Cisco Secure Firewall Intelligence API

The Intelligence API from Cisco Secure Firewall — 13 operation(s) for intelligence.

OpenAPI Specification

cisco-secure-firewall-intelligence-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Cisco Secure Firewall Intelligence API
  version: 1.13.0
  contact:
    name: Cisco Firepower TAC
    email: ngfw-support@cisco.com
  description: 'Operations tagged Intelligence across 2 of this provider''s published API definitions: cdfmc-openapi.yaml,
    cisco-secure-firewall-cdfmc-openapi.yml. Each path carries the servers of the definition it was published in.'
  x-provenance:
    method: harvested
    first_party: true
    harvested: '2026-08-19'
    source: https://raw.githubusercontent.com/CiscoDevNet/scc-public-api-docs/main/cdo/cdfmc-openapi.yaml
    source_repo: https://github.com/CiscoDevNet/scc-public-api-docs
    note: Verbatim first-party OpenAPI published by Cisco in the CiscoDevNet scc-public-api-docs repository, the source of
      record for developer.cisco.com/docs/cisco-security-cloud-control-firewall-manager/. Not authored or modified by API
      Evangelist.
    derived_view: Per-tag view of cisco-secure-firewall-cdfmc-openapi.yml, the provider's source document. Operations and
      schemas are the provider's, unmodified; only the partition is ours.
    derived_from: cisco-secure-firewall-cdfmc-openapi.yml
    operation_coverage: 21/21
  x-evidence:
    fetched: '2026-08-19'
    url: https://raw.githubusercontent.com/CiscoDevNet/scc-public-api-docs/main/cdo/cdfmc-openapi.yaml
    http_status: 200
servers:
- url: https://api.us.security.cisco.com/firewall
  description: US
- url: https://api.eu.security.cisco.com/firewall
  description: EU
- url: https://api.apj.security.cisco.com/firewall
  description: APJ
- url: https://api.au.security.cisco.com/firewall
  description: AUS
- url: https://api.in.security.cisco.com/firewall
  description: IN
- url: https://api.int.security.cisco.com/firewall
  description: Staging
- url: https://scale.manage.security.cisco.com/api/rest
  description: Scale
- url: https://ci.manage.security.cisco.com/api/rest
  description: CI
- url: https://manage.stg.secure.cisco/api/rest
  description: Stgf9
tags:
- name: Intelligence
paths:
  /v1/cdfmc/api/fmc_tid/v1/domain/{domainUUID}/taxiiconfig/collections:
    post:
      deprecated: false
      description: '**API Operations on Taxii Collection objects. _Check the response section for applicable examples (if
        any)._**'
      operationId: createRESTTaxiiCollection
      parameters:
      - $ref: '#/components/parameters/domainUUID'
        name: domainUUID
      requestBody:
        content:
          application/json:
            examples:
              'Example 1 : POST /fmc_tid/v1/domain/domainUUID/taxiiconfig/collections ( POST Example for collections )':
                value:
                  caCert: ''
                  clientCert: ''
                  clientPrivateKey: ''
                  discoveryInfo:
                  - collectionAddress: http://hailataxii.com:80/taxii-data
                    collectionContentBinding: '[]'
                    collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                    collectionName: DISCOVERY
                    collectionPollIntervalInMinutes: 0
                    collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                    type: taxii_collections
                  - collectionAddress: http://hailataxii.com:80/taxii-data
                    collectionContentBinding: '[]'
                    collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                    collectionName: COLLECTION_MANAGEMENT
                    collectionPollIntervalInMinutes: 0
                    collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                    type: taxii_collections
                  - collectionAddress: http://hailataxii.com:80/taxii-data
                    collectionContentBinding: '[]'
                    collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                    collectionName: POLL
                    collectionPollIntervalInMinutes: 0
                    collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                    type: taxii_collections
                  params:
                    hostnameVerifier: allow_all
                    selfSignedServerCertificate: 'false'
                  passwd: password
                  type: source
                  uri: http://hailataxii.com/taxii-discovery-service
                  username: username
                  version: 0.1.0
            schema:
              $ref: '#/components/schemas/RESTTaxiiCollection'
              type: object
        description: The input Taxii Collection object model.
        required: true
      responses:
        '201':
          content:
            application/json:
              examples:
                'Example 1 : POST /fmc_tid/v1/domain/domainUUID/taxiiconfig/collections ( POST Example for collections )':
                  value:
                    availableCollections:
                    - collectionAddress: http://hailataxii.com:80/taxii-data
                      collectionDescription: guest.Abuse_ch
                      collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                      collectionName: guest.Abuse_ch
                      collectionPollIntervalInMinutes: 0
                      collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                      type: taxii_collections
                    - collectionAddress: http://hailataxii.com:80/taxii-data
                      collectionDescription: guest.CyberCrime_Tracker
                      collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                      collectionName: guest.CyberCrime_Tracker
                      collectionPollIntervalInMinutes: 0
                      collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                      type: taxii_collections
                    - collectionAddress: http://hailataxii.com:80/taxii-data
                      collectionDescription: guest.EmergineThreats_rules
                      collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                      collectionName: guest.EmergineThreats_rules
                      collectionPollIntervalInMinutes: 0
                      collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                      type: taxii_collections
                    - collectionAddress: http://hailataxii.com:80/taxii-data
                      collectionDescription: guest.EmergingThreats_rules
                      collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                      collectionName: guest.EmergingThreats_rules
                      collectionPollIntervalInMinutes: 0
                      collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                      type: taxii_collections
                    - collectionAddress: http://hailataxii.com:80/taxii-data
                      collectionDescription: guest.Lehigh_edu
                      collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                      collectionName: guest.Lehigh_edu
                      collectionPollIntervalInMinutes: 0
                      collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                      type: taxii_collections
                    - collectionAddress: http://hailataxii.com:80/taxii-data
                      collectionDescription: guest.MalwareDomainList_Hostlist
                      collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                      collectionName: guest.MalwareDomainList_Hostlist
                      collectionPollIntervalInMinutes: 0
                      collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                      type: taxii_collections
                    - collectionAddress: http://hailataxii.com:80/taxii-data
                      collectionDescription: guest.blutmagie_de_torExits
                      collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                      collectionName: guest.blutmagie_de_torExits
                      collectionPollIntervalInMinutes: 0
                      collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                      type: taxii_collections
                    - collectionAddress: http://hailataxii.com:80/taxii-data
                      collectionDescription: guest.dataForLast_7daysOnly
                      collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                      collectionName: guest.dataForLast_7daysOnly
                      collectionPollIntervalInMinutes: 0
                      collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                      type: taxii_collections
                    - collectionAddress: http://hailataxii.com:80/taxii-data
                      collectionDescription: guest.dshield_BlockList
                      collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                      collectionName: guest.dshield_BlockList
                      collectionPollIntervalInMinutes: 0
                      collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                      type: taxii_collections
                    - collectionAddress: http://hailataxii.com:80/taxii-data
                      collectionDescription: guest.phishtank_com
                      collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                      collectionName: guest.phishtank_com
                      collectionPollIntervalInMinutes: 0
                      collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                      type: taxii_collections
                    - collectionAddress: http://hailataxii.com:80/taxii-data
                      collectionDescription: system.Default
                      collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                      collectionName: system.Default
                      collectionPollIntervalInMinutes: 0
                      collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                      type: taxii_collections
                    consumedIndicators: 0
                    consumedObservables: 0
                    consumedUnsupportedObservables: 0
                    discardedIndicators: 0
                    discoveryInfo:
                    - collectionAddress: http://hailataxii.com:80/taxii-data
                      collectionContentBinding: '[]'
                      collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                      collectionName: DISCOVERY
                      collectionPollIntervalInMinutes: 0
                      collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                      type: taxii_collections
                    - collectionAddress: http://hailataxii.com:80/taxii-data
                      collectionContentBinding: '[]'
                      collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                      collectionName: COLLECTION_MANAGEMENT
                      collectionPollIntervalInMinutes: 0
                      collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                      type: taxii_collections
                    - collectionAddress: http://hailataxii.com:80/taxii-data
                      collectionContentBinding: '[]'
                      collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                      collectionName: POLL
                      collectionPollIntervalInMinutes: 0
                      collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                      type: taxii_collections
                    downloadOn: false
                    feedStatus: new
                    id: sourceUUID
                    invalidObservables: 0
                    lastRun: 0
                    nextRun: 0
                    params:
                      hostnameVerifier: allow_all
                      selfSignedServerCertificate: 'false'
                    passwd: password
                    property:
                      action: monitor
                      allowlist: false
                      expirationTime: 0
                      publish: true
                      ttl: 90
                    refresh: 0
                    runNow: false
                    totalDiscardedIndicators: 0
                    totalIndicators: 0
                    totalInvalidObservables: 0
                    totalObservables: 0
                    totalUnsupportedObservables: 0
                    type: source
                    uri: http://hailataxii.com/taxii-discovery-service
                    username: username
              schema:
                $ref: '#/components/schemas/RESTTaxiiCollection'
                type: object
          description: Created
        default:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                type: object
          description: Error
      tags:
      - Intelligence
    servers:
    - url: https://api.us.security.cisco.com/firewall
      description: US
    - url: https://api.eu.security.cisco.com/firewall
      description: EU
    - url: https://api.apj.security.cisco.com/firewall
      description: APJ
    - url: https://api.au.security.cisco.com/firewall
      description: AUS
    - url: https://api.in.security.cisco.com/firewall
      description: IN
    - url: https://api.int.security.cisco.com/firewall
      description: Staging
    - url: https://scale.manage.security.cisco.com/api/rest
      description: Scale
    - url: https://ci.manage.security.cisco.com/api/rest
      description: CI
    - url: https://manage.stg.secure.cisco/api/rest
      description: Stgf9
  /v1/cdfmc/api/fmc_tid/v1/domain/{domainUUID}/taxiiconfig/discoveryinfo:
    post:
      deprecated: false
      description: '**API Operations on Discovery Info objects. _Check the response section for applicable examples (if any)._**'
      operationId: createRESTDiscoveryInfo
      parameters:
      - $ref: '#/components/parameters/domainUUID'
        name: domainUUID
      requestBody:
        content:
          application/json:
            examples:
              'Example 1 : POST /fmc_tid/v1/domain/domainUUID/taxiiconfig/discoveryinfo ( POST Example for discoveryinfo )':
                value:
                  caCert: ''
                  clientCert: ''
                  clientPrivateKey: ''
                  params:
                    hostnameVerifier: allow_all
                    selfSignedServerCertificate: 'false'
                  passwd: password
                  type: source
                  uri: http://hailataxii.com/taxii-discovery-service
                  username: username
                  version: 0.1.0
            schema:
              $ref: '#/components/schemas/RESTDiscoveryInfo'
              type: object
        description: The input Discovery Info object model.
        required: true
      responses:
        '201':
          content:
            application/json:
              examples:
                'Example 1 : POST /fmc_tid/v1/domain/domainUUID/taxiiconfig/discoveryinfo ( POST Example for discoveryinfo )':
                  value:
                    consumedIndicators: 0
                    consumedObservables: 0
                    consumedUnsupportedObservables: 0
                    discardedIndicators: 0
                    discoveryInfo:
                    - collectionAddress: http://hailataxii.com:80/taxii-data
                      collectionContentBinding: '[]'
                      collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                      collectionName: DISCOVERY
                      collectionPollIntervalInMinutes: 0
                      collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                      type: taxii_collections
                    - collectionAddress: http://hailataxii.com:80/taxii-data
                      collectionContentBinding: '[]'
                      collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                      collectionName: COLLECTION_MANAGEMENT
                      collectionPollIntervalInMinutes: 0
                      collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                      type: taxii_collections
                    - collectionAddress: http://hailataxii.com:80/taxii-data
                      collectionContentBinding: '[]'
                      collectionMessageBinding: '[urn:taxii.mitre.org:message:xml:1.1]'
                      collectionName: POLL
                      collectionPollIntervalInMinutes: 0
                      collectionProtocolBinding: urn:taxii.mitre.org:protocol:https:1.0
                      type: taxii_collections
                    downloadOn: false
                    feedStatus: new
                    id: id
                    invalidObservables: 0
                    lastRun: 0
                    nextRun: 0
                    params:
                      hostnameVerifier: allow_all
                      selfSignedServerCertificate: 'false'
                    passwd: password
                    property:
                      action: monitor
                      allowlist: false
                      expirationTime: 0
                      publish: true
                      ttl: 90
                    refresh: 0
                    runNow: false
                    totalDiscardedIndicators: 0
                    totalIndicators: 0
                    totalInvalidObservables: 0
                    totalObservables: 0
                    totalUnsupportedObservables: 0
                    type: source
                    uri: http://hailataxii.com/taxii-discovery-service
                    username: username
              schema:
                $ref: '#/components/schemas/RESTDiscoveryInfo'
                type: object
          description: Created
        default:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                type: object
          description: Error
      tags:
      - Intelligence
    servers:
    - url: https://api.us.security.cisco.com/firewall
      description: US
    - url: https://api.eu.security.cisco.com/firewall
      description: EU
    - url: https://api.apj.security.cisco.com/firewall
      description: APJ
    - url: https://api.au.security.cisco.com/firewall
      description: AUS
    - url: https://api.in.security.cisco.com/firewall
      description: IN
    - url: https://api.int.security.cisco.com/firewall
      description: Staging
    - url: https://scale.manage.security.cisco.com/api/rest
      description: Scale
    - url: https://ci.manage.security.cisco.com/api/rest
      description: CI
    - url: https://manage.stg.secure.cisco/api/rest
      description: Stgf9
  /v1/cdfmc/api/fmc_tid/v1/domain/{domainUUID}/tid/element:
    get:
      deprecated: false
      description: '**API Operations on Element objects.**'
      operationId: getAllRESTElement
      parameters:
      - $ref: '#/components/parameters/domainUUID'
        name: domainUUID
      - $ref: '#/components/parameters/offset'
        name: offset
      - $ref: '#/components/parameters/limit'
        name: limit
      - $ref: '#/components/parameters/expanded'
        name: expanded
      responses:
        '200':
          content:
            application/json:
              examples:
                'Example 1 : GET /fmc_tid/v1/domain/domainUUID/tid/elementUUID ( Get all ElementModel instances. )':
                  value:
                    items:
                    - id: elementUUID
                      name: Element Name
                      type: element
                    links:
                      self: /fmc_tid/v1/domain/domainUUID/tid/elementUUID
                    paging:
                      count: 1
                      limit: 1
                      offset: 0
                      pages: 1
              schema:
                $ref: '#/components/schemas/RESTElementListContainer'
                type: object
          description: OK
        default:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                type: object
          description: Error
      tags:
      - Intelligence
    servers:
    - url: https://api.us.security.cisco.com/firewall
      description: US
    - url: https://api.eu.security.cisco.com/firewall
      description: EU
    - url: https://api.apj.security.cisco.com/firewall
      description: APJ
    - url: https://api.au.security.cisco.com/firewall
      description: AUS
    - url: https://api.in.security.cisco.com/firewall
      description: IN
    - url: https://api.int.security.cisco.com/firewall
      description: Staging
    - url: https://scale.manage.security.cisco.com/api/rest
      description: Scale
    - url: https://ci.manage.security.cisco.com/api/rest
      description: CI
    - url: https://manage.stg.secure.cisco/api/rest
      description: Stgf9
  /v1/cdfmc/api/fmc_tid/v1/domain/{domainUUID}/tid/element/{objectId}:
    get:
      deprecated: false
      description: '**API Operations on Element objects.**'
      operationId: getRESTElement
      parameters:
      - description: Unique identifier of the Element.
        in: path
        name: objectId
        required: true
        schema:
          type: string
      - $ref: '#/components/parameters/domainUUID'
        name: domainUUID
      responses:
        '200':
          content:
            application/json:
              examples:
                'Example 1 : GET /fmc_tid/v1/domain/domainUUID/tid/element/elementUUID ( Get a single ElementModel instance )':
                  value:
                    caCert: '-----BEGIN CACERTIFICATE-----

                      MIIGLT...

                      -----END CACERTIFICATE-----

                      '
                    cert: '-----BEGIN CERTIFICATE-----

                      MIIGLT...

                      -----END CERTIFICATE-----

                      '
                    id: elementUUID
                    key: 'REDACTED_PRIVATE_KEY_EXAMPLE

                      '
                    links:
                      self: /fmc_tid/v1/domain/domainUUID/tid/element/elementUUID
                    miscData:
                      policyId: Sample Policy Id
                      policyName: Sample Policy
                      tidStatus: '1'
                    model: Sample Model
                    name: Sample Element
                    registrationDate: '1457566762'
                    status: SampleStatus
                    type: element
              schema:
                $ref: '#/components/schemas/RESTElement'
                type: object
          description: OK
        default:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                type: object
          description: Error
      tags:
      - Intelligence
    servers:
    - url: https://api.us.security.cisco.com/firewall
      description: US
    - url: https://api.eu.security.cisco.com/firewall
      description: EU
    - url: https://api.apj.security.cisco.com/firewall
      description: APJ
    - url: https://api.au.security.cisco.com/firewall
      description: AUS
    - url: https://api.in.security.cisco.com/firewall
      description: IN
    - url: https://api.int.security.cisco.com/firewall
      description: Staging
    - url: https://scale.manage.security.cisco.com/api/rest
      description: Scale
    - url: https://ci.manage.security.cisco.com/api/rest
      description: CI
    - url: https://manage.stg.secure.cisco/api/rest
      description: Stgf9
  /v1/cdfmc/api/fmc_tid/v1/domain/{domainUUID}/tid/incident:
    get:
      deprecated: false
      description: '**API Operations on Incident objects.**'
      operationId: getAllRESTIncident
      parameters:
      - $ref: '#/components/parameters/domainUUID'
        name: domainUUID
      - $ref: '#/components/parameters/offset'
        name: offset
      - $ref: '#/components/parameters/limit'
        name: limit
      - $ref: '#/components/parameters/expanded'
        name: expanded
      responses:
        '200':
          content:
            application/json:
              examples:
                'Example 1 : GET /fmc_tid/v1/domain/domainUUID/tid/incident ( Example of GET all incidents (concise view) )':
                  value:
                    items:
                    - id: incidentUUID
                      links:
                        self: /fmc_tid/v1/domain/domainUUID/tid/incident/incidentUUID
                      type: incident
                    - id: incidentUUID
                      links:
                        self: /fmc_tid/v1/domain/domainUUID/tid/incident/incidentUUID
                      type: incident
                    - id: incidentUUID
                      links:
                        self: /fmc_tid/v1/domain/domainUUID/tid/incident/incidentUUID
                      type: incident
                    - id: incidentUUID
                      links:
                        self: /fmc_tid/v1/domain/domainUUID/tid/incident/incidentUUID
                      type: incident
                    - id: incidentUUID
                      links:
                        self: /fmc_tid/v1/domain/domainUUID/tid/incident/incidentUUID
                      type: incident
                    - id: incidentUUID
                      links:
                        self: /fmc_tid/v1/domain/domainUUID/tid/incident/incidentUUID
                      type: incident
                    - id: incidentUUID
                      links:
                        self: /fmc_tid/v1/domain/domainUUID/tid/incident/incidentUUID
                      type: incident
                    links:
                      self: /fmc_tid/v1/domain/domainUUID/tid/incident
                    paging:
                      count: 7
                      limit: 7
                      offset: 0
                      pages: 1
                ? 'Example 2 : GET /fmc_tid/v1/domain/domainUUID/tid/incident?filter=updatedAt%3A1498629923..1499839523 (
                  Example of GET all incidents (with filter) )'
                : value:
                    items:
                    - id: incidentUUID
                      links:
                        self: /fmc_tid/v1/domain/domainUUID/tid/incident/incidentUUID
                      type: incident
                    - id: incidentUUID
                      links:
                        self: /fmc_tid/v1/domain/domainUUID/tid/incident/incidentUUID
                      type: incident
                    - id: incidentUUID
                      links:
                        self: /fmc_tid/v1/domain/domainUUID/tid/incident/incidentUUID
                      type: incident
                    - id: incidentUUID
                      links:
                        self: /fmc_tid/v1/domain/domainUUID/tid/incident/incidentUUID
                      type: incident
                    - id: incidentUUID
                      links:
                        self: /fmc_tid/v1/domain/domainUUID/tid/incident/incidentUUID
                      type: incident
                    - id: incidentUUID
                      links:
                        self: /fmc_tid/v1/domain/domainUUID/tid/incident/incidentUUID
                      type: incident
                    - id: incidentUUID
                      links:
                        self: /fmc_tid/v1/domain/domainUUID/tid/incident/incidentUUID
                      type: incident
                    links:
                      self: /fmc_tid/v1/domain/domainUUID/tid/incident?filter=updatedAt:1498629923..1499839523
                    paging:
                      count: 7
                      limit: 7
                      offset: 0
                      pages: 1
                'Example 3 : GET /fmc_tid/v1/domain/domainUUID/tid/incident?expanded=true ( Example of GET all incidents (expanded view) )':
                  value:
                    items:
                    - actionTaken: monitored
                      description: 123 blah
                      equation:
                        children:
                        - applyCondition: ANY
                          children:
                          - isRealized: false
                            type: LL_UNSUPPORTED_OBJECT_TYPE|Port
                            value: IDREF:{http://hailataxii.com}Observable-fc5c11a8-b038-4abc-9641-2b495c78774a
                          condition: EQUALS
                          isRealized: false
                        - applyCondition: ANY
                          children:
                          - isRealized: false
                            type: DomainNameObjectType
                            value: domainNameValue
                          condition: EQUALS
                          isRealized: false
                        - applyCondition: ANY
                          children:
                          - isRealized: true
                            type: IPV_4_ADDR
                            value: ipAddressValue
                          condition: EQUALS
                          isRealized: true
                        isRealized: true
                        op: OR
                      feedId: feedUUID
                      id: incidentUUID
                      indicatorId: indicatorUUID
                      indicatorName: Test Indicators
                      links:
                        self: /fmc_tid/v1/domain/domainUUID/tid/incident/incidentUUID
                      observations:
                      - count: 1
                        data:
                          actionTaken: none
                          miscData:
                            appId: ICMP
                            clientId: ICMP client
                            connectionSec: '1498739637'
                            counter: '83'
                            destIpAddress: ipAddressValue
                            destPort: '0'
                            destZone: AutomatedInlineSZ
                            instanceId: '1'
                            protocol: ICMP
                            srcIpAddress: ipAddressValue
                            srcPort: '8'
                            srcZone: AutomatedInlineSZ
                            userId: No Authentication Required
                          type: IPV_4_ADDR
                          value: ipAddressValue
                        elementId: elementUUID
                        elementName: elementName
                        timestamp: 1498739637.0
                        type: observation
                      property:
                        action: monitor
                        allowlist: false
                        expirationTime: 1506514677.0
                        publish: true
                        ttl: 90
                      realizedAt: 1498739702.0
                      sourceName: guest.dataForLast_7daysOnly
                      status: new
                      type: incident
                      updatedAt: 1499839877.0
                      version: 1.0.0
                    - actionTaken: monitored
                      equation:
                        children:
                        - applyCondition: ANY
                          children:
                          - isRealized: false
                            type: LL_UNSUPPORTED_OBJECT_TYPE|Port
                            value: IDREF:{http://hailataxii.com}Observable-fc5c11a8-b038-4abc-9641-2b495c78774a
                          condition: EQUALS
                          isRealized: false
                        - applyCondition: ANY
                          children:
                          - isRealized: false
                            type: DomainNameObjectType
                            value: domainNameValue
                          condition: EQUALS
                          isRealized: false
                        - applyCondition: ANY
                          children:
                          - isRealized: true
                     

# --- truncated at 32 KB (165 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cisco-secure-firewall/refs/heads/main/openapi/cisco-secure-firewall-intelligence-api-openapi.yml