Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A security engineer is troubleshooting a custom integration that uses a self-deployed engine. The integration tests successfully, but when a playbook attempts to run a command from this integration, it fails with an error indicating that the integration instance cannot be found or accessed. The engineer confirms the integration instance is enabled and configured correctly. What is the most likely cause of this issue?

  1. AThe XSOAR server's firewall is blocking outbound traffic to the external service.
  2. BThe integration's API key has expired, preventing authentication.
  3. CThe self-deployed engine is offline or unreachable from the XSOAR server.
  4. DThe playbook is trying to execute a command that is not defined in the integration.
Show answer & explanation

Correct answer: C. The self-deployed engine is offline or unreachable from the XSOAR server.

If an integration runs on a self-deployed engine, and the playbook cannot access it, it strongly suggests that the engine itself is unavailable or unreachable by the XSOAR server. The 'integration tests successfully' implies the configuration (API key, commands) is correct, but if the engine is offline, the XSOAR server cannot dispatch commands to it.

Why the other options are wrong

  • A. If the XSOAR server's firewall was blocking traffic, the *integration test* would also likely fail, as it would be initiated from the engine (or XSOAR server if not using an engine). The engine itself needs to be reachable.
  • B. An expired API key would typically result in an authentication error from the external service, not an 'integration instance cannot be found' error from XSOAR.
  • D. If the command was undefined, the error would likely be 'unknown command' or similar, not an access issue with the instance itself.

Troubleshooting Self-Deployed Engines

If an integration instance on a self-deployed engine is inaccessible by playbooks, the engine's operational status or network connectivity to the XSOAR server is a primary suspect.

  • Self-deployed engines run integrations closer to protected resources.
  • Require stable network connectivity to the XSOAR server.
  • Must be running and healthy to execute commands.

Memory trick: Engine offline means no command line.

More Integrations questions