Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ciac 6453/improve generic polling - hotfix #26372

Merged
merged 49 commits into from May 11, 2023

Conversation

AradCarmi
Copy link
Contributor

@AradCarmi AradCarmi commented May 7, 2023

Description

fix for PR.

Screenshot

image

@AradCarmi AradCarmi requested a review from dantavori May 7, 2023 18:05
Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com>
@AradCarmi
Copy link
Contributor Author

validate fails on GR103 since the newly added stopScheduleEntry is used in the js script but is not specified in the demisto-sdk server items list (fixed demisto/demisto-sdk#2983). requires force merge.

@AradCarmi
Copy link
Contributor Author

We decided to support the new feature only for XSOAR.
In order to support XSIAM, please refer to this Draft PR.

@content-bot
Copy link
Collaborator

This PR was automatically updated by a GitHub Action

  • CommonScripts pack version was bumped to 1.11.69.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@content-bot
Copy link
Collaborator

This PR was automatically updated by a GitHub Action

  • CommonScripts pack version was bumped to 1.11.70.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

Copy link
Contributor

@dantavori dantavori left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nice, see only docs changes

@content-bot
Copy link
Collaborator

This PR was automatically updated by a GitHub Action

  • CommonScripts pack version was bumped to 1.11.72.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

Copy link
Contributor

@ShahafBenYakir ShahafBenYakir left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice

@content-bot
Copy link
Collaborator

This PR was automatically updated by a GitHub Action

  • CommonScripts pack version was bumped to 1.11.73.

To stop automatic version bumps, add the ignore-auto-bump-version label to the github PR.

@AradCarmi AradCarmi requested a review from dantavori May 10, 2023 11:57
@ShahafBenYakir ShahafBenYakir merged commit 6f65a3e into master May 11, 2023
11 of 14 checks passed
@ShahafBenYakir ShahafBenYakir deleted the CIAC-6453/Improve_GenericPolling_v2 branch May 11, 2023 11:42
MosheEichler pushed a commit that referenced this pull request May 14, 2023
* Fixed script issues

* updated rn

* Updated rn

* Apply suggestions from code review

Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com>

* updated script min version

* fix pre-commit issues

* updated the script to support only XSOAR

* Bump pack from version CommonScripts to 1.11.69.

* update to use endTime instead of using the context

* updated rn

* Bump pack from version CommonScripts to 1.11.70.

* updated rn

* Update Packs/CommonScripts/ReleaseNotes/1_11_70.md

* updated rn and readme

* Updated rn

* updated rn

* updated script

* Apply suggestions from code review

Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com>

* Update Packs/CommonScripts/Scripts/ScheduleGenericPolling/ScheduleGenericPolling.py

Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com>

* Bump pack from version CommonScripts to 1.11.72.

* Bump pack from version CommonScripts to 1.11.73.

* updated script

* updated rn

* updated docker image

* updated script

* updated scripts

---------

Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com>
Co-authored-by: Content Bot <bot@demisto.com>
julieschwartz18 added a commit that referenced this pull request May 24, 2023
* Update README.md

Updates based on inputs from @PaulBartruff for PR #1312

* Update README.md

Updated based on @PaulBartruff's inputs

* Update README.md

Fixed capitalization of Gmail

* fail if modeling rules command fails (#26439)

* Ciac 6453/improve generic polling - hotfix (#26372)

* Fixed script issues

* updated rn

* Updated rn

* Apply suggestions from code review

Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com>

* updated script min version

* fix pre-commit issues

* updated the script to support only XSOAR

* Bump pack from version CommonScripts to 1.11.69.

* update to use endTime instead of using the context

* updated rn

* Bump pack from version CommonScripts to 1.11.70.

* updated rn

* Update Packs/CommonScripts/ReleaseNotes/1_11_70.md

* updated rn and readme

* Updated rn

* updated rn

* updated script

* Apply suggestions from code review

Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com>

* Update Packs/CommonScripts/Scripts/ScheduleGenericPolling/ScheduleGenericPolling.py

Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com>

* Bump pack from version CommonScripts to 1.11.72.

* Bump pack from version CommonScripts to 1.11.73.

* updated script

* updated rn

* updated docker image

* updated script

* updated scripts

---------

Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com>
Co-authored-by: Content Bot <bot@demisto.com>

* changed reviewers (#26457)

* changed reviewers

* Update Utils/github_workflow_scripts/handle_external_pr.py

Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com>

---------

Co-authored-by: EyalPintzov <91007713+eyalpalo@users.noreply.github.com>
Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com>

* Phishing enhance (#26428)

* XSIAM | Bluecat Address Manager ModelingRules (#26368)

* XSIAM | Bluecat Address Manager ModelingRules

* Updated ParsingRules

* Updated ModelingRules and added README

* Updated README file

* Updated README

* Updated README

* Updated Parsing Rules and README

* Update Packs/BluecatAddressManager/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/BluecatAddressManager/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Updated README

* Apply suggestions from code review

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Updated ReleaseNotes

* Updated ReleaseNotes

* Updated ReleaseNotes

---------

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* added sort field and direction to event-search and alert-search (#26413)

* added sort field and direction to event-search and alert-search

* updated release notes

* updated release notes

* changed docker version

* Updated release notes

* Update Packs/PrismaCloud/ReleaseNotes/4_1_0.md

* fixed flake8 errors

---------

Co-authored-by: Judah Schwartz <JudahSchwartz@users.noreply.github.com>

* Update Docker Image To demisto/python3  (#26472)

* Updated Metadata Of Pack QutteraWebsiteMalwareScanner

* Added release notes to pack QutteraWebsiteMalwareScanner

* Packs/QutteraWebsiteMalwareScanner/Integrations/QutteraWebsiteMalwareScanner/QutteraWebsiteMalwareScanner.yml Docker image update

* Updated Metadata Of Pack Rapid7_Nexpose

* Added release notes to pack Rapid7_Nexpose

* Packs/Rapid7_Nexpose/Integrations/Rapid7_Nexpose/Rapid7_Nexpose.yml Docker image update

* Updated Metadata Of Pack RiskIQDigitalFootprint

* Added release notes to pack RiskIQDigitalFootprint

* Packs/RiskIQDigitalFootprint/Integrations/RiskIQDigitalFootprint/RiskIQDigitalFootprint.yml Docker image update

* Updated Metadata Of Pack SOCRadar

* Added release notes to pack SOCRadar

* Packs/SOCRadar/Integrations/SOCRadarThreatFusion/SOCRadarThreatFusion.yml Docker image update

* Updated Metadata Of Pack SalesforceFusion

* Added release notes to pack SalesforceFusion

* Packs/SalesforceFusion/Integrations/SalesforceFusionIAM/SalesforceFusionIAM.yml Docker image update

* Updated Metadata Of Pack SecneurXAnalysis

* Added release notes to pack SecneurXAnalysis

* Packs/SecneurXAnalysis/Integrations/SecneurXAnalysis/SecneurXAnalysis.yml Docker image update

* Updated Metadata Of Pack SecneurXThreatFeeds

* Added release notes to pack SecneurXThreatFeeds

* Packs/SecneurXThreatFeeds/Integrations/SecneurXThreatFeeds/SecneurXThreatFeeds.yml Docker image update

* Updated Metadata Of Pack SecureWorks

* Added release notes to pack SecureWorks

* Packs/SecureWorks/Integrations/TaegisXDR/TaegisXDR.yml Docker image update

* Updated Metadata Of Pack ServiceDeskPlus

* Added release notes to pack ServiceDeskPlus

* Packs/ServiceDeskPlus/Integrations/ServiceDeskPlus/ServiceDeskPlus.yml Docker image update

* Updated Metadata Of Pack SingleConnect

* Added release notes to pack SingleConnect

* Packs/SingleConnect/Integrations/SingleConnect/SingleConnect.yml Docker image update

* [Marketplace Contribution] Tanium Threat Response - Content Pack Update (#25218)

* Reco add new type of alerts (#26469)

* Reco add new type of alerts (#26342)

* Update .devcontainer.json name

* Packs/Reco:  add reco alerts

Fetch alerts as incident.

Signed-off-by: Gal Nakash <gal@recolabs.ai>

* Packs/Reco: black fix lint issues

Signed-off-by: Gal Nakash <gal@recolabs.ai>

* Packs/Reco: fix pr comment

Signed-off-by: Gal Nakash <gal@recolabs.ai>

* Packs/Reco: change pack version and docs

Signed-off-by: Gal Nakash <gal@recolabs.ai>

* Packs/Reco: fix alert-id parser

decode based64 alert id as string to get single alert data

Signed-off-by: Gal Nakash <gal@recolabs.ai>

* Packs/Reco: fix flake8 errors

Signed-off-by: Gal Nakash <gal@recolabs.ai>

* Packs/Reco: reco fix tests

Signed-off-by: Gal Nakash <gal@recolabs.ai>

* Packs/Reco: reco fix tests

Signed-off-by: Gal Nakash <gal@recolabs.ai>

* Packs/Reco: generate magic link to the UI

Signed-off-by: Gal Nakash <gal@recolabs.ai>

* Packs/Reco: update release notes docker image

Signed-off-by: Gal Nakash <gal@recolabs.ai>

---------

Signed-off-by: Gal Nakash <gal@recolabs.ai>
Co-authored-by: GalNakash-RecoLabs <GalNakash-RecoLabs@users.noreply.github.com>

* Update docker image

---------

Signed-off-by: Gal Nakash <gal@recolabs.ai>
Co-authored-by: GalNakash-RecoLabs <71227802+GalNakash-RecoLabs@users.noreply.github.com>
Co-authored-by: GalNakash-RecoLabs <GalNakash-RecoLabs@users.noreply.github.com>
Co-authored-by: samuelFain <65926551+samuelFain@users.noreply.github.com>

* Yr xsup 22806 pan os fetching issues (multiple devices) (#26226)

* new helping func

* typing

* remove auto formated lines

* replace 'seqno' with  '@gobid'

* remove other changes

* Merge remote-tracking branch 'origin/master' into YR--XSUP-22806]-PAN-OS-fetching-issues-(Multiple-devices)

* revert

* add note for the user to narrow down the query

* remove the Dev

* remove code and add a max id func

* try

* adding a remove duplicates func

* adding support to store a limit per log type

* fixes

* using last run directly insted of passing it

* prepare to cr

* mypy

* add int

* mypy

* BC

* mypy

* mypy

* fix previus tests

* test

* test

* test

* conflict

* docker image

* flake 8

* Shirley fixes

* Tal's CR

* mypy

* fix a falling test and a mistake in fixing the func after CR

* CR

* mypy

* docker image

* Shachars CR

* tal katzir CR

* fix failing unit tests

* flake 8

* Guy afik CR

* fix a failed test

* Merge remote-tracking branch 'origin/master' into YR--XSUP-22806]-PAN-OS-fetching-issues-(Multiple-devices)

* adding notes for debugging, and fixing a test

* Merge remote-tracking branch 'origin/master' into YR--XSUP-22806]-PAN-OS-fetching-issues-(Multiple-devices)

* note

* Merge remote-tracking branch 'origin/master' into YR--XSUP-22806]-PAN-OS-fetching-issues-(Multiple-devices)

* remove the note from yesterday

* adding the 'forward' param to the request

* adding the notes

* docker

* change debug message

* fixn readme note

* avoid devices from previous cycles to be deleted

* Merge remote-tracking branch 'origin/master' into YR--XSUP-22806]-PAN-OS-fetching-issues-(Multiple-devices)

* typo

* Update Packs/PAN-OS/ReleaseNotes/1_17_0.md

* Merge remote-tracking branch 'origin/master' into YR--XSUP-22806]-PAN-OS-fetching-issues-(Multiple-devices)

* docker

---------

Co-authored-by: Shachar Kidor <82749224+ShacharKidor@users.noreply.github.com>

* dontcheckhostname verify false (#26410)

* dontcheckhostname verify false

* rn

* dont disable py2

* bump version

* Update Packs/Base/ReleaseNotes/1_32_0.md

* added script to md

* Update Packs/Base/ReleaseNotes/1_32_0.md

Co-authored-by: Shahaf Ben Yakir <44666568+ShahafBenYakir@users.noreply.github.com>

---------

Co-authored-by: Shahaf Ben Yakir <44666568+ShahafBenYakir@users.noreply.github.com>

* Use version 2.0.0 of argus-toolbelt docker image (#26321) (#26458)

* hotfix: use v2 not v3 of docker image

MSIDEV-316

* add release notes and bump version in pack_metadata

github.com//pull/26321

Co-authored-by: Konrad Urdahl Halnum <konrad@mnemonic.no>
Co-authored-by: merit-maita <49760643+merit-maita@users.noreply.github.com>

* Corelight Zeek / Prisma Cloud Modeling Rule fix4 (#26338)

* Url encode - enable the script (#26465)

* enable URLEncode transformer

* update RN

* Update Packs/FiltersAndTransformers/ReleaseNotes/1_2_17.md

Co-authored-by: Dean Arbel <darbel@paloaltonetworks.com>

* update docker

* add readme file

* update RN

* Update Packs/FiltersAndTransformers/ReleaseNotes/1_2_17.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* update docker

---------

Co-authored-by: Dean Arbel <darbel@paloaltonetworks.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Wildfile url param clarify desc (#26392)

* Creating Test Playbooks Checking Empty Inputs (#26048)

* add sane arg to support force using server formatted time strings (#26438)

* add sane arg to support force using server formatted time strings

* add new arg to params log

* add readme and dockerimage placeholder

* Bump pack from version Base to 1.31.97.

* Docker bump
Mypy fix
RN update

* RN fix

* Fixed unnecessary f string

* Bump pack from version Base to 1.32.1.

---------

Co-authored-by: Content Bot <bot@demisto.com>
Co-authored-by: sbenyakir <shahaf.benyakir@demisto.com>
Co-authored-by: Yonatan Roth <76961496+yonatan-roth@users.noreply.github.com>
Co-authored-by: Shahaf Ben Yakir <44666568+ShahafBenYakir@users.noreply.github.com>

* removed the from args (#26480)

* Trend Micro Deep Security Modeling Rules  (#CIAC-3156) (#26453)

* Trend Micro Deep Security Modeling Rules  (#CIAC-3156)

## Status
- [x] In Progress
- [ ] Ready
- [ ] In Hold - (Reason for hold)

## Related Issues
fixes: [CIAC-3156](https://jira-hq.paloaltonetworks.local/browse/CIAC-3156)

## Description
Modeling Rules for Trend Micro Deep Security

* Remove old Files

* Add Release Notes

* Update 1_0_5.md

* Updated README.md with XSIAM syslog conf. doc.

* Update README.md

* Update README.md

* fix syntax error on xif

* Update Packs/TrendMicroDeepSecurity/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/TrendMicroDeepSecurity/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/TrendMicroDeepSecurity/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/TrendMicroDeepSecurity/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/TrendMicroDeepSecurity/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/TrendMicroDeepSecurity/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/TrendMicroDeepSecurity/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/TrendMicroDeepSecurity/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/TrendMicroDeepSecurity/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update Packs/TrendMicroDeepSecurity/README.md

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* Update "Define Event Forwarding" section on README.md

* refine event type filters

* Update README.md: move XSIAM comment to XSIAM section

---------

Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>

* mdx fix

* format

* Update README.md

* Update README.md

removed <br> tags

* update docker image

* Update README.md

* Update README.md

---------

Signed-off-by: Gal Nakash <gal@recolabs.ai>
Co-authored-by: Darya Koval <72339940+daryakoval@users.noreply.github.com>
Co-authored-by: Arad Carmi <62752352+AradCarmi@users.noreply.github.com>
Co-authored-by: Dan Tavori <38749041+dantavori@users.noreply.github.com>
Co-authored-by: Content Bot <bot@demisto.com>
Co-authored-by: yucohen <86777474+yucohen@users.noreply.github.com>
Co-authored-by: EyalPintzov <91007713+eyalpalo@users.noreply.github.com>
Co-authored-by: ArikDay <115150768+ArikDay@users.noreply.github.com>
Co-authored-by: nkanon <109467661+nkanon@users.noreply.github.com>
Co-authored-by: ShirleyDenkberg <62508050+ShirleyDenkberg@users.noreply.github.com>
Co-authored-by: Jacob Levy <129657918+jlevypaloalto@users.noreply.github.com>
Co-authored-by: Judah Schwartz <JudahSchwartz@users.noreply.github.com>
Co-authored-by: content-bot <55035720+content-bot@users.noreply.github.com>
Co-authored-by: GalNakash-RecoLabs <71227802+GalNakash-RecoLabs@users.noreply.github.com>
Co-authored-by: GalNakash-RecoLabs <GalNakash-RecoLabs@users.noreply.github.com>
Co-authored-by: samuelFain <65926551+samuelFain@users.noreply.github.com>
Co-authored-by: Yehuda Rosenberg <90599084+RosenbergYehuda@users.noreply.github.com>
Co-authored-by: Shachar Kidor <82749224+ShacharKidor@users.noreply.github.com>
Co-authored-by: Shahaf Ben Yakir <44666568+ShahafBenYakir@users.noreply.github.com>
Co-authored-by: Konrad Urdahl Halnum <konrad@mnemonic.no>
Co-authored-by: merit-maita <49760643+merit-maita@users.noreply.github.com>
Co-authored-by: eepstain <116078117+eepstain@users.noreply.github.com>
Co-authored-by: Adi Daud <46249224+adi88d@users.noreply.github.com>
Co-authored-by: Dean Arbel <darbel@paloaltonetworks.com>
Co-authored-by: omerKarkKatz <95565843+omerKarkKatz@users.noreply.github.com>
Co-authored-by: Adi Peretz <130285835+AdiPeret@users.noreply.github.com>
Co-authored-by: David Binyamin <47333909+davidbinyamin@users.noreply.github.com>
Co-authored-by: sbenyakir <shahaf.benyakir@demisto.com>
Co-authored-by: Yonatan Roth <76961496+yonatan-roth@users.noreply.github.com>
Co-authored-by: Israel Lappe <79846863+ilappe@users.noreply.github.com>
Co-authored-by: cweltPA <129675344+cweltPA@users.noreply.github.com>
Co-authored-by: meichlerpanw <meichler@paloaltonetworks.com>
Co-authored-by: maimorag <mmorag@paloaltonetworks.com>
Co-authored-by: sapir shuker <49246861+sapirshuker@users.noreply.github.com>
Co-authored-by: sapirshuker <sshuker@paloaltonetworks.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
4 participants