GetIncidentsByQuery

Gets a list of incident objects and the associated incident outputs that match the specified query and filters. The results are returned in a structured data file. This automation runs using the default Limited User role, unless you explicitly change the permissions. For more information, see the section about permissions here: - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script

python · Base

Details

IDGetIncidentsByQuery
Languagepython
From Version5.0.0
Docker Imagedemisto/python3:3.12.13.10404775
Tagsml

README

Gets a list of incident objects and the associated incident outputs that
match the specified query and filters. The results are returned in a structured data file.

This automation runs using the default Limited User role, unless you explicitly change the permissions.
For more information, see the section about permissions here: For Cortex XSOAR 6, see the https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations for Cortex XSOAR 8 Cloud, see the https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script for Cortex XSOAR 8 On-prem, see the https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script.

Script Data


Name Description
Script Type python3
Tags ml
Cortex XSOAR Version 5.0.0

Used In


This script is used in the following playbooks and scripts.

  • DBot Create Phishing Classifier V2

Inputs


Argument Name Description
query Additional text by which to query incidents.
incidentTypes A comma-separated list of incident types by which to filter.
fromDate The start date by which to filter incidents. Date format will be the same as in the incidents query page, for example: “3 days ago”, ““2019-01-01T00:00:00 +0200”).
toDate The end date by which to filter incidents. Date format will be the same as in the incidents query page, for example: “3 days ago”, ““2019-01-01T00:00:00 +0200”).
limit The maximum number of incidents to fetch.
includeContext Deprecated due to performance considerations. Rather than using this argument, it is recommended to retrieve the context of the incidents separately, preferably for a limited number of incidents.
timeField The incident field to specify for the date range. Can be “created” or “modified”. The default is “created”. Due to performance considerations, you should only use “modified” if you have a large number of incidents.
NonEmptyFields A comma-separated list of non-empty value incident field names by which to filter incidents.
outputFormat The output file format.
populateFields A comma-separated list of fields in the object to poplulate.
pageSize Incidents query batch size

Outputs


Path Description Type
GetIncidentsByQuery.Filename The output file name. String
GetIncidentsByQuery.FileFormat The output file format. String
import json
import pickle

import demistomock as demisto
import GetIncidentsByQuery
import pytest
from CommonServerPython import DemistoException, EntryType


def test_encode_outputs():
    """
    Given: Search incidents results
    When: Running encode_outputs():
    - once with "json" format
    - once with "pickle" format
    - once with unexpected format
    Then: Ensure the results are encoded correctly, or an error is raised in case of unexpected format
    """
    from GetIncidentsByQuery import encode_outputs

    incidents = [{"id": 1}]
    assert json.loads(encode_outputs(incidents, "json")) == incidents
    assert pickle.loads(encode_outputs(incidents, "pickle")) == incidents  # guardrails-disable-line
    with pytest.raises(DemistoException):
        encode_outputs(incidents, "oyvey")


def test_to_file_entry(mocker):
    """
    Given: Search incidents results
    When: Running to_file_entry() with "json" format
    Then: Ensure a file entry is returned in the expected format
    """
    incidents = [{"id": 1}]
    mocker.patch.object(demisto, "investigation", return_value={"id": "inv"})
    res = GetIncidentsByQuery.to_file_entry(incidents, "json")
    assert res["Type"] == EntryType.FILE
    assert res["EntryContext"]["GetIncidentsByQuery"]["FileFormat"] == "json"
    assert res["Contents"] == incidents


def test_get_incidents_by_query_sanity_test(mocker):
    """
    Given: Search incidents query arguments
    When: Running main()
    Then: Ensure the expected incident is returned
    """
    mocker.patch.object(demisto, "args", return_value={"query": "oyvey", "outputFormat": "json"})
    mocker.patch.object(demisto, "executeCommand", return_value=[{"Contents": {"data": [{"id": 1}]}, "Type": "json"}])
    demisto_results = mocker.patch.object(demisto, "results")
    GetIncidentsByQuery.main()
    incidents = demisto_results.call_args[0][0]["Contents"]
    assert len(incidents) == 1
    assert incidents[0]["id"] == 1


def test_get_incidents_by_query_bad_inputs(mocker):
    """
    Given: Search incidents with no query arguments
    When: Running main()
    Then: Ensure an error entry is returned
    """
    return_error = mocker.patch.object(GetIncidentsByQuery, "return_error")
    GetIncidentsByQuery.main()
    assert "Incidents query is empty" in return_error.call_args[0][0]