A SOC engineer is building a custom integration in Cortex XSOAR to interact with an internal SIEM system. The SIEM's API occasionally returns large log datasets (up to 50MB) that can cause the integration command to time out if not handled efficiently. The default timeout for integration commands is 10 minutes. The engineer wants to explicitly set a 30-minute timeout for a specific command, `get-large-logs`, to accommodate these large responses without affecting other commands. How should this be achieved?
- AIncrease the `integration_command_timeout` server configuration in Cortex XSOAR to 30 minutes.
- BSet the `timeout` parameter in the `params` dictionary of the `demisto.command()` decorator for `get-large-logs`.
- CModify the `requests` library's default timeout globally within the integration code.
- DUse the `long_running=True` flag in the `demisto.command()` decorator for `get-large-logs` and configure the job timeout in Cortex XSOAR settings.
Show answer & explanationAnswer & explanation
Correct answer: D. Use the `long_running=True` flag in the `demisto.command()` decorator for `get-large-logs` and configure the job timeout in Cortex XSOAR settings.
For commands that are expected to take longer than the default 10-minute timeout, the `long_running=True` flag should be used in the `demisto.command()` decorator. This marks the command as long-running, allowing its timeout to be configured separately in Cortex XSOAR job settings, typically up to 60 minutes for tasks like fetching large datasets.
Why the other options are wrong
- A. Increasing the `integration_command_timeout` server configuration would change the default timeout for *all* integration commands across the entire XSOAR instance, which is not desired for a single command.
- B. There is no `timeout` parameter in the `params` dictionary of `demisto.command()` for setting command-specific execution timeouts in this manner.
- C. Modifying the `requests` library's default timeout would affect the HTTP request itself, not the overall integration command execution timeout, and would apply globally to all requests from that integration instance.
long_running Command Flag
The `long_running=True` flag in the `demisto.command()` decorator marks an integration command as potentially taking longer than the default timeout (10 minutes), allowing its execution timeout to be configured separately in Cortex XSOAR's job settings.
- Overrides the default 10-minute command timeout.
- Enables specific commands to run for extended periods.
- Requires configuration in Cortex XSOAR job settings for the actual timeout duration.
Memory trick: Long runs need a longer leash.