IBM QRadar SOAR

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Generic Email Parsing Script-missing code

    Posted Mon June 03, 2019 06:36 AM
    My question is with regards to the Generic Email Parsing Script available on the app exchange:
    https://exchange.xforce.ibmcloud.com/hub/extension/4ba70106b6f2dfa77cb1e3c921db7ff5

    The GenericEmailScript.res file version 1.0.1 seems to be missing portions of the script. I'm unable to determine the implication of the missing code. I have highlighted the portion of the impacted line in the attached file. It is the 11th displayed line in the image below, but in the actual script to find the location in question you may Ctrl + f for ""script_text": "import re\n\n". What is the missing code after '"import re'? Is there an updated script somewhere?
    -Thanks
    Missing code section highlighted.

    ------------------------------
    Justin Shoemaker
    ------------------------------


  • 2.  RE: Generic Email Parsing Script-missing code

    Posted Fri June 07, 2019 10:10 AM
    All the code is in there mate - You can see functions being defined as well. If you are having issue's I'd pull the latest RES file from their github.

    ------------------------------
    Nathan Getty
    ------------------------------