MicrosoftSentinelSubmitNewComment

Use this script to add a comment which will then be mirrored as a comment to a Sentinal event. This script should be run within an incident.

python · Microsoft Sentinel

Details

IDMicrosoftSentinelSubmitNewComment
Languagepython
From Version5.5.0
Docker Imagedemisto/python3:3.12.13.10404775
Tagsdynamic-section

README

Use this script to add a comment which will then be mirrored as a comment to a Sentinal event. This script should be run within an incident.

Note: Comments in Cortex XSOAR can only be added when the Mirroring Direction in the Instance Settings is set to Incoming or Incoming and Outgoing.

Script Data


Name Description
Script Type python3
Tags dynamic-section
Cortex XSOAR Version 5.5.0

Inputs


Argument Name Description Required
new_comment The comment text to be added to the incident comments. Required
incident_id The ID of the incident to add the comment to. This argument is relevant only when the script is called directly from the War Room. Optional (Required When the script is called directly from the War Room).

Outputs


Path Description Type
AzureSentinel.AddComment.InstanceName The name of the instance where the comment is added. string
AzureSentinel.AddComment.IncidentId The ID of the incident where the comment was added. string
AzureSentinel.AddComment.Message The message of the comment added to the incident. string
import CommonServerPython
import demistomock as demisto


def test_add_new_comment(mocker):
    context_results = {
        "CustomFields": {"sourceid": "incident-123"},
        "sourceInstance": "instance_test",
    }
    demisto_args = {"new_comment": "This is a new comment"}
    expected_instance_name = "instance_test"
    expected_incident_id = "incident-123"
    expected_new_comment = "This is a new comment"
    mocker.patch.object(demisto, "args", return_value=demisto_args)
    debug_mock = mocker.patch.object(demisto, "info")
    execute_command_mock = mocker.patch.object(CommonServerPython, "execute_command")
    table_to_markdown_mock = mocker.patch.object(CommonServerPython, "tableToMarkdown", return_value="Markdown Table")
    command_results_mock = mocker.patch.object(CommonServerPython, "CommandResults", return_value="Command Results")

    from MicrosoftSentinelSubmitNewComment import add_new_comment

    result = add_new_comment(context_results)
    debug_mock.assert_any_call(f"update remote incident with new XSOAR comment: {expected_new_comment}")

    execute_command_mock.assert_called_once_with(
        "azure-sentinel-incident-add-comment",
        {
            "using": expected_instance_name,
            "incident_id": expected_incident_id,
            "message": expected_new_comment,
        },
    )

    table_to_markdown_mock.assert_called_once_with(
        "The new comment has been recorded and will appear in your comments field shortly.",
        {"Instance Name": expected_instance_name, "New Comment": expected_new_comment},
        headers=["New Comment", "Instance Name"],
        removeNull=True,
    )

    assert result == "Command Results"
    command_results_mock.assert_called_once_with(
        readable_output="Markdown Table",
        outputs_prefix="AzureSentinel.AddComment",
        outputs={
            "IncidentId": expected_incident_id,
            "Message": expected_new_comment,
            "InstanceName": "instance_test",
        },
    )