Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A security analyst is developing a custom integration for Cortex XSOAR that needs to create incidents in the platform. The integration is designed to process external alerts and generate a corresponding incident in XSOAR. To ensure the incident is properly attributed and searchable, the analyst wants to include a custom field, `external_alert_id`, with the ID from the external system. How should this custom field be included when creating the incident from the integration?

  1. AAppend the `external_alert_id` as a tag to the incident.
  2. BInclude `external_alert_id` in the incident name or details field.
  3. CCreate a new argument for the `create-incident` command in the integration YAML to pass the ID.
  4. DAdd `external_alert_id` directly to the `demisto.incident()` function call within the `customFields` dictionary.
Show answer & explanation

Correct answer: D. Add `external_alert_id` directly to the `demisto.incident()` function call within the `customFields` dictionary.

Custom incident fields in Cortex XSOAR are populated by passing a dictionary of these fields and their values to the `customFields` parameter within the `demisto.incident()` function or when creating an incident via the API. This ensures proper data structuring and searchability.

Why the other options are wrong

  • A. Tags are useful for general categorization but are not designed for specific key-value data points like an external ID, and are not easily searchable as custom fields.
  • B. Embedding structured data like an ID within free-text fields (name or details) makes it difficult to extract, search, and automate based on that specific value.
  • C. While you might create an argument to *receive* the ID, the question asks how to *include* it when creating the incident in XSOAR, which is done via the `customFields` parameter of `demisto.incident()`.

Incident Custom Fields

Custom fields in Cortex XSOAR incidents allow for storing structured, user-defined data points specific to an incident type, enhancing data enrichment, searchability, and automation capabilities.

  • Defined in XSOAR settings (Settings > Object Setup > Incidents > Incident Fields).
  • Populated via the `customFields` parameter in `demisto.incident()` or API calls.
  • Enable structured data storage and advanced querying.

Memory trick: Custom Fields Craft Clear Context.

More Integrations questions