Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Status
Related Issues
fixes: link to the issue
Description
QRadar's TPB has been failing nightly due to the hard-coded offense ID used for two of it's jobs. Since Qradar offenses expire, the TPB needed to be updated every time it did. This PR focuses on using a dynamic offense ID retrieved in the TPB's runtime.
Changes:
1. Removed hard-coded offense_id from the playbook's inputs:
2. Changed the query in the
Get events with polling custom query
job from using the offense_id to a generic query.Before:
After:
3. Changed the offense_id field in the
Get offense with polling
job from the hard-coded input to a dynamic ID taken from the output of the!qradar-offenses-list
command.Before:
After:
Must have