first commit
Security: Sync from Public / sync-from-public (push) Has been cancelled
Test: Benchmark Nightly / build (push) Has been cancelled
Test: Benchmark Nightly / Notify Cats on failure (push) Has been cancelled
CI: Python / Checks (push) Has been cancelled
Test: Evals Python / Workflow Comparison Python (push) Has been cancelled
Util: Check Docs URLs / check-docs-urls (push) Has been cancelled
Test: Visual Storybook / Cloudflare Pages (push) Has been cancelled
Test: E2E Performance / build-and-test-performance (push) Has been cancelled
Test: Workflows Nightly / Run Workflow Tests (push) Has been cancelled
Util: Cleanup CI Docker Images / Delete stale CI images (push) Has been cancelled
Test: Benchmark Destroy Env / build (push) Has been cancelled
Util: Update Node Popularity / update-popularity (push) Has been cancelled
Test: E2E Coverage Weekly / Coverage Tests (push) Has been cancelled
Security: Sync from Public / sync-from-public (push) Has been cancelled
Test: Benchmark Nightly / build (push) Has been cancelled
Test: Benchmark Nightly / Notify Cats on failure (push) Has been cancelled
CI: Python / Checks (push) Has been cancelled
Test: Evals Python / Workflow Comparison Python (push) Has been cancelled
Util: Check Docs URLs / check-docs-urls (push) Has been cancelled
Test: Visual Storybook / Cloudflare Pages (push) Has been cancelled
Test: E2E Performance / build-and-test-performance (push) Has been cancelled
Test: Workflows Nightly / Run Workflow Tests (push) Has been cancelled
Util: Cleanup CI Docker Images / Delete stale CI images (push) Has been cancelled
Test: Benchmark Destroy Env / build (push) Has been cancelled
Util: Update Node Popularity / update-popularity (push) Has been cancelled
Test: E2E Coverage Weekly / Coverage Tests (push) Has been cancelled
This commit is contained in:
@@ -0,0 +1,18 @@
|
||||
{
|
||||
"node": "n8n-nodes-base.elasticSecurity",
|
||||
"nodeVersion": "1.0",
|
||||
"codexVersion": "1.0",
|
||||
"categories": ["Development"],
|
||||
"resources": {
|
||||
"credentialDocumentation": [
|
||||
{
|
||||
"url": "https://docs.n8n.io/integrations/builtin/credentials/elasticsecurity/"
|
||||
}
|
||||
],
|
||||
"primaryDocumentation": [
|
||||
{
|
||||
"url": "https://docs.n8n.io/integrations/builtin/app-nodes/n8n-nodes-base.elasticsecurity/"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,540 @@
|
||||
import type {
|
||||
IExecuteFunctions,
|
||||
IDataObject,
|
||||
ILoadOptionsFunctions,
|
||||
INodeExecutionData,
|
||||
INodePropertyOptions,
|
||||
INodeType,
|
||||
INodeTypeDescription,
|
||||
} from 'n8n-workflow';
|
||||
import { NodeConnectionTypes, NodeOperationError } from 'n8n-workflow';
|
||||
|
||||
import {
|
||||
caseCommentFields,
|
||||
caseCommentOperations,
|
||||
caseFields,
|
||||
caseOperations,
|
||||
caseTagFields,
|
||||
caseTagOperations,
|
||||
connectorFields,
|
||||
connectorOperations,
|
||||
} from './descriptions';
|
||||
import {
|
||||
elasticSecurityApiRequest,
|
||||
getConnector,
|
||||
getVersion,
|
||||
handleListing,
|
||||
throwOnEmptyUpdate,
|
||||
} from './GenericFunctions';
|
||||
import type { Connector, ConnectorCreatePayload, ConnectorType } from './types';
|
||||
|
||||
export class ElasticSecurity implements INodeType {
|
||||
description: INodeTypeDescription = {
|
||||
displayName: 'Elastic Security',
|
||||
name: 'elasticSecurity',
|
||||
icon: 'file:elasticSecurity.svg',
|
||||
group: ['transform'],
|
||||
version: 1,
|
||||
subtitle: '={{$parameter["operation"] + ": " + $parameter["resource"]}}',
|
||||
description: 'Consume the Elastic Security API',
|
||||
schemaPath: 'Elastic/ElasticSecurity',
|
||||
defaults: {
|
||||
name: 'Elastic Security',
|
||||
},
|
||||
usableAsTool: true,
|
||||
inputs: [NodeConnectionTypes.Main],
|
||||
outputs: [NodeConnectionTypes.Main],
|
||||
credentials: [
|
||||
{
|
||||
name: 'elasticSecurityApi',
|
||||
required: true,
|
||||
},
|
||||
],
|
||||
properties: [
|
||||
{
|
||||
displayName: 'Resource',
|
||||
name: 'resource',
|
||||
noDataExpression: true,
|
||||
type: 'options',
|
||||
options: [
|
||||
{
|
||||
name: 'Case',
|
||||
value: 'case',
|
||||
},
|
||||
{
|
||||
name: 'Case Comment',
|
||||
value: 'caseComment',
|
||||
},
|
||||
{
|
||||
name: 'Case Tag',
|
||||
value: 'caseTag',
|
||||
},
|
||||
{
|
||||
name: 'Connector',
|
||||
value: 'connector',
|
||||
},
|
||||
],
|
||||
default: 'case',
|
||||
},
|
||||
...caseOperations,
|
||||
...caseFields,
|
||||
...caseCommentOperations,
|
||||
...caseCommentFields,
|
||||
...caseTagOperations,
|
||||
...caseTagFields,
|
||||
...connectorOperations,
|
||||
...connectorFields,
|
||||
],
|
||||
};
|
||||
|
||||
methods = {
|
||||
loadOptions: {
|
||||
async getTags(this: ILoadOptionsFunctions): Promise<INodePropertyOptions[]> {
|
||||
const tags = (await elasticSecurityApiRequest.call(this, 'GET', '/cases/tags')) as string[];
|
||||
return tags.map((tag) => ({ name: tag, value: tag }));
|
||||
},
|
||||
|
||||
async getConnectors(this: ILoadOptionsFunctions): Promise<INodePropertyOptions[]> {
|
||||
const endpoint = '/cases/configure/connectors/_find';
|
||||
const connectors = (await elasticSecurityApiRequest.call(
|
||||
this,
|
||||
'GET',
|
||||
endpoint,
|
||||
)) as Connector[];
|
||||
return connectors.map(({ name, id }) => ({ name, value: id }));
|
||||
},
|
||||
},
|
||||
};
|
||||
|
||||
async execute(this: IExecuteFunctions): Promise<INodeExecutionData[][]> {
|
||||
const items = this.getInputData();
|
||||
const returnData: INodeExecutionData[] = [];
|
||||
|
||||
const resource = this.getNodeParameter('resource', 0);
|
||||
const operation = this.getNodeParameter('operation', 0);
|
||||
|
||||
let responseData;
|
||||
|
||||
for (let i = 0; i < items.length; i++) {
|
||||
try {
|
||||
if (resource === 'case') {
|
||||
// **********************************************************************
|
||||
// case
|
||||
// **********************************************************************
|
||||
|
||||
if (operation === 'create') {
|
||||
// ----------------------------------------
|
||||
// case: create
|
||||
// ----------------------------------------
|
||||
|
||||
// https://www.elastic.co/guide/en/security/current/cases-api-create.html
|
||||
|
||||
const body = {
|
||||
title: this.getNodeParameter('title', i),
|
||||
connector: {},
|
||||
owner: 'securitySolution',
|
||||
description: '',
|
||||
tags: [], // set via `caseTag: add` but must be present
|
||||
settings: {
|
||||
syncAlerts: this.getNodeParameter('additionalFields.syncAlerts', i, false),
|
||||
},
|
||||
} as IDataObject;
|
||||
|
||||
const connectorId = this.getNodeParameter('connectorId', i) as ConnectorType;
|
||||
|
||||
const {
|
||||
id: fetchedId,
|
||||
name: fetchedName,
|
||||
type: fetchedType,
|
||||
} = await getConnector.call(this, connectorId);
|
||||
|
||||
const selectedConnectorType = this.getNodeParameter(
|
||||
'connectorType',
|
||||
i,
|
||||
) as ConnectorType;
|
||||
|
||||
if (fetchedType !== selectedConnectorType) {
|
||||
throw new NodeOperationError(
|
||||
this.getNode(),
|
||||
'Connector Type does not match the type of the connector in Connector Name',
|
||||
{ itemIndex: i },
|
||||
);
|
||||
}
|
||||
|
||||
const connector = {
|
||||
id: fetchedId,
|
||||
name: fetchedName,
|
||||
type: fetchedType,
|
||||
fields: {},
|
||||
};
|
||||
|
||||
if (selectedConnectorType === '.jira') {
|
||||
connector.fields = {
|
||||
issueType: this.getNodeParameter('issueType', i),
|
||||
priority: this.getNodeParameter('priority', i),
|
||||
parent: null, // required but unimplemented
|
||||
};
|
||||
} else if (selectedConnectorType === '.servicenow') {
|
||||
connector.fields = {
|
||||
urgency: this.getNodeParameter('urgency', i),
|
||||
severity: this.getNodeParameter('severity', i),
|
||||
impact: this.getNodeParameter('impact', i),
|
||||
category: this.getNodeParameter('category', i),
|
||||
subcategory: null, // required but unimplemented
|
||||
};
|
||||
} else if (selectedConnectorType === '.resilient') {
|
||||
const rawIssueTypes = this.getNodeParameter('issueTypes', i) as string;
|
||||
connector.fields = {
|
||||
issueTypes: rawIssueTypes.split(',').map(Number),
|
||||
severityCode: this.getNodeParameter('severityCode', i) as number,
|
||||
incidentTypes: null, // required but undocumented
|
||||
};
|
||||
}
|
||||
|
||||
body.connector = connector;
|
||||
|
||||
const {
|
||||
syncAlerts, // ignored because already set
|
||||
...rest
|
||||
} = this.getNodeParameter('additionalFields', i);
|
||||
|
||||
if (Object.keys(rest).length) {
|
||||
Object.assign(body, rest);
|
||||
}
|
||||
|
||||
responseData = await elasticSecurityApiRequest.call(this, 'POST', '/cases', body);
|
||||
} else if (operation === 'delete') {
|
||||
// ----------------------------------------
|
||||
// case: delete
|
||||
// ----------------------------------------
|
||||
|
||||
// https://www.elastic.co/guide/en/security/current/cases-api-delete-case.html
|
||||
|
||||
const caseId = this.getNodeParameter('caseId', i);
|
||||
await elasticSecurityApiRequest.call(this, 'DELETE', `/cases?ids=["${caseId}"]`);
|
||||
responseData = { success: true };
|
||||
} else if (operation === 'get') {
|
||||
// ----------------------------------------
|
||||
// case: get
|
||||
// ----------------------------------------
|
||||
|
||||
// https://www.elastic.co/guide/en/security/current/cases-api-get-case.html
|
||||
|
||||
const caseId = this.getNodeParameter('caseId', i);
|
||||
responseData = await elasticSecurityApiRequest.call(this, 'GET', `/cases/${caseId}`);
|
||||
} else if (operation === 'getAll') {
|
||||
// ----------------------------------------
|
||||
// case: getAll
|
||||
// ----------------------------------------
|
||||
|
||||
// https://www.elastic.co/guide/en/security/current/cases-api-find-cases.html
|
||||
|
||||
const qs = {} as IDataObject;
|
||||
const { tags, status } = this.getNodeParameter('filters', i) as IDataObject & {
|
||||
tags: string[];
|
||||
status: string;
|
||||
};
|
||||
const sortOptions = this.getNodeParameter('sortOptions', i) as IDataObject;
|
||||
|
||||
qs.sortField = sortOptions.sortField ?? 'createdAt';
|
||||
qs.sortOrder = sortOptions.sortOrder ?? 'asc';
|
||||
|
||||
if (status) {
|
||||
qs.status = status;
|
||||
}
|
||||
|
||||
if (tags?.length) {
|
||||
qs.tags = tags.join(',');
|
||||
}
|
||||
|
||||
responseData = await handleListing.call(this, 'GET', '/cases/_find', {}, qs);
|
||||
} else if (operation === 'getStatus') {
|
||||
// ----------------------------------------
|
||||
// case: getStatus
|
||||
// ----------------------------------------
|
||||
|
||||
// https://www.elastic.co/guide/en/security/current/cases-api-get-status.html
|
||||
|
||||
responseData = await elasticSecurityApiRequest.call(this, 'GET', '/cases/status');
|
||||
} else if (operation === 'update') {
|
||||
// ----------------------------------------
|
||||
// case: update
|
||||
// ----------------------------------------
|
||||
|
||||
// https://www.elastic.co/guide/en/security/current/cases-api-update.html
|
||||
|
||||
const caseId = this.getNodeParameter('caseId', i);
|
||||
|
||||
const body = {} as IDataObject;
|
||||
const updateFields = this.getNodeParameter('updateFields', i);
|
||||
|
||||
if (!Object.keys(updateFields).length) {
|
||||
throwOnEmptyUpdate.call(this, resource);
|
||||
}
|
||||
|
||||
const { syncAlerts, ...rest } = updateFields;
|
||||
|
||||
Object.assign(body, {
|
||||
cases: [
|
||||
{
|
||||
id: caseId,
|
||||
version: await getVersion.call(this, `/cases/${caseId}`),
|
||||
...(syncAlerts && { settings: { syncAlerts } }),
|
||||
...rest,
|
||||
},
|
||||
],
|
||||
});
|
||||
|
||||
responseData = await elasticSecurityApiRequest.call(this, 'PATCH', '/cases', body);
|
||||
}
|
||||
} else if (resource === 'caseTag') {
|
||||
// **********************************************************************
|
||||
// caseTag
|
||||
// **********************************************************************
|
||||
|
||||
if (operation === 'add') {
|
||||
// ----------------------------------------
|
||||
// caseTag: add
|
||||
// ----------------------------------------
|
||||
|
||||
// https://www.elastic.co/guide/en/security/current/cases-api-create.html
|
||||
|
||||
const caseId = this.getNodeParameter('caseId', i);
|
||||
|
||||
const { title, connector, owner, description, settings, tags } =
|
||||
await elasticSecurityApiRequest.call(this, 'GET', `/cases/${caseId}`);
|
||||
|
||||
const tagToAdd = this.getNodeParameter('tag', i);
|
||||
|
||||
if (tags.includes(tagToAdd)) {
|
||||
throw new NodeOperationError(
|
||||
this.getNode(),
|
||||
`Cannot add tag "${tagToAdd}" to case ID ${caseId} because this case already has this tag.`,
|
||||
{ itemIndex: i },
|
||||
);
|
||||
}
|
||||
|
||||
const body = {};
|
||||
|
||||
Object.assign(body, {
|
||||
cases: [
|
||||
{
|
||||
id: caseId,
|
||||
title,
|
||||
connector,
|
||||
owner,
|
||||
description,
|
||||
settings,
|
||||
version: await getVersion.call(this, `/cases/${caseId}`),
|
||||
tags: [...tags, tagToAdd],
|
||||
},
|
||||
],
|
||||
});
|
||||
|
||||
responseData = await elasticSecurityApiRequest.call(this, 'PATCH', '/cases', body);
|
||||
} else if (operation === 'remove') {
|
||||
// https://www.elastic.co/guide/en/security/current/cases-api-update.html
|
||||
|
||||
const caseId = this.getNodeParameter('caseId', i);
|
||||
const tagToRemove = this.getNodeParameter('tag', i) as string;
|
||||
|
||||
const { title, connector, owner, description, settings, tags } =
|
||||
(await elasticSecurityApiRequest.call(
|
||||
this,
|
||||
'GET',
|
||||
`/cases/${caseId}`,
|
||||
)) as IDataObject & { tags: string[] };
|
||||
|
||||
if (!tags.includes(tagToRemove)) {
|
||||
throw new NodeOperationError(
|
||||
this.getNode(),
|
||||
`Cannot remove tag "${tagToRemove}" from case ID ${caseId} because this case does not have this tag.`,
|
||||
{ itemIndex: i },
|
||||
);
|
||||
}
|
||||
|
||||
const body = {};
|
||||
|
||||
Object.assign(body, {
|
||||
cases: [
|
||||
{
|
||||
id: caseId,
|
||||
title,
|
||||
connector,
|
||||
owner,
|
||||
description,
|
||||
settings,
|
||||
version: await getVersion.call(this, `/cases/${caseId}`),
|
||||
tags: tags.filter((tag) => tag !== tagToRemove),
|
||||
},
|
||||
],
|
||||
});
|
||||
|
||||
responseData = await elasticSecurityApiRequest.call(this, 'PATCH', '/cases', body);
|
||||
}
|
||||
} else if (resource === 'caseComment') {
|
||||
// **********************************************************************
|
||||
// caseComment
|
||||
// **********************************************************************
|
||||
|
||||
if (operation === 'add') {
|
||||
// ----------------------------------------
|
||||
// caseComment: add
|
||||
// ----------------------------------------
|
||||
|
||||
// https://www.elastic.co/guide/en/security/current/cases-api-add-comment.html
|
||||
|
||||
const simple = this.getNodeParameter('simple', i) as boolean;
|
||||
|
||||
const additionalFields = this.getNodeParameter('additionalFields', i);
|
||||
|
||||
const body = {
|
||||
comment: this.getNodeParameter('comment', i),
|
||||
type: 'user',
|
||||
owner: additionalFields.owner || 'securitySolution',
|
||||
} as IDataObject;
|
||||
|
||||
const caseId = this.getNodeParameter('caseId', i);
|
||||
const endpoint = `/cases/${caseId}/comments`;
|
||||
responseData = await elasticSecurityApiRequest.call(this, 'POST', endpoint, body);
|
||||
|
||||
if (simple) {
|
||||
const { comments } = responseData;
|
||||
responseData = comments[comments.length - 1];
|
||||
}
|
||||
} else if (operation === 'get') {
|
||||
// ----------------------------------------
|
||||
// caseComment: get
|
||||
// ----------------------------------------
|
||||
|
||||
// https://www.elastic.co/guide/en/security/current/cases-api-get-comment.html
|
||||
|
||||
const caseId = this.getNodeParameter('caseId', i);
|
||||
const commentId = this.getNodeParameter('commentId', i);
|
||||
|
||||
const endpoint = `/cases/${caseId}/comments/${commentId}`;
|
||||
responseData = await elasticSecurityApiRequest.call(this, 'GET', endpoint);
|
||||
} else if (operation === 'getAll') {
|
||||
// ----------------------------------------
|
||||
// caseComment: getAll
|
||||
// ----------------------------------------
|
||||
|
||||
// https://www.elastic.co/guide/en/security/current/cases-api-get-all-case-comments.html
|
||||
|
||||
const caseId = this.getNodeParameter('caseId', i);
|
||||
|
||||
const endpoint = `/cases/${caseId}/comments`;
|
||||
responseData = await handleListing.call(this, 'GET', endpoint);
|
||||
} else if (operation === 'remove') {
|
||||
// ----------------------------------------
|
||||
// caseComment: remove
|
||||
// ----------------------------------------
|
||||
|
||||
// https://www.elastic.co/guide/en/security/current/cases-api-delete-comment.html
|
||||
|
||||
const caseId = this.getNodeParameter('caseId', i);
|
||||
const commentId = this.getNodeParameter('commentId', i);
|
||||
|
||||
const endpoint = `/cases/${caseId}/comments/${commentId}`;
|
||||
await elasticSecurityApiRequest.call(this, 'DELETE', endpoint);
|
||||
responseData = { success: true };
|
||||
} else if (operation === 'update') {
|
||||
// ----------------------------------------
|
||||
// caseComment: update
|
||||
// ----------------------------------------
|
||||
|
||||
// https://www.elastic.co/guide/en/security/current/cases-api-update-comment.html
|
||||
|
||||
const simple = this.getNodeParameter('simple', i) as boolean;
|
||||
const caseId = this.getNodeParameter('caseId', i);
|
||||
const commentId = this.getNodeParameter('commentId', i);
|
||||
|
||||
const body = {
|
||||
comment: this.getNodeParameter('comment', i),
|
||||
id: commentId,
|
||||
type: 'user',
|
||||
owner: 'securitySolution',
|
||||
version: await getVersion.call(this, `/cases/${caseId}/comments/${commentId}`),
|
||||
} as IDataObject;
|
||||
|
||||
const patchEndpoint = `/cases/${caseId}/comments`;
|
||||
responseData = await elasticSecurityApiRequest.call(this, 'PATCH', patchEndpoint, body);
|
||||
|
||||
if (simple) {
|
||||
const { comments } = responseData;
|
||||
responseData = comments[comments.length - 1];
|
||||
}
|
||||
}
|
||||
} else if (resource === 'connector') {
|
||||
if (operation === 'create') {
|
||||
// ----------------------------------------
|
||||
// connector: create
|
||||
// ----------------------------------------
|
||||
|
||||
// https://www.elastic.co/guide/en/security/current/register-connector.html
|
||||
|
||||
const connectorType = this.getNodeParameter('connectorType', i) as ConnectorType;
|
||||
|
||||
const body: ConnectorCreatePayload = {
|
||||
connector_type_id: connectorType,
|
||||
name: this.getNodeParameter('name', i) as string,
|
||||
};
|
||||
|
||||
if (connectorType === '.jira') {
|
||||
body.config = {
|
||||
apiUrl: this.getNodeParameter('apiUrl', i) as string,
|
||||
projectKey: this.getNodeParameter('projectKey', i) as string,
|
||||
};
|
||||
body.secrets = {
|
||||
email: this.getNodeParameter('email', i) as string,
|
||||
apiToken: this.getNodeParameter('apiToken', i) as string,
|
||||
};
|
||||
} else if (connectorType === '.resilient') {
|
||||
body.config = {
|
||||
apiUrl: this.getNodeParameter('apiUrl', i) as string,
|
||||
orgId: this.getNodeParameter('orgId', i) as string,
|
||||
};
|
||||
body.secrets = {
|
||||
apiKeyId: this.getNodeParameter('apiKeyId', i) as string,
|
||||
apiKeySecret: this.getNodeParameter('apiKeySecret', i) as string,
|
||||
};
|
||||
} else if (connectorType === '.servicenow') {
|
||||
body.config = {
|
||||
apiUrl: this.getNodeParameter('apiUrl', i) as string,
|
||||
};
|
||||
body.secrets = {
|
||||
username: this.getNodeParameter('username', i) as string,
|
||||
password: this.getNodeParameter('password', i) as string,
|
||||
};
|
||||
}
|
||||
|
||||
responseData = await elasticSecurityApiRequest.call(
|
||||
this,
|
||||
'POST',
|
||||
'/actions/connector',
|
||||
body,
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
const executionData = this.helpers.constructExecutionMetaData(
|
||||
this.helpers.returnJsonArray(responseData as IDataObject[]),
|
||||
{ itemData: { item: i } },
|
||||
);
|
||||
returnData.push(...executionData);
|
||||
} catch (error) {
|
||||
if (this.continueOnFail()) {
|
||||
const executionErrorData = this.helpers.constructExecutionMetaData(
|
||||
this.helpers.returnJsonArray({ error: error.message }),
|
||||
{ itemData: { item: i } },
|
||||
);
|
||||
returnData.push(...executionErrorData);
|
||||
continue;
|
||||
}
|
||||
throw error;
|
||||
}
|
||||
}
|
||||
|
||||
return [returnData];
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,139 @@
|
||||
import type {
|
||||
IExecuteFunctions,
|
||||
IDataObject,
|
||||
ILoadOptionsFunctions,
|
||||
JsonObject,
|
||||
IRequestOptions,
|
||||
IHttpRequestMethods,
|
||||
} from 'n8n-workflow';
|
||||
import { NodeApiError, NodeOperationError } from 'n8n-workflow';
|
||||
|
||||
import type { Connector, ElasticSecurityApiCredentials } from './types';
|
||||
|
||||
export function tolerateTrailingSlash(baseUrl: string) {
|
||||
return baseUrl.endsWith('/') ? baseUrl.substr(0, baseUrl.length - 1) : baseUrl;
|
||||
}
|
||||
|
||||
export async function elasticSecurityApiRequest(
|
||||
this: IExecuteFunctions | ILoadOptionsFunctions,
|
||||
method: IHttpRequestMethods,
|
||||
endpoint: string,
|
||||
body: IDataObject = {},
|
||||
qs: IDataObject = {},
|
||||
) {
|
||||
const { baseUrl: rawBaseUrl } =
|
||||
await this.getCredentials<ElasticSecurityApiCredentials>('elasticSecurityApi');
|
||||
|
||||
const baseUrl = tolerateTrailingSlash(rawBaseUrl);
|
||||
|
||||
const options: IRequestOptions = {
|
||||
method,
|
||||
body,
|
||||
qs,
|
||||
uri: `${baseUrl}/api${endpoint}`,
|
||||
json: true,
|
||||
};
|
||||
|
||||
if (!Object.keys(body).length) {
|
||||
delete options.body;
|
||||
}
|
||||
|
||||
if (!Object.keys(qs).length) {
|
||||
delete options.qs;
|
||||
}
|
||||
|
||||
try {
|
||||
return await this.helpers.requestWithAuthentication.call(this, 'elasticSecurityApi', options);
|
||||
} catch (error) {
|
||||
if (error?.error?.error === 'Not Acceptable' && error?.error?.message) {
|
||||
error.error.error = `${error.error.error}: ${error.error.message}`;
|
||||
}
|
||||
|
||||
throw new NodeApiError(this.getNode(), error as JsonObject);
|
||||
}
|
||||
}
|
||||
|
||||
export async function elasticSecurityApiRequestAllItems(
|
||||
this: IExecuteFunctions,
|
||||
method: IHttpRequestMethods,
|
||||
endpoint: string,
|
||||
body: IDataObject = {},
|
||||
qs: IDataObject = {},
|
||||
) {
|
||||
let _page = 1;
|
||||
const returnData: IDataObject[] = [];
|
||||
let responseData: any;
|
||||
|
||||
const resource = this.getNodeParameter('resource', 0) as 'case' | 'caseComment';
|
||||
|
||||
do {
|
||||
responseData = await elasticSecurityApiRequest.call(this, method, endpoint, body, qs);
|
||||
_page++;
|
||||
|
||||
const items = resource === 'case' ? responseData.cases : responseData;
|
||||
|
||||
returnData.push(...(items as IDataObject[]));
|
||||
} while (returnData.length < responseData.total);
|
||||
|
||||
return returnData;
|
||||
}
|
||||
|
||||
export async function handleListing(
|
||||
this: IExecuteFunctions,
|
||||
method: IHttpRequestMethods,
|
||||
endpoint: string,
|
||||
body: IDataObject = {},
|
||||
qs: IDataObject = {},
|
||||
) {
|
||||
const returnAll = this.getNodeParameter('returnAll', 0);
|
||||
|
||||
if (returnAll) {
|
||||
return await elasticSecurityApiRequestAllItems.call(this, method, endpoint, body, qs);
|
||||
}
|
||||
|
||||
const responseData = await elasticSecurityApiRequestAllItems.call(
|
||||
this,
|
||||
method,
|
||||
endpoint,
|
||||
body,
|
||||
qs,
|
||||
);
|
||||
const limit = this.getNodeParameter('limit', 0);
|
||||
|
||||
return responseData.slice(0, limit);
|
||||
}
|
||||
|
||||
/**
|
||||
* Retrieve a connector name and type from a connector ID.
|
||||
*
|
||||
* https://www.elastic.co/guide/en/kibana/master/get-connector-api.html
|
||||
*/
|
||||
export async function getConnector(this: IExecuteFunctions, connectorId: string) {
|
||||
const endpoint = `/actions/connector/${connectorId}`;
|
||||
const {
|
||||
id,
|
||||
name,
|
||||
connector_type_id: type,
|
||||
} = (await elasticSecurityApiRequest.call(this, 'GET', endpoint)) as Connector;
|
||||
|
||||
return { id, name, type };
|
||||
}
|
||||
|
||||
export function throwOnEmptyUpdate(this: IExecuteFunctions, resource: string) {
|
||||
throw new NodeOperationError(
|
||||
this.getNode(),
|
||||
`Please enter at least one field to update for the ${resource}`,
|
||||
);
|
||||
}
|
||||
|
||||
export async function getVersion(this: IExecuteFunctions, endpoint: string) {
|
||||
const { version } = (await elasticSecurityApiRequest.call(this, 'GET', endpoint)) as {
|
||||
version?: string;
|
||||
};
|
||||
|
||||
if (!version) {
|
||||
throw new NodeOperationError(this.getNode(), 'Cannot retrieve version for resource');
|
||||
}
|
||||
|
||||
return version;
|
||||
}
|
||||
+95
@@ -0,0 +1,95 @@
|
||||
{
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"assignees": {
|
||||
"type": "array",
|
||||
"items": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"uid": {
|
||||
"type": "string"
|
||||
}
|
||||
}
|
||||
}
|
||||
},
|
||||
"category": {
|
||||
"type": "null"
|
||||
},
|
||||
"connector": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"fields": {
|
||||
"type": "null"
|
||||
},
|
||||
"id": {
|
||||
"type": "string"
|
||||
},
|
||||
"name": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"type": "string"
|
||||
}
|
||||
}
|
||||
},
|
||||
"created_at": {
|
||||
"type": "string"
|
||||
},
|
||||
"created_by": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"profile_uid": {
|
||||
"type": "string"
|
||||
},
|
||||
"username": {
|
||||
"type": "string"
|
||||
}
|
||||
}
|
||||
},
|
||||
"description": {
|
||||
"type": "string"
|
||||
},
|
||||
"external_service": {
|
||||
"type": "null"
|
||||
},
|
||||
"id": {
|
||||
"type": "string"
|
||||
},
|
||||
"owner": {
|
||||
"type": "string"
|
||||
},
|
||||
"settings": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"syncAlerts": {
|
||||
"type": "boolean"
|
||||
}
|
||||
}
|
||||
},
|
||||
"severity": {
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"type": "string"
|
||||
},
|
||||
"tags": {
|
||||
"type": "array",
|
||||
"items": {
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"title": {
|
||||
"type": "string"
|
||||
},
|
||||
"totalAlerts": {
|
||||
"type": "integer"
|
||||
},
|
||||
"totalComment": {
|
||||
"type": "integer"
|
||||
},
|
||||
"version": {
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"version": 1
|
||||
}
|
||||
+285
@@ -0,0 +1,285 @@
|
||||
import type { INodeProperties } from 'n8n-workflow';
|
||||
|
||||
export const caseCommentOperations: INodeProperties[] = [
|
||||
{
|
||||
displayName: 'Operation',
|
||||
name: 'operation',
|
||||
noDataExpression: true,
|
||||
type: 'options',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseComment'],
|
||||
},
|
||||
},
|
||||
options: [
|
||||
{
|
||||
name: 'Add',
|
||||
value: 'add',
|
||||
description: 'Add a comment to a case',
|
||||
action: 'Add a comment to a case',
|
||||
},
|
||||
{
|
||||
name: 'Get',
|
||||
value: 'get',
|
||||
description: 'Get a case comment',
|
||||
action: 'Get a case comment',
|
||||
},
|
||||
{
|
||||
name: 'Get Many',
|
||||
value: 'getAll',
|
||||
description: 'Retrieve many case comments',
|
||||
action: 'Get many case comments',
|
||||
},
|
||||
{
|
||||
name: 'Remove',
|
||||
value: 'remove',
|
||||
description: 'Remove a comment from a case',
|
||||
action: 'Remove a comment from a case',
|
||||
},
|
||||
{
|
||||
name: 'Update',
|
||||
value: 'update',
|
||||
description: 'Update a comment in a case',
|
||||
action: 'Update a comment from a case',
|
||||
},
|
||||
],
|
||||
default: 'add',
|
||||
},
|
||||
];
|
||||
|
||||
export const caseCommentFields: INodeProperties[] = [
|
||||
// ----------------------------------------
|
||||
// caseComment: add
|
||||
// ----------------------------------------
|
||||
{
|
||||
displayName: 'Case ID',
|
||||
name: 'caseId',
|
||||
description: 'ID of the case containing the comment to retrieve',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseComment'],
|
||||
operation: ['add'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Comment',
|
||||
name: 'comment',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseComment'],
|
||||
operation: ['add'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Simplify',
|
||||
name: 'simple',
|
||||
type: 'boolean',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseComment'],
|
||||
operation: ['add'],
|
||||
},
|
||||
},
|
||||
default: true,
|
||||
description: 'Whether to return a simplified version of the response instead of the raw data',
|
||||
},
|
||||
{
|
||||
displayName: 'Additional Fields',
|
||||
name: 'additionalFields',
|
||||
type: 'collection',
|
||||
placeholder: 'Add Field',
|
||||
default: {},
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseComment'],
|
||||
operation: ['add'],
|
||||
},
|
||||
},
|
||||
options: [
|
||||
{
|
||||
displayName: 'Owner',
|
||||
name: 'owner',
|
||||
type: 'string',
|
||||
description:
|
||||
'Valid application owner registered within the Cases Role Based Access Control system',
|
||||
default: '',
|
||||
},
|
||||
],
|
||||
},
|
||||
|
||||
// ----------------------------------------
|
||||
// caseComment: get
|
||||
// ----------------------------------------
|
||||
{
|
||||
displayName: 'Case ID',
|
||||
name: 'caseId',
|
||||
description: 'ID of the case containing the comment to retrieve',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseComment'],
|
||||
operation: ['get'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Comment ID',
|
||||
name: 'commentId',
|
||||
description: 'ID of the case comment to retrieve',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseComment'],
|
||||
operation: ['get'],
|
||||
},
|
||||
},
|
||||
},
|
||||
|
||||
// ----------------------------------------
|
||||
// caseComment: getAll
|
||||
// ----------------------------------------
|
||||
{
|
||||
displayName: 'Case ID',
|
||||
name: 'caseId',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseComment'],
|
||||
operation: ['getAll'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Return All',
|
||||
name: 'returnAll',
|
||||
type: 'boolean',
|
||||
default: false,
|
||||
description: 'Whether to return all results or only up to a given limit',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseComment'],
|
||||
operation: ['getAll'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Limit',
|
||||
name: 'limit',
|
||||
type: 'number',
|
||||
default: 50,
|
||||
description: 'Max number of results to return',
|
||||
typeOptions: {
|
||||
minValue: 1,
|
||||
},
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseComment'],
|
||||
operation: ['getAll'],
|
||||
returnAll: [false],
|
||||
},
|
||||
},
|
||||
},
|
||||
|
||||
// ----------------------------------------
|
||||
// caseComment: remove
|
||||
// ----------------------------------------
|
||||
{
|
||||
displayName: 'Case ID',
|
||||
name: 'caseId',
|
||||
description: 'ID of the case containing the comment to remove',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseComment'],
|
||||
operation: ['remove'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Comment ID',
|
||||
name: 'commentId',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseComment'],
|
||||
operation: ['remove'],
|
||||
},
|
||||
},
|
||||
},
|
||||
|
||||
// ----------------------------------------
|
||||
// caseComment: update
|
||||
// ----------------------------------------
|
||||
{
|
||||
displayName: 'Case ID',
|
||||
name: 'caseId',
|
||||
description: 'ID of the case containing the comment to retrieve',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseComment'],
|
||||
operation: ['update'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Comment ID',
|
||||
name: 'commentId',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseComment'],
|
||||
operation: ['update'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Comment',
|
||||
name: 'comment',
|
||||
description: 'Text to replace current comment message',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseComment'],
|
||||
operation: ['update'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Simplify',
|
||||
name: 'simple',
|
||||
type: 'boolean',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseComment'],
|
||||
operation: ['update'],
|
||||
},
|
||||
},
|
||||
default: true,
|
||||
description: 'Whether to return a simplified version of the response instead of the raw data',
|
||||
},
|
||||
];
|
||||
@@ -0,0 +1,568 @@
|
||||
import type { INodeProperties } from 'n8n-workflow';
|
||||
|
||||
export const caseOperations: INodeProperties[] = [
|
||||
{
|
||||
displayName: 'Operation',
|
||||
name: 'operation',
|
||||
noDataExpression: true,
|
||||
type: 'options',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
},
|
||||
},
|
||||
options: [
|
||||
{
|
||||
name: 'Create',
|
||||
value: 'create',
|
||||
description: 'Create a case',
|
||||
action: 'Create a case',
|
||||
},
|
||||
{
|
||||
name: 'Delete',
|
||||
value: 'delete',
|
||||
description: 'Delete a case',
|
||||
action: 'Delete a case',
|
||||
},
|
||||
{
|
||||
name: 'Get',
|
||||
value: 'get',
|
||||
description: 'Get a case',
|
||||
action: 'Get a case',
|
||||
},
|
||||
{
|
||||
name: 'Get Many',
|
||||
value: 'getAll',
|
||||
description: 'Retrieve many cases',
|
||||
action: 'Get many cases',
|
||||
},
|
||||
{
|
||||
name: 'Get Status',
|
||||
value: 'getStatus',
|
||||
description: 'Retrieve a summary of all case activity',
|
||||
action: 'Get the status of a case',
|
||||
},
|
||||
{
|
||||
name: 'Update',
|
||||
value: 'update',
|
||||
description: 'Update a case',
|
||||
action: 'Update a case',
|
||||
},
|
||||
],
|
||||
default: 'create',
|
||||
},
|
||||
];
|
||||
|
||||
export const caseFields: INodeProperties[] = [
|
||||
// ----------------------------------------
|
||||
// case: create
|
||||
// ----------------------------------------
|
||||
{
|
||||
displayName: 'Title',
|
||||
name: 'title',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['create'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Connector Name or ID',
|
||||
name: 'connectorId',
|
||||
description:
|
||||
'Connectors allow you to send Elastic Security cases into other systems (only ServiceNow, Jira, or IBM Resilient). Choose from the list, or specify an ID using an <a href="https://docs.n8n.io/code/expressions/">expression</a>.',
|
||||
type: 'options',
|
||||
required: true,
|
||||
default: '',
|
||||
typeOptions: {
|
||||
loadOptionsMethod: 'getConnectors',
|
||||
},
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['create'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Connector Type',
|
||||
name: 'connectorType',
|
||||
type: 'options',
|
||||
required: true,
|
||||
default: '.jira',
|
||||
options: [
|
||||
{
|
||||
name: 'IBM Resilient',
|
||||
value: '.resilient',
|
||||
},
|
||||
{
|
||||
name: 'Jira',
|
||||
value: '.jira',
|
||||
},
|
||||
{
|
||||
name: 'ServiceNow ITSM',
|
||||
value: '.servicenow',
|
||||
},
|
||||
],
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['create'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Issue Type',
|
||||
name: 'issueType',
|
||||
description: 'Type of the Jira issue to create for this case',
|
||||
type: 'string',
|
||||
placeholder: 'Task',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['create'],
|
||||
connectorType: ['.jira'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Priority',
|
||||
name: 'priority',
|
||||
description: 'Priority of the Jira issue to create for this case',
|
||||
type: 'string',
|
||||
placeholder: 'High',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['create'],
|
||||
connectorType: ['.jira'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Urgency',
|
||||
name: 'urgency',
|
||||
description: 'Urgency of the ServiceNow ITSM issue to create for this case',
|
||||
type: 'options',
|
||||
required: true,
|
||||
default: 1,
|
||||
options: [
|
||||
{
|
||||
name: 'Low',
|
||||
value: 1,
|
||||
},
|
||||
{
|
||||
name: 'Medium',
|
||||
value: 2,
|
||||
},
|
||||
{
|
||||
name: 'High',
|
||||
value: 3,
|
||||
},
|
||||
],
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['create'],
|
||||
connectorType: ['.servicenow'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Severity',
|
||||
name: 'severity',
|
||||
description: 'Severity of the ServiceNow ITSM issue to create for this case',
|
||||
type: 'options',
|
||||
required: true,
|
||||
default: 1,
|
||||
options: [
|
||||
{
|
||||
name: 'Low',
|
||||
value: 1,
|
||||
},
|
||||
{
|
||||
name: 'Medium',
|
||||
value: 2,
|
||||
},
|
||||
{
|
||||
name: 'High',
|
||||
value: 3,
|
||||
},
|
||||
],
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['create'],
|
||||
connectorType: ['.servicenow'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Impact',
|
||||
name: 'impact',
|
||||
description: 'Impact of the ServiceNow ITSM issue to create for this case',
|
||||
type: 'options',
|
||||
required: true,
|
||||
default: 1,
|
||||
options: [
|
||||
{
|
||||
name: 'Low',
|
||||
value: 1,
|
||||
},
|
||||
{
|
||||
name: 'Medium',
|
||||
value: 2,
|
||||
},
|
||||
{
|
||||
name: 'High',
|
||||
value: 3,
|
||||
},
|
||||
],
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['create'],
|
||||
connectorType: ['.servicenow'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Category',
|
||||
name: 'category',
|
||||
type: 'string',
|
||||
description: 'Category of the ServiceNow ITSM issue to create for this case',
|
||||
required: true,
|
||||
default: '',
|
||||
placeholder: 'Helpdesk',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['create'],
|
||||
connectorType: ['.servicenow'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Issue Types',
|
||||
name: 'issueTypes',
|
||||
description:
|
||||
'Comma-separated list of numerical types of the IBM Resilient issue to create for this case',
|
||||
type: 'string',
|
||||
placeholder: '123,456',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['create'],
|
||||
connectorType: ['.resilient'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Severity Code',
|
||||
name: 'severityCode',
|
||||
description: 'Severity code of the IBM Resilient issue to create for this case',
|
||||
type: 'number',
|
||||
typeOptions: {
|
||||
minValue: 0,
|
||||
},
|
||||
required: true,
|
||||
default: 1,
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['create'],
|
||||
connectorType: ['.resilient'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Additional Fields',
|
||||
name: 'additionalFields',
|
||||
type: 'collection',
|
||||
placeholder: 'Add Field',
|
||||
default: {},
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['create'],
|
||||
},
|
||||
},
|
||||
options: [
|
||||
{
|
||||
displayName: 'Description',
|
||||
name: 'description',
|
||||
type: 'string',
|
||||
default: '',
|
||||
},
|
||||
{
|
||||
displayName: 'Owner',
|
||||
name: 'owner',
|
||||
type: 'string',
|
||||
description:
|
||||
'Valid application owner registered within the Cases Role Based Access Control system',
|
||||
default: '',
|
||||
},
|
||||
{
|
||||
displayName: 'Sync Alerts',
|
||||
name: 'syncAlerts',
|
||||
description: 'Whether to synchronize with alerts',
|
||||
type: 'boolean',
|
||||
default: false,
|
||||
},
|
||||
],
|
||||
},
|
||||
|
||||
// ----------------------------------------
|
||||
// case: delete
|
||||
// ----------------------------------------
|
||||
{
|
||||
displayName: 'Case ID',
|
||||
name: 'caseId',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['delete'],
|
||||
},
|
||||
},
|
||||
},
|
||||
|
||||
// ----------------------------------------
|
||||
// case: get
|
||||
// ----------------------------------------
|
||||
{
|
||||
displayName: 'Case ID',
|
||||
name: 'caseId',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['get'],
|
||||
},
|
||||
},
|
||||
},
|
||||
|
||||
// ----------------------------------------
|
||||
// case: getAll
|
||||
// ----------------------------------------
|
||||
{
|
||||
displayName: 'Return All',
|
||||
name: 'returnAll',
|
||||
type: 'boolean',
|
||||
default: false,
|
||||
description: 'Whether to return all results or only up to a given limit',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['getAll'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Limit',
|
||||
name: 'limit',
|
||||
type: 'number',
|
||||
default: 50,
|
||||
description: 'Max number of results to return',
|
||||
typeOptions: {
|
||||
minValue: 1,
|
||||
},
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['getAll'],
|
||||
returnAll: [false],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Filters',
|
||||
name: 'filters',
|
||||
type: 'collection',
|
||||
default: {},
|
||||
placeholder: 'Add Filter',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['getAll'],
|
||||
},
|
||||
},
|
||||
options: [
|
||||
{
|
||||
displayName: 'Status',
|
||||
name: 'status',
|
||||
type: 'options',
|
||||
options: [
|
||||
{
|
||||
name: 'Open',
|
||||
value: 'open',
|
||||
},
|
||||
{
|
||||
name: 'In Progress',
|
||||
value: 'in-progress',
|
||||
},
|
||||
{
|
||||
name: 'Closed',
|
||||
value: 'closed',
|
||||
},
|
||||
],
|
||||
default: 'open',
|
||||
},
|
||||
{
|
||||
displayName: 'Tag Names or IDs',
|
||||
name: 'tags',
|
||||
type: 'multiOptions',
|
||||
description:
|
||||
'Choose from the list, or specify IDs using an <a href="https://docs.n8n.io/code/expressions/">expression</a>',
|
||||
default: [],
|
||||
typeOptions: {
|
||||
loadOptionsMethod: 'getTags',
|
||||
},
|
||||
},
|
||||
],
|
||||
},
|
||||
{
|
||||
displayName: 'Sort',
|
||||
name: 'sortOptions',
|
||||
type: 'fixedCollection',
|
||||
placeholder: 'Add Sort Options',
|
||||
default: {},
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['getAll'],
|
||||
},
|
||||
},
|
||||
options: [
|
||||
{
|
||||
displayName: 'Sort Options',
|
||||
name: 'sortOptionsProperties',
|
||||
values: [
|
||||
{
|
||||
displayName: 'Sort Key',
|
||||
name: 'sortField',
|
||||
type: 'options',
|
||||
options: [
|
||||
{
|
||||
name: 'Created At',
|
||||
value: 'createdAt',
|
||||
},
|
||||
{
|
||||
name: 'Updated At',
|
||||
value: 'updatedAt',
|
||||
},
|
||||
],
|
||||
default: 'createdAt',
|
||||
},
|
||||
{
|
||||
displayName: 'Sort Order',
|
||||
name: 'sortOrder',
|
||||
type: 'options',
|
||||
options: [
|
||||
{
|
||||
name: 'Ascending',
|
||||
value: 'asc',
|
||||
},
|
||||
{
|
||||
name: 'Descending',
|
||||
value: 'desc',
|
||||
},
|
||||
],
|
||||
default: 'asc',
|
||||
},
|
||||
],
|
||||
},
|
||||
],
|
||||
},
|
||||
|
||||
// ----------------------------------------
|
||||
// case: update
|
||||
// ----------------------------------------
|
||||
{
|
||||
displayName: 'Case ID',
|
||||
name: 'caseId',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['update'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Update Fields',
|
||||
name: 'updateFields',
|
||||
type: 'collection',
|
||||
placeholder: 'Add Field',
|
||||
default: {},
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['case'],
|
||||
operation: ['update'],
|
||||
},
|
||||
},
|
||||
options: [
|
||||
{
|
||||
displayName: 'Description',
|
||||
name: 'description',
|
||||
type: 'string',
|
||||
default: '',
|
||||
},
|
||||
{
|
||||
displayName: 'Status',
|
||||
name: 'status',
|
||||
type: 'options',
|
||||
default: 'open',
|
||||
options: [
|
||||
{
|
||||
name: 'Closed',
|
||||
value: 'closed',
|
||||
},
|
||||
{
|
||||
name: 'Open',
|
||||
value: 'open',
|
||||
},
|
||||
{
|
||||
name: 'In Progress',
|
||||
value: 'in-progress',
|
||||
},
|
||||
],
|
||||
},
|
||||
{
|
||||
displayName: 'Sync Alerts',
|
||||
name: 'syncAlerts',
|
||||
description: 'Whether to synchronize with alerts',
|
||||
type: 'boolean',
|
||||
default: false,
|
||||
},
|
||||
{
|
||||
displayName: 'Title',
|
||||
name: 'title',
|
||||
type: 'string',
|
||||
default: '',
|
||||
},
|
||||
{
|
||||
displayName: 'Version',
|
||||
name: 'version',
|
||||
type: 'string',
|
||||
default: '',
|
||||
},
|
||||
],
|
||||
},
|
||||
];
|
||||
@@ -0,0 +1,102 @@
|
||||
import type { INodeProperties } from 'n8n-workflow';
|
||||
|
||||
export const caseTagOperations: INodeProperties[] = [
|
||||
{
|
||||
displayName: 'Operation',
|
||||
name: 'operation',
|
||||
type: 'options',
|
||||
noDataExpression: true,
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseTag'],
|
||||
},
|
||||
},
|
||||
options: [
|
||||
{
|
||||
name: 'Add',
|
||||
value: 'add',
|
||||
description: 'Add a tag to a case',
|
||||
action: 'Add a tag to a case',
|
||||
},
|
||||
{
|
||||
name: 'Remove',
|
||||
value: 'remove',
|
||||
description: 'Remove a tag from a case',
|
||||
action: 'Remove a tag from a case',
|
||||
},
|
||||
],
|
||||
default: 'add',
|
||||
},
|
||||
];
|
||||
|
||||
export const caseTagFields: INodeProperties[] = [
|
||||
// ----------------------------------------
|
||||
// caseTag: add
|
||||
// ----------------------------------------
|
||||
{
|
||||
displayName: 'Case ID',
|
||||
name: 'caseId',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseTag'],
|
||||
operation: ['add'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Tag Name or ID',
|
||||
name: 'tag',
|
||||
type: 'options',
|
||||
description:
|
||||
'Tag to attach to the case. Choose from the list, or specify an ID using an <a href="https://docs.n8n.io/code/expressions/">expression</a>.',
|
||||
required: true,
|
||||
default: '',
|
||||
typeOptions: {
|
||||
loadOptionsMethod: 'getTags',
|
||||
},
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseTag'],
|
||||
operation: ['add'],
|
||||
},
|
||||
},
|
||||
},
|
||||
|
||||
// ----------------------------------------
|
||||
// caseTag: remove
|
||||
// ----------------------------------------
|
||||
{
|
||||
displayName: 'Case ID',
|
||||
name: 'caseId',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseTag'],
|
||||
operation: ['remove'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Tag Name or ID',
|
||||
name: 'tag',
|
||||
type: 'options',
|
||||
description:
|
||||
'Choose from the list, or specify an ID using an <a href="https://docs.n8n.io/code/expressions/">expression</a>',
|
||||
required: true,
|
||||
default: '',
|
||||
typeOptions: {
|
||||
loadOptionsMethod: 'getTags',
|
||||
},
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['caseTag'],
|
||||
operation: ['remove'],
|
||||
},
|
||||
},
|
||||
},
|
||||
];
|
||||
+211
@@ -0,0 +1,211 @@
|
||||
import type { INodeProperties } from 'n8n-workflow';
|
||||
|
||||
export const connectorOperations: INodeProperties[] = [
|
||||
{
|
||||
displayName: 'Operation',
|
||||
name: 'operation',
|
||||
noDataExpression: true,
|
||||
type: 'options',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['connector'],
|
||||
},
|
||||
},
|
||||
options: [
|
||||
{
|
||||
name: 'Create',
|
||||
value: 'create',
|
||||
description: 'Create a connector',
|
||||
action: 'Create a connector',
|
||||
},
|
||||
],
|
||||
default: 'create',
|
||||
},
|
||||
];
|
||||
|
||||
export const connectorFields: INodeProperties[] = [
|
||||
// ----------------------------------------
|
||||
// connector: create
|
||||
// ----------------------------------------
|
||||
{
|
||||
displayName: 'Connector Name',
|
||||
name: 'name',
|
||||
description:
|
||||
'Connectors allow you to send Elastic Security cases into other systems (only ServiceNow, Jira, or IBM Resilient)',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['connector'],
|
||||
operation: ['create'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Connector Type',
|
||||
name: 'connectorType',
|
||||
type: 'options',
|
||||
required: true,
|
||||
default: '.jira',
|
||||
options: [
|
||||
{
|
||||
name: 'IBM Resilient',
|
||||
value: '.resilient',
|
||||
},
|
||||
{
|
||||
name: 'Jira',
|
||||
value: '.jira',
|
||||
},
|
||||
{
|
||||
name: 'ServiceNow ITSM',
|
||||
value: '.servicenow',
|
||||
},
|
||||
],
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['connector'],
|
||||
operation: ['create'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'API URL',
|
||||
name: 'apiUrl',
|
||||
type: 'string',
|
||||
description: 'URL of the third-party instance',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['connector'],
|
||||
operation: ['create'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Email',
|
||||
name: 'email',
|
||||
description: 'Jira-registered email',
|
||||
type: 'string',
|
||||
placeholder: 'name@email.com',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['connector'],
|
||||
operation: ['create'],
|
||||
connectorType: ['.jira'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'API Token',
|
||||
name: 'apiToken',
|
||||
description: 'Jira API token',
|
||||
type: 'string',
|
||||
typeOptions: { password: true },
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['connector'],
|
||||
operation: ['create'],
|
||||
connectorType: ['.jira'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Project Key',
|
||||
name: 'projectKey',
|
||||
description: 'Jira Project Key',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['connector'],
|
||||
operation: ['create'],
|
||||
connectorType: ['.jira'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Username',
|
||||
name: 'username',
|
||||
description: 'ServiceNow ITSM username',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['connector'],
|
||||
operation: ['create'],
|
||||
connectorType: ['.servicenow'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Password',
|
||||
name: 'password',
|
||||
description: 'ServiceNow ITSM password',
|
||||
type: 'string',
|
||||
typeOptions: { password: true },
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['connector'],
|
||||
operation: ['create'],
|
||||
connectorType: ['.servicenow'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'API Key ID',
|
||||
name: 'apiKeyId',
|
||||
description: 'IBM Resilient API key ID',
|
||||
type: 'string',
|
||||
typeOptions: { password: true },
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['connector'],
|
||||
operation: ['create'],
|
||||
connectorType: ['.resilient'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'API Key Secret',
|
||||
name: 'apiKeySecret',
|
||||
description: 'IBM Resilient API key secret',
|
||||
type: 'string',
|
||||
typeOptions: { password: true },
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['connector'],
|
||||
operation: ['create'],
|
||||
connectorType: ['.resilient'],
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
displayName: 'Organization ID',
|
||||
name: 'orgId',
|
||||
description: 'IBM Resilient organization ID',
|
||||
type: 'string',
|
||||
required: true,
|
||||
default: '',
|
||||
displayOptions: {
|
||||
show: {
|
||||
resource: ['connector'],
|
||||
operation: ['create'],
|
||||
connectorType: ['.resilient'],
|
||||
},
|
||||
},
|
||||
},
|
||||
];
|
||||
@@ -0,0 +1,4 @@
|
||||
export * from './CaseDescription';
|
||||
export * from './CaseCommentDescription';
|
||||
export * from './CaseTagDescription';
|
||||
export * from './ConnectorDescription';
|
||||
@@ -0,0 +1 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" width="64" height="64" viewBox="2 0 32 32"><g fill="none" fill-rule="evenodd"><path d="M0 0h32v32H0z"/><path fill="#FA744E" d="M9 7.008V0h20v16.744c0 3.913-6.378 6.477-9.015 7.256V7.008z"/><path fill="#1DBAB0" d="M3 20.073V10h14v22Q3 25.97 3 20.073"/><path fill="#343741" d="M9 10h8v14c-2.983-1.14-8-3.756-8-7.043z"/></g></svg>
|
||||
|
After Width: | Height: | Size: 367 B |
@@ -0,0 +1,57 @@
|
||||
export type ElasticSecurityApiCredentials = {
|
||||
username?: string;
|
||||
password?: string;
|
||||
apiKey?: string;
|
||||
baseUrl: string;
|
||||
};
|
||||
|
||||
export type ConnectorType = '.jira' | '.servicenow' | '.resilient';
|
||||
|
||||
export type Connector = {
|
||||
id: string;
|
||||
name: string;
|
||||
connector_type_id: ConnectorType;
|
||||
};
|
||||
|
||||
export type ConnectorCreatePayload =
|
||||
| ServiceNowConnectorCreatePayload
|
||||
| JiraConnectorCreatePayload
|
||||
| IbmResilientConnectorCreatePayload;
|
||||
|
||||
type ServiceNowConnectorCreatePayload = {
|
||||
connector_type_id: '.servicenow';
|
||||
name: string;
|
||||
secrets?: {
|
||||
username: string;
|
||||
password: string;
|
||||
};
|
||||
config?: {
|
||||
apiUrl: string;
|
||||
};
|
||||
};
|
||||
|
||||
type JiraConnectorCreatePayload = {
|
||||
connector_type_id: '.jira';
|
||||
name: string;
|
||||
secrets?: {
|
||||
email: string;
|
||||
apiToken: string;
|
||||
};
|
||||
config?: {
|
||||
apiUrl: string;
|
||||
projectKey: string;
|
||||
};
|
||||
};
|
||||
|
||||
type IbmResilientConnectorCreatePayload = {
|
||||
connector_type_id: '.resilient';
|
||||
name: string;
|
||||
secrets?: {
|
||||
apiKeyId: string;
|
||||
apiKeySecret: string;
|
||||
};
|
||||
config?: {
|
||||
apiUrl: string;
|
||||
orgId: string;
|
||||
};
|
||||
};
|
||||
Reference in New Issue
Block a user