socfortress / CoPilot

SOCFortress CoPilot
https://www.socfortress.co
GNU Affero General Public License v3.0
196 stars 40 forks source link

invoke_alert_creation_collect #323

Open SecurityArsenal opened 1 week ago

SecurityArsenal commented 1 week ago

invoke_sigma_queries_collect 10/07/2024 17:37:55 invoke_sigma_queries_collect Invokes Sigma queries collection. Interval 5 minutes

500 POST /api/scheduler/jobs/run/invoke_alert_creation_collect

ERROR [apscheduler.executors.default] Job "invoke_alert_creation_collect (trigger: interval[0:05:00], next run at: 2024-10-07 17:42:54 UTC)" raised an exception Traceback (most recent call last): File "/opt/venv/lib/python3.11/site-packages/apscheduler/executors/base_py3.py", line 30, in run_coroutine_job retval = await job.func(*job.args, **job.kwargs) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/opt/copilot/backend/app/schedulers/services/invoke_alert_creation.py", line 23, in invoke_alert_creation_collect await create_alert_auto_route(session=session) File "/opt/copilot/backend/app/incidents/routes/incident_alert.py", line 167, in create_alert_auto_route alert_id = await create_alert(create_alert_request, session) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/opt/copilot/backend/app/incidents/services/incident_alert.py", line 642, in create_alert customer_code = await get_customer_code(dict(alert_details._source)) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/opt/copilot/backend/app/incidents/services/incident_alert.py", line 211, in get_customer_code raise HTTPException( fastapi.exceptions.HTTPException

taylorwalton commented 1 day ago

It looks like there is no customer code found. Can you confirm that the customer is created and provisioned via CoPilot?