ExpanseAggregateAttributionUser

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

Aggregate entries from multiple sources into AttributionUser

Script Data#


NameDescription
Script Typepython3
Tags
Demisto Version6.0.0

Used In#


This script is used in the following playbooks and scripts.

  • Expanse Attribution Subplaybook

Inputs#


Argument NameDescription
inputInput list.
currentCurrent aggregation state.
username_fieldsComma separated list of fields to treat as serial number.
sightings_fieldsComma separated list of field names to be considered sighting counts.

Outputs#


PathDescriptionType
Expanse.AttributionUser.usernameUsername of the userstring
Expanse.AttributionUser.domainDomain of the userstring
Expanse.AttributionUser.groupsList of groups the user is member ofUnknown
Expanse.AttributionUser.display-nameDisplay Namestring
Expanse.AttributionUser.descriptionDescription of the userstring
Expanse.AttributionUser.sightingsNumber of sessions seen on this devicenumber