Palo Alto Networks · Schema
IncidentSummary
IncidentSummary schema from Palo Alto Networks Enterprise DLP API
Cloud SecurityCybersecurityFirewallNetwork SecuritySASESOARThreat IntelligenceXDR
Properties
| Name | Type | Description |
|---|---|---|
| total_incidents | integer | Total number of incidents in the reporting period. |
| open_incidents | integer | Number of incidents still in open status. |
| resolved_incidents | integer | Number of resolved incidents. |
| by_severity | object | Incident count breakdown by severity. |
| by_channel | object | Incident count breakdown by detection channel. |
| top_data_patterns | array | Most frequently triggered data patterns. |
| top_users | array | Users with the most incidents. |
| reporting_period | object | Time range for the summary report. |
JSON Schema
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"title": "IncidentSummary",
"description": "IncidentSummary schema from Palo Alto Networks Enterprise DLP API",
"$id": "https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/json-schema/dlp-api-incident-summary-schema.json",
"type": "object",
"properties": {
"total_incidents": {
"type": "integer",
"description": "Total number of incidents in the reporting period."
},
"open_incidents": {
"type": "integer",
"description": "Number of incidents still in open status."
},
"resolved_incidents": {
"type": "integer",
"description": "Number of resolved incidents."
},
"by_severity": {
"type": "object",
"properties": {
"critical": {
"type": "integer"
},
"high": {
"type": "integer"
},
"medium": {
"type": "integer"
},
"low": {
"type": "integer"
},
"informational": {
"type": "integer"
}
},
"description": "Incident count breakdown by severity."
},
"by_channel": {
"type": "object",
"properties": {
"web": {
"type": "integer"
},
"ssl": {
"type": "integer"
},
"saas": {
"type": "integer"
},
"email": {
"type": "integer"
},
"endpoint": {
"type": "integer"
}
},
"description": "Incident count breakdown by detection channel."
},
"top_data_patterns": {
"type": "array",
"items": {
"type": "object",
"properties": {
"pattern_name": {
"type": "string"
},
"incident_count": {
"type": "integer"
}
}
},
"description": "Most frequently triggered data patterns."
},
"top_users": {
"type": "array",
"items": {
"type": "object",
"properties": {
"user": {
"type": "string"
},
"incident_count": {
"type": "integer"
}
}
},
"description": "Users with the most incidents."
},
"reporting_period": {
"type": "object",
"properties": {
"start_time": {
"type": "string",
"format": "date-time"
},
"end_time": {
"type": "string",
"format": "date-time"
}
},
"description": "Time range for the summary report."
}
}
}
Work with this as data
Every JSON Schema here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for schemas
4 MCP tools reach this
find_json_schemasBrowse and filter every JSON Schema in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This JSON Schema
curl "https://apis.io/api/v1/json-schemas/dlp-api-incident-summary"
All schemas
curl "https://apis.io/api/v1/json-schemas?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.