name: ExpanseAggregateAttributionUser comment: Deprecated. No available replacement. > Aggregate entries from multiple sources into AttributionUser. deprecated: true commonfields: id: ExpanseAggregateAttributionUser version: -1 args: - name: input description: Input list. isArray: true - name: current description: Current aggregation state. isArray: true - name: username_fields description: Comma separated list of fields to treat as serial number. defaultValue: source_user,srcuser,user isArray: true - name: sightings_fields description: Comma separated list of field names to be considered sighting counts. defaultValue: count isArray: true outputs: - contextPath: Expanse.AttributionUser.username description: Username of the user. type: string - contextPath: Expanse.AttributionUser.domain description: Domain of the user. type: string - contextPath: Expanse.AttributionUser.groups description: List of groups the user is member of. - contextPath: Expanse.AttributionUser.display-name description: Display Name. type: string - contextPath: Expanse.AttributionUser.description description: Description of the user. type: string - contextPath: Expanse.AttributionUser.sightings description: Number of sessions seen on this device. type: number script: '-' tags: [] timeout: '0' type: python subtype: python3 dockerimage: demisto/python3:3.10.13.83255 fromversion: 6.0.0 tests: - No tests (auto formatted)