category: Email provider: Google sectionorder: - Connect - Collect fromversion: 5.0.0 commonfields: id: Gmail Single User version: -1 configuration: - display: Email of user name: email required: true type: 0 defaultvalue: additionalinfo: section: Connect - display: Send as name: send_as type: 0 defaultvalue: additionalinfo: Allows you to specify the e-mail address from which to send e-mails from. section: Connect advanced: true required: false - display: "Client ID" name: credentials type: 9 section: Connect displaypassword: "Client Secret" required: false - display: "Client ID" name: client_id type: 0 defaultvalue: additionalinfo: "Required. Not relevant for deprecated GSuite Apps setup - see Help section" hidden: true section: Connect advanced: true required: false - display: "Client Secret" name: client_secret type: 4 defaultvalue: additionalinfo: "Required. Not relevant for deprecated GSuite Apps setup - see Help section" hidden: true section: Connect required: false - display: "Auth Redirect URI" name: redirect_uri type: 0 section: Connect defaultvalue: https://oproxy.demisto.ninja/authcode additionalinfo: "Requited. Not relevant for deprecated GSuite Apps setup - see Help section" required: false - display: '' name: auth_code_creds type: 9 displaypassword: "Auth Code (run the !gmail-auth-link command to start the auth flow - see Help section)" hiddenusername: true section: Connect required: false - display: "Auth Code (run the !gmail-auth-link command to start the auth flow - see Help section)" name: code type: 4 hidden: true defaultvalue: additionalinfo: section: Connect advanced: true required: false - display: Incident type name: incidentType type: 13 section: Connect required: false supportedModules: - agentix - xsiam - display: Incidents Fetch Interval name: incidentFetchInterval defaultvalue: '1' required: false type: 19 section: Collect advanced: true supportedModules: - agentix - xsiam - display: Fetch incidents name: isFetch type: 8 section: Collect required: false supportedModules: - agentix - xsiam - display: First fetch timestamp, in days. name: fetch_time type: 0 defaultvalue: 1 days additionalinfo: section: Collect required: false - defaultvalue: display: Events query (e.g., "from:example@demisto.com") additionalinfo: name: query type: 0 section: Collect advanced: true required: false - display: Maximum number of emails to pull per fetch name: fetch_limit type: 0 additionalinfo: A maximum of 200 emails per fetch (even if a higher number is configured). Default is 50. section: Collect required: false - display: Trust any certificate (not secure) name: insecure type: 8 additionalinfo: section: Connect advanced: true required: false - name: proxy display: Use system proxy settings type: 8 additionalinfo: section: Connect advanced: true required: false - display: Use legacy attachment name name: legacy_name section: Collect type: 8 advanced: true defaultvalue: 'false' description: Gmail API using OAuth 2.0. display: Gmail Single User name: Gmail Single User script: commands: - arguments: - name: max_results description: "Maximum number of emails to retrieve." defaultValue: "10" required: false - name: labels description: "List of label IDs to filter emails." isArray: true required: false - name: query description: "Additional Gmail search query string." required: false - name: subject description: "Filter emails by subject." required: false - name: from description: "Filter emails sent from a specific sender." required: false - name: to description: "Filter emails sent to a specific recipient." required: false - name: filename description: "Filter emails by attached filename." required: false - name: in description: "Specify the email folder to search (e.g., 'inbox', 'sent')." required: false - name: has_attachments description: "Whether to filter emails that contain attachments." auto: PREDEFINED predefined: - "true" - "false" defaultValue: "false" required: false - name: before description: "Filter emails before this date." required: false - name: after description: "Filter emails after this date." required: false name: gmail-get-incidents description: | Retrieves a list of emails from Gmail within a specific date range and formats them as incidents. - arguments: - description: A comma-separated list of email addresses of the recipients. isArray: true name: to required: true - description: Email address of the sender. name: from - description: The contents (body) of the email to be sent in plain text. name: body - description: Subject of the email to be sent. Should be the same as the subject of the email you are replying to in order for the reply to be a part of the same conversation. name: subject required: true - description: A comma-separated list of message IDs to reply to. isArray: true name: inReplyTo required: true - description: A comma-separated list of message IDs to refer to. isArray: true name: references - description: A comma-separated list of IDs of War Room entries that contain the files that need to be attached to the email. isArray: true name: attachIDs - description: A comma-separated list of additional recipient email addresses (CC). isArray: true name: cc - description: A comma-separated list of additional recipient email addresses (BCC). isArray: true name: bcc - description: The contents (body) of the email to be sent in HTML format. name: htmlBody - description: Address that needs to be used to reply to the message. name: replyTo - description: |- A comma-separated list of new names used to rename attachments corresponding to the order in which they were attached to the email. Examples - To rename the first and third file: attachNames=new_fileName1,,new_fileName3 To rename the second and fifth files: attachNames=,new_fileName2,,,new_fileName5. isArray: true name: attachNames - description: A comma-separated list of CID images to embed as attachments inside the email. isArray: true name: attachCIDs - description: |- Textual name for an attached file. Multiple files are supported as a comma-separated list. For example, transientFile="t1.txt,temp.txt,t3.txt" transientFileContent="test2,temporary file content,third file content" transientFileCID="t1.txt@xxx.yyy,t2.txt@xxx.zzz". isArray: true name: transientFile - description: |- Content for the attached file. Multiple files are supported as a comma-separated list. For example, transientFile="t1.txt,temp.txt,t3.txt" transientFileContent="test2,temporary file content,third file content" transientFileCID="t1.txt@xxx.yyy,t2.txt@xxx.zzz". isArray: true name: transientFileContent - description: |- CID image for an attached file to include within the email body. Multiple files are supported as a comma-separated list. For example, transientFile="t1.txt,temp.txt,t3.txt" transientFileContent="test 2,temporary file content,third file content" transientFileCID="t1.txt@xxx.yyy,t2.txt@xxx.zzz". isArray: true name: transientFileCID - description: 'A comma-separated list of additional headers in the format: headerName=headerValue. For example: "headerName1=headerValue1,headerName2=headerValue2".' isArray: true name: additionalHeader - description: |- 'Replaces {varname} variables with values from this parameter. Expected values are in the form of a JSON document. For example, {"varname" :{"value" "some value", "key": "context key"}}. Each var name can either be provided with the value or a context key to retrieve the value. Note that only context data is accessible for this argument, while incident fields are not.' name: templateParams - auto: PREDEFINED defaultValue: Text description: Whether message response body type is text or HTML. name: bodyType predefined: - HTML - Text - description: Indicates whether to render the email body. name: renderBody auto: PREDEFINED predefined: - 'true' - 'false' description: Replies to a mail using Gmail. name: reply-mail outputs: - contextPath: Gmail.SentMail.ID description: The immutable ID of the message. type: String - contextPath: Gmail.SentMail.Labels description: List of IDs of the labels applied to this message. type: String - contextPath: Gmail.SentMail.ThreadId description: The ID of the thread in which the message belongs. type: String - contextPath: Gmail.SentMail.To description: The recipients of the email. type: String - contextPath: Gmail.SentMail.From description: The sender of the email. type: Unknown - contextPath: Gmail.SentMail.Cc description: Additional recipient email addresses (CC). type: String - contextPath: Gmail.SentMail.Bcc description: Additional recipient email addresses (BCC). type: String - contextPath: Gmail.SentMail.Subject description: The subject of the email. type: String - contextPath: Gmail.SentMail.Body description: The plain-text version of the email. type: Unknown - contextPath: Gmail.SentMail.MailBox description: The mailbox from which the mail was sent. type: String - arguments: - description: Email addresses of the receiver. isArray: true name: to required: true - description: The contents (body) of the email to be sent in plain text. name: body - description: Subject of the email to be sent. name: subject required: true - description: A comma-separated list of IDs of War Room entries that contain files, which need be attached to the email. isArray: true name: attachIDs - description: The additional recipient email address (CC). isArray: true name: cc - description: The additional recipient email address (BCC). isArray: true name: bcc - description: The contents (body) of the email to be sent in HTML format. name: htmlBody - description: The email address used to reply to the message. name: replyTo - description: >- A comma-separated list of new names to rename for existing attachments, which relates to the order that they were attached to the email. For example, rename the first and third file attachNames=new_fileName1,,new_fileName3 To rename the second and fifth files, attachNames=,new_fileName2,,,new_fileName5. isArray: true name: attachNames - description: A comma-separated list of CID images to embed attachments in to the email. isArray: true name: attachCIDs - description: >- The textual name for an attached file. Multiple files are supported as a comma-separated list. For example, transientFile="t1.txt,temp.txt,t3.txt" transientFileContent="test 2,temporary file content,third file content" transientFileCID="t1.txt@xxx.yyy,t2.txt@xxx.zzz". isArray: true name: transientFile - description: >- The content for the attached file. Multiple files are supported as a comma-separated list. For example, transientFile="t1.txt,temp.txt,t3.txt" transientFileContent="test 2,temporary file content,third file content" transientFileCID="t1.txt@xxx.yyy,t2.txt@xxx.zzz". isArray: true name: transientFileContent - description: |- The CID image for an attached file to include within the email body. Multiple files are supported as comma-separated list. For example, transientFile="t1.txt,temp.txt,t3.txt" transientFileContent="test 2,temporary file content,third file content" transientFileCID="t1.txt@xxx.yyy,t2.txt@xxx.zzz". isArray: true name: transientFileCID - description: 'A comma-separated list of additional headers in the format: headerName=headerValue. For example, "headerName1=headerValue1,headerName2=headerValue2".' isArray: true name: additionalHeader - description: >- 'Replaces {varname} variables with values from this parameter. Expected values are in the form of a JSON document. For example, {"varname" :{"value" "some value", "key": "context key"}}. Each var name can either be provided with the value or a context key to retrieve the value.' name: templateParams - auto: PREDEFINED defaultValue: Text description: Whether message response body type is text or HTML. name: bodyType predefined: - HTML - Text - description: Indicates whether to render the email body. name: renderBody description: Sends an email using Gmail. name: send-mail outputs: - contextPath: Gmail.SentMail.ID description: The immutable ID of the message. type: String - contextPath: Gmail.SentMail.Labels description: List of IDs of labels applied to this message. type: String - contextPath: Gmail.SentMail.ThreadId description: The ID of the thread in which the message belongs. type: String - contextPath: Gmail.SentMail.To description: The recipient of the email. type: String - contextPath: Gmail.SentMail.From description: The sender of the email. type: String - contextPath: Gmail.SentMail.Cc description: Additional recipient email address (CC). type: String - contextPath: Gmail.SentMail.Bcc description: Additional recipient email address (BCC). type: String - contextPath: Gmail.SentMail.Subject description: The subject of the email. type: String - contextPath: Gmail.SentMail.Body description: The plain-text version of the email. type: String - contextPath: Gmail.SentMail.MailBox description: The mailbox from which the mail was sent. type: String - contextPath: Gmail.SentMail.BodyHTML description: The HTML version of the email. type: String - name: gmail-auth-link arguments: [] description: Starts the OAuth2 process. Get a link to use to authenticate to Gmail. outputs: [] - name: gmail-auth-test arguments: [] description: Tests that Gmail auth is configured properly. Use this command after completing the OAuth2 authentication process. outputs: [] - arguments: - description: The ID of the message to retrieve. name: message-id required: true description: Retrieves attachments from a sent Gmail message. name: gmail-get-attachments dockerimage: demisto/google-api-py3:1.0.0.10182333 isfetch: true runonce: false script: '-' type: python subtype: python3 tests: - Gmail Single User - Test defaultclassifier: Gmail Single User defaultmapperin: Gmail Single User-mapper