Palo Alto Networks · Schema
Investigation
A Cortex XSOAR investigation containing war room entries and playbook state.
Cloud SecurityCybersecurityFirewallNetwork SecuritySASESOARThreat IntelligenceXDR
Properties
| Name | Type | Description |
|---|---|---|
| id | string | |
| name | string | |
| status | integer | |
| incidentId | string | |
| created | string | |
| modified | string | |
| entries | array | |
| playbookId | string | |
| runningPlaybooks | array |
JSON Schema
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"title": "Investigation",
"description": "A Cortex XSOAR investigation containing war room entries and playbook state.",
"$id": "https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/json-schema/cortex-xsoar-api-investigation-schema.json",
"type": "object",
"properties": {
"id": {
"type": "string",
"readOnly": true
},
"name": {
"type": "string"
},
"status": {
"type": "integer"
},
"incidentId": {
"type": "string"
},
"created": {
"type": "string",
"format": "date-time"
},
"modified": {
"type": "string",
"format": "date-time"
},
"entries": {
"type": "array",
"items": {
"type": "object",
"description": "A war room entry in a Cortex XSOAR investigation.",
"properties": {
"id": {
"type": "string",
"readOnly": true
},
"investigationId": {
"type": "string"
},
"type": {
"type": "integer",
"description": "Entry type: 1 (Note), 2 (Download), 3 (File), 4 (Error), 5 (Pinned), 6 (UserManagement), 7 (Image), 8 (PlaygroundCommand), 9 (PlaybookStatusNote), 10 (Canvas), 11 (Widget), 12 (Summary), 13 (Section), 14 (Table)."
},
"user": {
"type": "string",
"description": "Username of the user who created the entry."
},
"created": {
"type": "string",
"format": "date-time"
},
"modified": {
"type": "string",
"format": "date-time"
},
"contents": {
"type": "string",
"description": "Entry content text."
},
"humanReadable": {
"type": "string",
"description": "Human-readable formatted content."
},
"tags": {
"type": "array",
"items": {
"type": "string"
}
}
}
}
},
"playbookId": {
"type": "string"
},
"runningPlaybooks": {
"type": "array",
"items": {
"type": "string"
}
}
}
}
Work with this as data
Every JSON Schema here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for schemas
4 MCP tools reach this
find_json_schemasBrowse and filter every JSON Schema in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This JSON Schema
curl "https://apis.io/api/v1/json-schemas/cortex-xsoar-api-investigation"
All schemas
curl "https://apis.io/api/v1/json-schemas?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.