Palo Alto Networks Audits API

{'$ref': 'desc/audits/audits.md'}

Operations 96

GET /api/v34.03/audits/access Get Docker Access Audit Events #
GET /api/v34.03/audits/access/download Download Docker Access Audit Events #
GET /api/v34.03/audits/admission Get Admission Audit Events #
GET /api/v34.03/audits/admission/download Download Admission Audit Events #
GET /api/v34.03/audits/firewall/app/agentless Get WAAS Agentless Audit Events #
GET /api/v34.03/audits/firewall/app/agentless/download Download WAAS Agentless Audit Events #
GET /api/v34.03/audits/firewall/app/agentless/timeslice Get WAAS Agentless Audit Events for a Timeframe #
GET /api/v34.03/audits/firewall/app/app-embedded Get WAAS App-embedded Audit Events #
GET /api/v34.03/audits/firewall/app/app-embedded/download Download WAAS App-embedded Audit Events #
GET /api/v34.03/audits/firewall/app/app-embedded/timeslice Get WAAS App-embedded Audit Events for a Timeframe #
GET /api/v34.03/audits/firewall/app/container Get WAAS Container Audit Events #
GET /api/v34.03/audits/firewall/app/container/download Download WAAS Container Audit Events #
GET /api/v34.03/audits/firewall/app/container/timeslice Get WAAS Container Audit Timeslice #
GET /api/v34.03/audits/firewall/app/host Get WAAS Host Audit Events #
GET /api/v34.03/audits/firewall/app/host/download Download WAAS Host Audit Events #
GET /api/v34.03/audits/firewall/app/host/timeslice Get WAAS Host Audit Timeslice #
GET /api/v34.03/audits/firewall/app/serverless Get WAAS Serverless Audit Events #
GET /api/v34.03/audits/firewall/app/serverless/download Download WAAS Serverless Audit Events #
GET /api/v34.03/audits/firewall/app/serverless/timeslice Get WAAS Serverless Audit Events for a Timeframe #
GET /api/v34.03/audits/firewall/network/container Get CNNS Container Audit Events #
GET /api/v34.03/audits/firewall/network/container/download Download CNNS Container Audit Events #
GET /api/v34.03/audits/firewall/network/host Get CNNS Host Audit Events #
GET /api/v34.03/audits/firewall/network/host/download Download CNNS Host Audit Events #
GET /api/v34.03/audits/incidents Get Incident Audit Events #
PATCH /api/v34.03/audits/incidents/acknowledge/{id} Archive an Incident Audit Event #
GET /api/v34.03/audits/incidents/download Download Incident Audit Events #
GET /api/v34.03/audits/kubernetes Get Kubernetes Audit Events #
GET /api/v34.03/audits/kubernetes/download Download Kubernetes Audit Events #
GET /api/v34.03/audits/mgmt Get Management Audit Events #
GET /api/v34.03/audits/mgmt/download Download Management Audit Events #
GET /api/v34.03/audits/mgmt/filters Get Management Audit Event Filters #
GET /api/v34.03/audits/runtime/app-embedded Get Runtime App-embedded Audit Events #
GET /api/v34.03/audits/runtime/app-embedded/download Download Runtime App-embedded Audit Events #
GET /api/v34.03/audits/runtime/container Get Runtime Container Audit Events #
GET /api/v34.03/audits/runtime/container/download Download Runtime Container Audit Events #
GET /api/v34.03/audits/runtime/container/timeslice Get Runtime Container Audit Events for a Timeframe #
GET /api/v34.03/audits/runtime/file-integrity Get Runtime File Integrity Audit Events #
GET /api/v34.03/audits/runtime/file-integrity/download Download Runtime File Integrity Audit Events #
GET /api/v34.03/audits/runtime/host Get Runtime Host Audit Events #
GET /api/v34.03/audits/runtime/host/download Download Runtime Host Audit Events #
GET /api/v34.03/audits/runtime/host/timeslice Get Runtime Host Audit Events for a Timeframe #
GET /api/v34.03/audits/runtime/log-inspection Get Runtime Log Inspection Audit Events #
GET /api/v34.03/audits/runtime/log-inspection/download Download Runtime Log Inspection Audit Events #
GET /api/v34.03/audits/runtime/serverless Get Runtime Serverless Audit Events #
GET /api/v34.03/audits/runtime/serverless/download Download Serverless Audit Events #
GET /api/v34.03/audits/runtime/serverless/timeslice Get Runtime Serverless Audit Events for a Timeframe #
GET /api/v34.03/audits/trust Get Trust Audit Events #
GET /api/v34.03/audits/trust/download Download Trust Audit Events #
GET /api/v34.04/audits/access Get Docker Access Audit Events #
GET /api/v34.04/audits/access/download Download Docker Access Audit Events #
GET /api/v34.04/audits/admission Get Admission Audit Events #
GET /api/v34.04/audits/admission/download Download Admission Audit Events #
GET /api/v34.04/audits/firewall/app/agentless Get WAAS Agentless Audit Events #
GET /api/v34.04/audits/firewall/app/agentless/download Download WAAS Agentless Audit Events #
GET /api/v34.04/audits/firewall/app/agentless/timeslice Get WAAS Agentless Audit Events for a Timeframe #
GET /api/v34.04/audits/firewall/app/app-embedded Get WAAS App-embedded Audit Events #
GET /api/v34.04/audits/firewall/app/app-embedded/download Download WAAS App-embedded Audit Events #
GET /api/v34.04/audits/firewall/app/app-embedded/timeslice Get WAAS App-embedded Audit Events for a Timeframe #
GET /api/v34.04/audits/firewall/app/container Get WAAS Container Audit Events #
GET /api/v34.04/audits/firewall/app/container/download Download WAAS Container Audit Events #
GET /api/v34.04/audits/firewall/app/container/timeslice Get WAAS Container Audit Timeslice #
GET /api/v34.04/audits/firewall/app/host Get WAAS Host Audit Events #
GET /api/v34.04/audits/firewall/app/host/download Download WAAS Host Audit Events #
GET /api/v34.04/audits/firewall/app/host/timeslice Get WAAS Host Audit Timeslice #
GET /api/v34.04/audits/firewall/app/serverless Get WAAS Serverless Audit Events #
GET /api/v34.04/audits/firewall/app/serverless/download Download WAAS Serverless Audit Events #
GET /api/v34.04/audits/firewall/app/serverless/timeslice Get WAAS Serverless Audit Events for a Timeframe #
GET /api/v34.04/audits/firewall/network/container Get CNNS Container Audit Events #
GET /api/v34.04/audits/firewall/network/container/download Download CNNS Container Audit Events #
GET /api/v34.04/audits/firewall/network/host Get CNNS Host Audit Events #
GET /api/v34.04/audits/firewall/network/host/download Download CNNS Host Audit Events #
GET /api/v34.04/audits/incidents Get Incident Audit Events #
PATCH /api/v34.04/audits/incidents/acknowledge/{id} Archive an Incident Audit Event #
GET /api/v34.04/audits/incidents/download Download Incident Audit Events #
GET /api/v34.04/audits/kubernetes Get Kubernetes Audit Events #
GET /api/v34.04/audits/kubernetes/download Download Kubernetes Audit Events #
GET /api/v34.04/audits/mgmt Get Management Audit Events #
GET /api/v34.04/audits/mgmt/download Download Management Audit Events #
GET /api/v34.04/audits/mgmt/filters Get Management Audit Event Filters #
GET /api/v34.04/audits/runtime/app-embedded Get Runtime App-embedded Audit Events #
GET /api/v34.04/audits/runtime/app-embedded/download Download Runtime App-embedded Audit Events #
GET /api/v34.04/audits/runtime/container Get Runtime Container Audit Events #
GET /api/v34.04/audits/runtime/container/download Download Runtime Container Audit Events #
GET /api/v34.04/audits/runtime/container/timeslice Get Runtime Container Audit Events for a Timeframe #
GET /api/v34.04/audits/runtime/file-integrity Get Runtime File Integrity Audit Events #
GET /api/v34.04/audits/runtime/file-integrity/download Download Runtime File Integrity Audit Events #
GET /api/v34.04/audits/runtime/host Get Runtime Host Audit Events #
GET /api/v34.04/audits/runtime/host/download Download Runtime Host Audit Events #
GET /api/v34.04/audits/runtime/host/timeslice Get Runtime Host Audit Events for a Timeframe #
GET /api/v34.04/audits/runtime/log-inspection Get Runtime Log Inspection Audit Events #
GET /api/v34.04/audits/runtime/log-inspection/download Download Runtime Log Inspection Audit Events #
GET /api/v34.04/audits/runtime/serverless Get Runtime Serverless Audit Events #
GET /api/v34.04/audits/runtime/serverless/download Download Serverless Audit Events #
GET /api/v34.04/audits/runtime/serverless/timeslice Get Runtime Serverless Audit Events for a Timeframe #
GET /api/v34.04/audits/trust Get Trust Audit Events #
GET /api/v34.04/audits/trust/download Download Trust Audit Events #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/palo-alto-networks-audits-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

palo-alto-networks-audits-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Palo Alto Networks Audits API
  x-description-source: desc/intro.md
  version: '1.0'
  description: 'Operations tagged Audits across 4 of this provider''s published API definitions: palo-alto-compute-34-03-openapi-34-03-138-sh-openapi.json, palo-alto-compute-openapi-34-04-145-sh-openapi.json, palo-alto-cwpp-34-03-openapi-34-03-138-saas-openapi.json, palo-alto-cwpp-openapi-34-04-145-saas-openapi.json. Each path carries the servers of the definition it was published in.'
servers:
- url: PATH_TO_CONSOLE
tags:
- name: Audits
  description: Audits. 48 operations in this definition.
  x-description-source: desc/audits/audits.md
paths:
  /api/v34.03/audits/access:
    get:
      description: 'Get Docker Access Audit Events. GET /api/v34.03/audits/access on the Audits API. Takes 13 query parameters. Documented responses: 200.'
      parameters:
      - description: 'Offsets the result to a specific report count. Offset starts from 0.

          '
        in: query
        name: offset
        schema:
          type: integer
      - description: 'Limit is the amount to fix.

          '
        in: query
        name: limit
        schema:
          type: integer
      - description: 'Sorts the result using a key.

          '
        in: query
        name: sort
        schema:
          type: string
      - description: 'Sorts the result in reverse order.

          '
        in: query
        name: reverse
        schema:
          type: boolean
      - description: 'From is an optional minimum time constraints for the audit.

          '
        in: query
        name: from
        schema:
          format: date-time
          type: string
      - description: 'To is an optional maximum time constraints for the audit.

          '
        in: query
        name: to
        schema:
          format: date-time
          type: string
      - description: 'Type is the audit type.

          '
        in: query
        name: type
        schema:
          type: string
      - description: 'RuleNames are the rules names to filter by.

          '
        in: query
        name: ruleName
        schema:
          description: 'RuleNames are the rules names to filter by.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'APIs are apis to filter by.

          '
        in: query
        name: api
        schema:
          description: 'APIs are apis to filter by.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Hosts are hosts to filter by.

          '
        in: query
        name: hostname
        schema:
          description: 'Hosts are hosts to filter by.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Users are users to filter by.

          '
        in: query
        name: user
        schema:
          description: 'Users are users to filter by.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Allow indicated whether allowed requests should be shown.

          '
        in: query
        name: allow
        schema:
          type: string
      - description: 'Clusters is the cluster filter.

          '
        in: query
        name: cluster
        schema:
          description: 'Clusters is the cluster filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/-_shared.Audit'
          description: ''
        default:
          description: ''
      tags:
      - Audits
      x-prisma-cloud-target-env:
        permission: monitorAccessDocker
      operationId: get-audits-access
      summary: Get Docker Access Audit Events
      x-description-source: desc/audits/access_get.md
  /api/v34.03/audits/access/download:
    get:
      description: 'Download Docker Access Audit Events. GET /api/v34.03/audits/access/download on the Audits API. Takes 13 query parameters. Documented responses: 200.'
      parameters:
      - description: 'Offsets the result to a specific report count. Offset starts from 0.

          '
        in: query
        name: offset
        schema:
          type: integer
      - description: 'Limit is the amount to fix.

          '
        in: query
        name: limit
        schema:
          type: integer
      - description: 'Sorts the result using a key.

          '
        in: query
        name: sort
        schema:
          type: string
      - description: 'Sorts the result in reverse order.

          '
        in: query
        name: reverse
        schema:
          type: boolean
      - description: 'From is an optional minimum time constraints for the audit.

          '
        in: query
        name: from
        schema:
          format: date-time
          type: string
      - description: 'To is an optional maximum time constraints for the audit.

          '
        in: query
        name: to
        schema:
          format: date-time
          type: string
      - description: 'Type is the audit type.

          '
        in: query
        name: type
        schema:
          type: string
      - description: 'RuleNames are the rules names to filter by.

          '
        in: query
        name: ruleName
        schema:
          description: 'RuleNames are the rules names to filter by.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'APIs are apis to filter by.

          '
        in: query
        name: api
        schema:
          description: 'APIs are apis to filter by.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Hosts are hosts to filter by.

          '
        in: query
        name: hostname
        schema:
          description: 'Hosts are hosts to filter by.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Users are users to filter by.

          '
        in: query
        name: user
        schema:
          description: 'Users are users to filter by.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Allow indicated whether allowed requests should be shown.

          '
        in: query
        name: allow
        schema:
          type: string
      - description: 'Clusters is the cluster filter.

          '
        in: query
        name: cluster
        schema:
          description: 'Clusters is the cluster filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      responses:
        '200':
          description: OK
        default:
          description: ''
      tags:
      - Audits
      x-prisma-cloud-target-env:
        permission: monitorAccessDocker
      operationId: get-audits-access-download
      summary: Download Docker Access Audit Events
      x-description-source: desc/audits/access_download_get.md
  /api/v34.03/audits/admission:
    get:
      description: 'Get Admission Audit Events. GET /api/v34.03/audits/admission on the Audits API. Takes 10 query parameters. Documented responses: 200.'
      parameters:
      - description: 'Offsets the result to a specific report count. Offset starts from 0.

          '
        in: query
        name: offset
        schema:
          type: integer
      - description: 'Limit is the amount to fix.

          '
        in: query
        name: limit
        schema:
          type: integer
      - description: 'Sorts the result using a key.

          '
        in: query
        name: sort
        schema:
          type: string
      - description: 'Sorts the result in reverse order.

          '
        in: query
        name: reverse
        schema:
          type: boolean
      - description: 'From is an optional minimum time constraints for the activity.

          '
        in: query
        name: from
        schema:
          format: date-time
          type: string
      - description: 'To is an optional maximum time constraints for the activity.

          '
        in: query
        name: to
        schema:
          format: date-time
          type: string
      - description: 'Namespaces is the list of namespaces to use for filtering.

          '
        in: query
        name: namespace
        schema:
          description: 'Namespaces is the list of namespaces to use for filtering.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Operations is the list of operations to use for filtering.

          '
        in: query
        name: operation
        schema:
          description: 'Operations is the list of operations to use for filtering.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Clusters is the cluster filter.

          '
        in: query
        name: cluster
        schema:
          description: 'Clusters is the cluster filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'AttackTechniques are the MITRE attack techniques.

          '
        in: query
        name: attackTechniques
        schema:
          description: 'AttackTechniques are the MITRE attack techniques.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/-_admission.Audit'
          description: ''
        default:
          description: ''
      tags:
      - Audits
      x-prisma-cloud-target-env:
        permission: monitorAccessKubernetes
      operationId: get-audits-admission
      summary: Get Admission Audit Events
      x-description-source: desc/audits/admission_get.md
  /api/v34.03/audits/admission/download:
    get:
      description: 'Download Admission Audit Events. GET /api/v34.03/audits/admission/download on the Audits API. Takes 10 query parameters. Documented responses: 200.'
      parameters:
      - description: 'Offsets the result to a specific report count. Offset starts from 0.

          '
        in: query
        name: offset
        schema:
          type: integer
      - description: 'Limit is the amount to fix.

          '
        in: query
        name: limit
        schema:
          type: integer
      - description: 'Sorts the result using a key.

          '
        in: query
        name: sort
        schema:
          type: string
      - description: 'Sorts the result in reverse order.

          '
        in: query
        name: reverse
        schema:
          type: boolean
      - description: 'From is an optional minimum time constraints for the activity.

          '
        in: query
        name: from
        schema:
          format: date-time
          type: string
      - description: 'To is an optional maximum time constraints for the activity.

          '
        in: query
        name: to
        schema:
          format: date-time
          type: string
      - description: 'Namespaces is the list of namespaces to use for filtering.

          '
        in: query
        name: namespace
        schema:
          description: 'Namespaces is the list of namespaces to use for filtering.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Operations is the list of operations to use for filtering.

          '
        in: query
        name: operation
        schema:
          description: 'Operations is the list of operations to use for filtering.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Clusters is the cluster filter.

          '
        in: query
        name: cluster
        schema:
          description: 'Clusters is the cluster filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'AttackTechniques are the MITRE attack techniques.

          '
        in: query
        name: attackTechniques
        schema:
          description: 'AttackTechniques are the MITRE attack techniques.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      responses:
        '200':
          description: OK
        default:
          description: ''
      tags:
      - Audits
      x-prisma-cloud-target-env:
        permission: monitorAccessKubernetes
      operationId: get-audits-admission-download
      summary: Download Admission Audit Events
      x-description-source: desc/audits/admission_download_get.md
  /api/v34.03/audits/firewall/app/agentless:
    get:
      description: 'Get WAAS Agentless Audit Events. GET /api/v34.03/audits/firewall/app/agentless on the Audits API. Takes 38 query parameters. Documented responses: 200.'
      parameters:
      - description: 'Offsets the result to a specific report count. Offset starts from 0.

          '
        in: query
        name: offset
        schema:
          type: integer
      - description: 'Limit is the amount to fix.

          '
        in: query
        name: limit
        schema:
          type: integer
      - description: 'Sorts the result using a key.

          '
        in: query
        name: sort
        schema:
          type: string
      - description: 'Sorts the result in reverse order.

          '
        in: query
        name: reverse
        schema:
          type: boolean
      - description: 'From is an optional minimum time constraints for the audit.

          '
        in: query
        name: from
        schema:
          format: date-time
          type: string
      - description: 'To is an optional maximum time constraints for the audit.

          '
        in: query
        name: to
        schema:
          format: date-time
          type: string
      - description: 'Images is the image names filter.

          '
        in: query
        name: imageName
        schema:
          description: 'Images is the image names filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Containers is the container names filter.

          '
        in: query
        name: containerName
        schema:
          description: 'Containers is the container names filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Hosts is the hostnames filter.

          '
        in: query
        name: hostname
        schema:
          description: 'Hosts is the hostnames filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'RuleNames is the rule names filter.

          '
        in: query
        name: ruleName
        schema:
          description: 'RuleNames is the rule names filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Types is the firewall audit type filter.

          '
        in: query
        name: type
        schema:
          description: 'Types is the firewall audit type filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Effect is used to filter by runtime audit effect.

          '
        in: query
        name: effect
        schema:
          type: string
      - description: 'RuleAppIDs is the rule app IDs filter.

          '
        in: query
        name: ruleAppID
        schema:
          description: 'RuleAppIDs is the rule app IDs filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'FunctionName is used to filter by function name.

          '
        in: query
        name: function
        schema:
          description: 'FunctionName is used to filter by function name.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Runtime is used to filter by runtime.

          '
        in: query
        name: runtime
        schema:
          description: 'Runtime is used to filter by runtime.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Namespaces is the list of namespaces to use for filtering.

          '
        in: query
        name: ns
        schema:
          description: 'Namespaces is the list of namespaces to use for filtering.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'AppIDs is the app embedded appID filter.

          '
        in: query
        name: appID
        schema:
          description: 'AppIDs is the app embedded appID filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Subnets is the source IPs filter.

          '
        in: query
        name: subnet
        schema:
          description: 'Subnets is the source IPs filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'ConnectingIPs is the connecting IPs filter.

          '
        in: query
        name: connectingIPs
        schema:
          description: 'ConnectingIPs is the connecting IPs filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Countries is the source IP country filter.

          '
        in: query
        name: country
        schema:
          description: 'Countries is the source IP country filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'UserAgents is the user agent header filter.

          '
        in: query
        name: userAgentHeader
        schema:
          description: 'UserAgents is the user agent header filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'URLs is the URL filter.

          '
        in: query
        name: url
        schema:
          description: 'URLs is the URL filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'RequestHosts is the request host filter.

          '
        in: query
        name: requestHost
        schema:
          description: 'RequestHosts is the request host filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Paths is the URL path filter.

          '
        in: query
        name: urlPath
        schema:
          description: 'Paths is the URL path filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Queries is the URL query filter.

          '
        in: query
        name: urlQuery
        schema:
          description: 'Queries is the URL query filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Methods is the request method filter.

          '
        in: query
        name: method
        schema:
          description: 'Methods is the request method filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'RequestHeaderNames is the request header names filter.

          '
        in: query
        name: requestHeaderNames
        schema:
          description: 'RequestHeaderNames is the request header names filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'OS is the OS filter.

          '
        in: query
        name: os
        schema:
          description: 'OS is the OS filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Messages is the audit message text filter.

          '
        in: query
        name: msg
        schema:
          description: 'Messages is the audit message text filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Cluster is the audit cluster filter.

          '
        in: query
        name: cluster
        schema:
          description: 'Cluster is the audit cluster filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'AttackTechniques are the MITRE attack techniques.

          '
        in: query
        name: attackTechniques
        schema:
          description: 'AttackTechniques are the MITRE attack techniques.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Aggregate indicates whether the result audits should be aggregated according to the Select field.

          '
        in: query
        name: aggregate
        schema:
          type: boolean
      - description: 'Protections is the firewall audit protection type filter.

          '
        in: query
        name: protection
        schema:
          description: 'Protections is the firewall audit protection type filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'EventID is the event IDs filter.

          '
        in: query
        name: eventID
        schema:
          description: 'EventID is the event IDs filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'OWASPTop10 is the OWASP top 10 filter.

          '
        in: query
        name: owaspTop10
        schema:
          description: 'OWASPTop10 is the OWASP top 10 filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'OWASPAPITop10 is the OWASP API top 10 filter.

          '
        in: query
        name: owaspAPITop10
        schema:
          description: 'OWASPAPITop10 is the OWASP API top 10 filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'AdditionalHash is used to filter by the additional hash value.

          '
        in: query
        name: additionalHash
        schema:
          description: 'AdditionalHash is used to filter by the additional hash value.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'ModelPath is used to filter by the API model path.

          '
        in: query
        name: modelPath
        schema:
          description: 'ModelPath is used to filter by the API model path.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/-_shared.AppFirewallAudit'
          description: ''
        default:
          description: ''
      tags:
      - Audits
      x-prisma-cloud-target-env:
        permission: monitorWAAS
      operationId: get-audits-firewall-app-agentless
      summary: Get WAAS Agentless Audit Events
      x-description-source: desc/audits/waas_agentless_get.md
  /api/v34.03/audits/firewall/app/agentless/download:
    get:
      description: 'Download WAAS Agentless Audit Events. GET /api/v34.03/audits/firewall/app/agentless/download on the Audits API. Takes 38 query parameters. Documented responses: 200.'
      parameters:
      - description: 'Offsets the result to a specific report count. Offset starts from 0.

          '
        in: query
        name: offset
        schema:
          type: integer
      - description: 'Limit is the amount to fix.

          '
        in: query
        name: limit
        schema:
          type: integer
      - description: 'Sorts the result using a key.

          '
        in: query
        name: sort
        schema:
          type: string
      - description: 'Sorts the result in reverse order.

          '
        in: query
        name: reverse
        schema:
          type: boolean
      - description: 'From is an optional minimum time constraints for the audit.

          '
        in: query
        name: from
        schema:
          format: date-time
          type: string
      - description: 'To is an optional maximum time constraints for the audit.

          '
        in: query
        name: to
        schema:
          format: date-time
          type: string
      - description: 'Images is the image names filter.

          '
        in: query
        name: imageName
        schema:
          description: 'Images is the image names filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Containers is the container names filter.

          '
        in: query
        name: containerName
        schema:
          description: 'Containers is the container names filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Hosts is the hostnames filter.

          '
        in: query
        name: hostname
        schema:
          description: 'Hosts is the hostnames filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'RuleNames is the rule names filter.

          '
        in: query
        name: ruleName
        schema:
          description: 'RuleNames is the rule names filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Types is the firewall audit type filter.

          '
        in: query
        name: type
        schema:
          description: 'Types is the firewall audit type filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Effect is used to filter by runtime audit effect.

          '
        in: query
        name: effect
        schema:
          type: string
      - description: 'RuleAppIDs is the rule app IDs filter.

          '
        in: query
        name: ruleAppID
        schema:
          description: 'RuleAppIDs is the rule app IDs filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'FunctionName is used to filter by function name.

          '
        in: query
        name: function
        schema:
          description: 'FunctionName is used to filter by function name.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Runtime is used to filter by runtime.

          '
        in: query
        name: runtime
        schema:
          description: 'Runtime is used to filter by runtime.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Namespaces is the list of namespaces to use for filtering.

          '
        in: query
        name: ns
        schema:
          description: 'Namespaces is the list of namespaces to use for filtering.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'AppIDs is the app embedded appID filter.

          '
        in: query
        name: appID
        schema:
          description: 'AppIDs is the app embedded appID filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Subnets is the source IPs filter.

          '
        in: query
        name: subnet
        schema:
          description: 'Subnets is the source IPs filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'ConnectingIPs is the connecting IPs filter.

          '
        in: query
        name: connectingIPs
        schema:
          description: 'ConnectingIPs is the connecting IPs filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Countries is the source IP country filter.

          '
        in: query
        name: country
        schema:
          description: 'Countries is the source IP country filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'UserAgents is the user agent header filter.

          '
        in: query
        name: userAgentHeader
        schema:
          description: 'UserAgents is the user agent header filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'URLs is the URL filter.

          '
        in: query
        name: url
        schema:
          description: 'URLs is the URL filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'RequestHosts is the request host filter.

          '
        in: query
        name: requestHost
        schema:
          description: 'RequestHosts is the request host filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Paths is the URL path filter.

          '
        in: query
        name: urlPath
        schema:
          description: 'Paths is the URL path filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Queries is the URL query filter.

          '
        in: query
        name: urlQuery
        schema:
          description: 'Queries is the URL query filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Methods is the request method filter.

          '
        in: query
        name: method
        schema:
          description: 'Methods is the request method filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'RequestHeaderNames is the request header names filter.

          '
        in: query
        name: requestHeaderNames
        schema:
          description: 'RequestHeaderNames is the request header names filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'OS is the OS filter.

          '
        in: query
        name: os
        schema:
          description: 'OS is the OS filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Messages is the audit message text filter.

          '
        in: query
        name: msg
        schema:
          description: 'Messages is the audit message text filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'Cluster is the audit cluster filter.

          '
        in: query
        name: cluster
        schema:
          description: 'Cluster is the audit cluster filter.

            '
          items:
            $ref: '#/components/schemas/string'
          type: array
      - description: 'AttackTechniques are the MITRE attack techniques.

          '
   

# --- truncated at 32 KB (714 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/openapi/palo-alto-networks-audits-api-openapi.yml