Prisma Cloud generates an alert when it detects a violation in a policy that is included in an active alert rule. You can use the API requests to manage alerts, including listing or viewing, snoozing or dismissing, reopening, or remediating alerts.When retrieving a list of alerts through an API request, you can set filters, time range parameters, or pagination parameters.### PaginationYou can limit the number of items in a response list from API resources that support pagination. Version 2 (V2) of the API requests to list alerts supports pagination and will accept the following request parameters.Request Parameter | Description -----------| -------**limit** | Maximum number of items to return per page. Without pagination, maximum number of items to return in a response.**offset** | Number of items to skip before selecting items to return. Default is zero.**pageToken** | Set to the **nextPageToken** value from the previous response object to return the next page of data.### FiltersAPI requests that use POST methods to request a list of alerts have filter parameters that enable you to narrow your request to alerts that meet a certain criteria.The [List Alert Filters](/prisma-cloud/api/cspm/get-alert-filter-options) requests return the available filters.
Palo Alto Networks Alerts API is one of 741 APIs that Palo Alto Networks publishes on the APIs.io network, described by a machine-readable OpenAPI specification.
Tagged areas include Alerts. The published artifact set on APIs.io includes an OpenAPI specification.
This API exposes
32 operations
across 27 paths,
and defines 108 schemas.
It is described by OpenAPI 3.2.0, at version 1.0.
Requests are made against 17 base URLs: https://api.prismacloud.io, https://api2.prismacloud.io, https://api3.prismacloud.io, https://api4.prismacloud.io, https://api.anz.prismacloud.io, https://api.eu.prismacloud.io, https://api2.eu.prismacloud.io, https://api.gov.prismacloud.io, https://api.prismacloud.cn, https://api.ca.prismacloud.io, https://api.sg.prismacloud.io, https://api.uk.prismacloud.io, https://api.ind.prismacloud.io, https://api.jp.prismacloud.io, https://api.fr.prismacloud.io, https://api.dig.security, PATH_TO_CONSOLE.
32 operations27 paths108 schemas16 GET2 PATCH13 POST1 PUT
Metadata
The identity and technical contract details declared by the specification.
Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://{firewall}/api/
Authentication
API Key
Resource Areas
1
Authentication & Security 1
Palo Alto Networks Alerts API declares
1 security scheme
for authenticating requests.
An API key is passed in the header as x-redlock-auth (x-redlock-auth).
x-redlock-auth — The x-redlock-auth value is a JSON Web Token (JWT).
Paths & Operations 32
Across 27 paths, the API surfaces 32 operations — 16 GET, 2 PATCH, 13 POST, 1 PUT. Each is listed below with its method, path, parameters, and response codes.
Alerts 32
Prisma Cloud generates an alert when it detects a violation in a policy that is included in an active alert rule. You can use the API requests to manage alerts, including listing…
The contract defines 108 schemas that model the data the API accepts and returns. The most detailed are AlertFilterSuggestion (36 properties), PolicyRiskScoreModel (27 properties), AlertModel (27 properties), PolicyRiskScoreModel_2 (27 properties). Each schema is shown below with its type and property counts.
RemediationAction
object
Action for remediation for data policy.
2 properties
RuleModel
object
Model for Rule
10 properties4 required
FilterSuggestionModel
object
Model for Filter Suggestions
2 properties1 required
AttributionEventModel
object
Model for AttributionEvent
3 properties
RemediationCliModel
object
Model for Remediation Command
4 properties
TargetTagModel
object
Model for Target Tag
2 properties
AlertRuleNotificationConfigModel
object
Model for Alert Rule Notification Config
17 properties
RelativeTimeRangeConfigModel
HistoryModel
object
Model for History
2 properties
ToNowTimeRangeConfigModel
TimeRangeConfigModel
object
See the [Time Range Model](/prisma-cloud/api/cspm/api-time-range-model) for details.
1 property1 required
RelativeTimeDurationModel
object
Model for RelativeTimeDuration
2 properties
AbsoluteTimeRangeConfigModel
RequireDismissalNoteConfigModel
object
Model for Require Dismissal Note Config
1 property
FilterSuggestion
object
Model for FilterSuggestion
3 properties
ComplianceMetadataModel
object
Model for ComplianceMetadata
12 properties
FilterModel
AsyncJob
object
Model for AsyncJob
9 properties
PolicyModel
object
Model for Policy
25 properties4 required
CountModel
object
Model used for just count
1 property
TargetFilterModel
object
Model for Target Filter
6 properties
AlertFilterSuggestion
object
Model for AlertFilterSuggestion
36 properties
UIFilterModel
object
Model for UIFilter
3 properties
ScoreModel
object
Model for Score
2 properties
JsonNode
object
21 properties
RuleCriteria
object
Criteria for Rule
3 properties
AlertsLookupKeyModel
object
Model for AlertsLookupKey
3 properties1 required
AlertStatusChangeRequestModel
object
Model for Alert Status Change Request
5 properties1 required
PolicyRiskScoreModel
object
Model for Policy Risk Score
27 properties4 required
WeekDay
object
2 properties
RemediationModel
object
Model for Remediation
3 properties
ResourceListIdsCollection
object
Model for holding the lists resource list ids by resource list type
1 property
AlertModel
object
Model for Alert
27 properties
ParsedTableFilter
object
Model for parsed table filter
8 properties
RiskDetailModel
object
Model for Risk Detail
4 properties
BaseFilterModel
object
Model for Filter
9 properties
ConnectionDetail
object
17 properties
PagedResultsAlertModel
object
6 properties
CloudResourceModel
object
Model for Cloud Resource
21 properties
AlertAttributionModel
object
Model for AlertAttribution
3 properties
InvestigateOptions
object
Model for InvestigateOptions
3 properties
AlertRulePolicyFilter
object
Model for Alert Rule Policy Filter
5 properties
PolicyScanConfigModel
object
Model for Policy Scan Config
17 properties2 required
NameValueIntegerString
object
2 properties
TimeModel
object
Model for Time
2 properties
CountDetails
object
2 properties
AbsoluteTimeRangeConfig
object
UIFilter
object
3 properties
FindingNodeMetadata
object
Finding Node Metadata
9 properties5 required
FindingBuildTimeRemediationMetadata
object
21 properties
PolicyPageResponse
object
3 properties
PolicyFilter
object
6 properties
ComplianceMetadata
object
Compliance Standards
15 properties
CloudNetworkNode
object
Represents a network node
9 properties3 required
EdgeMetadata
object
Edge Metadata
1 property1 required
VulnerabilityNode
object
1 required
FindingNode
object
1 required
CapabilityNodeMetadata
object
Capability Node Metadata
2 properties1 required
GroupPageResponse
object
4 properties
VulnerabilityMetadata
object
Vulnerability Node Metadata
5 properties5 required
GraphEdge
object
5 properties2 required
AlertEvidenceGraph
object
The resource specific graph
2 properties
PolicyVO
object
Policy data with alert count
14 properties
TimeRangeConfigModel_2
object
Model for TimeRangeConfig
4 properties1 required
CloudNetworkGraph
object
Represents the associated network graph for this finding
2 properties
SpringErrorResponse
object
6 properties5 required
FindingRemediationDetails
object
Represents the RemediationDetails for this finding
2 properties
Path
object
The associated paths in the network graph
1 property
GraphAlertEvidenceGraph
object
The list of graphs representing a primary asset and its associations
1 property
ToNowTimeRangeConfig
object
DataTypes
object
Data Sensitivity datatypes
3 properties
RelativeTimeRangeConfig
object
IAMPermissionsResponse
object
Permission graph items
11 properties
AssetGraphs
object
2 properties1 required
GroupsResponse
object
List of groups for selected group by field
13 properties
NodeDataType
object
The nodes associated with this network graph
2 properties
AssetNode
object
2 required
FromNowTimeRangeConfig
object
CloudNetworkGraphResponse
object
The cloud network graphs
2 properties
CapabilityNode
object
2 required
PrimaryAssetNode
object
2 required
RelativeTimeDuration
object
2 properties
AssetNodeMetadata
object
Primary Asset Node Metadata
5 properties3 required
FindingRuntimeRemediationMetadaa
object
1 property
Node
object
A dictionary of the node identifier and the associated node
2 properties
ErrorDetails
object
2 properties2 required
IAMPermissionGraph
object
Represents the associated permission graph for this finding
1 property
Time
object
2 properties
OnDemandNotificationConfig
object
6 properties3 required
OnDemandNotificationConfigRequest
object
3 properties2 required
NotificationResponse
object
4 properties
ErrorResponse
object
1 property1 required
SuccessfulEvents
object
5 properties
Error
object
4 properties2 required
Translation
object
3 properties1 required
FilterModel_2
object
Model for Filter
9 properties
PolicyModel_2
object
Model for Policy
25 properties4 required
PolicyRiskScoreModel_2
object
Model for Policy Risk Score
27 properties4 required
AlertModel_2
object
Model for Alert
24 properties
PolicyWithRemediation
object
9 properties
ScriptRemediation
object
The suggested Terraform-based remediation steps
5 properties
ManualRemediation
object
The manual remediation steps to be taken
4 properties
PolicyWithRemediationResponse
object
1 property
AiRemediation
object
3 properties
AssetLabelDashboardDTO
object
2 properties
AlertDTO
object
20 properties
UpdateAlertStatusResponseDTO
object
3 properties
LabelDashboardDTO
object
5 properties
Specification
The full machine-readable OpenAPI contract behind this narrative.
Every API here is available over the API and to AI agents over MCP. APIs is not yet its own endpoint on the v1 API. Reach this content through network search and the tag graph, or the MCP server below.
Installs https://mcp.apievangelist.com/mcp in Claude, Cursor, VS Code and the rest — one button, every client.
MCP tools for apis
4 tools reach this content
search_api_evangelistSearch every content type across the network at once.
find_relatedThe shared-tag relevance graph — what else covers this.
get_tagEverything one tag labels, across all content types.
guide_topicPRO — a curated bundle for a topic: area, guidance, rules, papers, stories, services.
A second provider on the same verified email joins the account you already have.
Your account
ⓘWhere this information came from
This is an independent, third-party profile of Palo Alto Networks Alerts API, published by
API Evangelist. We do not operate, host, resell, or
support these APIs, and we are not affiliated with or endorsed by the company unless stated above.
Everything here is built from publicly available information — the company's own site,
developer portal, documentation, public repositories, and the specifications it publishes for public use.
Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's
public API artifacts, scored against a published rubric. They are not certifications,
endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and
you do not need to justify the request. A removed company is recorded as unrated, never scored
zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy → On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.