IBM QRadar SOAR

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  How to access timer data from script/API

    Posted Fri May 15, 2020 03:41 PM
    Hi Everyone,

    First off, apologies if I'm posting in the wrong group/area first "timer" (no pun intended) here!

    I'm looking for some guidance on how to access timer data for a custom boolean field I created that I'm tracking time changes on and is manipulated via two Menu Item rules that essentially set the field state to on/off (true/false).

    While trying to enumerate a sample incident object's dictionary keys I came across the property incident.timer_field_summarized_incident_data - seems like what I'm looking for but it doesn't contain any data. I tried closing out the incident to see if the data wouldn't be populated until incident closure, but this doesn't seem to be the case.

    When looking into the boolean field under incident.properties it only appears to contain the boolean result (True or False - also Unknown since it's optional currently) and doesn't seem to contain the timer data.

    I'm trying to access the timer data for the total time spent while the field is set to true - any help is greatly appreciated!

    ------------------------------
    Jason Jemmott
    ------------------------------


  • 2.  RE: How to access timer data from script/API

    Posted Wed May 20, 2020 09:44 AM
    This was answered here : Link

    ------------------------------
    BENOIT ROSTAGNI
    ------------------------------