Hi team,
I currently working on integrating Jira Service Management cloud with my wazuh alerts to server as a ticketing system. Following blog posts and all for guidance I'm still not seeing the alert on my jira platform. Any help please.
How are you doing this integration? You've not explained what you are using to connect the two.
Alright sir. I'm using an integration script named custom-jira placed at "/var/ossec/integrations/" and given necessary permissions. From the integration logs, the script seems to be running fine with no errors.
Script:
#!/usr/bin/env python
import sysimport jsonimport requestsfrom requests.auth import HTTPBasicAuthimport timeimport os
# Configure loggingdebug_enabled = Truepwd = os.path.dirname(os.path.dirname(os.path.realpath(__file__)))log_file = '{0}/logs/integrations.log'.format(pwd)
def debug(msg):if debug_enabled:now = time.strftime("%a %b %d %H:%M:%S %Z %Y")msg = "{0}: {1}\n".format(now, msg)print(msg)f = open(log_file, "a")f.write(msg)f.close()
debug('Starting to run Jira integration')
# Set the project attributesproject_alias = 'issue key'issue_name ='Task'
# Read configuration parametersalert_file = open(sys.argv[1])user = sys.argv[2].split(':')[0]api_key = sys.argv[2].split(':')[1]hook_url = sys.argv[3]
# Read the alert filealert_json = json.loads(alert_file.read())alert_file.close()
# Extract issue fieldsagent_name = alert_json['agent']['name']alert_level = alert_json['rule']['level']description = alert_json['rule']['description']
# Generate requestmsg_data = {}msg_data['fields'] = {}msg_data['fields']['project'] = {}msg_data['fields']['project']['key'] = project_aliasmsg_data['fields']['summary'] = 'Wazuh alert: [' + description + ']'msg_data['fields']['description'] = '- State: ' + description + '\n- Alert level: ' + str(alert_level) + '\n- Agent name: ' + agent_namemsg_data['fields']['issuetype'] = {}msg_data['fields']['issuetype']['name'] = issue_nameheaders = {'content-type': 'application/json', 'Accept-Charset': 'UTF-8'}
debug('Sending message with the content: ' + str(msg_data))
# Send the requestresponse = requests.post(hook_url, data=json.dumps(msg_data), headers=headers, auth=(user, api_key))
debug('Jira replied: '+ response.text)
sys.exit(0)
Ok, I can't debug something that's in a library I do not know anything about, especially if it is not feeding back the errors Jira is giving it when the call fails.
Exactly my issue too. I'm not seeing any errors Jira is giving to know what's happening.
It looks like you're new here. Sign in or register to get started.