Palo Alto Networks Alert Rules API

Alert rules define what policy violations trigger alerts for cloud accounts within the selected account group and where to send the alert notifications. Alert rules give you a lot of flexibility in how you manage alerts and ensure that you can adhere to the administrative boundaries you have defined. You can create a single alert rule that alerts on all policy rules, or you can define granular alert rules that send very specific sets of alerts for specific cloud accounts, regions, and even resources to specific destinations.

Operations 5

GET /v2/alert/rule List Alert Rules V2 #
POST /alert/rule Add an Alert Rule #
GET /alert/rule/{id} Get Alert Rule by ID #
PUT /alert/rule/{id} Update Alert Rule #
DELETE /alert/rule/{id} Delete Alert Rule #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/palo-alto-networks-alert-rules-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

palo-alto-networks-alert-rules-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  contact: {}
  description: 'Access Keys are a secure way to enable programmatic access to the Prisma Cloud API. By default, only

    the System Admin has API access and can enable API access for other administrators. If you have API access,

    you can create up to two access keys. Create an access key for a limited time period and regenerate your API

    keys periodically to minimize exposure and follow security best practices.'
  title: Prisma Cloud Access Keys API Overview Alert Rules API
  version: Latest
servers:
- url: https://api.prismacloud.io
- url: https://api2.prismacloud.io
- url: https://api3.prismacloud.io
- url: https://api4.prismacloud.io
tags:
- description: 'Alert rules define what policy violations trigger alerts for cloud accounts within the selected account group

    and where to send the alert notifications.'
  name: Alert Rules
paths:
  /v2/alert/rule:
    get:
      description: 'Returns all alert rules you have permission to see based on your role. The data returned does not include an open alerts count.


        This request does not return a populated **alertRuleNotificationConfig** property

        in the response object. Use Get Alert Rule by ID

        to retrieve a response that includes a populated **alertRuleNotificationConfig** property.'
      operationId: get-alert-rules-v2
      parameters:
      - description: Process only enabled alert rules
        in: query
        name: enabled
        required: false
        schema:
          type: boolean
      responses:
        '200':
          content:
            application/json; charset=UTF-8:
              schema:
                items:
                  $ref: '#/components/schemas/PolicyScanConfigViewModel'
                type: array
          description: successful operation
        '500':
          description: internal_error
      security:
      - x-redlock-auth: []
      summary: List Alert Rules V2
      tags:
      - Alert Rules
  /alert/rule:
    post:
      description: 'Adds a new alert rule.


        By default, all alerts that this alert rule triggers will display on the Alerts page.

        You can also send Prisma Cloud alerts that this alert rule triggers to one or more third-party

        tools that you have integrated with the Prisma Cloud service. You can also configure the alert rule

        to send email notifications.


        To send a Prisma Cloud alert to a third-party tool, you must configure an **AlertRuleNotificationConfig** object

        as part of your request body parameters. The content of the **AlertRuleNotificationConfig** object

        depends on the third-party tool. If the tools require **AlertRuleNotificationConfig.id** or

        **AlertRuleNotificationConfig.templateId**, you can use

        Get Integrations to get such information.


        To add an Alert Rule, the required request body parameters are:


        * **name**

        * **description**

        * **allowAutoRemediate**

        * **enabled**

        * **target**

        * **target.accountGroups**

        * **scanAll**


        The default values for the optional boolean parameters are in the table below:


        Optional Request Body Parameter | Default

        ---------------------------------| -------

        **allowAutoRemediate** | false

        **notifyOnDismissed** | false

        **notifyOnOpen** | true

        **notifyOnResolved** | false

        **notifyOnSnoozed** | false

        **deleted** | false


        You can also specify addition **target** parameters to narrow the conditions that trigger alerts for this alert rule.


        If **policies** is empty, then Prisma Cloud will scan all policies for violations to trigger alerts.


        Under certain circumstances, you can also specify an array of **policyLabels** to identify policies. The following

        conditions must be met for you to use the **policyLabels** parameter:


        * The request body parameter **scanAll** must be false.

        * The policy associated with the policy label cannot be included in the request body parameter **policies**.'
      operationId: add-alert-rule
      requestBody:
        content:
          application/json; charset=UTF-8:
            schema:
              $ref: '#/components/schemas/PolicyScanConfigModel'
        description: Model for Policy Scan Config
        required: true
      responses:
        '200':
          content:
            application/json; charset=UTF-8:
              schema:
                $ref: '#/components/schemas/PolicyScanConfigModel'
          description: successful operation
        '400':
          description: invalid_param_value / auto_remediation_only_for_config_remediable_policies / missing_required_param / non_notification_state_selected / invalid_notification_state / invalid_resource_list_id / snooze_time_must_be_relative / dismissal_reason_required / has_overlaps_in_resource_list_rules / missing_required_param
        '500':
          description: internal_error
      security:
      - x-redlock-auth: []
      summary: Add an Alert Rule
      tags:
      - Alert Rules
  /alert/rule/{id}:
    get:
      description: Returns information about the alert rule with the specified ID.
      operationId: get-alert-rule
      parameters:
      - description: Alert rule ID (also known as the "policyScanConfigId")
        in: path
        name: id
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/json; charset=UTF-8:
              schema:
                $ref: '#/components/schemas/PolicyScanConfigViewModel'
          description: successful operation
        '400':
          description: invalid_policy_id
        '403':
          description: not_owner_or_same_role
        '404':
          description: no_results
        '500':
          description: internal_error
      security:
      - x-redlock-auth: []
      summary: Get Alert Rule by ID
      tags:
      - Alert Rules
    put:
      description: Updates information about the alert rule that has the specified ID.
      operationId: update-alert-rule
      parameters:
      - description: Alert rule ID (also known as the "policyScanConfigId")
        in: path
        name: id
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json; charset=UTF-8:
            schema:
              $ref: '#/components/schemas/PolicyScanConfigModel'
        description: Model for Policy Scan Config
        required: true
      responses:
        '200':
          content:
            application/json; charset=UTF-8:
              schema:
                $ref: '#/components/schemas/PolicyScanConfigModel'
          description: successful operation
        '400':
          description: invalid_policy_id / missing_required_param / non_notification_state_selected / invalid_notification_state / invalid_resource_list_id / snooze_time_must_be_relative / dismissal_reason_required / has_overlaps_in_resource_list_rules
        '404':
          description: not_found
        '500':
          description: internal_error
      security:
      - x-redlock-auth: []
      summary: Update Alert Rule
      tags:
      - Alert Rules
    delete:
      description: Deletes the alert rule that has the specified ID.
      operationId: delete-alert-rule
      parameters:
      - description: Alert rule ID (also known as the "policyScanConfigId")
        in: path
        name: id
        required: true
        schema:
          type: string
      responses:
        '204':
          description: successful operation
        '400':
          description: invalid_policy_id
        '403':
          description: incomplete_account_group_access
        '500':
          description: internal_error
      security:
      - x-redlock-auth: []
      summary: Delete Alert Rule
      tags:
      - Alert Rules
components:
  schemas:
    PolicyScanConfigViewModel:
      description: Model for Policy Scan Config View
      properties:
        alertRuleNotificationConfig:
          description: List of data for notifications to third-party tools
          items:
            $ref: '#/components/schemas/AlertRuleNotificationConfigModel'
          type: array
        allowAutoRemediate:
          description: Allow Auto-Remediation
          type: boolean
        delayNotificationMs:
          description: Delay notifications by the specified milliseconds
          format: int64
          type: integer
        description:
          description: Rule/Scan description
          type: string
        enabled:
          description: Rule/Scan is enabled
          type: boolean
        lastModifiedBy:
          description: Last modified by
          readOnly: true
          type: string
        lastModifiedOn:
          description: Last modified on this date/time in milliseconds
          format: int64
          readOnly: true
          type: integer
        name:
          description: Rule/Scan name
          type: string
        notificationChannels:
          description: List of notification channels
          items:
            type: string
          type: array
        notifyOnDismissed:
          description: include dismissed alerts in notification
          type: boolean
        notifyOnOpen:
          description: include open alerts in notification
          type: boolean
        notifyOnResolved:
          description: include resolved alerts in notification
          type: boolean
        notifyOnSnoozed:
          description: include snoozed alerts in notification
          type: boolean
        openAlertsCount:
          description: Open alerts count (Deprecated - will be removed soon)
          format: int32
          type: integer
        owner:
          description: Customer
          type: string
        policies:
          description: List of specific policies to scan
          items:
            type: string
          type: array
        policyLabels:
          description: Policy labels
          items:
            type: string
          type: array
        policyScanConfigId:
          description: Policy Scan Config ID
          type: string
        readOnly:
          description: Model is read-only
          type: boolean
        scanAll:
          description: Scan all policies
          type: boolean
        target:
          allOf:
          - $ref: '#/components/schemas/TargetFilterModel'
          - description: TargetFilter model (target accounts)
      required:
      - name
      - target
      type: object
    TargetFilterModel:
      description: Model for Target Filter
      properties:
        accountGroups:
          description: List of Account group(s)
          items:
            type: string
          type: array
        alertRulePolicyFilter:
          allOf:
          - $ref: '#/components/schemas/AlertRulePolicyFilter'
          - description: Policy Filters for the Alert Rule
        excludedAccounts:
          description: List of excluded accounts
          items:
            type: string
          type: array
        includedResourceLists:
          allOf:
          - $ref: '#/components/schemas/ResourceListIdsCollection'
          - description: List of resource lists included which the resource has to match on.
        regions:
          description: List of regions for which alerts will be triggered for account groups. Alerts not associated with specific regions will be triggered regardless of listed regions. If no regions are specified, then the alerts will be triggered for all regions.
          items:
            type: string
          type: array
        tags:
          description: List of TargetTag models (resource tags) for which alerts should be triggered
          items:
            $ref: '#/components/schemas/TargetTagModel'
          type: array
      type: object
    ResourceListIdsCollection:
      description: Model for holding the lists resource list ids by resource list type
      properties:
        computeAccessGroupIds:
          items:
            type: string
          type: array
      type: object
    AlertRulePolicyFilter:
      description: Model for Alert Rule Policy Filter
      properties:
        availablePolicyFilters:
          description: List of available Alert Rule Policy Filters
          items:
            type: string
          type: array
          uniqueItems: true
        cloud.type:
          description: Cloud Type Filter
          items:
            enum:
            - ALL
            - AWS
            - AZURE
            - GCP
            - ALIBABA_CLOUD
            - OCI
            - IBM
            type: string
          type: array
          uniqueItems: true
        policy.complianceStandard:
          description: Compliance Standard Filter
          items:
            type: string
          type: array
          uniqueItems: true
        policy.label:
          description: Policy Label Filter
          items:
            type: string
          type: array
          uniqueItems: true
        policy.severity:
          description: Policy Severity Filter
          items:
            type: string
          type: array
          uniqueItems: true
      type: object
    TargetTagModel:
      description: Model for Target Tag
      properties:
        key:
          description: Resource tag target
          type: string
        values:
          description: List of value(s) for resource tag key
          items:
            type: string
          type: array
      type: object
    AlertRuleNotificationConfigModel:
      description: Model for Alert Rule Notification Config
      properties:
        dayOfMonth:
          description: Day of month
          format: int32
          readOnly: true
          type: integer
        daysOfWeek:
          description: Days of week
          items:
            $ref: '#/components/schemas/WeekDay'
          readOnly: true
          type: array
        detailedReport:
          description: Provide csv detailed report
          type: boolean
        enabled:
          description: Scan enabled
          type: boolean
        frequency:
          enum:
          - as_it_happens
          - daily
          - weekly
          - monthly
          type: string
        frequencyFromRRule:
          description: Frequency from RRule
          readOnly: true
          type: string
        hourOfDay:
          description: Hour of day
          format: int32
          readOnly: true
          type: integer
        id:
          description: Alert rule notification config ID
          type: string
        includeRemediation:
          description: Include remediation in detailed report
          type: boolean
        lastUpdated:
          description: Last Updated
          format: int64
          type: integer
        last_sent_ts:
          description: Time of last notification in milliseconds
          format: int64
          type: integer
        recipients:
          description: '* For email notifications: List of unique email addresses to notify

            * For integrations without notification templates: List of integration ids

            * For integrations with notification templates: List of notification template ids

            '
          items:
            type: string
          type: array
          uniqueItems: true
        rruleSchedule:
          type: string
        templateId:
          description: Template ID
          type: string
        timezone:
          description: 'Java time zone ID (e.g. America/Los_Angeles) '
          readOnly: true
          type: string
        type:
          description: Integration type
          enum:
          - email
          - slack
          - splunk
          - amazon_sqs
          - jira
          - microsoft_teams
          - webhook
          - aws_security_hub
          - google_cscc
          - service_now
          - pager_duty
          - azure_service_bus_queue
          - demisto
          - aws_s3
          - snowflake
          type: string
        withCompression:
          description: Compress detailed report
          type: boolean
      type: object
    PolicyScanConfigModel:
      description: Model for Policy Scan Config
      properties:
        alertRuleNotificationConfig:
          description: List of data for notifications to third-party tools
          items:
            $ref: '#/components/schemas/AlertRuleNotificationConfigModel'
          type: array
        allowAutoRemediate:
          description: Allow Auto-Remediation
          type: boolean
        delayNotificationMs:
          description: Delay notifications by the specified milliseconds
          format: int64
          type: integer
        description:
          description: Rule/Scan description
          type: string
        enabled:
          description: Rule/Scan is enabled
          type: boolean
        lastModifiedBy:
          description: Last modified by
          readOnly: true
          type: string
        lastModifiedOn:
          description: Last modified on this date/time in milliseconds
          format: int64
          readOnly: true
          type: integer
        name:
          description: Rule/Scan name
          type: string
        notifyOnDismissed:
          description: include dismissed alerts in notification
          type: boolean
        notifyOnOpen:
          description: include open alerts in notification
          type: boolean
        notifyOnResolved:
          description: include resolved alerts in notification
          type: boolean
        notifyOnSnoozed:
          description: include snoozed alerts in notification
          type: boolean
        policies:
          description: List of specific policies to scan
          items:
            type: string
          type: array
        policyLabels:
          description: Policy labels
          items:
            type: string
          type: array
        policyScanConfigId:
          description: Policy Scan Config ID
          type: string
        scanAll:
          description: Scan all policies
          type: boolean
        target:
          allOf:
          - $ref: '#/components/schemas/TargetFilterModel'
          - description: TargetFilter model (target accounts)
      required:
      - name
      - target
      type: object
    WeekDay:
      properties:
        day:
          enum:
          - SU
          - MO
          - TU
          - WE
          - TH
          - FR
          - SA
          type: string
        offset:
          format: int32
          type: integer
      type: object
  securitySchemes:
    x-redlock-auth:
      description: The x-redlock-auth value is a JSON Web Token (JWT).
      in: header
      name: x-redlock-auth
      type: apiKey