UpdateSecuronixIncidentStatus
Update the status of the Securonix incident using the configuration provided in integration configuration.
python · Securonix
Details
| ID | UpdateSecuronixIncidentStatus |
|---|---|
| Language | python |
| From Version | 6.5.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
README
Update the status of the Securonix incident using the configuration provided in integration configuration.
Script Data
| Name | Description |
|---|---|
| Script Type | python3 |
| Cortex XSOAR Version | 6.5.0 |
Dependencies
This script uses the following commands and scripts.
- securonix-xsoar-state-mapping-get
- securonix-add-comment-to-incident
Inputs
| Argument Name | Description |
|---|---|
| incident_id | Incident ID. |
| active_state_action | Securonix action name mapped with XSOAR’s active state. |
| active_state_status | Securonix status to map with XSOAR’s active state. |
| close_state_action | Securonix action name mapped with XSOAR’s closed state. |
| close_state_status | Securonix status to map with XSOAR’s close state. |
| only_active | Whether to only change the status of Securonix incident to XSOAR’s respective active state. |
Outputs
There are no outputs for this script.
"""Unit test cases for UpdateSecuronixIncidentStatus script.""" from unittest.mock import patch from UpdateSecuronixIncidentStatus import main """Constants""" MOCK_ARGS = { "incident_id": "200", "active_state_status": "In Progress", "close_state_status": "closed", "active_state_action": "Start Investigation", "close_state_action": "Close Incident", "only_active": True, } MOCK_INCIDENT = {"id": "100", "CustomFields": {"securonixincidentstatus": "new"}} MOCK_RESPONSE_PERFORM_ACTION = [{"Contents": "submitted", "ContentsFormat": "text", "EntryContext": None, "Type": 4}] MOCK_RESPONSE_ADD_COMMENT = [{"Contents": True, "ContentsFormat": "text", "EntryContext": None, "Type": 4}] @patch("UpdateSecuronixIncidentStatus.demisto.args") @patch("UpdateSecuronixIncidentStatus.demisto.incident") @patch("UpdateSecuronixIncidentStatus.demisto.executeCommand") @patch("UpdateSecuronixIncidentStatus.return_results") def test_update_securonix_incident_to_active_state(mock_return, mock_execute_command, mock_incident, mock_args): """Test case for successful execution of script to update incident in active state.""" mock_args.return_value = MOCK_ARGS mock_incident.return_value = MOCK_INCIDENT mock_execute_command.side_effect = [MOCK_RESPONSE_PERFORM_ACTION, MOCK_RESPONSE_ADD_COMMENT] main() assert mock_return.call_args.args[0] == "Incident 200 has been moved to In Progress." @patch("UpdateSecuronixIncidentStatus.demisto.args") @patch("UpdateSecuronixIncidentStatus.demisto.incident") @patch("UpdateSecuronixIncidentStatus.demisto.executeCommand") @patch("UpdateSecuronixIncidentStatus.return_results") def test_update_securonix_incident_to_close_state(mock_return, mock_execute_command, mock_incident, mock_args): """Test case for successful execution of script to update incident in close state.""" MOCK_ARGS["only_active"] = False mock_args.return_value = MOCK_ARGS mock_incident.return_value = MOCK_INCIDENT mock_execute_command.side_effect = [ MOCK_RESPONSE_PERFORM_ACTION, MOCK_RESPONSE_ADD_COMMENT, MOCK_RESPONSE_PERFORM_ACTION, MOCK_RESPONSE_ADD_COMMENT, ] main() assert mock_return.call_args.args[0] == "Successfully closed incident 200 on Securonix." @patch("UpdateSecuronixIncidentStatus.demisto.args") @patch("UpdateSecuronixIncidentStatus.demisto.incident") @patch("UpdateSecuronixIncidentStatus.return_results") def test_update_securonix_incident_when_incident_already_in_close_sate(mock_return, mock_incident, mock_args): """Test case for successful execution of script when incident is already in closed state.""" MOCK_ARGS["only_active"] = False MOCK_INCIDENT["CustomFields"]["securonixincidentstatus"] = "closed" mock_args.return_value = MOCK_ARGS mock_incident.return_value = MOCK_INCIDENT main() assert mock_return.call_args.args[0] == "Incident 200 is already in closed state on Securonix."