Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A SOC engineer is building a custom integration with a ticketing system that returns a unique identifier (UUID) for each ticket created. This UUID is critical for subsequent operations (e.g., updating the ticket). The engineer needs to ensure that when a command like `ticketing-create-ticket` is executed, the UUID is not only displayed in the war room but also stored as structured data in the incident context for later use by playbooks. Which XSOAR function should the engineer use to achieve this?

  1. A`demisto.results()`
  2. B`return_results()`
  3. C`demisto.setContext()`
  4. D`demisto.executeCommand()`
Show answer & explanation

Correct answer: B. `return_results()`

The `return_results()` function (or `CommandResults` object passed to it) is the correct way to return data from an integration command. It allows specifying both the human-readable output (for the War Room) and the structured data to be stored in the incident context, ensuring the UUID is available for playbooks.

Why the other options are wrong

  • A. `demisto.results()` is an older function primarily for printing raw output to the War Room and does not effectively set structured context data.
  • C. `demisto.setContext()` directly sets context, but `return_results()` is preferred as it combines War Room output with context updates and handles error formatting.
  • D. `demisto.executeCommand()` is used to run other XSOAR commands from within a script or integration, not to return results from the current command.

return_results() Function

The XSOAR function used in Python scripts and integrations to return data, both human-readable and structured, to the War Room and incident context.

  • Preferred method for command output.
  • Takes a `CommandResults` object or dictionary.
  • Allows setting `readable_output`, `outputs`, and `raw_response`.

Memory trick: Return results to show, store, and make playbooks go.

More Integrations questions