Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A SOC engineer is implementing a custom command in a Cortex XSOAR integration. This command needs to query an external API and return the raw JSON response directly to the War Room for inspection by an analyst, without any further parsing or formatting. Which function should be used to achieve this specific output requirement?

  1. Areturn_error('Error: ...')
  2. Breturn_outputs({'json': json_data})
  3. Creturn_results(readable_output='...')
  4. Dreturn_results(json.dumps(raw_json_data), content_format=outputFormat.JSON)
Show answer & explanation

Correct answer: D. return_results(json.dumps(raw_json_data), content_format=outputFormat.JSON)

To return raw JSON directly to the War Room, `return_results()` should be used with the JSON data stringified (`json.dumps`) and specifying `content_format=outputFormat.JSON`. This instructs XSOAR to display the output as raw JSON, which is ideal for inspection.

Why the other options are wrong

  • A. `return_error` is used for indicating command failure, not for returning successful JSON data.
  • B. `return_outputs` is used to set context keys, not to display raw JSON in the War Room.
  • C. `readable_output` is for human-readable text, not raw JSON.

Return Raw JSON to War Room

The method in Cortex XSOAR custom integrations to display unformatted JSON data directly in the War Room, allowing analysts to inspect the full API response.

  • Uses `return_results()` function.
  • JSON data must be serialized to a string using `json.dumps()`.
  • `content_format=outputFormat.JSON` parameter is crucial for correct rendering.

Memory trick: Output format dictates display, use `outputFormat` for JSON.

More Integrations questions