetch. |
| includeContext | Deprecated due to performance considerations. Rather than using this argument, it is recommended to retrieve the context of the incidents separately, preferably for a limited number of incidents. |
| timeField | The incident field to specify for the date range. Can be “created” or “modified”. The default is “created”. Due to performance considerations, you should only use “modified” if you have a large number of incidents. |
| NonEmptyFields | A comma-separated list of non-empty value incident field names by which to filter incidents. |
| outputFormat | The output file format. |
| populateFields | A comma-separated list of fields in the object to poplulate. |
| pageSize | Incidents query batch size |
Outputs
| Path | Description | Type |
|---|---|---|
| GetIncidentsByQuery.Filename | The output file name. | String |
| GetIncidentsByQuery.FileFormat | The output file format. | String |
import json import pickle import demistomock as demisto import GetIncidentsByQuery import pytest from CommonServerPython import DemistoException, EntryType def test_encode_outputs(): """ Given: Search incidents results When: Running encode_outputs(): - once with "json" format - once with "pickle" format - once with unexpected format Then: Ensure the results are encoded correctly, or an error is raised in case of unexpected format """ from GetIncidentsByQuery import encode_outputs incidents = [{"id": 1}] assert json.loads(encode_outputs(incidents, "json")) == incidents assert pickle.loads(encode_outputs(incidents, "pickle")) == incidents # guardrails-disable-line with pytest.raises(DemistoException): encode_outputs(incidents, "oyvey") def test_to_file_entry(mocker): """ Given: Search incidents results When: Running to_file_entry() with "json" format Then: Ensure a file entry is returned in the expected format """ incidents = [{"id": 1}] mocker.patch.object(demisto, "investigation", return_value={"id": "inv"}) res = GetIncidentsByQuery.to_file_entry(incidents, "json") assert res["Type"] == EntryType.FILE assert res["EntryContext"]["GetIncidentsByQuery"]["FileFormat"] == "json" assert res["Contents"] == incidents def test_get_incidents_by_query_sanity_test(mocker): """ Given: Search incidents query arguments When: Running main() Then: Ensure the expected incident is returned """ mocker.patch.object(demisto, "args", return_value={"query": "oyvey", "outputFormat": "json"}) mocker.patch.object(demisto, "executeCommand", return_value=[{"Contents": {"data": [{"id": 1}]}, "Type": "json"}]) demisto_results = mocker.patch.object(demisto, "results") GetIncidentsByQuery.main() incidents = demisto_results.call_args[0][0]["Contents"] assert len(incidents) == 1 assert incidents[0]["id"] == 1 def test_get_incidents_by_query_bad_inputs(mocker): """ Given: Search incidents with no query arguments When: Running main() Then: Ensure an error entry is returned """ return_error = mocker.patch.object(GetIncidentsByQuery, "return_error") GetIncidentsByQuery.main() assert "Incidents query is empty" in return_error.call_args[0][0]