Palo Alto Networks Data Patterns API
The Data Patterns API from Palo Alto Networks — 2 operation(s) for data patterns.
The Data Patterns API from Palo Alto Networks — 2 operation(s) for data patterns.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/palo-alto-networks-data-patterns-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
contact: {}
description: 'Manage data patterns used for detecting sensitive information such as PII, financial data, healthcare
information, and custom patterns. Create, update, and configure detection patterns with various techniques
including regex, machine learning, and exact data matching.'
license:
name: MIT
url: https://opensource.org/license/mit
title: v2 Data Patterns API
version: 1.0.0
servers:
- url: https://api.dlp.paloaltonetworks.com
tags:
- name: Data Patterns
paths:
/v2/api/data-patterns:
get:
description: Returns a paginated list of data patterns for the authenticated tenant.
operationId: get-v2-api-data-patterns
parameters:
- description: Zero-based page index (0..N)
in: query
name: page
required: false
schema:
default: 0
minimum: 0
type: integer
- description: The size of the page to be returned
in: query
name: size
required: false
schema:
default: 20
minimum: 1
type: integer
- description: 'Sorting criteria in the format: property,(asc|desc). Default sort order is ascending. Multiple sort criteria are supported.'
in: query
name: sort
required: false
schema:
items:
type: string
type: array
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/PageDataPatternResponse'
description: Paginated list of data patterns
'401':
description: Unauthorized
'403':
description: Forbidden - insufficient privileges
security:
- Bearer: []
summary: List Data Patterns
tags:
- Data Patterns
post:
description: Creates a new custom data pattern for the authenticated tenant.
operationId: post-v2-api-data-patterns
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/DataPatternRequest'
required: true
responses:
'201':
content:
application/json:
schema:
$ref: '#/components/schemas/DataPatternResponse'
description: Data pattern created
'400':
description: Invalid request payload
'401':
description: Unauthorized
'403':
description: Forbidden - insufficient privileges
security:
- Bearer: []
summary: Create Data Pattern
tags:
- Data Patterns
/v2/api/data-patterns/{resourceId}:
delete:
description: Soft-deletes (archives) a data pattern by its ID.
operationId: delete-v2-api-data-patterns-resourceid
parameters:
- in: path
name: resourceId
required: true
schema:
type: string
responses:
'204':
description: Data pattern deleted
'401':
description: Unauthorized
'403':
description: Forbidden - insufficient privileges
'404':
description: Data pattern not found
security:
- Bearer: []
summary: Delete Data Pattern
tags:
- Data Patterns
get:
description: Retrieves a single data pattern by its ID.
operationId: get-v2-api-data-patterns-resourceid
parameters:
- in: path
name: resourceId
required: true
schema:
type: string
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/DataPatternResponse'
description: Data pattern found
'401':
description: Unauthorized
'403':
description: Forbidden - insufficient privileges
'404':
description: Data pattern not found
security:
- Bearer: []
summary: Get Data Pattern
tags:
- Data Patterns
patch:
description: Partially updates an existing data pattern using JSON Merge Patch semantics.
operationId: patch-v2-api-data-patterns-resourceid
parameters:
- in: path
name: resourceId
required: true
schema:
type: string
requestBody:
content:
application/merge-patch+json:
schema:
$ref: '#/components/schemas/DataPatternPatchRequest'
required: true
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/DataPatternResponse'
description: Data pattern updated
'400':
description: Invalid patch payload
'401':
description: Unauthorized
'403':
description: Forbidden - insufficient privileges
'404':
description: Data pattern not found
security:
- Bearer: []
summary: Patch Data Pattern
tags:
- Data Patterns
put:
description: Fully replaces an existing data pattern with the provided payload.
operationId: put-v2-api-data-patterns-resourceid
parameters:
- in: path
name: resourceId
required: true
schema:
type: string
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/DataPatternRequest'
required: true
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/DataPatternResponse'
description: Data pattern updated
'400':
description: Invalid request payload
'401':
description: Unauthorized
'403':
description: Forbidden - insufficient privileges
'404':
description: Data pattern not found
security:
- Bearer: []
summary: Update Data Pattern
tags:
- Data Patterns
/data-patterns:
get:
operationId: listDataPatterns
summary: Palo Alto Networks List Data Patterns
description: Returns a list of configured data patterns used for DLP detection. Includes both predefined system patterns (such as credit card numbers, social security numbers, and HIPAA identifiers) and custom patterns defined by the organization. Each pattern includes its detection rules, confidence thresholds, and associated data profile assignments.
tags:
- Data Patterns
parameters:
- name: offset
in: query
description: Pagination offset.
schema:
type: integer
default: 0
example: 0
- name: limit
in: query
description: Maximum number of patterns to return.
schema:
type: integer
default: 100
maximum: 500
example: 100
responses:
'200':
description: Data patterns returned successfully.
content:
application/json:
schema:
type: object
properties:
total:
type: integer
description: Total number of data patterns.
data_patterns:
type: array
items:
$ref: '#/components/schemas/DataPattern'
examples:
ListDataPatterns200Example:
summary: Default listDataPatterns 200 response
x-microcks-default: true
value:
total: 693
data_patterns:
- id: example-id
name: Production Gateway 48
description: Monitoring violation on alert network activity applied incident monitoring.
type: custom
category: custom
confidence: medium
detection_rules:
- rule_type: regex
value: example-value
proximity: 380
- rule_type: keyword
value: example-value
proximity: 94
enabled: true
incident_count: 23
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'500':
$ref: '#/components/responses/InternalServerError'
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
/data-patterns/{id}:
get:
operationId: getDataPattern
summary: Palo Alto Networks Get Data Pattern Details
description: Returns detailed configuration for a specific data pattern including its detection rules, regular expressions or keyword lists, proximity settings, and confidence scoring parameters.
tags:
- Data Patterns
parameters:
- name: id
in: path
required: true
description: Unique data pattern identifier.
schema:
type: string
example: example-id
responses:
'200':
description: Data pattern details returned successfully.
content:
application/json:
schema:
$ref: '#/components/schemas/DataPattern'
examples:
GetDataPattern200Example:
summary: Default getDataPattern 200 response
x-microcks-default: true
value:
id: example-id
name: Production Gateway 48
description: Monitoring violation on alert network activity applied incident monitoring.
type: custom
category: custom
confidence: medium
detection_rules:
- rule_type: regex
value: example-value
proximity: 380
- rule_type: keyword
value: example-value
proximity: 94
enabled: true
incident_count: 23
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'404':
$ref: '#/components/responses/NotFound'
'500':
$ref: '#/components/responses/InternalServerError'
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
components:
schemas:
DataPatternMatchingRules:
description: Optional matching rules controlling how the data pattern detects sensitive content
properties:
delimiter:
description: Delimiter character used to separate tokens
type: string
metadata_criteria:
description: Metadata criteria for additional filtering
items:
$ref: '#/components/schemas/MetadataCriterion'
type: array
proximity_distance:
description: Proximity distance for keyword matching (2-1000)
format: int32
maximum: 1000
minimum: 2
type: integer
proximity_keywords:
description: List of keywords that must appear within the proximity distance
items:
description: List of keywords that must appear within the proximity distance
type: string
type: array
regexes:
description: Weighted regular expressions used for detection
items:
$ref: '#/components/schemas/WeightedRegex'
type: array
type: object
PageableObject:
properties:
offset:
format: int64
type: integer
pageNumber:
format: int32
type: integer
pageSize:
format: int32
type: integer
paged:
type: boolean
sort:
$ref: '#/components/schemas/SortObject'
unpaged:
type: boolean
type: object
JsonNullableDataPatternTags:
description: New metadata tags
properties:
present:
type: boolean
undefined:
type: boolean
type: object
AuditResponse:
description: Audit metadata tracking creation and last-update information
properties:
created_at:
description: Timestamp when the resource was created
format: date-time
type: string
created_by:
description: Username or service that created the resource
type: string
updated_at:
description: Timestamp when the resource was last updated
format: date-time
type: string
updated_by:
description: Username or service that last updated the resource
type: string
type: object
MetadataCriterion:
description: Metadata criteria for additional filtering
properties:
comparisonOperatorType:
enum:
- less_than
- less_than_or_equal_to
- greater_than_or_equal_to
- greater_than
- equal_to
type: string
name:
type: string
type:
type: string
value:
type: string
type: object
JsonNullableDataPatternType:
description: New pattern type
properties:
present:
type: boolean
undefined:
type: boolean
type: object
JsonNullableDataPatternDetectionConfig:
description: New detection configuration
properties:
present:
type: boolean
undefined:
type: boolean
type: object
DataPatternDetectionConfig:
description: Detection configuration specifying the technique and supported confidence levels
properties:
supported_confidence_levels:
description: List of confidence levels supported by this pattern
items:
description: List of confidence levels supported by this pattern
enum:
- low
- medium
- high
type: string
type: array
technique:
description: Detection technique (e.g. regex, ml)
enum:
- edm
- document_fingerprint
- trainable_classifier
- ml_document
- regex
- weighted_regex
- ml
- titus_tag
- wildfire
- file_property
- dictionary
- pab
- document_classifier
type: string
required:
- technique
type: object
DataPatternRequest:
description: Request payload for creating or updating a data pattern
properties:
description:
description: Optional human-readable description
type: string
detection_config:
$ref: '#/components/schemas/DataPatternDetectionConfig'
matching_rules:
$ref: '#/components/schemas/DataPatternMatchingRules'
name:
description: Display name of the data pattern
example: SSN Pattern
maxLength: 64
minLength: 1
type: string
tags:
$ref: '#/components/schemas/DataPatternTags'
type:
description: Pattern type (e.g. regex, ml_based)
enum:
- predefined
- custom
- file_property
type: string
required:
- detection_config
- name
- type
type: object
DataPatternResponse:
description: Data pattern resource returned by the API
properties:
audit_metadata:
$ref: '#/components/schemas/AuditResponse'
description:
description: Optional human-readable description
type: string
detection_config:
$ref: '#/components/schemas/DataPatternDetectionConfig'
id:
description: Unique identifier of the data pattern
type: string
is_parent_managed:
description: Whether the pattern is managed by a parent tenant
type: boolean
license_type:
description: License type associated with the pattern
enum:
- standard
- enterprise
- essentials
type: string
matching_rules:
$ref: '#/components/schemas/DataPatternMatchingRules'
name:
description: Display name of the data pattern
type: string
status:
description: Current lifecycle status of the pattern
enum:
- active
- disabled
- deleted
- deprecated
- silent
type: string
tags:
$ref: '#/components/schemas/DataPatternTags'
tenant_id:
description: Tenant identifier that owns this pattern
type: string
type:
description: Pattern type
enum:
- predefined
- custom
- file_property
type: string
version:
description: Version number, incremented on each update
format: int32
type: integer
type: object
WeightedRegex:
description: Weighted regular expressions used for detection
properties:
regex:
maxLength: 2147483647
minLength: 1
type: string
weight:
format: int32
type: integer
required:
- regex
- weight
type: object
DataPatternTags:
description: Metadata tags
properties:
classification:
items:
type: string
type: array
compliance:
items:
type: string
type: array
geography:
items:
type: string
type: array
type: object
PageDataPatternResponse:
properties:
content:
items:
$ref: '#/components/schemas/DataPatternResponse'
type: array
empty:
type: boolean
first:
type: boolean
last:
type: boolean
number:
format: int32
type: integer
numberOfElements:
format: int32
type: integer
pageable:
$ref: '#/components/schemas/PageableObject'
size:
format: int32
type: integer
sort:
$ref: '#/components/schemas/SortObject'
totalElements:
format: int64
type: integer
totalPages:
format: int32
type: integer
type: object
SortObject:
properties:
empty:
type: boolean
sorted:
type: boolean
unsorted:
type: boolean
type: object
DataPatternPatchRequest:
description: Request payload for partially updating a data pattern (JSON Merge Patch)
properties:
description:
$ref: '#/components/schemas/JsonNullableString'
detection_config:
$ref: '#/components/schemas/JsonNullableDataPatternDetectionConfig'
matching_rules:
$ref: '#/components/schemas/JsonNullableDataPatternMatchingRules'
name:
$ref: '#/components/schemas/JsonNullableString'
tags:
$ref: '#/components/schemas/JsonNullableDataPatternTags'
type:
$ref: '#/components/schemas/JsonNullableDataPatternType'
required:
- detection_config
- name
- type
type: object
JsonNullableString:
description: New description (set to null to clear)
properties:
present:
type: boolean
undefined:
type: boolean
type: object
JsonNullableDataPatternMatchingRules:
description: New matching rules
properties:
present:
type: boolean
undefined:
type: boolean
type: object
ErrorResponse:
type: object
properties:
error:
type: string
description: Error code or type.
example: example-error
message:
type: string
description: Human-readable error message.
example: Policy blocked rule alert configured traffic Security activity.
DataPattern:
type: object
properties:
id:
type: string
description: Unique data pattern identifier.
example: example-id
name:
type: string
description: Display name of the data pattern.
example: Production Gateway 48
description:
type: string
description: Human-readable description of what the pattern detects.
example: Monitoring violation on alert network activity applied incident monitoring.
type:
type: string
enum:
- predefined
- custom
description: Whether the pattern is predefined or custom.
example: custom
category:
type: string
description: Pattern category (e.g., PII, PCI, HIPAA, Financial).
example: custom
confidence:
type: string
enum:
- high
- medium
- low
description: Confidence threshold for the pattern.
example: medium
detection_rules:
type: array
items:
type: object
properties:
rule_type:
type: string
enum:
- regex
- keyword
- dictionary
- file_property
example: dictionary
value:
type: string
example: example-value
proximity:
type: integer
example: 398
description: Detection rule definitions for the pattern.
example:
- rule_type: regex
value: example-value
proximity: 380
- rule_type: keyword
value: example-value
proximity: 94
enabled:
type: boolean
description: Whether the data pattern is active.
example: true
incident_count:
type: integer
description: Total number of incidents triggered by this pattern.
example: 23
securitySchemes:
Bearer:
scheme: bearer
type: http
bearerAuth:
type: http
scheme: bearer
bearerFormat: JWT
description: OAuth 2.0 bearer token obtained from the Palo Alto Networks SASE authentication service using the client credentials flow.
responses:
Unauthorized:
description: Invalid or expired bearer token.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
InternalServerError:
description: Internal server error.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
Forbidden:
description: Insufficient permissions for this operation.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
NotFound:
description: The requested resource was not found.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'