Palo Alto Networks · Schema
AsmIncident
An attack surface incident representing a confirmed exposure requiring remediation.
Cloud SecurityCybersecurityFirewallNetwork SecuritySASESOARThreat IntelligenceXDR
Properties
| Name | Type | Description |
|---|---|---|
| incident_id | string | Unique attack surface incident identifier. |
| incident_name | string | |
| status | string | |
| severity | string | |
| incident_type | array | Attack surface rule types that triggered this incident. |
| assigned_user_mail | string | |
| assigned_user_pretty_name | string | |
| alert_count | integer | |
| description | string | |
| creation_time | integer | Incident creation timestamp as Unix epoch milliseconds. |
| modification_time | integer | |
| resolved_by | string | |
| resolve_comment | string | |
| tags | array |
JSON Schema
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"title": "AsmIncident",
"description": "An attack surface incident representing a confirmed exposure requiring remediation.",
"$id": "https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/json-schema/cortex-xpanse-api-asm-incident-schema.json",
"type": "object",
"properties": {
"incident_id": {
"type": "string",
"description": "Unique attack surface incident identifier."
},
"incident_name": {
"type": "string"
},
"status": {
"type": "string",
"enum": [
"new",
"under_investigation",
"resolved",
"resolved_no_risk",
"resolved_risk_accepted",
"resolved_contested_asset",
"resolved_remediated_automatically"
]
},
"severity": {
"type": "string",
"enum": [
"critical",
"high",
"medium",
"low",
"informational"
]
},
"incident_type": {
"type": "array",
"items": {
"type": "string"
},
"description": "Attack surface rule types that triggered this incident."
},
"assigned_user_mail": {
"type": "string"
},
"assigned_user_pretty_name": {
"type": "string"
},
"alert_count": {
"type": "integer"
},
"description": {
"type": "string"
},
"creation_time": {
"type": "integer",
"description": "Incident creation timestamp as Unix epoch milliseconds."
},
"modification_time": {
"type": "integer"
},
"resolved_by": {
"type": "string"
},
"resolve_comment": {
"type": "string"
},
"tags": {
"type": "array",
"items": {
"type": "object",
"properties": {
"key": {
"type": "string"
},
"value": {
"type": "string"
}
}
}
}
}
}
Work with this as data
Every JSON Schema here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for schemas
4 MCP tools reach this
find_json_schemasBrowse and filter every JSON Schema in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This JSON Schema
curl "https://apis.io/api/v1/json-schemas/cortex-xpanse-api-asm-incident"
All schemas
curl "https://apis.io/api/v1/json-schemas?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.