Splunk_ShortID

Create Splunk Notable Event Short ID.

python · SplunkScripts

Details

IDSplunk_ShortID
Languagepython
From Version6.0.0
Docker Imagedemisto/python3:3.12.8.3296088
TagsUtility

README

Create Splunk Notable Event Short ID.

Script Data


Name Description
Script Type python3
Tags Utility

Dependencies


This script uses the following commands and scripts.

  • splunk-search

Inputs


Argument Name Description
event_id Splunk notable event id.

Outputs


There are no outputs for this script.

import base64
import hashlib

import demistomock as demisto  # noqa: F401
from CommonServerPython import *  # noqa: F401

inc = demisto.incident()
notable_eventid = demisto.args()["event_id"]

if notable_eventid:
    notable_eventid = notable_eventid.encode("UTF-8")
    sha1_object = hashlib.sha1(notable_eventid)  # nosec
    sha1 = sha1_object.digest()
    base64_object = base64.b64encode(sha1)
    base64_string = base64_object.decode("UTF-8")
    xref_id = base64_string[:6]
    notable_eventid = notable_eventid.decode()

    splunk_query = f"""`notable`
    | where isnull(notable_xref) and event_id=\"{notable_eventid}\"
    | eval notable_time=_time, xref_label=\"Short ID\", xref_name=\"short_id\", xref_id=\"{xref_id}\"
    | table event_id, notable_time, xref_id, xref_label, xref_name
    | outputlookup append=t notable_xref_lookup"""

    res = demisto.executeCommand("splunk-search", {"query": splunk_query})
    return_results(res[0])