SetByIncidentId
Works the same as the 'Set' command, but can work across incidents by specifying 'id' as an argument. Sets a value into the context with the given context key. Doesn't append by default. This automation runs using the default Limited User role, unless you explicitly change the permissions. For more information, see the section about permissions here: - For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations - For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script - For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script
python · Common Scripts
Details
| ID | SetByIncidentId |
|---|---|
| Language | python |
| From Version | 5.0.0 |
| Docker Image | demisto/python3:3.12.13.10404775 |
| Tags | DemistoAPI |
README
Sets a value into the context with the given context key. By default this will not append. This script works the same as the Set command, but can work across incidents by specifying ID as an argument.
Permissions
This automation runs using the default Limited User role, unless you explicitly change the permissions.
For more information, see the section about permissions here: For Cortex XSOAR 6, see the https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations for Cortex XSOAR 8 Cloud, see the https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script for Cortex XSOAR 8 On-prem, see the https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script.
Script Data
| Name | Description |
|---|---|
| Script Type | python3 |
| Tags | DemistoAPI |
Inputs
| Argument Name | Description |
|---|---|
| id | The incident to set the context values in. The default is “current incident”. |
| key | The key to set. |
| value | The value to set to the key. THis can be an array. Usually, a DQ expression. |
| append | Whether the context key will be overwritten, this will occur when set to false. If it is set to true then the script will append to existing context key. |
| errorUnfinished | Returns an error if not all of the incidents where modified. |
Outputs
There are no outputs for this script.
import demistomock as demisto from SetByIncidentId import main def test_set_by_incident_id(mocker): """ Given: - ID (1) of incident to update - Key (Key) to update - Value (Value) to update - Argument append set to false - Argument errorUnfinished set to false When: - Running SetByIncidentId Then: - Ensure executeCommand is called with expected args """ mocker.patch.object( demisto, "args", return_value={ "id": "1", "key": "Key", "value": "Value", "append": "false", "errorUnfinished": "false", }, ) mocker.patch.object(demisto, "results") mocker.patch.object(demisto, "executeCommand") main() demisto.executeCommand.assert_called_with( "executeCommandAt", { "arguments": {"append": "false", "key": "Key", "value": "Value"}, "command": "Set", "incidents": "1", }, )