Palo Alto Networks · Schema
Endpoint
An endpoint enrolled in Cortex XDR protection.
Cloud SecurityCybersecurityFirewallNetwork SecuritySASESOARThreat IntelligenceXDR
Properties
| Name | Type | Description |
|---|---|---|
| endpoint_id | string | Unique endpoint identifier. |
| endpoint_name | string | Endpoint hostname. |
| endpoint_type | string | |
| endpoint_status | string | |
| os_type | string | |
| ip | array | IP addresses assigned to the endpoint. |
| users | array | Users logged into the endpoint. |
| domain | string | |
| alias | string | |
| first_seen | integer | First connection timestamp as Unix epoch milliseconds. |
| last_seen | integer | Last connection timestamp as Unix epoch milliseconds. |
| content_version | string | Cortex XDR agent content version. |
| installation_package | string | |
| active_directory | string | |
| install_date | integer | |
| endpoint_version | string | Cortex XDR agent version. |
| is_isolated | string | |
| isolation_reason | string | |
| scan_status | string | |
| group_name | array |
JSON Schema
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"title": "Endpoint",
"description": "An endpoint enrolled in Cortex XDR protection.",
"$id": "https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/json-schema/cortex-xdr-api-endpoint-schema.json",
"type": "object",
"properties": {
"endpoint_id": {
"type": "string",
"description": "Unique endpoint identifier."
},
"endpoint_name": {
"type": "string",
"description": "Endpoint hostname."
},
"endpoint_type": {
"type": "string",
"enum": [
"SERVER",
"WORKSTATION",
"LAPTOP"
]
},
"endpoint_status": {
"type": "string",
"enum": [
"CONNECTED",
"DISCONNECTED",
"LOST",
"UNINSTALLED"
]
},
"os_type": {
"type": "string",
"enum": [
"AGENT_OS_WINDOWS",
"AGENT_OS_LINUX",
"AGENT_OS_MAC"
]
},
"ip": {
"type": "array",
"items": {
"type": "string"
},
"description": "IP addresses assigned to the endpoint."
},
"users": {
"type": "array",
"items": {
"type": "string"
},
"description": "Users logged into the endpoint."
},
"domain": {
"type": "string"
},
"alias": {
"type": "string"
},
"first_seen": {
"type": "integer",
"description": "First connection timestamp as Unix epoch milliseconds."
},
"last_seen": {
"type": "integer",
"description": "Last connection timestamp as Unix epoch milliseconds."
},
"content_version": {
"type": "string",
"description": "Cortex XDR agent content version."
},
"installation_package": {
"type": "string"
},
"active_directory": {
"type": "string"
},
"install_date": {
"type": "integer"
},
"endpoint_version": {
"type": "string",
"description": "Cortex XDR agent version."
},
"is_isolated": {
"type": "string",
"enum": [
"AGENT_ISOLATED",
"AGENT_UNISOLATED",
"PENDING_ISOLATION",
"PENDING_UNISOLATION"
]
},
"isolation_reason": {
"type": "string"
},
"scan_status": {
"type": "string",
"enum": [
"SCAN_STATUS_NONE",
"SCAN_STATUS_PENDING",
"SCAN_STATUS_IN_PROGRESS",
"SCAN_STATUS_DONE",
"SCAN_STATUS_FAILED",
"SCAN_STATUS_CANCELLED"
]
},
"group_name": {
"type": "array",
"items": {
"type": "string"
}
}
}
}
Work with this as data
Every JSON Schema here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for schemas
4 MCP tools reach this
find_json_schemasBrowse and filter every JSON Schema in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This JSON Schema
curl "https://apis.io/api/v1/json-schemas/cortex-xdr-api-endpoint"
All schemas
curl "https://apis.io/api/v1/json-schemas?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.