Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium
An incident responder is reviewing an integration's configuration within Cortex XSOAR. The integration, which fetches incidents from an external EDR platform, has a 'Fetch incidents' checkbox enabled and a 'Last Run' timestamp that is several hours old, despite new incidents being reported in the EDR platform. The responder needs to quickly identify if the issue is with the integration's ability to pull new data or with its schedule. Which specific integration configuration parameter should the responder inspect first to diagnose the scheduling aspect?
- AIncident type mapping
- BAPI Key validity
- CFetch interval (in minutes)
- DProxy settings
Show answer & explanationAnswer & explanation
Correct answer: C. Fetch interval (in minutes)
The 'Fetch interval (in minutes)' parameter directly controls how often the integration attempts to fetch new incidents. If the 'Last Run' timestamp is old and new incidents exist, a misconfigured or excessively long fetch interval is the most direct cause related to scheduling that prevents timely incident retrieval.
Why the other options are wrong
- A. Incident type mapping affects how fetched data is categorized, not when it is fetched.
- B. API key validity would prevent any fetches, not just delay them, and usually results in authentication errors.
- D. Proxy settings affect connectivity, not the scheduling of fetches. If misconfigured, fetches would likely fail entirely.
Integration Fetch Interval
A configuration parameter in Cortex XSOAR integrations that defines how frequently the integration attempts to retrieve new incidents or data from an external source.
- Expressed in minutes.
- Crucial for timely incident ingestion.
- Can be set to 0 to disable automated fetching.
Memory trick: Fetch interval defines when data is fetched, not how it's met.