<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Capture JSON for Alerts that are sent to SQS in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/capture-json-for-alerts-that-are-sent-to-sqs/m-p/271995#M155</link>
    <description>&lt;P&gt;I have configured Redlock to send alert to SQS queue. I am getting the below fields in JSON body when I fetch it from SQS:&lt;/P&gt;&lt;P&gt;However, When I try to fetch the alert details using Alert API I get the complete different schema.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SQS_JSON_Fields" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20464i3027F2C6FE312C57/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SQS_json.JPG" alt="SQS_JSON_Fields" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;SQS_JSON_Fields&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Alert_API_JSON" style="width: 285px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20465i516C5286561C2CA3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Alert_API_Detailed.JPG" alt="Alert_API_JSON" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Alert_API_JSON&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As soon as an alert is generated, then the JSON data for that alert is sent to SQS queue. (I have lambda that captures and process the data from queue and queue is empty)&lt;/P&gt;&lt;P&gt;Is there any way I can get the data in JSON format which are sent to SQS for the &lt;STRONG&gt;existing alert&lt;/STRONG&gt;?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;My aim is to&lt;/EM&gt;&lt;STRONG&gt;&lt;EM&gt; capture the JSON data from the existing alert instead of creating a new alert&lt;/EM&gt;&lt;/STRONG&gt; and use it to manipulate and process the data from SQS as per requirement&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Sep 2020 17:16:56 GMT</pubDate>
    <dc:creator>APaul</dc:creator>
    <dc:date>2020-09-02T17:16:56Z</dc:date>
    <item>
      <title>Capture JSON for Alerts that are sent to SQS</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/capture-json-for-alerts-that-are-sent-to-sqs/m-p/271995#M155</link>
      <description>&lt;P&gt;I have configured Redlock to send alert to SQS queue. I am getting the below fields in JSON body when I fetch it from SQS:&lt;/P&gt;&lt;P&gt;However, When I try to fetch the alert details using Alert API I get the complete different schema.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SQS_JSON_Fields" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20464i3027F2C6FE312C57/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SQS_json.JPG" alt="SQS_JSON_Fields" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;SQS_JSON_Fields&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Alert_API_JSON" style="width: 285px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20465i516C5286561C2CA3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Alert_API_Detailed.JPG" alt="Alert_API_JSON" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Alert_API_JSON&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As soon as an alert is generated, then the JSON data for that alert is sent to SQS queue. (I have lambda that captures and process the data from queue and queue is empty)&lt;/P&gt;&lt;P&gt;Is there any way I can get the data in JSON format which are sent to SQS for the &lt;STRONG&gt;existing alert&lt;/STRONG&gt;?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;My aim is to&lt;/EM&gt;&lt;STRONG&gt;&lt;EM&gt; capture the JSON data from the existing alert instead of creating a new alert&lt;/EM&gt;&lt;/STRONG&gt; and use it to manipulate and process the data from SQS as per requirement&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2020 17:16:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/capture-json-for-alerts-that-are-sent-to-sqs/m-p/271995#M155</guid>
      <dc:creator>APaul</dc:creator>
      <dc:date>2020-09-02T17:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: Capture JSON for Alerts that are sent to SQS</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/capture-json-for-alerts-that-are-sent-to-sqs/m-p/272174#M156</link>
      <description>&lt;P&gt;The alert metadata should be under the "resource" field of the Alert API response JSON.&amp;nbsp; Is the information not there?&amp;nbsp; If you're looking to get the EXACT same overall schema, then I don't believe that's possible.&amp;nbsp; You probably have to modify your Lambda to accommodate the Alert API format.&amp;nbsp; Or alternatively, (if you don't mind doing this), you can always delete the Cloud Account to get rid of all the alerts, then recreate it to send all the alert into SQS.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 14:52:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/capture-json-for-alerts-that-are-sent-to-sqs/m-p/272174#M156</guid>
      <dc:creator>kchen</dc:creator>
      <dc:date>2019-06-21T14:52:30Z</dc:date>
    </item>
  </channel>
</rss>

