I am working on a use case in Google SecOps SOAR where I want to automatically retrieve files attached to a case and submit them to an external platform for further analysis.
We are using the get_attachments function from the Siemplify SDK to retrieve attachments associated with a case. However, we have noticed that this function retrieves attachments added through case comments but does not seem to return attachments added by other actions.
For example, suppose an action adds a file attachment when it is executed within a case. The attachment is visible in the result of that action. Later, when another action runs on the same case and uses the get_attachments function from the Siemplify SDK, the attachment added by the previous action is not returned. However, attachments added through case comments are returned successfully.
Our goal is to retrieve files associated with a case, regardless of whether they were added through case comments or by other actions, so that we can use them in subsequent automation steps.
Is there a way to retrieve attachments added by actions in the case?
