when running a query through workflow below error is populated. This stopped working in production environment. No changes were applied.
Unable to run the pre-processing script for Function 'QRadar Search' from Workflow 'Qradar : Extract Logon IP, Logon Location & User Principle Name' due to the following errors: Invalid field name: qradar_query_param2
INPUT QUERY: SELECT QIDNAME(qid) as 'EventName',"Logon IP" as 'LogonIP',"Logon Location" as 'LogonLocation',"User Principal Name" as 'Username' FROM events WHERE INOFFENSE(%param1%) GROUP BY "EventName" LAST %param2% DAYS
Pre-Process Script
inputs.qradar_query_param1 = incident.properties.qradar_id
if rule.properties.days:
inputs.qradar_query_param2 = str(rule.properties.days)
else:
inputs.qradar_query_param2 = 30
work arounds done:
adjusted preporcess script :
inputs.qradar_query_param1 = incident.properties.qradar_id
(removed other config)
input field adjusted SELECT QIDNAME(qid) as 'EventName',"Logon IP" as 'LogonIP',"Logon Location" as 'LogonLocation',"User Principal Name" as 'Username' FROM events WHERE INOFFENSE(%param1%) GROUP BY "EventName" LAST 3 DAYS
any inputs on this ? could not understand where the issue is
------------------------------
Vijay Reddy
------------------------------