Palo Alto Networks Benchmark Monitoring API

Monitoring and reporting for benchmarked compliance frameworks with BPC verdict tracking.

OpenAPI Specification

palo-alto-networks-benchmark-monitoring-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Palo Alto Networks Benchmark Monitoring API
  contact:
    email: support@paloaltonetworks.com
    name: Palo Alto Networks Technical Support
    url: https://support.paloaltonetworks.com
  license:
    name: MIT
    url: https://opensource.org/license/mit
  termsOfService: https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/legal/palo-alto-networks-end-user-license-agreement-eula.pdf
  version: '1.0'
  description: 'Operations tagged Benchmark Monitoring across 2 of this provider''s published API definitions: palo-alto-scm-config-posture-management-compliance-framework-compliance-center-recent-v1-openapi.yaml, palo-alto-scm-config-posture-management-posture-openapi.yaml. Each path carries the servers of the definition it was published in.'
servers:
- url: https://api.strata.paloaltonetworks.com/posture/compliance-frameworks/v1
  description: Current
- url: https://api.strata.paloaltonetworks.com/posture
  description: Current
security:
- BearerAuth: []
tags:
- name: Benchmark Monitoring
  description: Monitoring and reporting for benchmarked compliance frameworks with BPC verdict tracking.
paths:
  /benchmark-monitoring:
    post:
      tags:
      - Benchmark Monitoring
      summary: Get Benchmark Monitoring Data
      description: Retrieve compliance monitoring data for benchmarked frameworks with filtering and pagination
      operationId: getBenchmarkMonitoring
      security:
      - BearerAuth: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                product:
                  type: string
                  description: Product filter
                  enum:
                  - sase
                  - ngfw
                  - all
                bpc_status:
                  type: array
                  description: BPC status filter
                  items:
                    type: string
                severity:
                  type: array
                  description: Severity filter
                  items:
                    type: string
                bpc_id:
                  type: array
                  description: BPC ID filter
                  items:
                    type: string
                object_type:
                  type: array
                  description: Object type filter
                  items:
                    type: string
                object_id:
                  type: array
                  description: Object ID filter
                  items:
                    type: string
                remediation_location:
                  type: array
                  description: Remediation location filter
                  items:
                    type: string
                action:
                  type: array
                  description: Action filter
                  items:
                    type: string
                device_type:
                  type: array
                  description: Device type filter
                  items:
                    type: string
            example:
              product: ngfw
              bpc_status: []
              severity: []
              bpc_id:
              - '100'
              - '102'
              - '103'
              - '104'
              - '105'
              - '107'
              - '108'
              - '109'
              - '111'
              - '117'
              - '12'
              - '121'
              - '122'
              - '123'
              - '124'
              - '125'
              - '126'
              - '127'
              - '128'
              - '129'
              - '13'
              - '130'
              - '131'
              - '132'
              - '133'
              - '134'
              - '136'
              - '138'
              - '139'
              - '141'
              - '142'
              - '143'
              - '144'
              - '145'
              - '149'
              - '150'
              - '151'
              - '154'
              - '155'
              - '157'
              - '158'
              - '159'
              - '16'
              - '164'
              - '165'
              - '17'
              - '173'
              - '174'
              - '177'
              - '178'
              - '182'
              - '183'
              - '184'
              - '185'
              - '186'
              - '187'
              - '188'
              - '189'
              - '19'
              - '190'
              - '194'
              - '196'
              - '197'
              - '199'
              - '200'
              - '203'
              - '207'
              - '208'
              - '21'
              - '211'
              - '212'
              - '215'
              - '216'
              - '217'
              - '223'
              - '224'
              - '227'
              - '228'
              - '231'
              - '233'
              - '234'
              - '241'
              - '242'
              - '243'
              - '247'
              - '249'
              - '253'
              - '259'
              - '26'
              - '260'
              - '261'
              - '262'
              - '263'
              - '264'
              - '267'
              - '268'
              - '27'
              - '271'
              - '272'
              - '273'
              - '276'
              - '277'
              - '278'
              - '279'
              - '280'
              - '281'
              - '282'
              - '283'
              - '284'
              - '285'
              - '287'
              - '288'
              - '289'
              - '292'
              - '293'
              - '294'
              - '295'
              - '296'
              - '297'
              - '298'
              - '299'
              - '3'
              - '300'
              - '301'
              - '302'
              - '303'
              - '304'
              - '305'
              - '306'
              - '307'
              - '308'
              - '311'
              - '312'
              - '317'
              - '32'
              - '320'
              - '321'
              - '322'
              - '323'
              - '324'
              - '325'
              - '326'
              - '327'
              - '328'
              - '329'
              - '33'
              - '330'
              - '331'
              - '332'
              - '333'
              - '339'
              - '340'
              - '341'
              - '344'
              - '345'
              - '346'
              - '347'
              - '38'
              - '4'
              - '40'
              - '41'
              - '42'
              - '43'
              - '44'
              - '45'
              - '47'
              - '49'
              - '5'
              - '51'
              - '52'
              - '53'
              - '55'
              - '57'
              - '58'
              - '6'
              - '60'
              - '63'
              - '65'
              - '67'
              - '68'
              - '69'
              - '7'
              - '71'
              - '72'
              - '74'
              - '76'
              - '77'
              - '78'
              - '79'
              - '80'
              - '86'
              - '87'
              - '89'
              - '9'
              - '90'
              - '91'
              - '92'
              - '94'
              - '95'
              - '97'
              - '98'
              object_type: []
              object_id: []
              remediation_location: []
              action: []
              device_type:
              - ngfw
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  device_serial:
                    type: array
                    items:
                      type: string
                  bpc_id:
                    type: array
                    items:
                      type: string
                  bpc_id_count:
                    type: array
                    items:
                      type: integer
                  manager:
                    type: array
                    items:
                      type: string
                  action:
                    type: array
                    items:
                      type: string
                  object_type:
                    type: array
                    items:
                      type: string
                  severity:
                    type: array
                    items:
                      type: string
                  location:
                    type: array
                    items:
                      type: string
                  remediation_location:
                    type: array
                    items:
                      type: string
                  object_id:
                    type: array
                    items:
                      type: string
                  pbpc_result_number:
                    type: array
                    items:
                      type: string
                  bpc_status:
                    type: array
                    items:
                      type: string
                  device_type:
                    type: array
                    items:
                      type: string
                  bpc_stats:
                    type: object
                    properties:
                      controls:
                        type: object
                        properties:
                          compliance_rate:
                            type: integer
                          data_available:
                            type: boolean
                            description: Whether compliance data is available
                          failed_assessments:
                            type: integer
                          severity:
                            type: object
                            properties:
                              critical:
                                type: integer
                              warning:
                                type: integer
                              informational:
                                type: integer
                              pass:
                                type: integer
                      exceptions:
                        type: object
                        properties:
                          total_exceptions:
                            type: integer
                          expiring_exceptions:
                            type: integer
                          severity:
                            type: object
                            properties:
                              critical:
                                type: integer
                              warning:
                                type: integer
                              informational:
                                type: integer
                  empty_filters:
                    type: boolean
                  update_time:
                    type: integer
                    format: int64
              example:
                device_serial:
                - '026101000023'
                - 007951000388678
                - 007051000239252
                - 007051000239253
                - 007958000455738
                - 007951000388704
                bpc_id:
                - '44'
                - '45'
                - '89'
                - '47'
                - '271'
                - '272'
                - '196'
                - '273'
                - '197'
                - '111'
                - '155'
                - '159'
                - '117'
                - '90'
                - '91'
                - '92'
                - '94'
                - '51'
                - '95'
                - '52'
                - '53'
                - '97'
                - '55'
                - '12'
                - '13'
                - '57'
                - '58'
                - '19'
                - '241'
                - '121'
                - '242'
                - '122'
                - '243'
                - '200'
                - '3'
                - '4'
                - '203'
                - '5'
                - '6'
                - '249'
                - '7'
                - '128'
                - '207'
                - '9'
                - '208'
                - '60'
                - '21'
                - '253'
                - '132'
                - '177'
                - '178'
                - '212'
                - '215'
                - '259'
                - '216'
                - '217'
                - '33'
                - '38'
                - '260'
                - '261'
                - '262'
                - '263'
                - '340'
                - '264'
                - '341'
                - '100'
                - '102'
                - '223'
                - '267'
                - '344'
                - '103'
                - '345'
                - '104'
                - '346'
                - '105'
                - '347'
                - '227'
                - '107'
                - '228'
                - '108'
                - '109'
                - '40'
                - '42'
                - '86'
                - '43'
                - '87'
                bpc_id_count:
                - 4
                - 3
                - 6
                - 3
                - 3
                - 3
                - 4
                - 4
                - 6
                - 6
                - 6
                - 6
                - 6
                - 6
                - 6
                - 6
                - 6
                - 4
                - 6
                - 4
                - 4
                - 6
                - 6
                - 6
                - 5
                - 6
                - 6
                - 2
                - 6
                - 6
                - 6
                - 6
                - 6
                - 3
                - 28
                - 28
                - 6
                - 28
                - 28
                - 6
                - 28
                - 1
                - 4
                - 28
                - 28
                - 31
                - 6
                - 7
                - 1
                - 1
                - 1
                - 31
                - 6
                - 4
                - 6
                - 6
                - 3
                - 7
                - 4
                - 6
                - 6
                - 6
                - 4
                - 6
                - 4
                - 5
                - 6
                - 6
                - 17
                - 4
                - 6
                - 4
                - 6
                - 4
                - 6
                - 6
                - 4
                - 6
                - 12
                - 6
                - 6
                - 7
                - 3
                - 4
                - 4
                - 4
                manager:
                - ngfw
                action:
                - ''
                - alert
                - block
                object_type:
                - device_setup_general
                - authentication_sequences
                - anti_spyware_profile
                - certificate
                - interface_management_profile
                - device_setup_management_interface
                - file_blocking_profile
                - app_override
                - device_setup_logging_reporting
                - device_setup_authentication
                - device_setup_secure_communication
                - zone_protection_profile
                - zone
                - device_setup_telemetry
                - log_forwarding_profile
                - device_setup_services
                - device_setup_wildfire
                - security_rule
                - security_rulebase
                - device_setup_policy_rulebase
                - url_filtering_profile
                - decryption_rule
                - antivirus_profile
                - wildfire_analysis_profile
                - log_settings_system
                - decryption_profile
                - device_setup_minimum_password_complexity
                - device_setup_content_id
                - vulnerability_protection_profile
                - authentication_profiles
                - device_setup_session
                severity:
                - Warning
                - Informational
                - Critical
                location:
                - ''
                - shared
                - vsys1
                - predefined
                remediation_location:
                - tsgid:1001536090/Device:007951000388704/Device Setup Wildfire:Device Setup Wildfire/
                - tsgid:1001536090/Device:007051000239253/Device Setup Management Interface:Device Setup Management Interface/
                - NOT PROVIDED
                object_id:
                - to-dns-proxy-poc
                - Untrust
                - adns
                - Trust-L3
                - best-practice
                - Device Setup Minimum Password Complexity
                - APAC-Policy
                - Log Settings System
                pbpc_result_number:
                - '1768939214207450'
                - '1768248135671578'
                - '1771099216266731'
                - '1769025625152288'
                - '1768161788021773'
                - '1769371209414697'
                bpc_status:
                - exception
                - fail
                - pass
                device_type:
                - ngfw
                bpc_stats:
                  controls:
                    compliance_rate: 57
                    data_available: true
                    failed_assessments: 248
                    severity:
                      critical: 65
                      warning: 84
                      informational: 99
                      pass: 333
                  exceptions:
                    total_exceptions: 76
                    expiring_exceptions: 0
                    severity:
                      critical: 52
                      warning: 10
                      informational: 14
                empty_filters: false
                update_time: 1771099212424
        '400':
          description: Bad request - invalid filter criteria in request body
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _errors:
                - code: API_CF_E00001
                  message: Invalid input
                  details:
                  - Invalid filter criteria or malformed request body
                  help: https://docs.paloaltonetworks.com/compliance-center/api/errors#API_CF_E00001
                _request_id: eb18eb0c-d5b7-43f3-9e38-38464ee11e2f
        '403':
          $ref: '#/components/responses/ForbiddenError'
        '404':
          $ref: '#/components/responses/NotFoundError'
        '500':
          $ref: '#/components/responses/InternalServerError'
    servers:
    - url: https://api.strata.paloaltonetworks.com/posture/compliance-frameworks/v1
      description: Current
  /benchmark-monitoring/download:
    post:
      tags:
      - Benchmark Monitoring
      summary: Download Benchmark Data
      description: Download benchmark monitoring data in specified format (CSV, etc.)
      operationId: getBenchmarkMonitoringDownload
      security:
      - BearerAuth: []
      parameters:
      - name: offset
        in: query
        required: false
        schema:
          type: integer
          format: int64
          default: 0
          minimum: 0
        description: Number of records to skip for pagination
        example: 0
      - name: limit
        in: query
        required: false
        schema:
          type: integer
          format: int64
          default: 0
          minimum: 0
        description: Maximum number of records to return (0 for no limit)
        example: 100
      - name: format
        in: query
        required: false
        schema:
          type: string
          default: csv
          enum:
          - csv
          - json
        description: Export format
        example: csv
      - name: compression
        in: query
        required: false
        schema:
          type: string
          default: 'no'
          enum:
          - 'no'
          - gzip
          - zip
        description: Compression type
        example: 'no'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                product:
                  type: string
                  description: Product filter
                  enum:
                  - sase
                  - ngfw
                  - all
                bpc_status:
                  type: array
                  description: BPC status filter
                  items:
                    type: string
                severity:
                  type: array
                  description: Severity filter
                  items:
                    type: string
                bpc_id:
                  type: array
                  description: BPC ID filter
                  items:
                    type: string
                object_type:
                  type: array
                  description: Object type filter
                  items:
                    type: string
                object_id:
                  type: array
                  description: Object ID filter
                  items:
                    type: string
                remediation_location:
                  type: array
                  description: Remediation location filter
                  items:
                    type: string
                action:
                  type: array
                  description: Action filter
                  items:
                    type: string
                device_type:
                  type: array
                  description: Device type filter
                  items:
                    type: string
            example:
              product: ngfw
              bpc_status: []
              severity: []
              bpc_id:
              - '100'
              - '102'
              - '103'
              - '104'
              - '105'
              - '107'
              - '108'
              - '109'
              - '111'
              - '117'
              - '12'
              - '121'
              - '122'
              - '123'
              - '124'
              - '125'
              - '126'
              - '127'
              - '128'
              - '129'
              - '13'
              - '130'
              - '131'
              - '132'
              - '133'
              - '134'
              - '136'
              - '138'
              - '139'
              - '141'
              - '142'
              - '143'
              - '144'
              - '145'
              - '149'
              - '150'
              - '151'
              - '154'
              - '155'
              - '157'
              - '158'
              - '159'
              - '16'
              - '164'
              - '165'
              - '17'
              - '173'
              - '174'
              - '177'
              - '178'
              - '182'
              - '183'
              - '184'
              - '185'
              - '186'
              - '187'
              - '188'
              - '189'
              - '19'
              - '190'
              - '194'
              - '196'
              - '197'
              - '199'
              - '200'
              - '203'
              - '207'
              - '208'
              - '21'
              - '211'
              - '212'
              - '215'
              - '216'
              - '217'
              - '223'
              - '224'
              - '227'
              - '228'
              - '231'
              - '233'
              - '234'
              - '241'
              - '242'
              - '243'
              - '247'
              - '249'
              - '253'
              - '259'
              - '26'
              - '260'
              - '261'
              - '262'
              - '263'
              - '264'
              - '267'
              - '268'
              - '27'
              - '271'
              - '272'
              - '273'
              - '276'
              - '277'
              - '278'
              - '279'
              - '280'
              - '281'
              - '282'
              - '283'
              - '284'
              - '285'
              - '287'
              - '288'
              - '289'
              - '292'
              - '293'
              - '294'
              - '295'
              - '296'
              - '297'
              - '298'
              - '299'
              - '3'
              - '300'
              - '301'
              - '302'
              - '303'
              - '304'
              - '305'
              - '306'
              - '307'
              - '308'
              - '311'
              - '312'
              - '317'
              - '32'
              - '320'
              - '321'
              - '322'
              - '323'
              - '324'
              - '325'
              - '326'
              - '327'
              - '328'
              - '329'
              - '33'
              - '330'
              - '331'
              - '332'
              - '333'
              - '339'
              - '340'
              - '341'
              - '344'
              - '345'
              - '346'
              - '347'
              - '38'
              - '4'
              - '40'
              - '41'
              - '42'
              - '43'
              - '44'
              - '45'
              - '47'
              - '49'
              - '5'
              - '51'
              - '52'
              - '53'
              - '55'
              - '57'
              - '58'
              - '6'
              - '60'
              - '63'
              - '65'
              - '67'
              - '68'
              - '69'
              - '7'
              - '71'
              - '72'
              - '74'
              - '76'
              - '77'
              - '78'
              - '79'
              - '80'
              - '86'
              - '87'
              - '89'
              - '9'
              - '90'
              - '91'
              - '92'
              - '94'
              - '95'
              - '97'
              - '98'
              object_type: []
              object_id: []
              remediation_location: []
              action: []
              device_type:
              - ngfw
      responses:
        '200':
          description: 'Success - Returns benchmark monitoring data in the requested format.


            **CSV Format Columns:**

            1. BPC Title - Description of the best practice check

            2. Device Serial - Serial number of the device

            3. Bpc Id - Best Practice Check ID

            4. Product - Product type (ngfw, sase, all)

            5. Object Type - Type of configuration object

            6. Severity - Severity level (Critical, Warning, Informational)

            7. Location - Configuration location context

            8. Remediation Location - Full path to the remediation location

            9. Object Id - Object identifier

            10. Bpc Status - Status of the check (pass, fail, exception)

            11. User Excluded - Whether the check was user-excluded (true/false)

            '
          content:
            application/octet-stream:
              schema:
                type: string
                format: binary
            text/csv:
              schema:
                type: string
                format: binary
              example: 'BPC Title,Device Serial,Bpc Id,Product,Object Type,Severity,Location,Remediation Location,Object Id,Bpc Status,User Excluded

                The Permitted IP Addresses list on the management interface of the firewall should be used to prevent access from unauthorized sources,007051000239252,100,ngfw,device_setup_management_interface,Informational,,tsgid:1001536090/Device:007051000239252/Device Setup Management Interface:Device Setup Management Interface/,Device Setup Management Interface,fail,false

                Administrative management interface services should not allow unencrypted protocols like HTTP and Telnet,007051000239252,102,ngfw,device_setup_management_interface,Warning,,tsgid:1001536090/Device:007051000239252/Device Setup Management Interface:Device Setup Management Interface/,Device Setup Management Interface,pass,false

                '
        '400':
          description: Bad request - invalid format, compression type, or filter criteria
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              example:
                _errors:
                - code: API_CF_E00001
                  message: Invalid input
                  details:
                  - Invalid format or compression type specified
                  help: https://docs.paloaltonetworks.com/compliance-center/api/errors#API_CF_E00001
                _request_id: eb18eb0c-d5b7-43f3-9e38-38464ee11e2f
        '403':
          $ref: '#/components/responses/ForbiddenError'
        '404':
          $ref: '#/components/responses/NotFoundError'
        '500':
          $ref: '#/components/responses/InternalServerError'
    servers:
    - url: https://api.strata.paloaltonetworks.com/posture/compliance-frameworks/v1
      description: Current
  /compliance-frameworks/v1/benchmark-monitoring:
    post:
      tags:
      - Benchmark Monitoring
      summary: Get Benchmark Monitoring Data
      description: Retrieve compliance monitoring data for benchmarked frameworks with filtering and pagination.
      operationId: GetBenchmarkMonitoring
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/BenchmarkMonitoringRequest'
      responses:
        '200':
          description: Success.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BenchmarkMonitoringResponse'
        '400':
          description: Bad request - invalid filter criteria in request body.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden - insufficient permissions.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Internal server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
    servers:
    - url: https://api.strata.paloaltonetworks.com/posture
      description: Current
  /compliance-frameworks/v1/benchmark-monitoring/download:
    post:
      tags:
      - Benchmark Monitoring
      summary: Download Benchmark Data
      description: Download benchmark monitoring data in specified format (CSV or JSON).
      operationId: DownloadBenchmarkMonitoring
      parameters:
      - name: offset
        in: query
        required: false
        schema:
          type: integer
          format: int64
          default: 0
          minimum: 0
        description: Number of records to skip for pagination.
      - name: limit
        in: query
        required: false
        schema:
          type: integer
          format: int64
          default: 0
          minimum: 0
        description: Maximum number of

# --- truncated at 32 KB (41 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/openapi/palo-alto-networks-benchmark-monitoring-api-openapi.yml