Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsHard

A security engineer is developing a custom integration for Cortex XSOAR that needs to retrieve a large volume of historical logs from an external SIEM. The SIEM's API implements cursor-based pagination, where each response includes a `next_cursor` value that must be sent in the subsequent request to fetch the next batch of logs. How should the integration manage this `next_cursor` value to retrieve all pages of data?

  1. AImplement a loop within the command function that iteratively calls the API with the updated `next_cursor`.
  2. BDefine `next_cursor` as a persistent integration parameter that is updated by the integration.
  3. CStore `next_cursor` in `demisto.setContext()` and retrieve it in the next command execution.
  4. DPass `next_cursor` as a global variable that is updated after each API call.
Show answer & explanation

Correct answer: A. Implement a loop within the command function that iteratively calls the API with the updated `next_cursor`.

For cursor-based pagination within a single command execution, the most effective approach is to implement a loop within the command function. This loop iteratively calls the external API, extracting the `next_cursor` from each response and using it in the subsequent request until no more `next_cursor` is returned, signifying the end of the data.

Why the other options are wrong

  • B. Persistent integration parameters are for configuration, not for dynamic state like a `next_cursor` that changes with every page fetched. While `demisto.setIntegrationContext` can store state, a loop is needed *within* the command to process all pages.
  • C. Storing in `demisto.setContext()` is for playbook interaction across tasks, not for continuous pagination within a single command's execution.
  • D. Global variables are generally discouraged and do not persist across command executions, nor do they provide the looping mechanism needed for continuous pagination.

Cursor-Based Pagination Loop

An iterative loop implemented within a custom integration's command function that repeatedly calls an external API, extracting a `next_cursor` from each response and using it in the subsequent request to fetch all pages of data.

  • Used for APIs returning a `next_cursor` or similar token.
  • Implemented as a `while` loop within a command.
  • Fetches all pages within a single command execution.

Memory trick: Looping through cursors fetches all the pages.

More Integrations questions