New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Azure Sentinel] Fix first fetch #31058
Conversation
|
||
if not raw_incidents: | ||
# if we don't have any raw incidents, we want to keep the last incident id and update the last_created_time to now | ||
latest_created_time = datetime.utcnow() |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
if last created time exists(so it is not 0) shouldn't we just preserve it and not override it with now?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
You right, we can keep the old time.
The latest_created_time always exist so we can delete this line.
The only change is to continue to fetch by timestamp if the latest incident number is 0.
Related Issues
fixes: https://jira-dc.paloaltonetworks.com/browse/XSUP-29015
Description
last_incident_number
is 0 or None, beacuse it means that no incidents were fetched.