Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A security analyst is troubleshooting a custom integration where a specific command, `get-indicator-details`, sometimes takes a very long time to complete due to the external API's latency. Other commands in the same integration are fast. The analyst wants to prevent XSOAR from prematurely terminating *only* this slow command while allowing other commands to use default timeouts. How can this be achieved?

  1. ADecorate the `get-indicator-details` command function with `@demisto.command(long_running=True)`.
  2. BModify the `fetch_interval` to a higher value for the integration instance.
  3. CIncrease the global integration timeout parameter in the instance configuration.
  4. DSet the `timeout` parameter in the `_http_request` call specifically for `get-indicator-details`.
Show answer & explanation

Correct answer: A. Decorate the `get-indicator-details` command function with `@demisto.command(long_running=True)`.

Decorating a specific command function with `@demisto.command(long_running=True)` signals to Cortex XSOAR that this command is expected to take a long time, preventing XSOAR's internal mechanism from prematurely terminating it. This applies only to the specified command, leaving other commands to their default timeout settings.

Why the other options are wrong

  • B. `fetch_interval` controls how often incidents are fetched, completely unrelated to command execution timeouts.
  • C. Increasing the global integration timeout would affect *all* commands, which is not the specific requirement.
  • D. Setting the `timeout` in `_http_request` only controls the HTTP connection timeout, not the overall command execution timeout within XSOAR.

`long_running` Command Flag

A flag in the `@demisto.command()` decorator (`long_running=True`) used in Cortex XSOAR custom integrations to indicate that a specific command is expected to take a long time, preventing XSOAR's internal timeout mechanisms from prematurely terminating it.

  • Applies to individual commands.
  • Prevents XSOAR's default command timeout.
  • Used for commands with potentially long execution times.

Memory trick: Long-running flag lets slow commands finish their race.

More Integrations questions