-
Notifications
You must be signed in to change notification settings - Fork 25
/
alerts_details.go
110 lines (97 loc) · 2.63 KB
/
alerts_details.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
//
// Author:: Salim Afiune Maya (<[email protected]>)
// Copyright:: Copyright 2020, Lacework Inc.
// License:: Apache License, Version 2.0
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
//
package api
import (
"fmt"
"net/http"
"github.com/pkg/errors"
)
type alertScope int
const (
AlertDetailsScope alertScope = iota
AlertInvestigationScope
AlertEventsScope
AlertRelatedAlertsScope
AlertIntegrationsScope
AlertTimelineScope
)
var AlertScopes = map[alertScope]string{
AlertDetailsScope: "Details",
AlertInvestigationScope: "Investigation",
AlertEventsScope: "Events",
AlertRelatedAlertsScope: "RelatedAlerts",
AlertIntegrationsScope: "Integrations",
AlertTimelineScope: "Timeline",
}
func (i alertScope) String() string {
return AlertScopes[i]
}
type AlertDetails struct {
Alert
EntityMap map[string]interface{} `json:"entityMap"` // @dhazekamp: this needs to be built out properly
}
type AlertDetailsResponse struct {
Data AlertDetails `json:"data"`
}
func (svc *AlertsService) Get(id int, scope alertScope) (interface{}, error) {
switch scope {
case AlertDetailsScope:
return svc.GetDetails(id)
case AlertInvestigationScope:
return svc.GetInvestigation(id)
case AlertEventsScope:
return svc.GetEvents(id)
case AlertRelatedAlertsScope:
return svc.GetRelatedAlerts(id)
case AlertIntegrationsScope:
return svc.GetIntegrations(id)
case AlertTimelineScope:
return svc.GetTimeline(id)
default:
return nil, errors.New(fmt.Sprintf("alert scope (%s) not recognized", scope))
}
}
func (svc *AlertsService) GetDetails(id int) (
response AlertDetailsResponse,
err error,
) {
err = svc.client.RequestDecoder(
"GET",
fmt.Sprintf(apiV2AlertsDetails, id, AlertDetailsScope),
nil,
&response,
)
return
}
func (svc *AlertsService) Exists(id int) (bool, error) {
var response AlertDetailsResponse
err := svc.client.RequestDecoder(
"GET",
fmt.Sprintf(apiV2AlertsDetails, id, AlertDetailsScope),
nil,
&response,
)
if err == nil {
return true, nil
}
errResponse, ok := err.(*errorResponse)
if ok && errResponse.Response.StatusCode == http.StatusNotFound {
return false, nil
}
return false, err
}