Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A security analyst is troubleshooting a custom integration in Cortex XSOAR that intermittently fails with a `Connection timed out` error when interacting with an external threat intelligence platform. The platform is known to have occasional high latency. The analyst suspects that the default timeout for HTTP requests is too short. Which parameter should the analyst adjust to increase the waiting period for API responses?

  1. AThe `fetch_interval` parameter in the integration instance configuration.
  2. BThe `timeout` argument within the `BaseClient`'s `_http_request` method.
  3. CThe `long_running_command` flag in the integration YAML.
  4. DThe `timeout` parameter in the `demisto.command()` decorator.
Show answer & explanation

Correct answer: B. The `timeout` argument within the `BaseClient`'s `_http_request` method.

The `timeout` argument within the `BaseClient`'s `_http_request` method (or its wrapper `self._http_request`) directly controls the maximum time to wait for a response from the external API. Increasing this value will allow the integration to wait longer for high-latency responses.

Why the other options are wrong

  • A. `fetch_interval` controls how often the integration fetches incidents, not the timeout for individual API requests.
  • C. `long_running_command` prevents XSOAR from killing a command, but doesn't configure the HTTP request timeout itself.
  • D. The `timeout` in `demisto.command()` is for the *command execution* timeout within XSOAR, not the HTTP request timeout.

HTTP Request Timeout

A configurable parameter that specifies the maximum amount of time an integration will wait for a response from an external API after sending an HTTP request, before raising a timeout error.

  • Prevents indefinite waiting for responses.
  • Typically configured in the `_http_request` method.
  • Important for stability with high-latency APIs.

Memory trick: HTTP Request Timeout: Patience is a virtue for slow APIs.

More Integrations questions