Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium
A security analyst is developing a custom integration for Cortex XSOAR that needs to create incidents in the platform. The integration is designed to process external alerts and generate a corresponding incident in XSOAR. To ensure the incident is properly attributed and searchable, the analyst wants to include a custom field, `external_alert_id`, with the ID from the external system. How should this custom field be included when creating the incident from the integration?
- AAppend the `external_alert_id` as a tag to the incident.
- BInclude `external_alert_id` in the incident name or details field.
- CCreate a new argument for the `create-incident` command in the integration YAML to pass the ID.
- DAdd `external_alert_id` directly to the `demisto.incident()` function call within the `customFields` dictionary.
Show answer & explanationAnswer & explanation
Correct answer: D. Add `external_alert_id` directly to the `demisto.incident()` function call within the `customFields` dictionary.
Custom incident fields in Cortex XSOAR are populated by passing a dictionary of these fields and their values to the `customFields` parameter within the `demisto.incident()` function or when creating an incident via the API. This ensures proper data structuring and searchability.
Why the other options are wrong
- A. Tags are useful for general categorization but are not designed for specific key-value data points like an external ID, and are not easily searchable as custom fields.
- B. Embedding structured data like an ID within free-text fields (name or details) makes it difficult to extract, search, and automate based on that specific value.
- C. While you might create an argument to *receive* the ID, the question asks how to *include* it when creating the incident in XSOAR, which is done via the `customFields` parameter of `demisto.incident()`.
Incident Custom Fields
Custom fields in Cortex XSOAR incidents allow for storing structured, user-defined data points specific to an incident type, enhancing data enrichment, searchability, and automation capabilities.
- Defined in XSOAR settings (Settings > Object Setup > Incidents > Incident Fields).
- Populated via the `customFields` parameter in `demisto.incident()` or API calls.
- Enable structured data storage and advanced querying.
Memory trick: Custom Fields Craft Clear Context.