Palo Alto Networks Manage Intelligent Feeds API

The ManageIntelligentFeeds API from Palo Alto Networks — 2 operation(s) for manageintelligentfeeds.

OpenAPI Specification

palo-alto-networks-manageintelligentfeeds-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  contact: {}
  description: "An intelligent feed, also called an external dynamic list, is a list that you or third-parties can host on an external web server. You can specify the Intelligence Feed as the source or destination of your security rule. The NGFW checks the hosted list at hourly or daily intervals, and enforces your security rules based on the latest entries on your list, without requiring you to make any configuration changes.  \n\nFor more information about feeds, see [EDL hosting service](https://docs.paloaltonetworks.com/resources/edl-hosting-service.html).\n"
  title: Manage Intelligent Feeds API
  version: 1.0.0
servers:
- url: https://api.us-east-1.aws.cloudngfw.paloaltonetworks.com
tags:
- name: ManageIntelligentFeeds
paths:
  /v1/config/rulestacks/{rulestackname}/feeds:
    post:
      description: 'Create intelligence feed to analyze threat data.

        '
      operationId: post-v1-config-rulestacks-rulestackname-feeds
      parameters:
      - description: 'The name of the rulestack.

          '
        in: path
        name: rulestackname
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateIntelligentFeedRequest'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreateIntelligentFeedResponse'
          description: OK
      summary: Create an IntelligentFeed
      tags:
      - ManageIntelligentFeeds
  /v1/config/rulestacks/{rulestackname}/feeds/{name}:
    delete:
      description: 'Delete the threat intelligence feeds received for a specified rulestack.

        '
      operationId: delete-v1-config-rulestacks-rulestackname-feeds-name
      parameters:
      - description: 'The name of the rulestack.

          '
        in: path
        name: rulestackname
        required: true
        schema:
          type: string
      - description: 'The name of the feed.

          '
        in: path
        name: name
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/DeleteIntelligentFeedRequest'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DeleteIntelligentFeedResponse'
          description: OK
      summary: Delete an IntelligentFeed
      tags:
      - ManageIntelligentFeeds
    get:
      description: "Returns the intelligence feed data collected for the specified rulestack. \n"
      operationId: get-v1-config-rulestacks-rulestackname-feeds-name
      parameters:
      - description: 'The name of the rulestack.

          '
        in: path
        name: rulestackname
        required: true
        schema:
          type: string
      - description: 'The name of the feed.

          '
        in: path
        name: name
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/DescribeIntelligentFeedRequest'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DescribeIntelligentFeedResponse'
          description: OK
      summary: Describe an IntelligentFeed
      tags:
      - ManageIntelligentFeeds
    put:
      description: 'Update the threat intelligence feeds for a rulestack.

        '
      operationId: put-v1-config-rulestacks-rulestackname-feeds-name
      parameters:
      - description: 'The name of the rulestack.

          '
        in: path
        name: rulestackname
        required: true
        schema:
          type: string
      - description: 'The name of the feed.

          '
        in: path
        name: name
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateIntelligentFeedRequest'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UpdateIntelligentFeedResponse'
          description: OK
      summary: Update an IntelligentFeed
      tags:
      - ManageIntelligentFeeds
components:
  schemas:
    DescribeIntelligentFeedResponse.Result:
      additionalProperties: false
      properties:
        ErrorCode:
          default: 0
          description: "Default value of a successful response is 0. Any other number indicates an error code.  \n\n400—HTTP bad request\n* InvalidRequestException—Operation failed due to invalid request. For example, unsupported parameter name or value in the request.\n* LimitExceededException—Operation failed due to violation in limit settings.\n* ThrottlingException—Operation failed due to throttling limitations.\n* AccessDeniedException—You do not have sufficient access to perform this action.\n\n500—Bad request \n* InternalServerError—Your request is valid but Cloud NGFW could not perform the operation due to a system issue.\n"
          title: Errorcode
          type: integer
        Reason:
          description: 'The error description.

            '
          title: Reason
          type: string
      title: Result
      type: object
    DeleteIntelligentFeedResponse.ResponseData:
      additionalProperties: false
      properties:
        FeedEntry:
          $ref: '#/components/schemas/DeleteIntelligentFeedResponse.FeedDetails'
          description: 'The intelligent feed list entry.

            '
        Name:
          description: "Name of the intelligent feed list.    \n"
          title: Name
          type: string
        RuleStackName:
          description: "Name of the rulestack. \n"
          title: Rulestackname
          type: string
      title: ResponseData
      type: object
    UpdateIntelligentFeedResponse.FeedDetails:
      additionalProperties: false
      properties:
        AuditComment:
          description: 'The intelligent feed audit remarks.

            '
          title: Auditcomment
          type: string
        Certificate:
          description: 'The threat intelligence feed certificate.

            '
          title: Certificate
          type: string
        Description:
          description: 'A description of feed.

            '
          title: Description
          type: string
        FeedURL:
          description: 'The intelligence feed URL.

            '
          title: Feedurl
          type: string
        Frequency:
          description: 'The frequency of feed refresh.

            '
          enum:
          - HOURLY
          - DAILY
          title: Frequency
          type: string
        Time:
          description: "The timestamp of the feed. \n"
          maximum: 23
          minimum: 0
          title: Time
          type: integer
        Type:
          description: 'Type of the feed; category feeds, source feeds, and destination feeds.

            '
          enum:
          - IP_LIST
          - URL_LIST
          title: Type
          type: string
        UpdateToken:
          default: '1'
          description: "Refresh the token.    \n"
          title: Updatetoken
          type: string
      title: FeedDetails
      type: object
    DescribeIntelligentFeedResponse.ResponseData:
      additionalProperties: false
      properties:
        FeedCandidate:
          $ref: '#/components/schemas/DescribeIntelligentFeedResponse.FeedDetails'
          description: 'The intelligent feed list candidate.

            '
        FeedRunning:
          $ref: '#/components/schemas/DescribeIntelligentFeedResponse.FeedDetails'
          description: 'The intelligent feeds on run state.

            '
        Name:
          description: "Name of the intelligent feed entry.    \n"
          title: Name
          type: string
        RuleStackName:
          description: "Name of the rulestack. \n"
          title: Rulestackname
          type: string
      title: ResponseData
      type: object
    DescribeIntelligentFeedResponse.FeedDetails:
      additionalProperties: false
      properties:
        AuditComment:
          description: 'The intelligent feed audit remarks.

            '
          title: Auditcomment
          type: string
        Certificate:
          description: 'The threat intelligence feed certificate.

            '
          title: Certificate
          type: string
        Description:
          description: 'A description of feed.

            '
          title: Description
          type: string
        FeedURL:
          description: 'The intelligence feed URL.

            '
          title: Feedurl
          type: string
        Frequency:
          description: 'The frequency of feed refresh.

            '
          enum:
          - HOURLY
          - DAILY
          title: Frequency
          type: string
        Time:
          description: "The timestamp of the feed. \n"
          maximum: 23
          minimum: 0
          title: Time
          type: integer
        Type:
          description: 'Type of the feed; category feeds, source feeds, and destination feeds.

            '
          enum:
          - IP_LIST
          - URL_LIST
          title: Type
          type: string
        UpdateToken:
          default: '1'
          description: 'Refresh the token.

            '
          title: Updatetoken
          type: string
      title: FeedDetails
      type: object
    CreateIntelligentFeedResponse.ResponseData:
      additionalProperties: false
      properties:
        FeedEntry:
          $ref: '#/components/schemas/CreateIntelligentFeedResponse.FeedDetails'
          description: 'The intelligent feed list entry.

            '
        Name:
          description: "Name of the intelligent feed list.    \n"
          title: Name
          type: string
        RuleStackName:
          description: "Name of the rulestack. \n"
          title: Rulestackname
          type: string
      title: ResponseData
      type: object
    DeleteIntelligentFeedRequest:
      additionalProperties: false
      properties: {}
      title: DeleteIntelligentFeedRequest
      type: object
    UpdateIntelligentFeedRequest:
      additionalProperties: false
      properties:
        AuditComment:
          description: 'The intelligent feed audit remarks.

            '
          maxLength: 512
          title: Auditcomment
          type: string
        Certificate:
          description: 'The threat intelligence feed certificate.

            '
          title: Certificate
          type: string
        Description:
          description: 'A description of feed.

            '
          maxLength: 512
          title: Description
          type: string
        FeedURL:
          description: 'The intelligence feed URL.

            '
          maxLength: 255
          minLength: 1
          pattern: ^(http|https)://.+$
          title: Feedurl
          type: string
        Frequency:
          description: 'The frequency of feed refresh.

            '
          enum:
          - HOURLY
          - DAILY
          title: Frequency
          type: string
        Time:
          default: 3
          description: "The timestamp of the feed. \n"
          maximum: 23
          minimum: 0
          title: Time
          type: integer
        Type:
          description: 'Type of the feed; category feeds, source feeds, and destination feeds.

            '
          enum:
          - IP_LIST
          - URL_LIST
          title: Type
          type: string
        UpdateToken:
          description: 'Refresh the token.

            '
          title: Updatetoken
          type: string
      required:
      - FeedURL
      - Type
      - Frequency
      title: UpdateIntelligentFeedRequest
      type: object
    CreateIntelligentFeedResponse.FeedDetails:
      additionalProperties: false
      properties:
        AuditComment:
          description: 'The intelligent feed audit remarks.

            '
          title: Auditcomment
          type: string
        Certificate:
          description: 'The threat intelligence feed certificate.

            '
          title: Certificate
          type: string
        Description:
          description: 'A description of feed.

            '
          title: Description
          type: string
        FeedURL:
          description: 'The intelligence feed URL.

            '
          title: Feedurl
          type: string
        Frequency:
          description: 'The frequency of feed refresh.

            '
          enum:
          - HOURLY
          - DAILY
          title: Frequency
          type: string
        Time:
          description: "The timestamp of the feed. \n"
          maximum: 23
          minimum: 0
          title: Time
          type: integer
        Type:
          description: 'Type of the feed; category feeds, source feeds, and destination feeds.

            '
          enum:
          - IP_LIST
          - URL_LIST
          title: Type
          type: string
        UpdateToken:
          default: '1'
          description: "Refresh the token.    \n"
          title: Updatetoken
          type: string
      title: FeedDetails
      type: object
    CreateIntelligentFeedResponse.Result:
      additionalProperties: false
      properties:
        ErrorCode:
          default: 0
          description: "Default value of a successful response is 0. Any other number indicates an error code.  \n\n400—HTTP bad request\n* InvalidRequestException—Operation failed due to invalid request. For example, unsupported parameter name or value in the request.\n* LimitExceededException—Operation failed due to violation in limit settings.\n* ThrottlingException—Operation failed due to throttling limitations.\n* AccessDeniedException—You do not have sufficient access to perform this action.\n\n500—Bad request \n* InternalServerError—Your request is valid but Cloud NGFW could not perform the operation due to a system issue.\n* InsufficientCapacityException—AWS currently does not have enough capacity to fulfill your request.\n"
          title: Errorcode
          type: integer
        Reason:
          description: "The error description. \n"
          title: Reason
          type: string
      title: Result
      type: object
    UpdateIntelligentFeedResponse:
      additionalProperties: false
      properties:
        Response:
          $ref: '#/components/schemas/UpdateIntelligentFeedResponse.ResponseData'
          description: 'The API call response.

            '
        ResponseStatus:
          $ref: '#/components/schemas/UpdateIntelligentFeedResponse.Result'
          description: 'The API call response status.

            '
      title: UpdateIntelligentFeedResponse
      type: object
    UpdateIntelligentFeedResponse.Result:
      additionalProperties: false
      properties:
        ErrorCode:
          default: 0
          description: "Default value of a successful response is 0. Any other number indicates an error code.  \n\n400—HTTP bad request\n* InvalidRequestException—Operation failed due to invalid request. For example, unsupported parameter name or value in the request.\n* LimitExceededException—Operation failed due to violation in limit settings.\n* ThrottlingException—Operation failed due to throttling limitations.\n* AccessDeniedException—You do not have sufficient access to perform this action.\n\n500—Bad request \n* InternalServerError—Your request is valid but Cloud NGFW could not perform the operation due to a system issue.\n* InsufficientCapacityException—AWS currently does not have enough capacity to fulfill your request.\n"
          title: Errorcode
          type: integer
        Reason:
          description: "The error description.   \n"
          title: Reason
          type: string
      title: Result
      type: object
    DeleteIntelligentFeedResponse.FeedDetails:
      additionalProperties: false
      properties:
        AuditComment:
          description: 'The intelligent feed audit remarks.

            '
          title: Auditcomment
          type: string
        Certificate:
          description: 'The threat intelligence feed certificate.

            '
          title: Certificate
          type: string
        Description:
          description: 'A description of feed.

            '
          title: Description
          type: string
        FeedURL:
          description: 'The intelligence feed URL.

            '
          title: Feedurl
          type: string
        Frequency:
          description: 'The frequency of feed refresh.

            '
          enum:
          - HOURLY
          - DAILY
          title: Frequency
          type: string
        Time:
          description: "The timestamp of the feed. \n"
          maximum: 23
          minimum: 0
          title: Time
          type: integer
        Type:
          description: 'Type of the feed; category feeds, source feeds, and destination feeds.

            '
          enum:
          - IP_LIST
          - URL_LIST
          title: Type
          type: string
        UpdateToken:
          default: '1'
          description: "Refresh the token.    \n"
          title: Updatetoken
          type: string
      title: FeedDetails
      type: object
    DescribeIntelligentFeedResponse:
      additionalProperties: false
      properties:
        Response:
          $ref: '#/components/schemas/DescribeIntelligentFeedResponse.ResponseData'
          description: 'The API call response.

            '
        ResponseStatus:
          $ref: '#/components/schemas/DescribeIntelligentFeedResponse.Result'
          description: 'The API call response status.

            '
      title: DescribeIntelligentFeedResponse
      type: object
    DeleteIntelligentFeedResponse.Result:
      additionalProperties: false
      properties:
        ErrorCode:
          default: 0
          description: "Default value of a successful response is 0. Any other number indicates an error code.  \n\n400—HTTP bad request\n* InvalidRequestException—Operation failed due to invalid request. For example, unsupported parameter name or value in the request.\n* LimitExceededException—Operation failed due to violation in limit settings.\n* ResourceNotFoundException—Unable to locate a resource using the parameters you provided.\n* ThrottlingException—Operation failed due to throttling limitations.\n* AccessDeniedException—You do not have sufficient access to perform this action.\n\n500—Bad request \n* InternalServerError—Your request is valid but Cloud NGFW could not perform the operation due to a system issue.\n* InsufficientCapacityException—AWS currently does not have enough capacity to fulfill your request.\n"
          title: Errorcode
          type: integer
        Reason:
          description: 'The error description.

            '
          title: Reason
          type: string
      title: Result
      type: object
    CreateIntelligentFeedRequest:
      additionalProperties: false
      properties:
        AuditComment:
          description: 'The intelligent feed audit remarks.

            '
          maxLength: 512
          title: Auditcomment
          type: string
        Certificate:
          description: 'The threat intelligence feed certificate.

            '
          title: Certificate
          type: string
        Description:
          description: 'A description of feed.

            '
          maxLength: 512
          title: Description
          type: string
        FeedURL:
          description: 'The intelligence feed URL.

            '
          maxLength: 255
          minLength: 1
          pattern: ^(http|https)://.+$
          title: Feedurl
          type: string
        Frequency:
          description: 'The frequency of feed refresh.

            '
          enum:
          - HOURLY
          - DAILY
          title: Frequency
          type: string
        Name:
          description: 'Name of the rulestack.

            '
          maxLength: 63
          minLength: 1
          pattern: ^[a-zA-Z0-9-]+$
          title: Name
          type: string
        Time:
          default: 3
          description: "The timestamp of the feed. \n"
          maximum: 23
          minimum: 0
          title: Time
          type: integer
        Type:
          description: 'Type of the feed; category feeds, source feeds, and destination feeds.

            '
          enum:
          - IP_LIST
          - URL_LIST
          title: Type
          type: string
      required:
      - Name
      - FeedURL
      - Type
      - Frequency
      title: CreateIntelligentFeedRequest
      type: object
    UpdateIntelligentFeedResponse.ResponseData:
      additionalProperties: false
      properties:
        FeedEntry:
          $ref: '#/components/schemas/UpdateIntelligentFeedResponse.FeedDetails'
          description: 'The intelligent feed list entry.

            '
        Name:
          description: "Name of the intelligent feed list.    \n"
          title: Name
          type: string
        RuleStackName:
          description: "Name of the rulestack. \n"
          title: Rulestackname
          type: string
      title: ResponseData
      type: object
    DeleteIntelligentFeedResponse:
      additionalProperties: false
      properties:
        Response:
          $ref: '#/components/schemas/DeleteIntelligentFeedResponse.ResponseData'
          description: 'The API call response.

            '
        ResponseStatus:
          $ref: '#/components/schemas/DeleteIntelligentFeedResponse.Result'
          description: 'The API call response status.

            '
      title: DeleteIntelligentFeedResponse
      type: object
    DescribeIntelligentFeedRequest:
      additionalProperties: false
      properties:
        Candidate:
          default: true
          description: 'Intelligent feed candidate.

            '
          title: Candidate
          type: boolean
        Running:
          default: false
          description: 'Intelligent feeds in run state.

            '
          title: Running
          type: boolean
      title: DescribeIntelligentFeedRequest
      type: object
    CreateIntelligentFeedResponse:
      additionalProperties: false
      properties:
        Response:
          $ref: '#/components/schemas/CreateIntelligentFeedResponse.ResponseData'
          description: 'The API call response.

            '
        ResponseStatus:
          $ref: '#/components/schemas/CreateIntelligentFeedResponse.Result'
          description: 'The API call response status.

            '
      title: CreateIntelligentFeedResponse
      type: object