Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium
A security engineer is developing a custom integration for Cortex XSOAR. The integration needs to perform a series of operations that might take several minutes to complete, such as querying a large database or initiating a long-running scan. The engineer wants to ensure that the integration's output (results, errors) from these potentially long operations is reliably captured and displayed in the War Room, even if the connection to the XSOAR server is temporarily lost or the integration container restarts. Which `demisto` function should be used to ensure persistent output capture?
- A`demisto.results()`
- B`demisto.debug()`
- C`demisto.setContext()`
- D`demisto.log()`
Show answer & explanationAnswer & explanation
Correct answer: A. `demisto.results()`
`demisto.results()` is specifically designed to send output to the War Room and ensures that this output is persisted and displayed, even for long-running commands or in cases of connectivity issues or container restarts, thus serving as the primary method for returning command results.
Why the other options are wrong
- B. `demisto.debug()` is for internal debugging messages that appear in the integration logs, not for user-facing command output in the War Room.
- C. `demisto.setContext()` is used to store data in the incident context for playbook automation and data sharing, but it doesn't directly display output in the War Room in a user-friendly format for command results.
- D. `demisto.log()` is for general logging messages that appear in the integration logs, similar to `demisto.debug()`, and not for displaying command results in the War Room.
War Room Output Persistence
In Cortex XSOAR, `demisto.results()` is the primary function for sending command output to the War Room. It ensures that output is persisted and displayed to the user, even for long-running commands or if the integration's execution environment encounters temporary disruptions.
- Sends output to the War Room.
- Ensures persistence of results.
- Handles various output types (text, markdown, file, JSON).
Memory trick: Results are for the Room, Context is for the Code.