Palo Alto Networks Resource Explorer API

### Where Do I Find the RRN For My Resource? You can find the RRN for a resource in the URL when you view that resource in the Prisma Cloud Resource explorer. The following is an example of such a URL. The RRN is in the URL query string. ``` https://app.prismacloud.io/investigate/details?resourceId=rrn:aws:storageBucket:us-east-1:123456789012:test-bucket ``` ### Account Representation If the **regionId** and **resourceId** are not in the RRN, then the **cloudType** and **resourceType** fields in thr RRN are optional. In this siutation, the RRN identifies an account. Full RRN: ``` rrn:::us-west-1:12345678901:i-ABCDEFGH ``` Abridged RRN: ``` rrn::::12345678901 ```

Operations 8

POST /resource Get Resource #
POST /resource/alert Get Alerts for Resource #
POST /resource/network Get Resource Network Settings #
GET /resource/external_finding List Host Findings For Alert #
POST /resource/external_finding List Host Findings #
POST /resource/timeline Get Resource Timeline #
POST /resource/raw Get Resource (Raw) #
POST /resource/external_integration Get External Ingest Integrations for the resource #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/palo-alto-networks-resource-explorer-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

palo-alto-networks-resource-explorer-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  contact: {}
  description: 'Access Keys are a secure way to enable programmatic access to the Prisma Cloud API. By default, only

    the System Admin has API access and can enable API access for other administrators. If you have API access,

    you can create up to two access keys. Create an access key for a limited time period and regenerate your API

    keys periodically to minimize exposure and follow security best practices.'
  title: Prisma Cloud Access Keys API Overview Resource Explorer API
  version: Latest
servers:
- url: https://api.prismacloud.io
- url: https://api2.prismacloud.io
- url: https://api3.prismacloud.io
- url: https://api4.prismacloud.io
tags:
- description: '### Where Do I Find the RRN For My Resource?'
  name: Resource Explorer
paths:
  /resource:
    post:
      description: 'Returns detailed information for the resource with the given **rrn**.


        Generally, the data field in the response object contains the raw JSON blob as is received from the

        source cloud service provider API for the given resource.


        Only the **rrn** parameter in the request body is used for this API. Ignore the **timelineItemId** and

        **findingType** fields for this API.


        An example request body is:

        ```

        {

        "rrn": "rrn::storageBucket:us-east-1:123456789012:test-bucket"

        }

        ```'
      operationId: get-resource
      requestBody:
        content:
          application/json; charset=UTF-8:
            schema:
              $ref: '#/components/schemas/ResourceExplorerRequest'
      responses:
        '200':
          content:
            application/json; charset=UTF-8:
              schema:
                $ref: '#/components/schemas/ResourceMetaModel'
          description: successful operation
        '400':
          description: bad_request / no_results / invalid_parameter_value
        '404':
          description: not_found
        '500':
          description: internal_error
      security:
      - x-redlock-auth: []
      summary: Get Resource
      tags:
      - Resource Explorer
  /resource/alert:
    post:
      description: 'Get a list of alerts associated with a given resource.


        Only the **rrn** parameter in the request body is used for this API. Ignore the **timelineItemId** and

        **findingType** fields for this API.


        An example request body is:

        ```

        {

        "rrn": "rrn::storageBucket:us-east-1:123456789012:test-bucket"

        }

        ```'
      operationId: get-alerts-for-resource
      requestBody:
        content:
          application/json; charset=UTF-8:
            schema:
              $ref: '#/components/schemas/ResourceExplorerRequest'
      responses:
        '200':
          content:
            application/json; charset=UTF-8:
              schema:
                items:
                  $ref: '#/components/schemas/AlertIdAndSeverity'
                type: array
          description: successful operation
        '400':
          description: bad_request / invalid_parameter_value
      security:
      - x-redlock-auth: []
      summary: Get Alerts for Resource
      tags:
      - Resource Explorer
  /resource/network:
    post:
      description: 'Fetch network port settings and configuration for a resource.


        Only the **rrn** parameter in the request body is used for this API. Ignore the **timelineItemId** and

        **findingType** fields for this API.


        An example request body is:

        ```

        {

        "rrn": "rrn::storageBucket:us-east-1:123456789012:test-bucket"

        }

        ```'
      operationId: get-network-for-resource
      requestBody:
        content:
          application/json; charset=UTF-8:
            schema:
              $ref: '#/components/schemas/ResourceExplorerRequest'
      responses:
        '200':
          content:
            application/json; charset=UTF-8:
              schema:
                items:
                  $ref: '#/components/schemas/SecurityGroupDetail'
                type: array
          description: success / no_results
        '400':
          description: bad_request / invalid_parameter_value
      security:
      - x-redlock-auth: []
      summary: Get Resource Network Settings
      tags:
      - Resource Explorer
  /resource/external_finding:
    get:
      description: Get a list of all host findings for a specific alert.
      operationId: get-host-findings-for-alert
      parameters:
      - in: query
        name: alertId
        required: true
        schema:
          type: string
      - explode: true
        in: query
        name: type
        required: false
        schema:
          items:
            type: string
          type: array
      - explode: true
        in: query
        name: source
        required: false
        schema:
          items:
            type: string
          type: array
      responses:
        '200':
          content:
            application/json; charset=UTF-8:
              schema:
                items:
                  $ref: '#/components/schemas/ExternalFindingView'
                type: array
          description: successful operation
        '400':
          description: bad_request / invalid_parameter_value
      security:
      - x-redlock-auth: []
      summary: List Host Findings For Alert
      tags:
      - Resource Explorer
    post:
      description: 'Returns a list of all host findings for the current resource.


        Supported finding types:


        Finding Type | Key

        -----------| ----

        AWS GuardDuty Host | **guard_duty_host**

        AWS GuardDuty IAM | **guard_duty_iam**

        AWS Inspector Security Best Practices | **inspector_sbp**

        AWS Runtime Behavior Analysis | **inspector_rba_count**

        CIS Compliance | **compliance_cis**

        Host Vulnerability | **host_vulnerability_cve**


        Only the **rrn** parameter in the request body is used for this API. Ignore the **timelineItemId**

        field for this API.


        An example request body with a specified finding type is:

        ```json

        {

        "findingType": [ "host_vulnerability_cve", "inspector_sbp" ],

        "rrn": "rrn::instance:us-east-1:i-xxxxxxxxxx"

        }

        ```


        An example request body for all finding types is:

        ```json

        {

        "rrn": "rrn::instance:us-east-1:i-xxxxxxxxxx"

        }'
      operationId: get-host-findings
      requestBody:
        content:
          application/json; charset=UTF-8:
            schema:
              $ref: '#/components/schemas/ResourceExplorerRequest'
      responses:
        '200':
          content:
            application/json; charset=UTF-8:
              schema:
                items:
                  $ref: '#/components/schemas/ExternalFindingView'
                type: array
          description: successful operation
        '400':
          description: bad_request / invalid_parameter_value
      security:
      - x-redlock-auth: []
      summary: List Host Findings
      tags:
      - Resource Explorer
  /resource/timeline:
    post:
      description: 'Returns a timeline of events and alerts for the given resource.


        Only the **rrn** parameter in the request body is used for this API. Ignore the **timelineItemId** and

        **findingType** fields for this API.


        An example request body is:

        ```json

        {

        ""rrn": "rrn::instance:us-east-1:i-xxxxxxxxxx"

        }

        ```'
      operationId: get-timeline-for-resource
      requestBody:
        content:
          application/json; charset=UTF-8:
            schema:
              $ref: '#/components/schemas/ResourceExplorerRequest'
      responses:
        '200':
          content:
            application/json; charset=UTF-8:
              schema:
                items:
                  $ref: '#/components/schemas/ResourceTimelineItem'
                type: array
          description: successful operation
        '400':
          description: invalid_parameter_value
        '404':
          description: not_found
        '500':
          description: internal_error
      security:
      - x-redlock-auth: []
      summary: Get Resource Timeline
      tags:
      - Resource Explorer
  /resource/raw:
    post:
      description: 'Returns the raw metadata of the configuration of a resource at a given point in time.


        Generally, the response object contains the raw JSON blob as is received from the

        source cloud service provider API.


        Only the **rrn** parameter in the request body is used for this API. Ignore the **findingType**

        field for this API.


        You can find the **timelineItemId** for your resource from the timeline results that

        Get Resource Timeline

        returns.


        An example request body is:

        ```json

        {

        "rrn": "rrn::instance:us-east-1:i-xxxxxxxxxx",

        "timelineItemId": "xxxxxxxxxxxxxx"

        }

        ```'
      operationId: get-resource-raw
      requestBody:
        content:
          application/json; charset=UTF-8:
            schema:
              $ref: '#/components/schemas/ResourceExplorerRequest'
      responses:
        '200':
          content:
            application/json; charset=UTF-8:
              schema:
                type: object
          description: successful operation
        '400':
          description: invalid_parameter_value
        '404':
          description: not_found
        '500':
          description: internal_error
      security:
      - x-redlock-auth: []
      summary: Get Resource (Raw)
      tags:
      - Resource Explorer
  /resource/external_integration:
    post:
      description: Returns a list of external ingestion integrations for the specified resource.
      operationId: get-external-integrations-for-resource
      requestBody:
        content:
          application/json; charset=UTF-8:
            schema:
              $ref: '#/components/schemas/ResourceExplorerRequest'
      responses:
        '200':
          content:
            application/json; charset=UTF-8:
              schema:
                items:
                  $ref: '#/components/schemas/ExternalIntegrationView'
                type: array
          description: success / no_results
        '400':
          description: bad_request / invalid_parameter_value
      security:
      - x-redlock-auth: []
      summary: Get External Ingest Integrations for the resource
      tags:
      - Resource Explorer
components:
  schemas:
    ExternalIntegrationView:
      properties:
        assetJson:
          type: string
        firstSeen:
          format: int64
          type: integer
        hasAgent:
          type: boolean
        id:
          type: string
        lastSeen:
          format: int64
          type: integer
        name:
          type: string
        rlUpdatedOn:
          format: int64
          type: integer
        source:
          enum:
          - AWS_INSPECTOR
          - AWS_GUARD_DUTY
          - TENABLE
          - QUALYS
          - PRISMA_CLOUD
          - AZURE_SECURITY_CENTER
          type: string
        tags:
          items:
            type: string
          type: array
      type: object
    AlertIdAndSeverity:
      properties:
        id:
          type: string
        severity:
          enum:
          - INFORMATIONAL
          - LOW
          - MEDIUM
          - HIGH
          - CRITICAL
          type: string
      type: object
    ExternalFindingView:
      properties:
        accountId:
          type: string
        count:
          type: string
        createdOn:
          format: int64
          type: integer
        customerId:
          format: int32
          type: integer
        cveId:
          type: string
        description:
          type: string
        externalFindingId:
          format: int64
          type: integer
        findingId:
          type: string
        normalizedName:
          type: string
        normalizedNames:
          items:
            type: string
          type: array
        nvdUrl:
          type: string
        rawData:
          type: string
        regionId:
          type: string
        resourceCloudId:
          type: string
        resourceId:
          format: int64
          type: integer
        resourceUrl:
          type: string
        riskFactors:
          items:
            enum:
            - CRITICAL_SEVERITY
            - HIGH_SEVERITY
            - MEDIUM_SEVERITY
            - HAS_FIX
            - REMOTE_EXECUTION
            - DOS
            - RECENT_VULNERABILITY
            - EXPLOIT_EXISTS
            - ATTACK_COMPLEXITY_LOW
            - ATTACK_VECTOR_NETWORK
            - REACHABLE_FROM_THE_INTERNET
            - LISTENING_PORTS
            - CONTAINER_IS_RUNNING_AS_ROOT
            - NO_MANDATORY_SECURITY_PROFILE_APPLIED
            - RUNNING_AS_PRIVILEGED_CONTAINER
            - PACKAGE_IN_USE
            type: string
          type: array
          uniqueItems: true
        rlUpdatedOn:
          format: int64
          type: integer
        scanId:
          type: string
        score:
          type: object
        severity:
          enum:
          - INFORMATIONAL
          - LOW
          - MEDIUM
          - HIGH
          - CRITICAL
          type: string
        source:
          enum:
          - AWS_INSPECTOR
          - AWS_GUARD_DUTY
          - TENABLE
          - QUALYS
          - PRISMA_CLOUD
          - AZURE_SECURITY_CENTER
          type: string
        sourceData:
          additionalProperties:
            type: object
          type: object
        status:
          enum:
          - PENDING
          - NO_ERROR
          - ERROR
          - ENABLED
          - DISABLED
          - OPEN
          - DISMISSED
          - RESOLVED
          - DESCOPED
          - RISK_SCORING_ERROR
          - ACTIVE
          - CLOSED
          - SUPPRESSED
          type: string
        title:
          type: string
        type:
          enum:
          - HOST_VULNERABILITY_CVE
          - COMPLIANCE_ISSUE_CIS
          - AWS_INSPECTOR_SECURITY_BEST_PRACTICES
          - AWS_INSPECTOR_RUNTIME_BEHAVIOR_ANALYSIS
          - AWS_GUARD_DUTY_HOST_FINDING
          - AWS_GUARD_DUTY_IAM_FINDING
          - SERVERLESS_VULNERABILITY
          - AZURE_SECURITY_CENTER_ALERTS
          - PACKAGE_VULNERABILITY
          - NETWORK_REACHABILITY
          - AWS_GUARD_DUTY_EKS_FINDING
          - AWS_GUARD_DUTY_ECS_FINDING
          - AWS_GUARD_DUTY_CONTAINER_FINDING
          type: string
        updatedOn:
          format: int64
          type: integer
      type: object
    ResourceTimelineVulnerability:
      properties:
        id:
          type: string
        url:
          type: string
      type: object
    RRNModel:
      description: Model for RRN
      properties:
        accountId:
          description: Account ID
          readOnly: true
          type: string
        cloudType:
          description: Cloud type
          enum:
          - ALL
          - AWS
          - AZURE
          - GCP
          - ALIBABA_CLOUD
          - OCI
          - IBM
          readOnly: true
          type: string
        idmapId:
          description: Hashed generated ID
          readOnly: true
          type: string
        regionId:
          description: Region ID
          readOnly: true
          type: string
        resourceId:
          description: Resource ID
          readOnly: true
          type: string
        resourceType:
          description: Resource type
          readOnly: true
          type: string
      type: object
    ResourceExplorerRequest:
      properties:
        excludeSeverityList:
          description: External Findings Severitys to exclude
          items:
            type: string
          type: array
        findingSource:
          description: External Finding Sources
          items:
            enum:
            - AWS_INSPECTOR
            - AWS_GUARD_DUTY
            - TENABLE
            - QUALYS
            - PRISMA_CLOUD
            - AZURE_SECURITY_CENTER
            type: string
          readOnly: true
          type: array
        findingType:
          description: External Finding Types
          items:
            type: string
          type: array
        riskFactors:
          description: External finding risk factors
          items:
            enum:
            - CRITICAL_SEVERITY
            - HIGH_SEVERITY
            - MEDIUM_SEVERITY
            - HAS_FIX
            - REMOTE_EXECUTION
            - DOS
            - RECENT_VULNERABILITY
            - EXPLOIT_EXISTS
            - ATTACK_COMPLEXITY_LOW
            - ATTACK_VECTOR_NETWORK
            - REACHABLE_FROM_THE_INTERNET
            - LISTENING_PORTS
            - CONTAINER_IS_RUNNING_AS_ROOT
            - NO_MANDATORY_SECURITY_PROFILE_APPLIED
            - RUNNING_AS_PRIVILEGED_CONTAINER
            - PACKAGE_IN_USE
            type: string
          type: array
        rrn:
          description: Restricted Resource Name
          type: string
        rrnList:
          description: Restricted Resource Name
          items:
            type: string
          type: array
        timelineItemId:
          description: Timeline Item ID
          type: string
      type: object
    SecurityGroupDetail:
      properties:
        access:
          type: string
        direction:
          type: string
        id:
          format: int64
          type: integer
        ips:
          type: string
        ports:
          type: string
        priority:
          format: int32
          type: integer
        protocol:
          type: string
      type: object
    ResourceMetaModel:
      description: Model containing resource metadata
      properties:
        accountGroupName:
          description: Account group name
          type: string
        accountId:
          description: Account ID
          type: string
        accountName:
          description: Account name
          type: string
        allowDrillDown:
          description: allowDrillDown
          type: boolean
        assetId:
          description: Asset ID
          type: string
        cloudType:
          description: Cloud Type
          enum:
          - ALL
          - AWS
          - AZURE
          - GCP
          - ALIBABA_CLOUD
          - OCI
          - IBM
          type: string
        createdTs:
          description: Creation timestamp
          format: int64
          type: integer
        data:
          description: Raw JSON data for the resource
          type: object
        deleted:
          description: Deleted
          type: boolean
        dynamicData:
          additionalProperties:
            type: object
          description: Dynamic data
          type: object
        hasExtFindingRiskFactors:
          description: Has risk factors
          type: boolean
        hasExternalFinding:
          description: Has external finding
          type: boolean
        hasExternalIntegration:
          description: Has external integration
          type: boolean
        hasNetwork:
          description: Has network
          type: boolean
        id:
          description: ID
          type: string
        insertTs:
          description: Insertion timestamp
          format: int64
          type: integer
        name:
          description: Name
          type: string
        regionId:
          description: Region ID
          type: string
        regionName:
          description: Region name
          type: string
        resourceConfigJsonAvailable:
          description: allowDrillDown
          type: boolean
        resourceType:
          description: Resource type
          type: string
        riskGrade:
          description: Risk grade
          type: string
        rrn:
          allOf:
          - $ref: '#/components/schemas/RRNModel'
          - description: RRN
        service:
          description: Service
          type: string
        stateId:
          description: State ID
          type: string
        tags:
          additionalProperties:
            type: string
          description: Tags
          type: object
        url:
          description: URL
          type: string
        vpcId:
          description: Virtual private cloud ID
          type: string
        vpcName:
          description: Virtual private cloud name
          type: string
      type: object
    ResourceTimelineItem:
      properties:
        alertIds:
          items:
            type: string
          type: array
        discoveredTs:
          format: int64
          type: integer
        eventName:
          type: string
        eventType:
          type: string
        firstState:
          type: boolean
        id:
          type: string
        previousStateId:
          type: string
        similarSince:
          format: int64
          type: integer
        similarStateCount:
          format: int64
          type: integer
        timestamp:
          format: int64
          type: integer
        type:
          enum:
          - STATE_CHANGE
          - EVENT
          - VULNERABILITY
          type: string
        user:
          type: string
        vulnerabilities:
          items:
            $ref: '#/components/schemas/ResourceTimelineVulnerability'
          type: array
      type: object
  securitySchemes:
    x-redlock-auth:
      description: The x-redlock-auth value is a JSON Web Token (JWT).
      in: header
      name: x-redlock-auth
      type: apiKey