Skip to content

Commit

Permalink
Akamai update incident name (#33727)
Browse files Browse the repository at this point in the history
* change name

* RN

* docker

* pre-commit fixes

* conflicts

* version

* Added request ID to incident name

* fix UT

* Fix search hash in sandbox generic cs falcon (#33719)

* Added limit for each report to be retrieved on a hash
+ removed the transformer "firstarrayelment"

* Added limit for each report to be retrieved on a hash
+ removed the transformer "firstarrayelment"

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

---------

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* new dashboard (#33696)

* new dashboard

* Added RN

* RN

* Update Packs/CommonDashboards/ReleaseNotes/1_4_1.md

Co-authored-by: Sasha Sokolovich <88268646+ssokolovich@users.noreply.github.com>

* Update Packs/CommonDashboards/ReleaseNotes/1_4_1.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

---------

Co-authored-by: Sasha Sokolovich <88268646+ssokolovich@users.noreply.github.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Staging Update Docker 31 03 (#33641)

* upgrade images (#33516)

* upgrade images (#33519)

* Update `demisto/google-k8s-engine` 0-50 coverage rate (#33515)

* upgrade images

* retrigger build

* testing original docker image

* testing updated docker

* testing updated docker

* testing updated image

* using latest image

---------

Co-authored-by: barryyosi-panw <byosilevich@paloaltonetworks.com>

* Update `demisto/xsoar-tools` 75-100-Nightly coverage rate (#33329)

* upgrade images (#33314)

* upgrade images

* Fixed validate import issue

* Update `demisto/py3-tools` 75-100-Nightly coverage rate (#33318)

* upgrade images

* Fixed the UT

* Update `demisto/powershell` 75-100-Nightly coverage rate (#33328)

* upgrade images

* test changes

* changed back

* retriggering checks

* Pipeline re-trigger

* bump Common Scripts version

* revert Common Scripts version

* bump Common Scripts version

* debug

* bump version

* rolling back RN and version bump

---------

Co-authored-by: barryyosi-panw <byosilevich@paloaltonetworks.com>

* upgrade images (#33357)

* Update `demisto/sane-pdf-reports` 75-100-Nightly coverage rate (#33344)

* upgrade images

* Retriggering the build

* Rollback redundant change

---------

Co-authored-by: barryyosi-panw <byosilevich@paloaltonetworks.com>

* upgrade images (#33359)

* Test

* Updating to latest image and supporting recent tshark versions' behaviour. (#33458)

* Test new image

* Fixed missing pack_metadata

* Fixed build issue

* Removed unnecessary raws

* revet changes from other base branch

* revet changes from other base branch

* revet changes from tests

---------

Co-authored-by: barryyosi-panw <byosilevich@paloaltonetworks.com>
Co-authored-by: barryyosi-panw <158817412+barryyosi-panw@users.noreply.github.com>

* upgrade images (#33535)

* upgrade images (#33534)

Co-authored-by: barryyosi-panw <byosilevich@paloaltonetworks.com>

* upgrade images (#33537)

* upgrade images (#33552)

* upgrade images (#33580)

Co-authored-by: barryyosi-panw <byosilevich@paloaltonetworks.com>

* Update `demisto/gdetect` 50-100  coverage rate (#33553)

* upgrade images

* testing older image version

* upgrading to latest image

* adapting gdetect usage to match newer version

* testing updated docker

* testing updated docker

* testing updated docker

* Supporting latest gdetect version

* Supporting latest gdetect version

* Supporting latest gdetect version

* Supporting latest gdetect version

---------

Co-authored-by: barryyosi-panw <byosilevich@paloaltonetworks.com>

* Update `demisto/vmware` 50-100-Non-Nightly coverage rate (#33418)

* upgrade images

* testing latest vsphere version

* testing latest vsphere version

* testing updated docker

* upgrading image

---------

Co-authored-by: barryyosi-panw <byosilevich@paloaltonetworks.com>

* pep8 fix

* upgrade images (#33583)

Co-authored-by: barryyosi-panw <byosilevich@paloaltonetworks.com>

* upgrade images (#33555)

* upgrade images (#33556)

* upgrade image (#33559)

* upgrade images (#33560)

Co-authored-by: barryyosi-panw <byosilevich@paloaltonetworks.com>

* change docker images (#33619)

* Update demisto/stringsifter 50-100-Non-Nightly coverage rate  (#33591)

* update docker image

* change stringsifter dockerimage

* upgrade images (#33602)

Co-authored-by: TalZich <tzichlinsky@paloaltonetworks.com>

* Update demisto/xsoar tools 75 100 nightly (#33600)

* upgrade images (#33314)

* upgrade images

* Fixed validate import issue

* Update `demisto/py3-tools` 75-100-Nightly coverage rate (#33318)

* upgrade images

* Fixed the UT

* Update `demisto/powershell` 75-100-Nightly coverage rate (#33328)

* upgrade images

* test changes

* changed back

* retriggering checks

* Pipeline re-trigger

* bump Common Scripts version

* revert Common Scripts version

* bump Common Scripts version

* debug

* bump version

* rolling back RN and version bump

---------

Co-authored-by: barryyosi-panw <byosilevich@paloaltonetworks.com>

* upgrade images (#33357)

* Update `demisto/sane-pdf-reports` 75-100-Nightly coverage rate (#33344)

* upgrade images

* Retriggering the build

* Rollback redundant change

---------

Co-authored-by: barryyosi-panw <byosilevich@paloaltonetworks.com>

* upgrade images (#33359)

* Test

* Updating to latest image and supporting recent tshark versions' behaviour. (#33458)

* Test new image

* Fixed missing pack_metadata

* Fixed build issue

* Removed unnecessary raws

* revet changes from other base branch

* revet changes from other base branch

* revet changes from tests

* Fixed the issue without changing the image

* Fixed build issue

* fixed pre-commit notes

* fixed pre-commit notes

* fixed build

---------

Co-authored-by: barryyosi-panw <byosilevich@paloaltonetworks.com>
Co-authored-by: barryyosi-panw <158817412+barryyosi-panw@users.noreply.github.com>

* updated release notes

* Bump pack from version Base to 1.33.48.

* resolved conflicts

* resolved conflicts

---------

Co-authored-by: barryyosi-panw <byosilevich@paloaltonetworks.com>
Co-authored-by: barryyosi-panw <158817412+barryyosi-panw@users.noreply.github.com>
Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com>
Co-authored-by: TalZich <tzichlinsky@paloaltonetworks.com>
Co-authored-by: Content Bot <bot@demisto.com>

* Fixing incident alerts and artifacts is not populated   (#33558)

* reproduce test case

* fix

* fix rl

* adding a unit test that fail using the new incident format

* adding the fix

* removing logs

* update

* update

* update

* update

* [Marketplace Contribution] NetskopeV2 - Content Pack Update (#33549)

* [Marketplace Contribution] NetskopeV2 - Content Pack Update (#33527)

* "contribution update to pack 'NetskopeV2'"

* Update 1_0_3.md

* remove empty display

* Remove duplicate API Key parameter in table

---------

Co-authored-by: Randy Baldwin <32545292+randomizerxd@users.noreply.github.com>

* Update Packs/NetskopeV2/ReleaseNotes/1_0_3.md

---------

Co-authored-by: xsoar-bot <67315154+xsoar-bot@users.noreply.github.com>
Co-authored-by: Randy Baldwin <32545292+randomizerxd@users.noreply.github.com>
Co-authored-by: merit-maita <49760643+merit-maita@users.noreply.github.com>

* Ciac 985 qradar (#33239)

* Add ID argument to QRadar_V3 qradar_log_sources_list

* remove redundant parantheses

* Add qradar-event-collectors-list command to QRadar_V3

* Add wincollect-destinations-list command to QRadar_V3

* Add qradar-disconnected-log-collectors-list command to QRadar_V3

* Fix command description on qradar-disconnected-log-collectors-list

* Start building log-source-types command in QRadar_v3

* Build log-source-types-list command on QRadar_v3

* Build log-source-extensions-list command on QRadar_v3

* Build log-source-languages-list command on QRadar_v3

* Build log-source-groups-list command on QRadar_v3

* Remove unnecessary field from log-source-types HR on QRadar_V3

* Add qradar-log-source-protocol-types command to QRadar_V3

* Add qradar-log-source-delete command to QRadar_V3

* Add qradar-log-source-create command to QRadar_V3

* Clean qradar-log-source-create command

* add qradar-log-source-update command to QRadar_v3 and make some bug fixes to old commands

* start writing tests

* checkout

* Address CR

* Update Packs/QRadar/Integrations/QRadar_v3/QRadar_v3.yml

Co-authored-by: Judah Schwartz <JudahSchwartz@users.noreply.github.com>

* Address CR

* Add commands to playbook and fix bugs

* Fix playbook

* Menually merge master tpb

* merge in master

* checkout

* fix pre commit errors

* address pre-commit issues

* address pre-commit issues

* checkout

* checkout

* Bump pack from version QRadar to 2.4.52.

* checkout

* Remove map_raw_to_labels parameter from qradar settings

* Update Packs/QRadar/Integrations/QRadar_v3/QRadar_v3.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/QRadar/Integrations/QRadar_v3/QRadar_v3.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* add timeout to qradar events polling

* Bump pack from version QRadar to 2.4.53.

* checkout

* raise qradar timeout

* checkout

* remove timeout parameter from qradar-search-retrieve-events command

* make qradar-log-source-delete not crash when deleting non-existing id

* Update Packs/QRadar/Integrations/QRadar_v3/QRadar_v3.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/QRadar/Integrations/QRadar_v3/QRadar_v3.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/QRadar/Integrations/QRadar_v3/QRadar_v3.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/QRadar/Integrations/QRadar_v3/QRadar_v3.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/QRadar/Integrations/QRadar_v3/QRadar_v3.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/QRadar/Integrations/QRadar_v3/QRadar_v3.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* address doc review

* address doc review

* restore pre-commit and update command examples

* address lint issues

* address pre-commit errors

* address pre-commit errors

* address Juda's CR

* Update Packs/QRadar/Integrations/QRadar_v3/QRadar_v3.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/QRadar/Integrations/QRadar_v3/QRadar_v3.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/QRadar/Integrations/QRadar_v3/QRadar_v3.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/QRadar/Integrations/QRadar_v3/QRadar_v3.yml

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* address doc review

* fix RN

* regenerate docs

* Update Packs/QRadar/ReleaseNotes/2_4_53.md

Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com>

---------

Co-authored-by: Judah Schwartz <JudahSchwartz@users.noreply.github.com>
Co-authored-by: Content Bot <bot@demisto.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com>

* Update docker pcap (#33450)

* updated dockeר image

* rn

* Bump pack from version CommonScripts to 1.14.21.

* Bump pack from version CommonScripts to 1.14.22.

---------

Co-authored-by: Content Bot <bot@demisto.com>

* added validations to validation_config file (#33493)

* added validations to validation_config file

* fixes

* test

* changes

* fixes

* remove BA100

* adding back support_multithreading (#33542)

* adding back support_multithreading

* generate container id and add debug logs and RN

* fix UT

* RN

* add DEMISTO_SDK_GRAPH_FORCE_CREATE to validate in bucket upload (#33563)

* add DEMISTO_SDK_GRAPH_FORCE_CREATE to validate in bucket upload

* trigger build

* remove tmp file from repo (#33582)


force merge: accidental file added

* SplunkPy: documentation updates (#33565)

* update doc

* RN

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

---------

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* [pre-commit] - skip some hooks on nightly (#33578)

* [pre-commit] - skip validate-deleted-files in nightly

* Empty-Commit

* init (#33577)

* Scheduled Task Sanitize (#33368)

* XSUP-34767 - add utf8bom to csv header when needed (#33567)

* XSUP-34767 - add utf8bom to csv header when needed

* [MicrosoftGraphIdentityandAccess] update permissions (#33564)

* update scopes

* Revert "update scopes"

This reverts commit b250caf.

* update scopes

* pre commit

* update desc

* Aws e2c create vpc endpoint (#33517)

* code, readme, tests

* code, readme, tests, rn

* fix

* pre-commit

* fix

* fix

* demo and pre commit

* known words

* CR

* CR

* test fix

* pre commit

* gitlab pre-commit not mandatoary (#33594)

force merge: making pre-commit not mandatory

* [MicrosoftCloudAppSecurity] Fix the fetch in XSOAR 8 (#33588)

* [MicrosoftCloudAppSecurity] Fix the fetch in XSOAR 8

* Update Packs/MicrosoftCloudAppSecurity/ReleaseNotes/2_1_58.md

Co-authored-by: Binat Ziser <89336697+bziser@users.noreply.github.com>

---------

Co-authored-by: Binat Ziser <89336697+bziser@users.noreply.github.com>

* [Mail Sender (New)] Fix for EML Files with ASCII Encoding Error" (#33417)

* fix

* test PB

* rn

* Update docker

* fix tpb

* Empty-Commit

* fix tpb

* pre-commit path validations  (#33589)

* add validate-content-paths hook

* fix name

* no need for nightly

* remove test file

* use three-dot-diff (#33599)

* removed DO105 (#33605)

* RedCanary: fix detection without relationship (#33593)

* fix wrong code

* fix test name

* fix pre commit

* Update README.md (#33543) (#33574)

Added note indicating why integration doesn't support REST API token.

Co-authored-by: gbouzar <113393855+gbouzar@users.noreply.github.com>

* poetry files (#33606)

Co-authored-by: Content Bot <bot@demisto.com>

* update

* update

* deleying file

* adjustments

* adjustments

* adding logs

* fix lambda

* removing logs

* removing logs

* fix unit test

* cr fixes

* cr fixes

* mypy fixes

* Update Packs/CortexXDR/ReleaseNotes/6_1_27.md

Co-authored-by: EyalPintzov <91007713+eyalpalo@users.noreply.github.com>

* Update Packs/CortexXDR/ReleaseNotes/6_1_27.md

Co-authored-by: EyalPintzov <91007713+eyalpalo@users.noreply.github.com>

* adding unit test

* unit test that repreduce XSUP-35253

* fixing bug

* Update CortexXDRIR_test.py

removing last unit test

* fixing bug

* fixing bug

* pre commit

---------

Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com>
Co-authored-by: xsoar-bot <67315154+xsoar-bot@users.noreply.github.com>
Co-authored-by: Randy Baldwin <32545292+randomizerxd@users.noreply.github.com>
Co-authored-by: merit-maita <49760643+merit-maita@users.noreply.github.com>
Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com>
Co-authored-by: Judah Schwartz <JudahSchwartz@users.noreply.github.com>
Co-authored-by: Content Bot <bot@demisto.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com>
Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com>
Co-authored-by: Yuval Hayun <70104171+YuvHayun@users.noreply.github.com>
Co-authored-by: JudithB <132264628+jbabazadeh@users.noreply.github.com>
Co-authored-by: ilaner <88267954+ilaner@users.noreply.github.com>
Co-authored-by: Israel Lappe <79846863+ilappe@users.noreply.github.com>
Co-authored-by: Guy Afik <53861351+GuyAfik@users.noreply.github.com>
Co-authored-by: Jacob Levy <129657918+jlevypaloalto@users.noreply.github.com>
Co-authored-by: tkatzir <tkatzir@paloaltonetworks.com>
Co-authored-by: David Binyamin <47333909+davidbinyamin@users.noreply.github.com>
Co-authored-by: michal-dagan <109464765+michal-dagan@users.noreply.github.com>
Co-authored-by: EyalPintzov <91007713+eyalpalo@users.noreply.github.com>
Co-authored-by: Menachem Weinfeld <90556466+mmhw@users.noreply.github.com>
Co-authored-by: Binat Ziser <89336697+bziser@users.noreply.github.com>
Co-authored-by: Shmuel Kroizer <69422117+shmuel44@users.noreply.github.com>
Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com>
Co-authored-by: gbouzar <113393855+gbouzar@users.noreply.github.com>

* fix: prevent incidents time range control at fetch incidents (#33590) (#33741)

Co-authored-by: Okan <okan.turksever@logsign.net>
Co-authored-by: Menachem Weinfeld <90556466+mmhw@users.noreply.github.com>

* Update Docker Image To demisto/python3  (#33675)

* Updated Metadata Of Pack QualysFIM

* Added release notes to pack QualysFIM

* Packs/QualysFIM/Integrations/QualysFIM/QualysFIM.yml Docker image update

* Updated Metadata Of Pack FortiSIEM

* Added release notes to pack FortiSIEM

* Packs/FortiSIEM/Integrations/FortiSIEMV2/FortiSIEMV2.yml Docker image update

* Updated Metadata Of Pack KnowBe4_KMSAT

* Added release notes to pack KnowBe4_KMSAT

* Packs/KnowBe4_KMSAT/Integrations/KnowBe4KMSATEventCollector/KnowBe4KMSATEventCollector.yml Docker image update

* Packs/KnowBe4_KMSAT/Integrations/KnowBe4KMSAT/KnowBe4KMSAT.yml Docker image update

* Updated Metadata Of Pack SymantecCloudSecureWebGateway

* Added release notes to pack SymantecCloudSecureWebGateway

* Packs/SymantecCloudSecureWebGateway/Integrations/SymantecCloudSecureWebGatewayEventCollector/SymantecCloudSecureWebGatewayEventCollector.yml Docker image update

* Updated Metadata Of Pack SafeNet_Trusted_Access

* Added release notes to pack SafeNet_Trusted_Access

* Packs/SafeNet_Trusted_Access/Integrations/SafeNetTrustedAccessEventCollector/SafeNetTrustedAccessEventCollector.yml Docker image update

* Updated Metadata Of Pack DelineaSS

* Added release notes to pack DelineaSS

* Packs/DelineaSS/Integrations/DelineaSS/DelineaSS.yml Docker image update

* Updated Metadata Of Pack Cryptocurrency

* Added release notes to pack Cryptocurrency

* Packs/Cryptocurrency/Integrations/Cryptocurrency/Cryptocurrency.yml Docker image update

* Updated Metadata Of Pack PANOSPolicyOptimizer

* Added release notes to pack PANOSPolicyOptimizer

* Packs/PANOSPolicyOptimizer/Integrations/PANOSPolicyOptimizer/PANOSPolicyOptimizer.yml Docker image update

* Updated Metadata Of Pack Lumu

* Added release notes to pack Lumu

* Packs/Lumu/Integrations/Lumu/Lumu.yml Docker image update

* Updated Metadata Of Pack FlashpointFeed

* Added release notes to pack FlashpointFeed

* Packs/FlashpointFeed/Integrations/FlashpointFeed/FlashpointFeed.yml Docker image update

* Updated Metadata Of Pack Fortimail

* Added release notes to pack Fortimail

* Packs/Fortimail/Integrations/Fortimail/Fortimail.yml Docker image update

* Updated Metadata Of Pack Wiz

* Added release notes to pack Wiz

* Packs/Wiz/Integrations/Wiz/Wiz.yml Docker image update

* Updated Metadata Of Pack FeedLOLBAS

* Added release notes to pack FeedLOLBAS

* Packs/FeedLOLBAS/Integrations/FeedLOLBAS/FeedLOLBAS.yml Docker image update

* Updated Metadata Of Pack Hackuity

* Added release notes to pack Hackuity

* Packs/Hackuity/Integrations/Hackuity/Hackuity.yml Docker image update

* Updated Metadata Of Pack Grafana

* Added release notes to pack Grafana

* Packs/Grafana/Integrations/Grafana/Grafana.yml Docker image update

* Updated Metadata Of Pack Binalyze

* Added release notes to pack Binalyze

* Packs/Binalyze/Integrations/BinalyzeAIR/BinalyzeAIR.yml Docker image update

* Updated Metadata Of Pack ServiceDeskPlus

* Added release notes to pack ServiceDeskPlus

* Packs/ServiceDeskPlus/Integrations/ServiceDeskPlus/ServiceDeskPlus.yml Docker image update

* Updated Metadata Of Pack Oracle_IAM

* Added release notes to pack Oracle_IAM

* Packs/Oracle_IAM/Integrations/OracleIAM/OracleIAM.yml Docker image update

* Updated Metadata Of Pack AccentureCTI

* Added release notes to pack AccentureCTI

* Packs/AccentureCTI/Integrations/ACTIIndicatorQuery/ACTIIndicatorQuery.yml Docker image update

* Updated Metadata Of Pack CarbonBlackDefense

* Added release notes to pack CarbonBlackDefense

* Packs/CarbonBlackDefense/Integrations/CarbonBlackEndpointStandardEventCollector/CarbonBlackEndpointStandardEventCollector.yml Docker image update

* Updated Metadata Of Pack SpyCloudEnterpriseProtection

* Added release notes to pack SpyCloudEnterpriseProtection

* Packs/SpyCloudEnterpriseProtection/Integrations/SpyCloudEnterpriseProtectionEnrichment/SpyCloudEnterpriseProtectionEnrichment.yml Docker image update

* Updated Metadata Of Pack VMwareWorkspaceONEUEM

* Added release notes to pack VMwareWorkspaceONEUEM

* Packs/VMwareWorkspaceONEUEM/Integrations/VMwareWorkspaceONEUEM/VMwareWorkspaceONEUEM.yml Docker image update

* Updated Metadata Of Pack SalesforceFusion

* Added release notes to pack SalesforceFusion

* Packs/SalesforceFusion/Integrations/SalesforceFusionIAM/SalesforceFusionIAM.yml Docker image update

* Updated Metadata Of Pack RecordedFuture

* Added release notes to pack RecordedFuture

* Packs/RecordedFuture/Integrations/RecordedFuture/RecordedFuture.yml Docker image update

* Packs/RecordedFuture/Integrations/RecordedFutureLists/RecordedFutureLists.yml Docker image update

* Packs/RecordedFuture/Integrations/RecordedFutureEventCollector/RecordedFutureEventCollector.yml Docker image update

* Packs/RecordedFuture/Integrations/RecordedFuturePlaybookAlerts/RecordedFuturePlaybookAlerts.yml Docker image update

* Updated Metadata Of Pack ZeroFox

* Added release notes to pack ZeroFox

* Packs/ZeroFox/Integrations/ZeroFox/ZeroFox.yml Docker image update

* Updated Metadata Of Pack AppNovi

* Added release notes to pack AppNovi

* Packs/AppNovi/Integrations/appNovi/appNovi.yml Docker image update

* Updated Metadata Of Pack Ataya

* Added release notes to pack Ataya

* Packs/Ataya/Integrations/Ataya/Ataya.yml Docker image update

* Updated Metadata Of Pack AHA

* Added release notes to pack AHA

* Packs/AHA/Integrations/AHA/AHA.yml Docker image update

* Updated Metadata Of Pack ForcepointDLP

* Added release notes to pack ForcepointDLP

* Packs/ForcepointDLP/Integrations/ForcepointEventCollector/ForcepointEventCollector.yml Docker image update

* Updated Metadata Of Pack AzureStorageFileShare

* Added release notes to pack AzureStorageFileShare

* Packs/AzureStorageFileShare/Integrations/AzureStorageFileShare/AzureStorageFileShare.yml Docker image update

* Updated Metadata Of Pack CiscoSMA

* Added release notes to pack CiscoSMA

* Packs/CiscoSMA/Integrations/CiscoSMA/CiscoSMA.yml Docker image update

* Updated Metadata Of Pack AMP

* Added release notes to pack AMP

* Packs/AMP/Integrations/AMPv2/AMPv2.yml Docker image update

* Packs/AMP/Integrations/CiscoAMPEventCollector/CiscoAMPEventCollector.yml Docker image update

* Updated Metadata Of Pack EmailHippo

* Added release notes to pack EmailHippo

* Packs/EmailHippo/Integrations/EmailHippo/EmailHippo.yml Docker image update

* Updated Metadata Of Pack IronPort

* Added release notes to pack IronPort

* Packs/IronPort/Integrations/CiscoEmailSecurityApplianceIronPortV2/CiscoEmailSecurityApplianceIronPortV2.yml Docker image update

* Updated Metadata Of Pack QutteraWebsiteMalwareScanner

* Added release notes to pack QutteraWebsiteMalwareScanner

* Packs/QutteraWebsiteMalwareScanner/Integrations/QutteraWebsiteMalwareScanner/QutteraWebsiteMalwareScanner.yml Docker image update

* Updated Metadata Of Pack VaronisSaaS

* Added release notes to pack VaronisSaaS

* Packs/VaronisSaaS/Integrations/VaronisSaaS/VaronisSaaS.yml Docker image update

* Updated Metadata Of Pack HYASProtect

* Added release notes to pack HYASProtect

* Packs/HYASProtect/Integrations/HYASProtect/HYASProtect.yml Docker image update

* Updated Metadata Of Pack epo

* Added release notes to pack epo

* Packs/epo/Integrations/epoV2/epoV2.yml Docker image update

* Updated Metadata Of Pack CiscoStealthwatch

* Added release notes to pack CiscoStealthwatch

* Packs/CiscoStealthwatch/Integrations/CiscoStealthwatch/CiscoStealthwatch.yml Docker image update

* Updated Metadata Of Pack ThreatConnect

* Added release notes to pack ThreatConnect

* Packs/ThreatConnect/Integrations/ThreatConnectV3/ThreatConnectV3.yml Docker image update

* Updated Metadata Of Pack RiskIQDigitalFootprint

* Added release notes to pack RiskIQDigitalFootprint

* Packs/RiskIQDigitalFootprint/Integrations/RiskIQDigitalFootprint/RiskIQDigitalFootprint.yml Docker image update

* Updated Metadata Of Pack DomainToolsIrisDetect

* Added release notes to pack DomainToolsIrisDetect

* Packs/DomainToolsIrisDetect/Integrations/DomainToolsIrisDetect/DomainToolsIrisDetect.yml Docker image update

* Updated Metadata Of Pack AtlassianConfluenceCloud

* Added release notes to pack AtlassianConfluenceCloud

* Packs/AtlassianConfluenceCloud/Integrations/AtlassianConfluenceCloud/AtlassianConfluenceCloud.yml Docker image update

* Updated Metadata Of Pack Gatewatcher-AionIQ

* Added release notes to pack Gatewatcher-AionIQ

* Packs/Gatewatcher-AionIQ/Integrations/GCenter/GCenter.yml Docker image update

* Updated Metadata Of Pack RecordedFutureASI

* Added release notes to pack RecordedFutureASI

* Packs/RecordedFutureASI/Integrations/RecordedFutureASI/RecordedFutureASI.yml Docker image update

* Bump pack from version SafeNet_Trusted_Access to 2.0.39.

---------

Co-authored-by: Content Bot <bot@demisto.com>

* Qualys VMDR unify (#33240)

* added fetch assets

* added test

* fixed cr comments

* unify

* removed the collector

* update redame, rn

* update rn. and added qualys-get-assets to yml

* fixed

* fixed mypy

* changed the limit

* update readme

* mypy

* added breaking Changes

* added since_datetime to test_module

* description

* fetch interval and dataset name

* Hyperlink extract from office docs - added to extract indicators from file playbook (#33634)

* Added ExtractHyperLinksFromOfficeFiles task

* RN + image

* Removed Doc support

* Added support for xsoar 8

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Bump pack from version CommonPlaybooks to 2.6.28.

---------

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Co-authored-by: Content Bot <bot@demisto.com>

* Xsup 35665 part 2 (#33771)

* ews workaround

* fix find folders

* access directly

* Update Packs/MicrosoftExchangeOnline/Integrations/EWSO365/EWSO365.py

* Update Packs/MicrosoftExchangeOnline/Integrations/EWSO365/EWSO365.py

access directly

* fixed search

* fixed tests

* added rn

* Update Packs/MicrosoftExchangeOnline/ReleaseNotes/1_3_0.md

Co-authored-by: Judah Schwartz <JudahSchwartz@users.noreply.github.com>

* added fix for search by id

* Added rn

---------

Co-authored-by: Dan Tavori <dtavori@paloaltonetworks.com>
Co-authored-by: Judah Schwartz <juschwartz@paloaltonetworks.com>
Co-authored-by: Judah Schwartz <JudahSchwartz@users.noreply.github.com>

* AWS Lambda - Update Layer Version Command Enhancement (#33609)

* updated the aws-lambda-update-layer-version arguments

* updated readme

* updated rn

* Changed arguments order

* format

* undo change to a command argument

* fixes the test py

* update RN

* fix long line

* fix long line

* update docker image

---------

Co-authored-by: RotemAmit <ramit@paloaltonetworks.com>

* Web file repository - Fixed where large file uploading fails. (#33645) (#33779)

* Merge

* revert package-lock.json

* Fixed where large file uploading fails.

* Update RN

* Fixed CircleCI errors

* Fixed CircleCI errors

* Fixed CircleCI errors

* Fixed CircleCI errors

* Fixed CircleCI errors

* Small fix

---------

Co-authored-by: Masahiko Inoue <54964121+spearmin10@users.noreply.github.com>
Co-authored-by: Menachem Weinfeld <90556466+mmhw@users.noreply.github.com>

* remove allow failure from new validate steps (#33763)

Co-authored-by: GuyAfik <guyafik11@gmail.com>

* [Marketplace Contribution] Community Common Dashboards - Content Pack Update (#33369) (#33775)

* "contribution update to pack 'Community Common Dashboards'"

* Update README.md

* Update XSOARValueMetrics.py

res = demisto.executeCommand('demisto-api-post', 
 
changed to 

res = demisto.executeCommand('core-api-post',

* Update XSOARValueMetrics.py

Fix Unit Test findings

* Update XMetricsTotal.py

Fix unit test findings

* Update XMetrics.py

Fix unit test findings

* Update XMetrics.py

Remove trailing whitespace

* Update XMetricsTotal.py

Remove trailing whitespace

* Update XSOARValueMetrics.py

Fix trailing whitespace

* Update XMetrics.py

Remove trailing whitespace

* Update XSOARValueMetrics.py

Remove trailing whitespace

* Update XSOARValueMetrics.py

Whitespace around operator

* Update 2_0_0.md

---------

Co-authored-by: xsoar-bot <67315154+xsoar-bot@users.noreply.github.com>
Co-authored-by: David Uhrlaub <90627446+rurhrlaub@users.noreply.github.com>
Co-authored-by: Moshe Galitzky <112559840+moishce@users.noreply.github.com>

* CR fixes

---------

Co-authored-by: Dean Arbel <darbel@paloaltonetworks.com>
Co-authored-by: Sasha Sokolovich <88268646+ssokolovich@users.noreply.github.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Co-authored-by: Karina Fishman <147307864+karinafishman@users.noreply.github.com>
Co-authored-by: Arad Carmi <62752352+AradCarmi@users.noreply.github.com>
Co-authored-by: barryyosi-panw <byosilevich@paloaltonetworks.com>
Co-authored-by: barryyosi-panw <158817412+barryyosi-panw@users.noreply.github.com>
Co-authored-by: Tal Zichlinsky <35036457+talzich@users.noreply.github.com>
Co-authored-by: TalZich <tzichlinsky@paloaltonetworks.com>
Co-authored-by: Content Bot <bot@demisto.com>
Co-authored-by: Mai Morag <81917647+maimorag@users.noreply.github.com>
Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com>
Co-authored-by: xsoar-bot <67315154+xsoar-bot@users.noreply.github.com>
Co-authored-by: Randy Baldwin <32545292+randomizerxd@users.noreply.github.com>
Co-authored-by: merit-maita <49760643+merit-maita@users.noreply.github.com>
Co-authored-by: Judah Schwartz <JudahSchwartz@users.noreply.github.com>
Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com>
Co-authored-by: Yuval Cohen <86777474+yucohen@users.noreply.github.com>
Co-authored-by: Yuval Hayun <70104171+YuvHayun@users.noreply.github.com>
Co-authored-by: JudithB <132264628+jbabazadeh@users.noreply.github.com>
Co-authored-by: ilaner <88267954+ilaner@users.noreply.github.com>
Co-authored-by: Israel Lappe <79846863+ilappe@users.noreply.github.com>
Co-authored-by: Guy Afik <53861351+GuyAfik@users.noreply.github.com>
Co-authored-by: Jacob Levy <129657918+jlevypaloalto@users.noreply.github.com>
Co-authored-by: tkatzir <tkatzir@paloaltonetworks.com>
Co-authored-by: David Binyamin <47333909+davidbinyamin@users.noreply.github.com>
Co-authored-by: michal-dagan <109464765+michal-dagan@users.noreply.github.com>
Co-authored-by: EyalPintzov <91007713+eyalpalo@users.noreply.github.com>
Co-authored-by: Menachem Weinfeld <90556466+mmhw@users.noreply.github.com>
Co-authored-by: Binat Ziser <89336697+bziser@users.noreply.github.com>
Co-authored-by: Shmuel Kroizer <69422117+shmuel44@users.noreply.github.com>
Co-authored-by: dorschw <81086590+dorschw@users.noreply.github.com>
Co-authored-by: gbouzar <113393855+gbouzar@users.noreply.github.com>
Co-authored-by: Okan <okan.turksever@logsign.net>
Co-authored-by: Moshe Galitzky <112559840+moishce@users.noreply.github.com>
Co-authored-by: Shahaf Ben Yakir <44666568+ShahafBenYakir@users.noreply.github.com>
Co-authored-by: Dan Tavori <dtavori@paloaltonetworks.com>
Co-authored-by: Judah Schwartz <juschwartz@paloaltonetworks.com>
Co-authored-by: Ben Melamed <bmelamed@paloaltonetworks.com>
Co-authored-by: RotemAmit <ramit@paloaltonetworks.com>
Co-authored-by: Masahiko Inoue <54964121+spearmin10@users.noreply.github.com>
Co-authored-by: GuyAfik <guyafik11@gmail.com>
Co-authored-by: David Uhrlaub <90627446+rurhrlaub@users.noreply.github.com>
  • Loading branch information
Show file tree
Hide file tree
Showing 5 changed files with 14 additions and 7 deletions.
7 changes: 4 additions & 3 deletions Packs/Akamai_SIEM/Integrations/Akamai_SIEM/Akamai_SIEM.py
Expand Up @@ -305,10 +305,11 @@ def fetch_incidents_command(
incidents = []
if raw_response:
for event in raw_response:
attack_data = event.get('attackData', {})
http_message = event.get('httpMessage', {})
incidents.append({
'name': f"{INTEGRATION_NAME}: {event.get('attackData').get('configId')}",
'occurred': date_format_converter(from_format='epoch',
date_before=event.get('httpMessage', {}).get('start')),
'name': f"{INTEGRATION_NAME}: {attack_data.get('configId')} - {http_message.get('requestId')}",
'occurred': date_format_converter(from_format='epoch', date_before=http_message.get('start')),
'rawJSON': json.dumps(event)
})

Expand Down
2 changes: 1 addition & 1 deletion Packs/Akamai_SIEM/Integrations/Akamai_SIEM/Akamai_SIEM.yml
Expand Up @@ -208,7 +208,7 @@ script:
- contextPath: IP.Geo.Country
description: The country in which the IP address is located.
type: String
dockerimage: demisto/auth-utils:1.0.0.90978
dockerimage: demisto/auth-utils:1.0.0.91447
isfetch: true
isfetch:marketplacev2: false
isfetchevents: true
Expand Down
@@ -1,11 +1,11 @@
[
{
"name": "Akamai SIEM: 50170",
"name": "Akamai SIEM: 50170 - 3fbce3e",
"occurred": "2019-12-10T18:28:27Z",
"rawJSON": {"type":"akamai_siem","format":"json","version":"1.0","attackData":{"configId":"50170","policyId":"1234","clientIP":"8.8.8.8","rules":"","ruleVersions":"","ruleMessages":"","ruleTags":"","ruleData":"","ruleSelectors":"","ruleActions":""},"httpMessage":{"requestId":"3fbce3e","start":"1576002507","protocol":"HTTP/1.1","method":"HEAD","host":"google.com","port":"80","path":"index","requestHeaders":"Test","status":"403","bytes":"0","responseHeaders":"Server"},"geo":{"continent":"NA","country":"US","city":"LOSANGELES","regionCode":"CA","asn":"5650"}}
},
{
"name": "Akamai SIEM: 50170",
"name": "Akamai SIEM: 50170 - 3fbd757",
"occurred": "2019-12-10T18:28:26Z",
"rawJSON": {"type":"akamai_siem","format":"json","version":"1.0","attackData":{"configId":"50170","policyId":"1234","clientIP":"8.8.8.8","rules":"","ruleVersions":"","ruleMessages":"","ruleTags":"","ruleData":"","ruleSelectors":"","ruleActions":""},"httpMessage":{"requestId":"3fbd757","start":"1576002506","protocol":"HTTP/1.1","method":"HEAD","host":"google.com","port":"80","path":"index","requestHeaders":"Test","status":"403","bytes":"0","responseHeaders":"Server"},"geo":{"continent":"NA","country":"US","city":"LOSANGELES","regionCode":"CA","asn":"5650"}}
}
Expand Down
6 changes: 6 additions & 0 deletions Packs/Akamai_SIEM/ReleaseNotes/1_1_1.md
@@ -0,0 +1,6 @@

#### Integrations

##### Akamai WAF SIEM
- Updated the Docker image to: *demisto/auth-utils:1.0.0.91447*.
- Added the *requestId* field to the name of created incidents. This will prevent the creation of incidents with the same name.
2 changes: 1 addition & 1 deletion Packs/Akamai_SIEM/pack_metadata.json
Expand Up @@ -2,7 +2,7 @@
"name": "Akamai WAF SIEM",
"description": "Use the Akamai WAF SIEM integration to retrieve security events from Akamai Web Application Firewall (WAF) service.",
"support": "xsoar",
"currentVersion": "1.1.0",
"currentVersion": "1.1.1",
"author": "Cortex XSOAR",
"url": "https://www.paloaltonetworks.com/cortex",
"email": "",
Expand Down

0 comments on commit 1dc2b50

Please sign in to comment.