Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A SOC engineer is building a custom integration that interacts with a threat intelligence platform. The platform's API returns a large JSON object containing various indicators, but for the War Room, only a subset of specific indicator types and their values are relevant. How should the `return_results()` function be used to display only the necessary information clearly in the War Room?

  1. AReturn multiple `CommandResults` objects, one for each relevant indicator type.
  2. BUse `return_results(CommandResults(readable_output=parsed_data))` after filtering and formatting the JSON.
  3. CStore the full JSON in context and reference it with `return_results('See context for full data')`.
  4. DReturn the raw JSON object directly using `return_results(json.dumps(raw_data))`.
Show answer & explanation

Correct answer: B. Use `return_results(CommandResults(readable_output=parsed_data))` after filtering and formatting the JSON.

The `CommandResults` object, specifically its `readable_output` field, is designed for presenting formatted and concise information to the War Room. By filtering and formatting the large JSON object into a human-readable summary before passing it to `readable_output`, the engineer ensures clarity and relevance for the War Room user.

Why the other options are wrong

  • A. Returning multiple `CommandResults` for a single command might clutter the War Room and isn't typically how a summary of indicators is presented.
  • C. While storing in context is good for machine readability, a direct War Room output is still needed for immediate analyst consumption.
  • D. Returning raw JSON makes the War Room output noisy and difficult to parse for analysts.

War Room Readable Output

To present relevant, filtered, and formatted information from an integration command in the Cortex XSOAR War Room, use the `CommandResults` object with its `readable_output` field.

  • Designed for human readability.
  • Supports Markdown for formatting.
  • Focuses on concise, relevant information.

Memory trick: For 'readable' results, 'command' the output to be 'short and sweet'.

More Integrations questions