Palo Alto Networks · Schema
Incident
Incident schema from Palo Alto Networks SaaS Security API
Cloud SecurityCybersecurityFirewallNetwork SecuritySASESOARThreat IntelligenceXDR
Properties
| Name | Type | Description |
|---|---|---|
| id | string | Unique incident identifier. |
| title | string | Summary title of the incident. |
| description | string | Detailed description of the security incident. |
| status | string | Current incident status. |
| severity | string | Incident severity level. |
| app_id | string | ID of the SaaS application where the incident occurred. |
| app_name | string | Name of the SaaS application. |
| policy_name | string | Name of the policy that triggered the incident. |
| affected_assets | array | IDs of assets involved in the incident. |
| affected_users | array | User IDs of users involved in the incident. |
| assignee_id | string | User ID of the assigned analyst. |
| created_at | string | Timestamp when the incident was detected. |
| updated_at | string | Timestamp of the most recent update. |
JSON Schema
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"title": "Incident",
"description": "Incident schema from Palo Alto Networks SaaS Security API",
"$id": "https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/json-schema/saas-security-api-incident-schema.json",
"type": "object",
"properties": {
"id": {
"type": "string",
"description": "Unique incident identifier."
},
"title": {
"type": "string",
"description": "Summary title of the incident."
},
"description": {
"type": "string",
"description": "Detailed description of the security incident."
},
"status": {
"type": "string",
"enum": [
"new",
"in_progress",
"resolved",
"dismissed"
],
"description": "Current incident status."
},
"severity": {
"type": "string",
"enum": [
"low",
"medium",
"high",
"critical"
],
"description": "Incident severity level."
},
"app_id": {
"type": "string",
"description": "ID of the SaaS application where the incident occurred."
},
"app_name": {
"type": "string",
"description": "Name of the SaaS application."
},
"policy_name": {
"type": "string",
"description": "Name of the policy that triggered the incident."
},
"affected_assets": {
"type": "array",
"items": {
"type": "string"
},
"description": "IDs of assets involved in the incident."
},
"affected_users": {
"type": "array",
"items": {
"type": "string"
},
"description": "User IDs of users involved in the incident."
},
"assignee_id": {
"type": "string",
"description": "User ID of the assigned analyst."
},
"created_at": {
"type": "string",
"format": "date-time",
"description": "Timestamp when the incident was detected."
},
"updated_at": {
"type": "string",
"format": "date-time",
"description": "Timestamp of the most recent update."
}
}
}
Work with this as data
Every JSON Schema here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for schemas
4 MCP tools reach this
find_json_schemasBrowse and filter every JSON Schema in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This JSON Schema
curl "https://apis.io/api/v1/json-schemas/saas-security-api-incident"
All schemas
curl "https://apis.io/api/v1/json-schemas?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.