2017-01-26 00:37:23 +01:00
|
|
|
# Webhooks for external integrations.
|
2019-02-02 23:53:55 +01:00
|
|
|
from typing import Any, Dict
|
2017-11-16 00:43:10 +01:00
|
|
|
|
|
|
|
from django.http import HttpRequest, HttpResponse
|
|
|
|
|
2017-10-31 04:25:48 +01:00
|
|
|
from zerver.decorator import api_key_only_webhook_view
|
|
|
|
from zerver.lib.request import REQ, has_request_variables
|
2019-02-02 23:53:55 +01:00
|
|
|
from zerver.lib.response import json_success
|
2018-03-16 22:53:50 +01:00
|
|
|
from zerver.lib.webhooks.common import check_send_webhook_message
|
2018-11-01 21:23:48 +01:00
|
|
|
from zerver.models import MAX_TOPIC_NAME_LENGTH, UserProfile
|
2017-01-26 00:37:23 +01:00
|
|
|
|
|
|
|
@api_key_only_webhook_view('Splunk')
|
|
|
|
@has_request_variables
|
2017-12-24 15:55:02 +01:00
|
|
|
def api_splunk_webhook(request: HttpRequest, user_profile: UserProfile,
|
2018-03-16 22:53:50 +01:00
|
|
|
payload: Dict[str, Any]=REQ(argument_type='body')) -> HttpResponse:
|
2017-01-26 00:37:23 +01:00
|
|
|
|
|
|
|
# use default values if expected data is not provided
|
|
|
|
search_name = payload.get('search_name', 'Missing search_name')
|
|
|
|
results_link = payload.get('results_link', 'Missing results_link')
|
|
|
|
host = payload.get('result', {}).get('host', 'Missing host')
|
|
|
|
source = payload.get('result', {}).get('source', 'Missing source')
|
|
|
|
raw = payload.get('result', {}).get('_raw', 'Missing _raw')
|
|
|
|
|
2018-03-16 22:53:50 +01:00
|
|
|
# for the default topic, use search name but truncate if too long
|
2018-11-01 21:23:48 +01:00
|
|
|
if len(search_name) >= MAX_TOPIC_NAME_LENGTH:
|
|
|
|
topic = "{}...".format(search_name[:(MAX_TOPIC_NAME_LENGTH - 3)])
|
2018-03-16 22:53:50 +01:00
|
|
|
else:
|
|
|
|
topic = search_name
|
2017-01-26 00:37:23 +01:00
|
|
|
|
|
|
|
# construct the message body
|
|
|
|
body = "Splunk alert from saved search"
|
|
|
|
body_template = ('\n[{search}]({link})\nhost: {host}'
|
|
|
|
'\nsource: {source}\n\nraw: {raw}')
|
|
|
|
body += body_template.format(search = search_name, link = results_link,
|
|
|
|
host = host, source = source, raw = raw)
|
|
|
|
|
|
|
|
# send the message
|
2018-03-16 22:53:50 +01:00
|
|
|
check_send_webhook_message(request, user_profile, topic, body)
|
2017-01-26 00:37:23 +01:00
|
|
|
|
|
|
|
return json_success()
|