Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A security analyst is troubleshooting a custom integration in Cortex XSOAR that frequently encounters `429 Too Many Requests` errors from a third-party API. The API documentation suggests implementing an exponential backoff strategy with a maximum of 5 retries and an initial delay of 1 second. Which `BaseClient` parameter or method should be configured to automatically handle these rate limiting errors?

  1. AAdjust the `fetch_max_events` parameter in the integration instance configuration.
  2. BSet `self._timeout` to a higher value in the `BaseClient` constructor.
  3. CConfigure `retries` and `backoff_factor` in the `BaseClient` constructor for `requests`.
  4. DImplement a custom retry logic within the `_http_request` method using `time.sleep()`.
Show answer & explanation

Correct answer: C. Configure `retries` and `backoff_factor` in the `BaseClient` constructor for `requests`.

The `BaseClient` in Cortex XSOAR (which internally uses the `requests` library) supports configuring retry mechanisms directly. By setting `retries` to 5 and `backoff_factor` to 1 in the `BaseClient` constructor, an exponential backoff strategy is automatically applied for HTTP errors like 429.

Why the other options are wrong

  • A. `fetch_max_events` controls the number of incidents fetched per run for a feed integration, unrelated to API rate limiting retries.
  • B. Increasing `_timeout` only affects how long to wait for a response, not how to retry after a 429 error.
  • D. While effective, this is a less efficient and more complex solution than leveraging the built-in `BaseClient` retry mechanism provided by `requests`.

BaseClient Exponential Backoff

The Cortex XSOAR `BaseClient` can be configured to automatically retry failed HTTP requests (e.g., `429 Too Many Requests`) using an exponential backoff strategy via `retries` and `backoff_factor` parameters.

  • Leverages `requests` library's retry capabilities.
  • Configured in the `BaseClient` constructor.
  • Handles temporary network issues and rate limits.
  • Retries increase wait time exponentially.

Memory trick: Retries and Backoff Factor: The Rate Limit Rescuers.

More Integrations questions