import json, os, sys, urllib.request, urllib.parse, urllib.error MUTATION = ( "mutation AlertTriggerActions($id: String!, $verdict: AnalystVerdict!) {" " alertTriggerActions(" " filter: { or: [ { and: [ { fieldId: \"id\", stringEqual: { value: $id } } ] } ] }," " actions: [ { id: \"S1/alert/analystVerdictUpdate\", payload: { analystVerdict: { value: $verdict } } } ]" " ) { __typename ... on ActionsTriggered { actions { actionId alertCount" " success { id } failure { id errorType errorMessage } skip { id } } } } }" ) def request(method, url, headers, body=None): data = json.dumps(body).encode("utf-8") if body is not None else None req = urllib.request.Request(url, data=data, headers=headers, method=method) with urllib.request.urlopen(req, timeout=30) as resp: raw = resp.read() return json.loads(raw) if raw else {} def main(): secrets = json.loads(os.environ.get("INTEGRATION_SECRETS", "{}")) inputs = json.loads(os.environ.get("INTEGRATION_INPUTS", "{}")) base = secrets.get("url", "").rstrip("/") + "/web/api/v2.1" headers = { "Authorization": "ApiToken " + secrets.get("api_token", ""), "Accept": "application/json", "Content-Type": "application/json", } variables = {"id": inputs.get("alert_id"), "verdict": inputs.get("analyst_verdict")} body = {"query": MUTATION, "variables": variables} print(json.dumps(request("POST", base + "/unifiedalerts/graphql", headers, body))) try: main() except urllib.error.HTTPError as e: print(json.dumps({"error": "HTTP " + str(e.code), "detail": e.read().decode("utf-8", "replace")})) sys.exit(1) except Exception as e: print(json.dumps({"error": str(e)})) sys.exit(1)