IncidentsCheck-PlaybooksFailingCommands
Health Check dynamic section, showing the top ten commands of the failed incidents in a pie chart.
Details
| ID | IncidentsCheck-PlaybooksFailingCommands |
|---|---|
| Language | python |
| From Version | 6.0.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Tags | dynamic-section failedIncidents |
README
Health Check dynamic section, showing the top ten commands of the failed incidents in a pie chart.
Script Data
| Name | Description |
|---|---|
| Script Type | python3 |
| Tags | dynamic-section, failedIncidents |
| Cortex XSOAR Version | 6.0.0 |
Inputs
There are no inputs for this script.
Outputs
There are no outputs for this script.
import demistomock as demisto # noqa: F401 from CommonServerPython import * # noqa: F401 import collections import random from collections import Counter def parse_data(failed_commands): commands_data = [] commands_collections: Counter = collections.Counter(failed_commands) top_commands = commands_collections.most_common(10) commands_count = len(top_commands) command_number = 0 while command_number < commands_count: for command in top_commands: random_number = random.randint(0, 16777215) hex_number = str(hex(random_number)) # convert to hexadecimal color = f"#{hex_number[2:].zfill(6)}" # remove 0x and prepend '#' command_widget_data = { "data": [command[1]], "groups": None, "name": str(command[0]), "label": str(command[0]), "color": color, } commands_data.append(command_widget_data) command_number += 1 return {"Type": 17, "ContentsFormat": "pie", "Contents": {"stats": commands_data, "params": {"layout": "vertical"}}} def main(): incident = demisto.incidents() failed_commands = incident[0].get("CustomFields", {}).get("playbooksfailedcommands") if failed_commands: data = parse_data(failed_commands) else: data = { "Type": 17, "ContentsFormat": "pie", "Contents": { "stats": [ {"data": [0], "groups": None, "name": "N/A", "label": "N/A", "color": "rgb(255, 23, 68)"}, ], "params": {"layout": "vertical"}, }, } demisto.results(data) if __name__ in ["__main__", "builtin", "builtins"]: main()