Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium
A security analyst is troubleshooting a custom integration in Cortex XSOAR that frequently encounters `429 Too Many Requests` errors from a third-party API. The API documentation suggests implementing an exponential backoff strategy with a maximum of 5 retries and an initial delay of 1 second. Which `BaseClient` parameter or method should be configured to automatically handle these rate limiting errors?
- AAdjust the `fetch_max_events` parameter in the integration instance configuration.
- BSet `self._timeout` to a higher value in the `BaseClient` constructor.
- CConfigure `retries` and `backoff_factor` in the `BaseClient` constructor for `requests`.
- DImplement a custom retry logic within the `_http_request` method using `time.sleep()`.
Show answer & explanationAnswer & explanation
Correct answer: C. Configure `retries` and `backoff_factor` in the `BaseClient` constructor for `requests`.
The `BaseClient` in Cortex XSOAR (which internally uses the `requests` library) supports configuring retry mechanisms directly. By setting `retries` to 5 and `backoff_factor` to 1 in the `BaseClient` constructor, an exponential backoff strategy is automatically applied for HTTP errors like 429.
Why the other options are wrong
- A. `fetch_max_events` controls the number of incidents fetched per run for a feed integration, unrelated to API rate limiting retries.
- B. Increasing `_timeout` only affects how long to wait for a response, not how to retry after a 429 error.
- D. While effective, this is a less efficient and more complex solution than leveraging the built-in `BaseClient` retry mechanism provided by `requests`.
BaseClient Exponential Backoff
The Cortex XSOAR `BaseClient` can be configured to automatically retry failed HTTP requests (e.g., `429 Too Many Requests`) using an exponential backoff strategy via `retries` and `backoff_factor` parameters.
- Leverages `requests` library's retry capabilities.
- Configured in the `BaseClient` constructor.
- Handles temporary network issues and rate limits.
- Retries increase wait time exponentially.
Memory trick: Retries and Backoff Factor: The Rate Limit Rescuers.