2017-01-26 00:37:23 +01:00
|
|
|
# Webhooks for external integrations.
|
2017-11-16 00:43:10 +01:00
|
|
|
from django.http import HttpRequest, HttpResponse
|
|
|
|
|
2020-08-20 00:32:15 +02:00
|
|
|
from zerver.decorator import webhook_view
|
2019-02-02 23:53:55 +01:00
|
|
|
from zerver.lib.response import json_success
|
2023-08-12 09:34:31 +02:00
|
|
|
from zerver.lib.typed_endpoint import WebhookPayload, typed_endpoint
|
|
|
|
from zerver.lib.validator import WildValue, check_string
|
2018-03-16 22:53:50 +01:00
|
|
|
from zerver.lib.webhooks.common import check_send_webhook_message
|
2018-11-01 21:23:48 +01:00
|
|
|
from zerver.models import MAX_TOPIC_NAME_LENGTH, UserProfile
|
2017-01-26 00:37:23 +01:00
|
|
|
|
2019-04-17 03:31:56 +02:00
|
|
|
MESSAGE_TEMPLATE = """
|
|
|
|
Splunk alert from saved search:
|
|
|
|
* **Search**: [{search}]({link})
|
|
|
|
* **Host**: {host}
|
|
|
|
* **Source**: `{source}`
|
|
|
|
* **Raw**: `{raw}`
|
|
|
|
""".strip()
|
|
|
|
|
2021-02-12 08:19:30 +01:00
|
|
|
|
2021-02-12 08:20:45 +01:00
|
|
|
@webhook_view("Splunk")
|
2023-08-12 09:34:31 +02:00
|
|
|
@typed_endpoint
|
2021-02-12 08:19:30 +01:00
|
|
|
def api_splunk_webhook(
|
|
|
|
request: HttpRequest,
|
|
|
|
user_profile: UserProfile,
|
2023-08-12 09:34:31 +02:00
|
|
|
*,
|
|
|
|
payload: WebhookPayload[WildValue],
|
2021-02-12 08:19:30 +01:00
|
|
|
) -> HttpResponse:
|
2017-01-26 00:37:23 +01:00
|
|
|
# use default values if expected data is not provided
|
2022-06-23 16:20:27 +02:00
|
|
|
search_name = payload.get("search_name", "Missing search_name").tame(check_string)
|
|
|
|
results_link = payload.get("results_link", "Missing results_link").tame(check_string)
|
|
|
|
host = payload.get("result", {}).get("host", "Missing host").tame(check_string)
|
|
|
|
source = payload.get("result", {}).get("source", "Missing source").tame(check_string)
|
|
|
|
raw = payload.get("result", {}).get("_raw", "Missing _raw").tame(check_string)
|
2017-01-26 00:37:23 +01:00
|
|
|
|
2018-03-16 22:53:50 +01:00
|
|
|
# for the default topic, use search name but truncate if too long
|
2018-11-01 21:23:48 +01:00
|
|
|
if len(search_name) >= MAX_TOPIC_NAME_LENGTH:
|
2020-06-09 00:25:09 +02:00
|
|
|
topic = f"{search_name[:(MAX_TOPIC_NAME_LENGTH - 3)]}..."
|
2018-03-16 22:53:50 +01:00
|
|
|
else:
|
|
|
|
topic = search_name
|
2017-01-26 00:37:23 +01:00
|
|
|
|
|
|
|
# construct the message body
|
2019-04-17 03:31:56 +02:00
|
|
|
body = MESSAGE_TEMPLATE.format(
|
2021-02-12 08:19:30 +01:00
|
|
|
search=search_name,
|
|
|
|
link=results_link,
|
|
|
|
host=host,
|
|
|
|
source=source,
|
|
|
|
raw=raw,
|
2019-04-17 03:31:56 +02:00
|
|
|
)
|
2017-01-26 00:37:23 +01:00
|
|
|
|
|
|
|
# send the message
|
2018-03-16 22:53:50 +01:00
|
|
|
check_send_webhook_message(request, user_profile, topic, body)
|
2017-01-26 00:37:23 +01:00
|
|
|
|
2022-01-31 13:44:02 +01:00
|
|
|
return json_success(request)
|