Palo Alto Networks Incidents API

Incident management and investigation.

Operations 20

POST /incidents/get_incidents Palo Alto Networks List Incidents #
POST /incidents/get_incident_extra_data Palo Alto Networks Get Incident Details #
POST /incidents/update_incident Palo Alto Networks Update Incident #
POST /incident_management/get_incidents Palo Alto Networks Get Attack Surface Incidents #
POST /incident_management/update_incident Palo Alto Networks Update Attack Surface Incident #
POST /incident Palo Alto Networks Create Incident #
GET /incidents/search Palo Alto Networks Search Incidents (GET) #
POST /incidents/search Palo Alto Networks Search Incidents (POST) #
GET /incident/{id} Palo Alto Networks Get Incident #
POST /incident/update Palo Alto Networks Update Incident #
GET /incidents Palo Alto Networks List DLP Incidents #
GET /incidents/{incident_id} Palo Alto Networks Get DLP Incident by ID #
PUT /incidents/{incident_id} Palo Alto Networks Update DLP Incident #
GET /incidents/{incident_id}/snippets Palo Alto Networks Get Incident Content Snippets #
GET /email-incidents Palo Alto Networks List Email Incidents #
GET /email-incidents/{id} Palo Alto Networks Get Email Incident Details #
PUT /email-incidents/{id}/verdict Palo Alto Networks Update Email Incident Verdict #
GET /api/incidents Palo Alto Networks List Incidents #
GET /api/incidents/{id} Palo Alto Networks Get Incident Details #
PUT /api/incidents/{id} Palo Alto Networks Update Incident #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/palo-alto-networks-incidents-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

palo-alto-networks-incidents-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Palo Alto Networks Incidents API
  license:
    name: Proprietary
    url: https://www.paloaltonetworks.com/legal
  version: '1.0'
  description: 'Operations tagged Incidents across 8 of this provider''s published API definitions: palo-alto-cortex-xdr-api-openapi-original.yml, palo-alto-cortex-xpanse-api-openapi-original.yml, palo-alto-cortex-xsiam-api-openapi-original.yml, palo-alto-cortex-xsoar-api-openapi-original.yml, palo-alto-dlp-api-openapi-original.yml, palo-alto-email-dlp-api-openapi-original.yml, palo-alto-networks-incidents-api-openapi.yml, palo-alto-saas-security-api-openapi-original.yml.'
servers:
- url: https://api-{fqdn}/public_api/v1
  description: Cortex XDR tenant API endpoint.
  variables:
    fqdn:
      description: Tenant FQDN from the Cortex XDR settings page (e.g., example.xdr.us.paloaltonetworks.com).
      default: example.xdr.us.paloaltonetworks.com
- url: https://{xsoar-server}
  description: Cortex XSOAR server endpoint.
  variables:
    xsoar-server:
      description: Hostname or IP address of the Cortex XSOAR server.
      default: xsoar.example.com
- url: https://api.dlp.paloaltonetworks.com/v4
  description: Enterprise DLP API production server.
- url: https://api.{region}.dlp.paloaltonetworks.com/v1
  description: Email DLP API production server.
  variables:
    region:
      description: Deployment region for the Email DLP service. Choose the region matching your tenant data residency.
      default: us
      enum:
      - us
      - eu
      - in
      - apac
      - uk
      - jp
      - au
- url: https://api.stratacloud.paloaltonetworks.com/aiops/bpa/v1
  description: AIOps for NGFW BPA API production server.
- url: https://api.aperture.paloaltonetworks.com
  description: SaaS Security (Aperture) API production server.
tags:


# --- truncated at 32 KB (124 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/openapi/palo-alto-networks-incidents-api-openapi.yml