Palo Alto Networks Search Manager API

The Search Manager APIs enable you to manage your recent and saved Resource Query Language (RQL) queries.

Operations 4

GET /search/history View Search History #
GET /search/history/{id} Get Search Query by ID #
POST /search/history/{id} Save Search Query #
DELETE /search/history/{id} Delete Saved Search Query #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/palo-alto-networks-search-manager-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

palo-alto-networks-search-manager-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  contact: {}
  description: 'Access Keys are a secure way to enable programmatic access to the Prisma Cloud API. By default, only

    the System Admin has API access and can enable API access for other administrators. If you have API access,

    you can create up to two access keys. Create an access key for a limited time period and regenerate your API

    keys periodically to minimize exposure and follow security best practices.'
  title: Prisma Cloud Access Keys API Overview Search Manager API
  version: Latest
servers:
- url: https://api.prismacloud.io
- url: https://api2.prismacloud.io
- url: https://api3.prismacloud.io
- url: https://api4.prismacloud.io
tags:
- description: 'The Search Manager APIs enable you to manage your recent

    and saved Resource Query Language (RQL) queries.'
  name: Search Manager
paths:
  /search/history:
    get:
      description: Lists saved or recent search queries based on your filter.
      operationId: search-history
      parameters:
      - description: 'Available values: recent, saved'
        in: query
        name: filter
        required: true
        schema:
          type: string
      - description: Maximum number of searches to be returned. A single API call retrieves a maximum of 1000 searches, which is also the default. Setting the limit to -1 will also return the default.
        in: query
        name: limit
        required: false
        schema:
          format: int32
          type: integer
      responses:
        '200':
          content:
            application/json; charset=UTF-8:
              schema:
                items:
                  $ref: '#/components/schemas/SavedRecentSearch'
                type: array
          description: successful operation
        '500':
          description: internal_error
      security:
      - x-redlock-auth: []
      summary: View Search History
      tags:
      - Search Manager
  /search/history/{id}:
    get:
      description: Returns a search query. You can access only queries that are either saved or recent searches.
      operationId: search-history-by-id
      parameters:
      - description: Search ID
        in: path
        name: id
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/json; charset=UTF-8:
              schema:
                $ref: '#/components/schemas/SearchModel'
          description: successful operation
        '500':
          description: internal_error
      security:
      - x-redlock-auth: []
      summary: Get Search Query by ID
      tags:
      - Search Manager
    post:
      description: 'Saves a search query to the **Saved Searches** list under the specified ID.


        Required parameters include the search ID, the RQL query, the flag that

        marks this search as saved, and a unique name for the saved search. A best

        practice is to copy data from the results of a search history, update the

        data as necessary, and set the **saved** parameter to **true**.


        This API requires Prisma Cloud system administrator role access if you don''t own the search with the given search ID.'
      operationId: search-history-save
      parameters:
      - description: Search ID
        in: path
        name: id
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SearchModel'
        required: true
      responses:
        '200':
          content:
            application/json; charset=UTF-8:
              schema:
                $ref: '#/components/schemas/SearchResponseModelSearchModel'
          description: successful operation
        '400':
          description: bad_request / unsupported_search_query / duplicate_search_name
        '403':
          description: cannot_update_default_saved_search / not_owner_or_same_role
        '404':
          description: not_found
        '500':
          description: internal_error
      security:
      - x-redlock-auth: []
      summary: Save Search Query
      tags:
      - Search Manager
    delete:
      description: Deletes a saved search query.
      operationId: search-history-delete
      parameters:
      - description: Search ID
        in: path
        name: id
        required: true
        schema:
          type: string
      responses:
        '204':
          description: success
        '400':
          description: bad_request
        '403':
          description: unauthorized_access
        '404':
          description: not_found
        '409':
          description: conflict_saved_search
        '500':
          description: internal_error
      security:
      - x-redlock-auth: []
      summary: Delete Saved Search Query
      tags:
      - Search Manager
components:
  schemas:
    SavedRecentSearch:
      properties:
        createdBy:
          type: string
        description:
          type: string
        id:
          type: string
        lastModifiedBy:
          type: string
        policies:
          items:
            additionalProperties:
              type: string
            type: object
          type: array
        query:
          type: string
        searchModel:
          $ref: '#/components/schemas/SearchModel'
        searchName:
          type: string
        timestamp:
          format: int64
          type: integer
      type: object
    RelativeTimeDurationModel:
      description: Model for RelativeTimeDuration
      properties:
        amount:
          description: Number of time units
          format: int32
          type: integer
        unit:
          description: Time unit
          enum:
          - minute
          - hour
          - day
          - week
          - month
          - year
          type: string
      type: object
    RelativeTimeRangeConfigModel:
      allOf:
      - $ref: '#/components/schemas/TimeRangeConfigModel'
      - description: Model for RelativeTimeRangeConfig
        properties:
          relativeTimeType:
            description: Direction in which to count time. Default = BACKWARD
            enum:
            - BACKWARD
            - FORWARD
            type: string
          type:
            example: relative
            type: string
          value:
            allOf:
            - $ref: '#/components/schemas/RelativeTimeDurationModel'
            - description: Time range object
        required:
        - value
        type: object
    SearchModel:
      properties:
        alertId:
          description: Alert ID
          readOnly: true
          type: string
        async:
          description: true = Is Async
          readOnly: true
          type: boolean
        asyncResultUrl:
          description: Async Result Url
          example: /search/config/jobs/2df49d4f72e842b582b123bc2b7826b3/download
          readOnly: true
          type: string
        cloudType:
          description: Cloud Type
          enum:
          - aws
          - azure
          - gcp
          - alibaba_cloud
          - oci
          type: string
        cursor:
          description: Cursor
          format: int32
          readOnly: true
          type: integer
        default:
          type: boolean
        description:
          description: Search Description
          type: string
        filters:
          description: View Order
          items:
            $ref: '#/components/schemas/UIFilterModel'
          readOnly: true
          type: array
        groupBy:
          description: Group By
          items:
            type: string
          readOnly: true
          type: array
        id:
          description: Search ID
          type: string
        name:
          description: Search Name
          type: string
        query:
          description: RQL Query
          type: string
        saved:
          description: Search Exists
          type: boolean
        searchType:
          description: Search Type
          enum:
          - network
          - audit_event
          - config
          - asset
          readOnly: true
          type: string
        timeGranularity:
          description: Time Granularity
          readOnly: true
          type: string
        timeRange:
          allOf:
          - $ref: '#/components/schemas/TimeRangeConfigModel'
          - description: Time Range
      required:
      - query
      - timeRange
      type: object
    ToNowTimeRangeConfigModel:
      allOf:
      - $ref: '#/components/schemas/TimeRangeConfigModel'
      - description: Model for ToNowTimeRangeConfig
        properties:
          value:
            description: Time range object
            enum:
            - MINUTE
            - HOUR
            - DAY
            - WEEK
            - MONTH
            - YEAR
            - EPOCH
            - LOGIN
            type: string
        type: object
    AbsoluteTimeRangeConfigModel:
      allOf:
      - $ref: '#/components/schemas/TimeRangeConfigModel'
      - description: Model for AbsoluteTimeRangeConfig
        properties:
          type:
            example: absolute
            type: string
          value:
            allOf:
            - $ref: '#/components/schemas/TimeModel'
            - description: Time range object
        required:
        - value
        type: object
    UIFilterModel:
      description: Model for UIFilter
      properties:
        name:
          description: Name
          type: string
        operator:
          description: Operator
          enum:
          - '='
          type: string
        value:
          description: Value
          type: string
      type: object
    TimeModel:
      description: Model for Time
      properties:
        endTime:
          description: End timestamp
          format: int64
          type: integer
        startTime:
          description: Start timestamp
          format: int64
          type: integer
      type: object
    SearchResponseModelSearchModel:
      properties:
        alertId:
          description: Alert ID
          readOnly: true
          type: string
        async:
          description: true = Is Async
          readOnly: true
          type: boolean
        asyncResultUrl:
          description: Async Result Url
          example: /search/config/jobs/2df49d4f72e842b582b123bc2b7826b3/download
          readOnly: true
          type: string
        cloudType:
          description: Cloud Type
          enum:
          - aws
          - azure
          - gcp
          - alibaba_cloud
          - oci
          type: string
        cursor:
          description: Cursor
          format: int32
          readOnly: true
          type: integer
        data:
          $ref: '#/components/schemas/SearchModel'
        default:
          type: boolean
        description:
          description: Search Description
          type: string
        filters:
          description: View Order
          items:
            $ref: '#/components/schemas/UIFilterModel'
          readOnly: true
          type: array
        groupBy:
          description: Group By
          items:
            type: string
          readOnly: true
          type: array
        id:
          description: Search ID
          type: string
        name:
          description: Search Name
          type: string
        query:
          description: RQL Query
          type: string
        saved:
          description: Search Exists
          type: boolean
        searchType:
          description: Search Type
          enum:
          - network
          - audit_event
          - config
          - asset
          readOnly: true
          type: string
        timeGranularity:
          description: Time Granularity
          readOnly: true
          type: string
        timeRange:
          allOf:
          - $ref: '#/components/schemas/TimeRangeConfigModel'
          - description: Time Range
      required:
      - query
      - timeRange
      type: object
    TimeRangeConfigModel:
      description: 'See the [Time Range Model](/prisma-cloud/api/cspm/api-time-range-model) for details.

        '
      discriminator:
        mapping:
          absolute: '#/components/schemas/AbsoluteTimeRangeConfigModel'
          relative: '#/components/schemas/RelativeTimeRangeConfigModel'
          to_now: '#/components/schemas/ToNowTimeRangeConfigModel'
        propertyName: type
      oneOf:
      - $ref: '#/components/schemas/RelativeTimeRangeConfigModel'
      - $ref: '#/components/schemas/AbsoluteTimeRangeConfigModel'
      - $ref: '#/components/schemas/ToNowTimeRangeConfigModel'
      properties:
        type:
          description: Time type
          type: string
      required:
      - type
      type: object
  securitySchemes:
    x-redlock-auth:
      description: The x-redlock-auth value is a JSON Web Token (JWT).
      in: header
      name: x-redlock-auth
      type: apiKey