Palo Alto Networks Alerts API

Prisma Cloud generates an alert when it detects a violation in a policy that is included in an active alert rule. You can use the API requests to manage alerts, including listing or viewing, snoozing or dismissing, reopening, or remediating alerts. When retrieving a list of alerts through an API request, you can set filters, time range parameters, or pagination parameters. ### Pagination You can limit the number of items in a response list from API resources that support pagination. Version 2 (V2) of the API requests to list alerts supports pagination and will accept the following request parameters. Request Parameter | Description -----------| ------- **limit** | Maximum number of items to return per page. Without pagination, maximum number of items to return in a response. **offset** | Number of items to skip before selecting items to return. Default is zero. **pageToken** | Set to the **nextPageToken** value from the previous response object to return the next page of data. ### Filters API requests that use POST methods to request a list of alerts have filter parameters that enable you to narrow your request to alerts that meet a certain criteria.The [List Alert Filters](/prisma-cloud/api/cspm/get-alert-filter-options) requests return the available filters.

Business capability
Threat Detection & Response Management BC-620.30

Operations 37

POST /alerts/get_alerts Palo Alto Networks Get Alerts #
POST /alert/v1/policy Return policy with alert count #
POST /alert/v1/aggregate Group by Policy field #
GET /alert/v1/{id}/graph Alert Evidence Graph #
POST /alerts/api/v1/notification/ondemand Create On Demand Notification #
GET /filter/alert/suggest List Alert Filters #
POST /filter/alert/suggest List Alert Filter Autocomplete Suggestions #
GET /alert List Alerts - GET #
POST /alert List Alerts - POST #
GET /v2/alert List Alerts V2 - GET #
POST /v2/alert List Alerts V2 - POST #
GET /alert/policy List Alert Counts By Policy - GET #
POST /alert/policy List Alert Counts By Policy - POST #
GET /alert/{id} Alert Info #
POST /alert/dismiss Dismiss Alerts #
GET /alert/dismiss/require_dismissal_note Is Dismissal Note Required #
PUT /alert/dismiss/require_dismissal_note Update Dismissal Note Requirement #
POST /alert/reopen Reopen Alerts #
GET /alert/count/{status} Get Alerts Count By Status #
POST /alert/jobs Submit Job to List Alerts #
GET /alert/jobs/{id}/status Get Alerts List Job Status #
GET /alert/jobs/{id}/download Download Alerts List JSON #
POST /alert/csv Submit Alert CSV Generation Job #
GET /alert/csv/{id}/status Get Alert CSV Job Status #
GET /alert/csv/{id}/download Download Alert CSV #
POST /alert/policy/jobs Submit Job to List Alerts By Policy #
GET /alert/policy/jobs/{id}/status Get Policy Alert Job Status #
GET /alert/policy/jobs/{id}/download Download Policy Alerts JSON #
POST /alert/remediation List Alert Remediation Commands #
PATCH /alert/remediation/{id} Remediate Alert #
GET /policy/api/v1/fetch/remediation/{policyId} Get Policy Remediation #
PATCH /v1/alerts/id/{id}/status/{status} Update Alert Status #
GET /v1/alerts List DDR Alerts #
GET /alert/list Palo Alto Networks List Security Alerts #
GET /alert/detail Palo Alto Networks Get Alert Details #
PUT /alert/update Palo Alto Networks Update Alert Status #
GET /dspm/api/v1/alerts Palo Alto Networks List Data Security Alerts #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/palo-alto-networks-alerts-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

palo-alto-networks-alerts-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Palo Alto Networks Alerts API
  x-refined-note:
  - x-description-source differs across the merged source definitions and was not carried
  version: '1.0'
  description: 'Operations tagged Alerts across 11 of this provider''s published API definitions: palo-alto-cortex-xdr-api-openapi-original.yml, palo-alto-cortex-xsiam-api-openapi-original.yml, palo-alto-cspm-alertsmicroservices-openapi.json, palo-alto-cspm-alertsnotificationmicroservice-openapi.json, palo-alto-cspm-consolidated-spec-cspm-spec-openapi.json, palo-alto-cspm-pia-openapi-openapi.json, palo-alto-dspm-dspm-openapi.json, palo-alto-iot-security-api-openapi-original.yml…'
servers:
- url: https://api-{fqdn}/public_api/v1
  description: Cortex XDR tenant API endpoint.
  variables:
    fqdn:
      description: Tenant FQDN from the Cortex XDR settings page (e.g., example.xdr.us.paloaltonetworks.com).
      default: example.xdr.us.paloaltonetworks.com
- url: https://api.prismacloud.io
- url: https://api2.prismacloud.io
- url: https://api3.prismacloud.io
- url: https://api4.prismacloud.io
- url: https://api.anz.prismacloud.io
- url: https://api.eu.prismacloud.io
- url: https://api2.eu.prismacloud.io
- url: https://api.gov.prismacloud.io
- url: https://api.prismacloud.cn
- url: https://api.ca.prismacloud.io
- url: https://api.sg.prismacloud.io
- url: https://api.uk.prismacloud.io
- url: https://api.ind.prismacloud.io
- url: https://api.jp.prismacloud.io
- url: https://api.fr.prismacloud.io
- url: https://api.dig.security
  description: Dig Security public API
- url: PATH_TO_CONSOLE
- url: https://{customer}.iot.paloaltonetworks.com/pub/v4.0
  description: IoT Security API production server.
  variables:
    customer:
      description: Customer-specific tenant identifier.
      default: customer-tenant
- url: https://api.stratacloud.paloaltonetworks.com/aiops/bpa/v1
  description: AIOps for NGFW BPA API production server.
tags:


# --- truncated at 32 KB (188 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/openapi/palo-alto-networks-alerts-api-openapi.yml