Update Identical Event
LAST UPDATED: APRIL 15, 2025
This command identifies the first original event from the same data source and site that matches the search condition in MongoDB. Then, it retrieves the event data from the playbook runtime and uses this data to update the fields of the originally found event. Incidents directly related to the original event will also be updated by invoking the "Set Incident Fields" command using the input parameter "Incident Fields".
READER NOTE
Please note that this command can only be executed within an event playbook's "On Event Ingestion" trigger.
Implementation | System |
Command Category | System Utility |
Tags | EVENT EVENT MANAGEMENT |
Inputs
Parameter Name | Required/Optional | Description | Sample Data |
---|---|---|---|
Search Conditions | Required | Specify the search condition in a JSON object for the event you wish to update. If an original event matches this search condition (with system field name as key name), new field values will be updated in the original event. If the field did not exist, then it will be created. The value query corresponding to the key supports regular expressions, string, number, { "$in": ["value1", "value2"] }, and, date:"$date": "2023-08-01T00:00:00Z" format. |
CODE
|
Incident Fields | Required | A JSON object of an incident with fields to be updated. Fields could be Title, SiteName, IncidentType, Status, SeverityName, Disposition, Tags, DueDate, Description, IncidentCategory, DateEnded, Owner, DateOccurred and CustomFields. Date format: yyyy-mm-dd hh:mm:ss |
CODE
|
Skip Event Creation | Optional | Whether to skip creating duplicate events. By default, the value is No – a new event is created even if an identical one exists. | Yes |