Palo Alto Networks Intelligent Feed API

The IntelligentFeed API from Palo Alto Networks — 2 operation(s) for intelligentfeed.

Operations 4

POST /v1/config/rulestacks/{rulestackname}/feeds Create intelligence feed #
DELETE /v1/config/rulestacks/{rulestackname}/feeds/{name} Delete intelligence feed #
GET /v1/config/rulestacks/{rulestackname}/feeds/{name} Retrieve feed data #
PUT /v1/config/rulestacks/{rulestackname}/feeds/{name} Update intelligence feed #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/palo-alto-networks-intelligentfeed-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

palo-alto-networks-intelligentfeed-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  contact: {}
  description: "An intelligent feed, also called an external dynamic list, is a list that you or third-parties can host on an external web server. You can specify the Intelligence Feed as the source or destination of your security rule. The NGFW checks the hosted list at hourly or daily intervals, and enforces your security rules based on the latest entries on your list, without requiring you to make any configuration changes.  \n\nFor more information about feeds, see [EDL hosting service](https://docs.paloaltonetworks.com/resources/edl-hosting-service.html).\n\n### Permission Policies\n\n| Action                      | Local Firewall Administrator | Local Rulestack Administrator | Global Rulestack Administrator|\n| --------------------------- | :--------------------------: | :---------------------------: | :---------------------------: |\n| Create Intelligent Feed     | ☐                      | **☑**                   | **☑**                   |\n| Delete Intelligent Feed     | ☐                      | **☑**                   | **☑**                   |                        \n| Update Intelligent Feed     | ☐                      | **☑**                   | **☑**                   |  \n| Describe Intelligent Feed   | **☑**                  | **☑**                   | **☑**                   |\n| List Intelligent Feeds      | **☑**                  | **☑**                   | **☑**                   |\n"
  title: Manage Intelligent Feed API
  version: 1.0.0
servers:
- url: https://api.us-east-1.aws.cloudngfw.paloaltonetworks.com
tags:
- name: IntelligentFeed
paths:
  /v1/config/rulestacks/{rulestackname}/feeds:
    post:
      description: 'Create an intelligence feed to analyze threat data.

        '
      operationId: post-v1-config-rulestacks-rulestackname-feeds
      parameters:
      - description: 'The name of the rulestack.

          '
        in: path
        name: rulestackname
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateIntelligentFeedRequest'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreateIntelligentFeedResponse'
          description: OK
      summary: Create intelligence feed
      tags:
      - IntelligentFeed
  /v1/config/rulestacks/{rulestackname}/feeds/{name}:
    delete:
      description: 'Delete the threat intelligence feeds for a specified rulestack.

        '
      operationId: delete-v1-config-rulestacks-rulestackname-feeds-name
      parameters:
      - description: 'The name of the rulestack.

          '
        in: path
        name: rulestackname
        required: true
        schema:
          type: string
      - description: 'The name of the feed.

          '
        in: path
        name: name
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/DeleteIntelligentFeedRequest'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DeleteIntelligentFeedResponse'
          description: OK
      summary: Delete intelligence feed
      tags:
      - IntelligentFeed
    get:
      description: 'Retrieve the intelligence feed data collected for the specified rulestack.

        '
      operationId: get-v1-config-rulestacks-rulestackname-feeds-name
      parameters:
      - description: 'The name of the rulestack.

          '
        in: path
        name: rulestackname
        required: true
        schema:
          type: string
      - description: 'The name of the feed.

          '
        in: path
        name: name
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/DescribeIntelligentFeedRequest'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DescribeIntelligentFeedResponse'
          description: OK
      summary: Retrieve feed data
      tags:
      - IntelligentFeed
    put:
      description: 'Update the threat intelligence feeds for a rulestack.

        '
      operationId: put-v1-config-rulestacks-rulestackname-feeds-name
      parameters:
      - description: 'The name of the rulestack.

          '
        in: path
        name: rulestackname
        required: true
        schema:
          type: string
      - description: 'The name of the feed.

          '
        in: path
        name: name
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateIntelligentFeedRequest'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UpdateIntelligentFeedResponse'
          description: OK
      summary: Update intelligence feed
      tags:
      - IntelligentFeed
components:
  schemas:
    UpdateIntelligentFeedRequest:
      additionalProperties: false
      properties:
        AuditComment:
          maxLength: 512
          title: Auditcomment
          type: string
        Certificate:
          title: Certificate
          type: string
        Description:
          maxLength: 512
          title: Description
          type: string
        FeedURL:
          maxLength: 255
          minLength: 1
          pattern: ^(http|https)://.+$
          title: Feedurl
          type: string
        Frequency:
          enum:
          - HOURLY
          - DAILY
          title: Frequency
          type: string
        Time:
          default: 3
          maximum: 23
          minimum: 0
          title: Time
          type: integer
        Type:
          enum:
          - IP_LIST
          - URL_LIST
          title: Type
          type: string
        UpdateToken:
          title: Updatetoken
          type: string
      required:
      - FeedURL
      - Type
      - Frequency
      title: UpdateIntelligentFeedRequest
      type: object
    UpdateIntelligentFeedResponse.Result:
      additionalProperties: false
      properties:
        ErrorCode:
          default: 0
          title: Errorcode
          type: integer
        Reason:
          title: Reason
          type: string
      title: Result
      type: object
    CreateIntelligentFeedRequest:
      additionalProperties: false
      properties:
        AuditComment:
          maxLength: 512
          title: Auditcomment
          type: string
        Certificate:
          title: Certificate
          type: string
        Description:
          maxLength: 512
          title: Description
          type: string
        FeedURL:
          maxLength: 255
          minLength: 1
          pattern: ^(http|https)://.+$
          title: Feedurl
          type: string
        Frequency:
          enum:
          - HOURLY
          - DAILY
          title: Frequency
          type: string
        Name:
          maxLength: 63
          minLength: 1
          pattern: ^[a-zA-Z0-9-]+$
          title: Name
          type: string
        Time:
          default: 3
          maximum: 23
          minimum: 0
          title: Time
          type: integer
        Type:
          enum:
          - IP_LIST
          - URL_LIST
          title: Type
          type: string
      required:
      - Name
      - FeedURL
      - Type
      - Frequency
      title: CreateIntelligentFeedRequest
      type: object
    DeleteIntelligentFeedResponse.ResponseData:
      additionalProperties: false
      properties:
        FeedEntry:
          $ref: '#/components/schemas/DeleteIntelligentFeedResponse.FeedDetails'
        Name:
          title: Name
          type: string
        RuleStackName:
          title: Rulestackname
          type: string
      title: ResponseData
      type: object
    UpdateIntelligentFeedResponse:
      additionalProperties: false
      properties:
        Response:
          $ref: '#/components/schemas/UpdateIntelligentFeedResponse.ResponseData'
        ResponseStatus:
          $ref: '#/components/schemas/UpdateIntelligentFeedResponse.Result'
      title: UpdateIntelligentFeedResponse
      type: object
    CreateIntelligentFeedResponse.Result:
      additionalProperties: false
      properties:
        ErrorCode:
          default: 0
          title: Errorcode
          type: integer
        Reason:
          title: Reason
          type: string
      title: Result
      type: object
    UpdateIntelligentFeedResponse.FeedDetails:
      additionalProperties: false
      properties:
        AuditComment:
          title: Auditcomment
          type: string
        Certificate:
          title: Certificate
          type: string
        Description:
          title: Description
          type: string
        FeedURL:
          title: Feedurl
          type: string
        Frequency:
          enum:
          - HOURLY
          - DAILY
          title: Frequency
          type: string
        Time:
          maximum: 23
          minimum: 0
          title: Time
          type: integer
        Type:
          enum:
          - IP_LIST
          - URL_LIST
          title: Type
          type: string
        UpdateToken:
          default: '1'
          title: Updatetoken
          type: string
      title: FeedDetails
      type: object
    DescribeIntelligentFeedRequest:
      additionalProperties: false
      properties:
        Candidate:
          default: true
          title: Candidate
          type: boolean
        Running:
          default: false
          title: Running
          type: boolean
      title: DescribeIntelligentFeedRequest
      type: object
    DeleteIntelligentFeedResponse.FeedDetails:
      additionalProperties: false
      properties:
        AuditComment:
          title: Auditcomment
          type: string
        Certificate:
          title: Certificate
          type: string
        Description:
          title: Description
          type: string
        FeedURL:
          title: Feedurl
          type: string
        Frequency:
          enum:
          - HOURLY
          - DAILY
          title: Frequency
          type: string
        Time:
          maximum: 23
          minimum: 0
          title: Time
          type: integer
        Type:
          enum:
          - IP_LIST
          - URL_LIST
          title: Type
          type: string
        UpdateToken:
          default: '1'
          title: Updatetoken
          type: string
      title: FeedDetails
      type: object
    CreateIntelligentFeedResponse.ResponseData:
      additionalProperties: false
      properties:
        FeedEntry:
          $ref: '#/components/schemas/CreateIntelligentFeedResponse.FeedDetails'
        Name:
          title: Name
          type: string
        RuleStackName:
          title: Rulestackname
          type: string
      title: ResponseData
      type: object
    UpdateIntelligentFeedResponse.ResponseData:
      additionalProperties: false
      properties:
        FeedEntry:
          $ref: '#/components/schemas/UpdateIntelligentFeedResponse.FeedDetails'
        Name:
          title: Name
          type: string
        RuleStackName:
          title: Rulestackname
          type: string
      title: ResponseData
      type: object
    DescribeIntelligentFeedResponse.FeedDetails:
      additionalProperties: false
      properties:
        AuditComment:
          title: Auditcomment
          type: string
        Certificate:
          title: Certificate
          type: string
        Description:
          title: Description
          type: string
        FeedURL:
          title: Feedurl
          type: string
        Frequency:
          enum:
          - HOURLY
          - DAILY
          title: Frequency
          type: string
        Time:
          maximum: 23
          minimum: 0
          title: Time
          type: integer
        Type:
          enum:
          - IP_LIST
          - URL_LIST
          title: Type
          type: string
        UpdateToken:
          default: '1'
          title: Updatetoken
          type: string
      title: FeedDetails
      type: object
    CreateIntelligentFeedResponse:
      additionalProperties: false
      properties:
        Response:
          $ref: '#/components/schemas/CreateIntelligentFeedResponse.ResponseData'
        ResponseStatus:
          $ref: '#/components/schemas/CreateIntelligentFeedResponse.Result'
      title: CreateIntelligentFeedResponse
      type: object
    DeleteIntelligentFeedResponse:
      additionalProperties: false
      properties:
        Response:
          $ref: '#/components/schemas/DeleteIntelligentFeedResponse.ResponseData'
        ResponseStatus:
          $ref: '#/components/schemas/DeleteIntelligentFeedResponse.Result'
      title: DeleteIntelligentFeedResponse
      type: object
    DescribeIntelligentFeedResponse:
      additionalProperties: false
      properties:
        Response:
          $ref: '#/components/schemas/DescribeIntelligentFeedResponse.ResponseData'
        ResponseStatus:
          $ref: '#/components/schemas/DescribeIntelligentFeedResponse.Result'
      title: DescribeIntelligentFeedResponse
      type: object
    CreateIntelligentFeedResponse.FeedDetails:
      additionalProperties: false
      properties:
        AuditComment:
          title: Auditcomment
          type: string
        Certificate:
          title: Certificate
          type: string
        Description:
          title: Description
          type: string
        FeedURL:
          title: Feedurl
          type: string
        Frequency:
          enum:
          - HOURLY
          - DAILY
          title: Frequency
          type: string
        Time:
          maximum: 23
          minimum: 0
          title: Time
          type: integer
        Type:
          enum:
          - IP_LIST
          - URL_LIST
          title: Type
          type: string
        UpdateToken:
          default: '1'
          title: Updatetoken
          type: string
      title: FeedDetails
      type: object
    DeleteIntelligentFeedRequest:
      additionalProperties: false
      properties: {}
      title: DeleteIntelligentFeedRequest
      type: object
    DescribeIntelligentFeedResponse.ResponseData:
      additionalProperties: false
      properties:
        FeedCandidate:
          $ref: '#/components/schemas/DescribeIntelligentFeedResponse.FeedDetails'
        FeedRunning:
          $ref: '#/components/schemas/DescribeIntelligentFeedResponse.FeedDetails'
        Name:
          title: Name
          type: string
        RuleStackName:
          title: Rulestackname
          type: string
      title: ResponseData
      type: object
    DescribeIntelligentFeedResponse.Result:
      additionalProperties: false
      properties:
        ErrorCode:
          default: 0
          title: Errorcode
          type: integer
        Reason:
          title: Reason
          type: string
      title: Result
      type: object
    DeleteIntelligentFeedResponse.Result:
      additionalProperties: false
      properties:
        ErrorCode:
          default: 0
          title: Errorcode
          type: integer
        Reason:
          title: Reason
          type: string
      title: Result
      type: object