Palo Alto Networks DLP API API

DLP API

OpenAPI Specification

palo-alto-networks-dlp-api-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: public dlp DLP API API
  version: 1.0.0
  description: DLP Public API
  license:
    name: MIT
    url: https://opensource.org/license/mit
  contact:
    email: support@paloaltonetworks.com
    name: Palo Alto Networks Technical Support
    url: https://support.paloaltonetworks.com
servers:
- url: https://api.dlp.paloaltonetworks.com
  description: Prod host
security:
- JWTAuth: []
tags:
- name: DLP API
  description: DLP API
paths:
  /v1/public/report/{reportId}:
    summary: Get DLP Report
    description: Get DLP report
    parameters:
    - name: fetchSnippets
      description: (Optional) Boolean field when set to true, retrieves snippets from the DLP report.
      schema:
        type: boolean
      in: query
    get:
      tags:
      - DLP API
      parameters:
      - name: reportId
        description: ID of the retrieved report
        schema:
          type: string
        in: path
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ScanContentResponse'
              examples:
                sample report:
                  value:
                    txn_id: '483332512'
                    report_id: '483332512'
                    data_profile_id: '11995014'
                    data_profile_name: Sensitive Content
                    type: basic
                    tenant_id: '7830962012064884736'
                    fileSha: 90d068df2381ebd8342c99cf59907e7c9fc7ab3d7c4c6fdc2a3d814eb7ed374f
                    file_name: google_finance_template_1mb.txt
                    file_type: txt
                    file_size_in_bytes: 1005626
                    extracted_file_size_in_bytes: 1005635
                    detection_time: 10/15/2020 21:16:24 UTC
                    data_pattern_rule_1_verdict: MATCHED
                    scanContentRawReport:
                      data_pattern_rule_1_results:
                      - data_pattern_id: 5ee3c51c99025d000161ab9a
                        version: 1
                        name: Bank - American Bankers Association Routing Number - ABA
                        technique: regex
                        type: predefined
                        strict_detection_frequency: 0
                        proximity_detection_frequency: 0
                        detection_frequency: 0
                        unique_strict_detection_frequency: 0
                        unique_checksum_detection_frequency: 0
                        unique_proximity_detection_frequency: 0
                        unique_detection_frequency: 0
                        weighted_frequency: 0
                        high_confidence_frequency: 0
                        medium_confidence_frequency: 0
                        low_confidence_frequency: 0
                        unique_high_confidence_frequency: 0
                        unique_medium_confidence_frequency: 0
                        unique_low_confidence_frequency: 0
                        state: EVALUATED
                      - data_pattern_id: 5ee3c51c99025d000161aba6
                        version: 1
                        name: Voyager Credit Card
                        technique: regex
                        type: predefined
                        strict_detection_frequency: 0
                        proximity_detection_frequency: 0
                        detection_frequency: 0
                        unique_strict_detection_frequency: 0
                        unique_checksum_detection_frequency: 0
                        unique_proximity_detection_frequency: 0
                        unique_detection_frequency: 0
                        weighted_frequency: 0
                        high_confidence_frequency: 0
                        medium_confidence_frequency: 0
                        low_confidence_frequency: 0
                        unique_high_confidence_frequency: 0
                        unique_medium_confidence_frequency: 0
                        unique_low_confidence_frequency: 0
                        state: EVALUATED
                      - data_pattern_id: 5ee3c51d99025d000161ac52
                        version: 1
                        name: NationalId - US Social Security Number - SSN
                        technique: regex
                        type: predefined
                        strict_detection_frequency: 0
                        proximity_detection_frequency: 3
                        detection_frequency: 3
                        unique_strict_detection_frequency: 0
                        unique_checksum_detection_frequency: 0
                        unique_proximity_detection_frequency: 3
                        unique_detection_frequency: 3
                        weighted_frequency: 0
                        high_confidence_frequency: 3
                        medium_confidence_frequency: 0
                        low_confidence_frequency: 3
                        unique_high_confidence_frequency: 3
                        unique_medium_confidence_frequency: 0
                        unique_low_confidence_frequency: 3
                        matched_confidence_level: high
                        state: EVALUATED
                report with snippets:
                  value:
                    fileSha: a4d58aa3caeb73b56028f597de2b3263d64e2835f277f31c97be53bc76a29e47
                    scanContentRawReport:
                      data_pattern_rule_1_results:
                      - detections:
                        - left: "\n\n\n\n\n\n tax id number ***-**-**99 abs cupp\nIBAN CH9300762011623852957 cusip "
                          right: ' | *****0BG4 DEA *****3839 | *****5341 CLIA 24C3872984 | 05D0911402

                            HETU number ******-856E | *******0490

                            CPF | **************1-30 CNPJ

                            *-****-****-6246 SHAKAI HOSHŌ ZEI BANGŌ SEIDO MAINANBA ****-**'
                          detection: '*******00'
                          original_text: '*******00'
                          origOffSet: 75
                          textLength: 0
                        - left: 'HOSHŌ ZEI BANGŌ SEIDO MAINANBA ****-****-6333

                            UK Tax UTR ******1030 ******1031 NINO GP 32 76 63 *****280B Germany Tax ID *******1827 *******8911 *******8796 visa 4556501518562241 4929091695478411 aba '
                          right: ' *****3532 ssn 098-07-33 16 480-33-1945 Canada SIN *** *** 425 *****3197 Australia Tax ID 45322 1716 98754015 Access Key ID 022QF06E7MXBSH9DHM02 AWS Secret Key kWcrlUX5JEDGM/LtmEENI/ aVmYvHNif5zB+d9+c'
                          detection: '*******55'
                          original_text: '*******55'
                          origOffSet: 446
                          textLength: 0
                        - left: "\n\n\n\n\n\n tax id number "
                          right: ' abs cupp

                            IBAN CH9300762011623852957 cusip *******00 | *****0BG4 DEA *****3839 | *****5341 CLIA 24C3872984 | 05D0911402

                            HETU number ******-856E | *******0490

                            CPF | **************1-30 CNPJ

                            *-****-***'
                          detection: '***-**-**99'
                          original_text: '***-**-**99'
                          origOffSet: 21
                          textLength: 0
                        data_pattern_id: 6374e1b4dee31d91c40b179d
                        version: 1
                        name: National Id - US Social Security Number - SSN
                        technique: regex
                        type: predefined
                        strict_detection_frequency: 0
                        proximity_detection_frequency: 7
                        detection_frequency: 7
                        unique_strict_detection_frequency: 0
                        unique_checksum_detection_frequency: 0
                        unique_proximity_detection_frequency: 7
                        unique_detection_frequency: 7
                        weighted_frequency: 0
                        high_confidence_frequency: 7
                        medium_confidence_frequency: 0
                        low_confidence_frequency: 7
                        unique_high_confidence_frequency: 7
                        unique_medium_confidence_frequency: 0
                        unique_low_confidence_frequency: 7
                        matched_confidence_level: high
                        state: EVALUATED
                        high_confidence_detections: {}
                        medium_confidence_detections: {}
                        low_confidence_detections: {}
                        edm_columns: []
                    txn_id: '163570374'
                    report_id: '163570374'
                    data_profile_id: '11995044'
                    data_profile_version: 1
                    data_profile_name: PII
                    type: basic
                    tenant_id: '5886928188517009408'
                    file_name: SSNpattern
                    file_type: pdf
                    file_size_in_bytes: 930
                    extracted_file_size_in_bytes: 937
                    detection_time: 02/10/2024 23:34:14 GMT
                    action: block
                    data_pattern_rule_1_verdict: MATCHED
          description: OK
        '400':
          description: Bad Request. Got an invalid JSON.
        '401':
          description: Unauthorized access. An issue occurred during authentication. This can indicate an incorrect key, ID, or other invalid authentication parameters.
        '403':
          description: Forbidden access. The provided API Key does not have the required permissions to run this API.
        '500':
          description: Internal server error. A unified status for API communication type errors.
      security:
      - JWTAuth: []
      summary: Get Reports
      description: Get report
      operationId: getReport
  /v1/api/incidents/{incidentID}/assignee:
    description: Assign Incidents
    servers:
    - url: https://api.dlp.paloaltonetworks.com
      description: ''
    put:
      requestBody:
        description: UUID of assignee
        content:
          application/json:
            schema:
              type: string
            examples:
              UUID of assignee:
                value: 00d53ebf-c386-4b95-ad05-6819517c3450
        required: true
      tags:
      - DLP API
      parameters:
      - name: region
        description: region the incident are belongs to (default to us)
        schema:
          enum:
          - us
          - eu
          - uk
          - jp
          - in
          - ap
          - ca
          - au
          - par
          type: string
        in: query
        required: false
      - name: incidentID
        description: ID of the Incident to be updated
        schema:
          type: string
        in: path
        required: true
      responses:
        '200':
          description: OK
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '500':
          description: Internal server error
      security:
      - JWTAuth: []
      summary: Assign Incidents
      operationId: updateIncidentAssignee
  /v1/api/incidents/{incidentID}/notes:
    description: Update incident with notes
    servers:
    - url: https://api.dlp.paloaltonetworks.com
      description: ''
    put:
      operationId: updateIncidentNotes
      requestBody:
        content:
          application/json:
            schema:
              type: string
            examples:
              sample notes:
                value: This is a note for incident
        required: true
      tags:
      - DLP API
      parameters:
      - name: incidentID
        description: ID of the Incident to be updated
        schema:
          type: string
        in: path
        required: true
      - name: region
        description: region the incident belongs to (default to us)
        schema:
          enum:
          - us
          - eu
          - uk
          - jp
          - in
          - ap
          - ca
          - au
          - par
          type: string
        in: query
        required: false
      responses:
        '200':
          description: OK
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '500':
          description: Internal server error
      security:
      - JWTAuth: []
      summary: Update Inicident Note
    delete:
      operationId: deleteIncidentNotes
      tags:
      - DLP API
      parameters:
      - name: incidentID
        description: ID of the Incident
        schema:
          type: string
        in: path
        required: true
      - name: region
        description: region the incident belongs to (default to us)
        schema:
          enum:
          - us
          - eu
          - uk
          - jp
          - in
          - ap
          - ca
          - au
          - par
          type: string
        in: query
        required: false
      responses:
        '200':
          description: notes are deleted
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '500':
          description: Internal server error
      summary: Remove Incident Notes
  /v1/api/incidents/{incidentID}/resolution-status:
    description: Update incident resolution status
    servers:
    - url: https://api.dlp.paloaltonetworks.com
      description: ''
    put:
      requestBody:
        content:
          application/json:
            schema:
              type: string
            examples:
              resolution status:
                value: assigned
        required: true
      tags:
      - DLP API
      parameters:
      - name: incidentID
        description: ID of the Incident to be updated
        schema:
          type: string
        in: path
        required: true
      - name: region
        description: region that incident belongs to (default to us)
        schema:
          enum:
          - us
          - eu
          - uk
          - jp
          - in
          - ap
          - ca
          - au
          - par
          type: string
        in: query
        required: false
      responses:
        '200':
          description: OK
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '500':
          description: Internal server error
      security:
      - JWTAuth: []
      summary: Update Incident Resolution
      operationId: updateIncidentResolutionStatus
  /v1/api/incidents/assignee:
    summary: Get All Assignees
    description: Get All Assignees
    servers:
    - url: https://api.dlp.paloaltonetworks.com
      description: ''
    get:
      operationId: getIncidentAssignees
      tags:
      - DLP API
      responses:
        '200':
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/IncidentAssignee'
              examples:
                assignees:
                  value:
                  - id: 00d53ebf-c386-4b95-ad05-6819517c3450
                    tenantId: '5886928188517009408'
                    firstName: test u
                    lastName: test
                    emailAddress: test@test.com
                    status: ACTIVE
                    createdAt: 2024-Jan-11 23:16:33 UTC
                    updatedAt: 2024-Feb-14 19:13:01 UTC
                  - id: 133b9b0d-6e64-40ca-abec-15ff3b906b80
                    tenantId: '5886928188517009408'
                    firstName: user
                    lastName: my last name
                    emailAddress: user1@test.com
                    status: ACTIVE
                    createdAt: 2023-Aug-03 21:23:39 UTC
          description: OK
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '500':
          description: Internal server error
      security:
      - JWTAuth: []
      summary: Get All Assignees
    put:
      operationId: createOrUpdateIncidentAssignees
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/IncidentAssigneeDTO'
        required: true
      tags:
      - DLP API
      responses:
        '200':
          description: OK
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '500':
          description: Internal server error
      security:
      - JWTAuth: []
      summary: Create or Update Incident Assignee
  /v1/api/incidents/assignee/{assigneeId}:
    get:
      tags:
      - DLP API
      parameters:
      - name: assigneeId
        description: The ID of the assignee for the incident.
        schema:
          type: string
        in: path
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IncidentAssignee'
              examples:
                assignee:
                  value:
                    id: 00d53ebf-c386-4b95-ad05-6819517c3450
                    tenantId: '5886928188517009408'
                    firstName: test
                    lastName: test
                    emailAddress: test@test.com
                    status: ACTIVE
                    createdAt: 2024-Jan-11 23:16:33 UTC
          description: OK
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '500':
          description: Internal server error
      security:
      - JWTAuth: []
      summary: Get Assignee by ID
      operationId: getIncidentAssigneesById
  /v2/api/incidents/{incidentID}:
    description: Get Incident Details
    servers:
    - url: https://api.dlp.paloaltonetworks.com
      description: ''
    parameters:
    - name: region
      description: region(default to us)
      schema:
        enum:
        - us
        - eu
        - uk
        - jp
        - in
        - ap
        - ca
        - au
        - par
        type: string
      in: query
    get:
      tags:
      - DLP API
      parameters:
      - examples:
          IncidentID Example:
            value: 3fb38abe-a83b-44e5-99d5-4bec3765bba6
        name: incidentID
        description: ID of the incident
        schema:
          type: string
        in: path
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IncidentResponseDTO'
              examples:
                incident detail:
                  value:
                    incident_id: 1a762308-3735-4d29-8edd-4595d4e3f982
                    tenant_id: '5886928188517009408'
                    report_id: '1107089697'
                    data_profile_id: 11995044
                    data_profile_name: PII
                    file_sha: a4d58aa3caeb73b56028f597de2b3263d64e2835f277f31c97be53bc76a29e47
                    file_name: SSNpattern
                    incident_creation_time: 2024-Jan-18 21:46:54 UTC
                    channel: ngfw
                    source: ngfw
                    action: alert
                    match_info:
                      6374e1b4dee31d91c40b1705:
                        name: Driver License - Slovenia
                        version: 1
                        lcf: 5
                        hcf: 0
                        mcf: 0
                        ulcf: 5
                        uhcf: 0
                        umcf: 0
                        detection_technique: regex
                      6374e1b4dee31d91c40b1708:
                        name: Driver License - Canada
                        version: 1
                        lcf: 13
                        hcf: 0
                        mcf: 0
                        ulcf: 13
                        uhcf: 0
                        umcf: 0
                        detection_technique: regex
                      6374e1b4dee31d91c40b1709:
                        name: Driver License - US
                        version: 1
                        lcf: 17
                        hcf: 0
                        mcf: 0
                        ulcf: 17
                        uhcf: 0
                        umcf: 0
                        detection_technique: regex
                    snippets:
                      6374e1b4dee31d91c40b1705:
                        version: 1
                        low_confidence_detections:
                        - left: "\n\n\n\n\n\n tax id number ***-**-**99 abs cupp\nIBAN CH9300762011623852957 cusip "
                          right: ' | *****0BG4 DEA *****3839 | *****5341 CLIA 24C3872984 | 05D0911402

                            HETU number ******-856E | *******0490

                            CPF | **************1-30 CNPJ

                            *-****-****-6246 SHAKAI HOSHŌ ZEI BANGŌ SEIDO MAINANBA ****-**'
                          detection: '*******00'
                          original_text: '*******00'
                          origOffSet: 75
                          textLength: 0
                        - left: 'HOSHŌ ZEI BANGŌ SEIDO MAINANBA ****-****-6333

                            UK Tax UTR ******1030 ******1031 NINO GP 32 76 63 *****280B Germany Tax ID *******1827 *******8911 *******8796 visa 4556501518562241 4929091695478411 aba '
                          right: ' *****3532 ssn 098-07-33 16 480-33-1945 Canada SIN *** *** 425 *****3197 Australia Tax ID 45322 1716 98754015 Access Key ID 022QF06E7MXBSH9DHM02 AWS Secret Key kWcrlUX5JEDGM/LtmEENI/ aVmYvHNif5zB+d9+c'
                          detection: '*******55'
                          original_text: '*******55'
                          origOffSet: 446
                          textLength: 0
                        - left: 'BANGŌ SEIDO MAINANBA ****-****-6333

                            UK Tax UTR ******1030 ******1031 NINO GP 32 76 63 *****280B Germany Tax ID *******1827 *******8911 *******8796 visa 4556501518562241 4929091695478411 aba *******55 '
                          right: ' ssn 098-07-33 16 480-33-1945 Canada SIN *** *** 425 *****3197 Australia Tax ID 45322 1716 98754015 Access Key ID 022QF06E7MXBSH9DHM02 AWS Secret Key kWcrlUX5JEDGM/LtmEENI/ aVmYvHNif5zB+d9+ct ;5301250'
                          detection: '*****3532'
                          original_text: '*****3532'
                          origOffSet: 456
                          textLength: 0
                      6374e1b4dee31d91c40b1708:
                        version: 1
                        low_confidence_detections:
                        - left: "\n\n\n\n\n\n tax id number ***-**-**99 abs cupp\nIBAN CH9300762011623852957 cusip "
                          right: ' | *****0BG4 DEA *****3839 | *****5341 CLIA 24C3872984 | 05D0911402

                            HETU number ******-856E | *******0490

                            CPF | **************1-30 CNPJ

                            *-****-****-6246 SHAKAI HOSHŌ ZEI BANGŌ SEIDO MAINANBA ****-**'
                          detection: '*******00'
                          original_text: '*******00'
                          origOffSet: 75
                          textLength: 0
                        - left: "\n\n\n\n\n\n tax id number ***-**-**99 abs cupp\nIBAN CH9300762011623852957 cusip *******00 | *****0BG4 DEA *****3839 | "
                          right: ' CLIA 24C3872984 | 05D0911402

                            HETU number ******-856E | *******0490

                            CPF | **************1-30 CNPJ

                            *-****-****-6246 SHAKAI HOSHŌ ZEI BANGŌ SEIDO MAINANBA ****-****-6333

                            UK Tax UTR ******1030 ******10'
                          detection: '*****5341'
                          original_text: '*****5341'
                          origOffSet: 113
                          textLength: 0
                        - left: "\n\n\n\n\n\n tax id number ***-**-**99 abs cupp\nIBAN CH9300762011623852957 cusip *******00 | *****0BG4 DEA "
                          right: ' | *****5341 CLIA 24C3872984 | 05D0911402

                            HETU number ******-856E | *******0490

                            CPF | **************1-30 CNPJ

                            *-****-****-6246 SHAKAI HOSHŌ ZEI BANGŌ SEIDO MAINANBA ****-****-6333

                            UK Tax UTR ******1'
                          detection: '*****3839'
                          original_text: '*****3839'
                          origOffSet: 101
                          textLength: 0
                      6374e1b4dee31d91c40b1709:
                        version: 1
                        low_confidence_detections:
                        - left: "\n\n\n\n\n\n tax id number ***-**-**99 abs cupp\nIBAN CH9300762011623852957 cusip "
                          right: ' | *****0BG4 DEA *****3839 | *****5341 CLIA 24C3872984 | 05D0911402

                            HETU number ******-856E | *******0490

                            CPF | **************1-30 CNPJ

                            *-****-****-6246 SHAKAI HOSHŌ ZEI BANGŌ SEIDO MAINANBA ****-**'
                          detection: '*******00'
                          original_text: '*******00'
                          origOffSet: 75
                          textLength: 0
                        - left: "\n\n\n\n\n\n tax id number ***-**-**99 abs cupp\nIBAN CH9300762011623852957 cusip *******00 | *****0BG4 DEA *****3839 | *****5341 CLIA 24C3872984 | 05D0911402\nHETU number "
                          right: '-856E | *******0490

                            CPF | **************1-30 CNPJ

                            *-****-****-6246 SHAKAI HOSHŌ ZEI BANGŌ SEIDO MAINANBA ****-****-6333

                            UK Tax UTR ******1030 ******1031 NINO GP 32 76 63 *****280B Germany Tax ID ***'
                          detection: '******'
                          original_text: '******'
                          origOffSet: 164
                          textLength: 0
                        - left: "\n\n\n\n\n\n tax id number "
                          right: ' abs cupp

                            IBAN CH9300762011623852957 cusip *******00 | *****0BG4 DEA *****3839 | *****5341 CLIA 24C3872984 | 05D0911402

                            HETU number ******-856E | *******0490

                            CPF | **************1-30 CNPJ

                            *-****-***'
                          detection: '***-**-**99'
                          original_text: '***-**-**99'
                          origOffSet: 21
                          textLength: 0
          description: OK
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '500':
          description: Internal server error
      security:
      - JWTAuth: []
      summary: Get Incident Details
      operationId: getIncident
  /v2/api/incidents:
    description: Get Bulk Incidents
    servers:
    - url: https://api.dlp.paloaltonetworks.com
      description: ''
    get:
      tags:
      - DLP API
      parameters:
      - name: ascending
        description: get the list of incident in ascending order or not(default false)
        schema:
          type: boolean
        in: query
        required: false
      - name: channel
        description: ngfw or prisma-access
        schema:
          enum:
          - ngfw
          - prisma-access
          type: string
        in: query
        required: false
      - name: end_time
        description: query incident until
        schema:
          format: date-time
          type: string
        in: query
        required: false
      - name: file_shas
        description: get incidents triggered by file hash. must be a comma separated list of one or more sha256 hashes of files
        schema:
          type: string
        in: query
        required: false
      - name: page_number
        description: page_number
        schema:
          format: int32
          type: integer
        in: query
        required: false
      - name: page_size
        description: page_size
        schema:
          format: int32
          type: integer
        in: query
        required: false
      - name: region
        description: region (defaults to us)
        schema:
          type: string
          enum:
          - us
          - eu
          - uk
          - jp
          - in
          - ap
          - ca
          - au
          - par
        in: query
        required: false
      - name: report_ids
        description: report_ids
        schema:
          type: array
          items:
            type: string
        in: query
        required: false
      - name: sort_by
        description: sort by. default sort by creation time
        schema:
          type: string
        in: query
        required: false
      - name: start_time
        description: start_time
        schema:
          format: date-time
          type: string
        in: query
        required: false
      - name: user_ids
        description: query by user ids
        schema:
          type: array
          items:
            type: string
        in: query
        required: false
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/IncidentResponse'
              examples:
                incidentResponseExample:
                  value:
                    page:
                      size: 10
                      number: 1
                      total_elements: 290
                      total_pages: 29
                    resources:
                    - incident_id: 7c3dca3d-1c08-4147-b171-9faba84739d4
                      tenant_id: '5886928188517009408'
                      report_id: '1572154781'
                      data_profile_id: 11995044
                      data_profile_name: PII
                      file_sha: a4d58aa3caeb73b56028f597de2b3263d64e2835f277f31c97be53bc76a29e47
                      file_name: SSNpattern
                      file_type: pdf
                      incident_creation_time: 2023-Dec-07 18:41:12 UTC
                      channel: ngfw
                      source: ngfw
                      action: alert
                    - incident_id: 81985a40-dae5-4e80-8147-678892ccfc00
                      tenant_id: '5886928188517009408'
                      report_id: '2968440380'
                      data_profile_id: 11995410
                      data_profile_name: Portugal_LNAME_high
                      file_sha: 6c25d79cd1dee00b3a6ee6bbb985dae6ee5bdfa31a8dfcffa241786c8c3893a7
                      file_name: test_portugal_LNAME.txt
                      file_type: txt
                      incident_creation_time: 2023-Dec-07 18:39:38 UTC
                      channel: ngfw
                      source: ngfw
                      action: alert
                    - incident_id: 08f014d8-ed13-490e-bfc4-7363f43a4af1
                      tenant_id: '5886928188517009408'
                      report_id: '1347859663'
                      data_profile_id: 11995355
                      data_profile_name: inline_timing_11_12_edm
                      file_sha: 6c8d18c544aba3b44cfa487d5020ec102a6317a6a5164e270bbecf6ea37df925
                      file_name: all_patterns_data_1_MB.txt
                      file_type: txt
                      incident_creation_time: 2023-Dec-06 19:39:46 UTC
                      channel: ngfw
                    

# --- truncated at 32 KB (42 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/openapi/palo-alto-networks-dlp-api-api-openapi.yml