Palo Alto Networks Certified Security Automation Engineer (PCSAE)PlaybooksMedium

A security engineer is optimizing a playbook that involves fetching logs from an external system. The playbook is designed to fetch logs for the last 24 hours. The engineer wants to ensure that the time range for fetching logs is dynamic and always relative to the current playbook execution time. The task input for the time range expects a string like `1 day ago`. Which XSOAR function should be used in the task input to achieve this dynamic time calculation?

  1. Adate('now - 1 day')
  2. Bnow() - 1 day
  3. Csubtract(now(), '1 day')
  4. Ddatetime.now() - timedelta(days=1)
Show answer & explanation

Correct answer: A. date('now - 1 day')

The `date()` function in XSOAR, when used with a string like 'now - 1 day', correctly calculates a relative timestamp. This is the idiomatic way to handle dynamic time calculations for task inputs.

Why the other options are wrong

  • B. This is not a valid XSOAR function for date calculations.
  • C. While `subtract` might exist in some contexts, `date('now - X')` is the standard and most direct XSOAR function for this use case.
  • D. This is Python syntax and would only work within a script task, not directly in a task input field.

Dynamic Date/Time Calculation

Dynamic date/time calculation in XSOAR playbooks involves using built-in functions like `date()` with relative time expressions to generate timestamps that adjust based on the current execution time.

  • Uses `date()` function.
  • Supports relative time expressions (e.g., 'now - 1 day', 'tomorrow').
  • Ensures playbooks always operate on current time ranges.

Memory trick: Time flies, but with `date()`, your playbook ties to the now.

More Playbooks questions