Palo Alto Networks Certified Security Automation Engineer (PCSAE)IntegrationsMedium

A SOC engineer is updating a custom integration for Cortex XSOAR. The integration currently uses `demisto.results()` to output a simple string message to the War Room. The requirement has changed to also include a raw JSON object in the War Room output, which contains additional diagnostic details, without making it the primary readable output. How should the engineer modify the `demisto.results()` call to achieve this?

  1. AUse `demisto.debug()` to print the JSON object to the War Room.
  2. BCall `demisto.results()` twice, once for the string and once for the JSON.
  3. CPass a dictionary to `demisto.results()` with `ContentsFormat` set to `json` and `Contents` as the JSON object.
  4. DInclude the raw JSON object directly within the string message.
Show answer & explanation

Correct answer: C. Pass a dictionary to `demisto.results()` with `ContentsFormat` set to `json` and `Contents` as the JSON object.

To output both a readable string and a raw JSON object to the War Room, `demisto.results()` should be called with a dictionary containing `Type: EntryType.NOTE`, `ContentsFormat: EntryFormat.JSON`, and `Contents` as the JSON object. This creates a separate entry in the War Room for the JSON data, visible as a raw JSON block.

Why the other options are wrong

  • A. `demisto.debug()` prints to the XSOAR logs, not directly to the War Room for user visibility.
  • B. Calling `demisto.results()` twice creates two separate entries, but the question asks for *including* raw JSON, typically as a secondary part of a single logical output.
  • D. Including JSON directly in a string message makes it unreadable and unparseable in the War Room UI.

War Room Raw JSON Output

In Cortex XSOAR custom integrations, outputting raw JSON to the War Room using `demisto.results()` by providing a dictionary with `ContentsFormat: EntryFormat.JSON` and the JSON data in the `Contents` field, making it viewable as a collapsible JSON block.

  • Uses `demisto.results()` with a dictionary.
  • Requires `ContentsFormat: EntryFormat.JSON`.
  • Displays as a raw, collapsible JSON block in War Room.

Memory trick: Results are versatile: just structure the content right.

More Integrations questions