How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Palo Alto Networks Audits API

{'$ref': 'desc/audits/audits.md'}

Palo Alto Networks Audits API is one of 741 APIs that Palo Alto Networks publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Audits. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 96 operations across 96 paths, and defines 64 schemas. It is described by OpenAPI 3.2.0, at version 1.0.

Requests are made against a single base URL, PATH_TO_CONSOLE.

96 operations 96 paths 64 schemas 94 GET2 PATCH

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://{firewall}/api/
Resource Areas
1

Paths & Operations 96

Across 96 paths, the API surfaces 96 operations — 94 GET, 2 PATCH. Each is listed below with its method, path, parameters, and response codes.

Audits 96

Audits. 48 operations in this definition.

GET
/api/v34.03/audits/access
Get Docker Access Audit Events
get-audits-access 13 params → 200default
GET
/api/v34.03/audits/access/download
Download Docker Access Audit Events
get-audits-access-download 13 params → 200default
GET
/api/v34.03/audits/admission
Get Admission Audit Events
get-audits-admission 10 params → 200default
GET
/api/v34.03/audits/admission/download
Download Admission Audit Events
get-audits-admission-download 10 params → 200default
GET
/api/v34.03/audits/firewall/app/agentless
Get WAAS Agentless Audit Events
get-audits-firewall-app-agentless 38 params → 200default
GET
/api/v34.03/audits/firewall/app/agentless/download
Download WAAS Agentless Audit Events
get-audits-firewall-app-agentless-download 38 params → 200default
GET
/api/v34.03/audits/firewall/app/agentless/timeslice
Get WAAS Agentless Audit Events for a Timeframe
get-audits-firewall-app-agentless-timeslice 39 params → 200default
GET
/api/v34.03/audits/firewall/app/app-embedded
Get WAAS App-embedded Audit Events
get-audits-firewall-app-app-embedded 38 params → 200default
GET
/api/v34.03/audits/firewall/app/app-embedded/download
Download WAAS App-embedded Audit Events
get-audits-firewall-app-app-embedded-download 38 params → 200default
GET
/api/v34.03/audits/firewall/app/app-embedded/timeslice
Get WAAS App-embedded Audit Events for a Timeframe
get-audits-firewall-app-app-embedded-timeslice 39 params → 200default
GET
/api/v34.03/audits/firewall/app/container
Get WAAS Container Audit Events
get-audits-firewall-app-container 38 params → 200default
GET
/api/v34.03/audits/firewall/app/container/download
Download WAAS Container Audit Events
get-audits-firewall-app-container-download 38 params → 200default
GET
/api/v34.03/audits/firewall/app/container/timeslice
Get WAAS Container Audit Timeslice
get-audits-firewall-app-container-timeslice 39 params → 200default
GET
/api/v34.03/audits/firewall/app/host
Get WAAS Host Audit Events
get-audits-firewall-app-host 38 params → 200default
GET
/api/v34.03/audits/firewall/app/host/download
Download WAAS Host Audit Events
get-audits-firewall-app-host-download 38 params → 200default
GET
/api/v34.03/audits/firewall/app/host/timeslice
Get WAAS Host Audit Timeslice
get-audits-firewall-app-host-timeslice 39 params → 200default
GET
/api/v34.03/audits/firewall/app/serverless
Get WAAS Serverless Audit Events
get-audits-firewall-app-serverless 38 params → 200default
GET
/api/v34.03/audits/firewall/app/serverless/download
Download WAAS Serverless Audit Events
get-audits-firewall-app-serverless-download 38 params → 200default
GET
/api/v34.03/audits/firewall/app/serverless/timeslice
Get WAAS Serverless Audit Events for a Timeframe
get-audits-firewall-app-serverless-timeslice 39 params → 200default
GET
/api/v34.03/audits/firewall/network/container
Get CNNS Container Audit Events
get-audits-firewall-network-container 9 params → 200default
GET
/api/v34.03/audits/firewall/network/container/download
Download CNNS Container Audit Events
get-audits-firewall-network-container-download 9 params → 200default
GET
/api/v34.03/audits/firewall/network/host
Get CNNS Host Audit Events
get-audits-firewall-network-host 8 params → 200default
GET
/api/v34.03/audits/firewall/network/host/download
Download CNNS Host Audit Events
get-audits-firewall-network-host-download 8 params → 200default
GET
/api/v34.03/audits/incidents
Get Incident Audit Events
get-audits-incidents 17 params → 200default
PATCH
/api/v34.03/audits/incidents/acknowledge/{id}
Archive an Incident Audit Event
patch-audits-incidents-acknowledge-id 1 param body → 200default
GET
/api/v34.03/audits/incidents/download
Download Incident Audit Events
get-audits-incidents-download 17 params → 200default
GET
/api/v34.03/audits/kubernetes
Get Kubernetes Audit Events
get-audits-kubernetes 9 params → 200default
GET
/api/v34.03/audits/kubernetes/download
Download Kubernetes Audit Events
get-audits-kubernetes-download 9 params → 200default
GET
/api/v34.03/audits/mgmt
Get Management Audit Events
get-audits-mgmt 8 params → 200default
GET
/api/v34.03/audits/mgmt/download
Download Management Audit Events
get-audits-mgmt-download 8 params → 200default
GET
/api/v34.03/audits/mgmt/filters
Get Management Audit Event Filters
get-audits-mgmt-filters 8 params → 200default
GET
/api/v34.03/audits/runtime/app-embedded
Get Runtime App-embedded Audit Events
get-audits-runtime-app-embedded 33 params → 200default
GET
/api/v34.03/audits/runtime/app-embedded/download
Download Runtime App-embedded Audit Events
get-audits-runtime-app-embedded-download 33 params → 200default
GET
/api/v34.03/audits/runtime/container
Get Runtime Container Audit Events
get-audits-runtime-container 33 params → 200default
GET
/api/v34.03/audits/runtime/container/download
Download Runtime Container Audit Events
get-audits-runtime-container-download 33 params → 200default
GET
/api/v34.03/audits/runtime/container/timeslice
Get Runtime Container Audit Events for a Timeframe
get-audits-runtime-container-timeslice 34 params → 200default
GET
/api/v34.03/audits/runtime/file-integrity
Get Runtime File Integrity Audit Events
get-audits-runtime-file-integrity 11 params → 200default
GET
/api/v34.03/audits/runtime/file-integrity/download
Download Runtime File Integrity Audit Events
get-audits-runtime-file-integrity-download 11 params → 200default
GET
/api/v34.03/audits/runtime/host
Get Runtime Host Audit Events
get-audits-runtime-host 33 params → 200default
GET
/api/v34.03/audits/runtime/host/download
Download Runtime Host Audit Events
get-audits-runtime-host-download 33 params → 200default
GET
/api/v34.03/audits/runtime/host/timeslice
Get Runtime Host Audit Events for a Timeframe
get-audits-runtime-host-timeslice 34 params → 200default
GET
/api/v34.03/audits/runtime/log-inspection
Get Runtime Log Inspection Audit Events
get-audits-runtime-log-inspection 10 params → 200default
GET
/api/v34.03/audits/runtime/log-inspection/download
Download Runtime Log Inspection Audit Events
get-audits-runtime-log-inspection-download 10 params → 200default
GET
/api/v34.03/audits/runtime/serverless
Get Runtime Serverless Audit Events
get-audits-runtime-serverless 18 params → 200default
GET
/api/v34.03/audits/runtime/serverless/download
Download Serverless Audit Events
get-audits-runtime-serverless-download 33 params → 200default
GET
/api/v34.03/audits/runtime/serverless/timeslice
Get Runtime Serverless Audit Events for a Timeframe
get-audits-runtime-serverless-timeslice 34 params → 200default
GET
/api/v34.03/audits/trust
Get Trust Audit Events
get-audits-trust 9 params → 200default
GET
/api/v34.03/audits/trust/download
Download Trust Audit Events
get-audits-trust-download 9 params → 200default
GET
/api/v34.04/audits/access
Get Docker Access Audit Events
get-audits-access 13 params → 200default
GET
/api/v34.04/audits/access/download
Download Docker Access Audit Events
get-audits-access-download 13 params → 200default
GET
/api/v34.04/audits/admission
Get Admission Audit Events
get-audits-admission 10 params → 200default
GET
/api/v34.04/audits/admission/download
Download Admission Audit Events
get-audits-admission-download 10 params → 200default
GET
/api/v34.04/audits/firewall/app/agentless
Get WAAS Agentless Audit Events
get-audits-firewall-app-agentless 38 params → 200default
GET
/api/v34.04/audits/firewall/app/agentless/download
Download WAAS Agentless Audit Events
get-audits-firewall-app-agentless-download 38 params → 200default
GET
/api/v34.04/audits/firewall/app/agentless/timeslice
Get WAAS Agentless Audit Events for a Timeframe
get-audits-firewall-app-agentless-timeslice 39 params → 200default
GET
/api/v34.04/audits/firewall/app/app-embedded
Get WAAS App-embedded Audit Events
get-audits-firewall-app-app-embedded 38 params → 200default
GET
/api/v34.04/audits/firewall/app/app-embedded/download
Download WAAS App-embedded Audit Events
get-audits-firewall-app-app-embedded-download 38 params → 200default
GET
/api/v34.04/audits/firewall/app/app-embedded/timeslice
Get WAAS App-embedded Audit Events for a Timeframe
get-audits-firewall-app-app-embedded-timeslice 39 params → 200default
GET
/api/v34.04/audits/firewall/app/container
Get WAAS Container Audit Events
get-audits-firewall-app-container 38 params → 200default
GET
/api/v34.04/audits/firewall/app/container/download
Download WAAS Container Audit Events
get-audits-firewall-app-container-download 38 params → 200default
GET
/api/v34.04/audits/firewall/app/container/timeslice
Get WAAS Container Audit Timeslice
get-audits-firewall-app-container-timeslice 39 params → 200default
GET
/api/v34.04/audits/firewall/app/host
Get WAAS Host Audit Events
get-audits-firewall-app-host 38 params → 200default
GET
/api/v34.04/audits/firewall/app/host/download
Download WAAS Host Audit Events
get-audits-firewall-app-host-download 38 params → 200default
GET
/api/v34.04/audits/firewall/app/host/timeslice
Get WAAS Host Audit Timeslice
get-audits-firewall-app-host-timeslice 39 params → 200default
GET
/api/v34.04/audits/firewall/app/serverless
Get WAAS Serverless Audit Events
get-audits-firewall-app-serverless 38 params → 200default
GET
/api/v34.04/audits/firewall/app/serverless/download
Download WAAS Serverless Audit Events
get-audits-firewall-app-serverless-download 38 params → 200default
GET
/api/v34.04/audits/firewall/app/serverless/timeslice
Get WAAS Serverless Audit Events for a Timeframe
get-audits-firewall-app-serverless-timeslice 39 params → 200default
GET
/api/v34.04/audits/firewall/network/container
Get CNNS Container Audit Events
get-audits-firewall-network-container 9 params → 200default
GET
/api/v34.04/audits/firewall/network/container/download
Download CNNS Container Audit Events
get-audits-firewall-network-container-download 9 params → 200default
GET
/api/v34.04/audits/firewall/network/host
Get CNNS Host Audit Events
get-audits-firewall-network-host 8 params → 200default
GET
/api/v34.04/audits/firewall/network/host/download
Download CNNS Host Audit Events
get-audits-firewall-network-host-download 8 params → 200default
GET
/api/v34.04/audits/incidents
Get Incident Audit Events
get-audits-incidents 17 params → 200default
PATCH
/api/v34.04/audits/incidents/acknowledge/{id}
Archive an Incident Audit Event
patch-audits-incidents-acknowledge-id 1 param body → 200default
GET
/api/v34.04/audits/incidents/download
Download Incident Audit Events
get-audits-incidents-download 17 params → 200default
GET
/api/v34.04/audits/kubernetes
Get Kubernetes Audit Events
get-audits-kubernetes 9 params → 200default
GET
/api/v34.04/audits/kubernetes/download
Download Kubernetes Audit Events
get-audits-kubernetes-download 9 params → 200default
GET
/api/v34.04/audits/mgmt
Get Management Audit Events
get-audits-mgmt 8 params → 200default
GET
/api/v34.04/audits/mgmt/download
Download Management Audit Events
get-audits-mgmt-download 8 params → 200default
GET
/api/v34.04/audits/mgmt/filters
Get Management Audit Event Filters
get-audits-mgmt-filters 8 params → 200default
GET
/api/v34.04/audits/runtime/app-embedded
Get Runtime App-embedded Audit Events
get-audits-runtime-app-embedded 33 params → 200default
GET
/api/v34.04/audits/runtime/app-embedded/download
Download Runtime App-embedded Audit Events
get-audits-runtime-app-embedded-download 33 params → 200default
GET
/api/v34.04/audits/runtime/container
Get Runtime Container Audit Events
get-audits-runtime-container 33 params → 200default
GET
/api/v34.04/audits/runtime/container/download
Download Runtime Container Audit Events
get-audits-runtime-container-download 33 params → 200default
GET
/api/v34.04/audits/runtime/container/timeslice
Get Runtime Container Audit Events for a Timeframe
get-audits-runtime-container-timeslice 34 params → 200default
GET
/api/v34.04/audits/runtime/file-integrity
Get Runtime File Integrity Audit Events
get-audits-runtime-file-integrity 11 params → 200default
GET
/api/v34.04/audits/runtime/file-integrity/download
Download Runtime File Integrity Audit Events
get-audits-runtime-file-integrity-download 11 params → 200default
GET
/api/v34.04/audits/runtime/host
Get Runtime Host Audit Events
get-audits-runtime-host 33 params → 200default
GET
/api/v34.04/audits/runtime/host/download
Download Runtime Host Audit Events
get-audits-runtime-host-download 33 params → 200default
GET
/api/v34.04/audits/runtime/host/timeslice
Get Runtime Host Audit Events for a Timeframe
get-audits-runtime-host-timeslice 34 params → 200default
GET
/api/v34.04/audits/runtime/log-inspection
Get Runtime Log Inspection Audit Events
get-audits-runtime-log-inspection 10 params → 200default
GET
/api/v34.04/audits/runtime/log-inspection/download
Download Runtime Log Inspection Audit Events
get-audits-runtime-log-inspection-download 10 params → 200default
GET
/api/v34.04/audits/runtime/serverless
Get Runtime Serverless Audit Events
get-audits-runtime-serverless 18 params → 200default
GET
/api/v34.04/audits/runtime/serverless/download
Download Serverless Audit Events
get-audits-runtime-serverless-download 33 params → 200default
GET
/api/v34.04/audits/runtime/serverless/timeslice
Get Runtime Serverless Audit Events for a Timeframe
get-audits-runtime-serverless-timeslice 34 params → 200default
GET
/api/v34.04/audits/trust
Get Trust Audit Events
get-audits-trust 9 params → 200default
GET
/api/v34.04/audits/trust/download
Download Trust Audit Events
get-audits-trust-download 9 params → 200default

Schemas 64

The contract defines 64 schemas that model the data the API accepts and returns. The most detailed are shared.AppFirewallAudit (60 properties), shared.RuntimeAudit (50 properties), shared.Incident (31 properties), cnnf.ContainerAudit (18 properties). Each schema is shown below with its type and property counts.

shared.ContainerNetworkFirewallSubtypeAudits
object
ContainerNetworkFirewallSubtypeAudits represents the container network firewall sub type audits per profile
2 properties
prisma.AssetType
integer
AssetType is the integral value that we need to pass to PC in the UAI and Unified Alerts integrations to identify the asset type Mappings of the asset types ag…
kubeaudit.EventUserInfo
object
EventUserInfo holds the information about the user that authenticated to Kubernentes
3 properties
mitre.Technique
string
Technique is the MITRE framework attack technique
shared.ContainerNetworkFirewallProfileAudits
object
ContainerNetworkFirewallProfileAudits represents the container network firewall profile audits
10 properties
-_shared.AppFirewallAudit
array
waas.Protection
string
Protection is the type of protection
admission.Audit
object
Audit represents an admission audit
16 properties
shared.FileMetadata
object
FileMetadata represents the metadata of a single file/directory
3 properties
kubeaudit.Audit
object
Audit represents a Kubernetes audit - this is the data that is stored for matched audits
14 properties
types.MgmtAuditFilters
object
MgmtAuditFilters are filters for management audit queries
2 properties
-_shared.HostNetworkFirewallProfileAudits
array
shared.RuntimeAttackType
string
RuntimeAttackType is the sub-category of the attack (e.g., malware process, process not in model, etc...)
shared.HostNetworkFirewallSubtypeAudits
object
HostNetworkFirewallSubtypeAudits represents the host network firewall sub type audits per profile
2 properties
types.AuditTimeslice
object
AuditTimeslice counts the number of audit events for a given time period
3 properties
shared.RuntimeSeverity
string
RuntimeSeverity represents the runtime severity
common.CloudProvider
string
CloudProvider specifies the cloud provider name
string
string
-_shared.ContainerNetworkFirewallProfileAudits
array
waas.AttackType
string
AttackType is the type of the attack
waas.OWASPTop10
string
OWASPTop10 represents OWASP top 10 attacks
prisma.ServiceProvider
string
ServiceProvider represents service provider id or "other" in case it is non cloud.
shared.TrustAudits
object
TrustAudits represents the trust profile audits
10 properties
shared.Incident
object
Incident represents an incident
31 properties
shared.MgmtType
string
MgmtType represents management audit types
shared.AppFirewallAudit
object
AppFirewallAudit represents a firewall audit event
60 properties
waas.FirewallType
string
FirewallType represents the firewall type
shared.LogInspectionEvent
object
LogInspectionEvent is a log inspection event detected according to the log inspection rules
9 properties
shared.FileIntegrityEvent
object
FileIntegrityEvent represents a single file integrity event detected according to the file integrity monitoring rules
15 properties
prisma.CloudType
integer
CloudType is the prisma cloud type of the resource that is used for policy verdict creation Cloud type values are documented here - https://docs.google.com/spr…
-_shared.TrustAudits
array
-_admission.Audit
array
shared.TrustRegistryRepoAudits
object
TrustRegistryRepoAudits represents the trust registry/repo audits per profile
2 properties
shared.FileIntegrityEventType
string
FileIntegrityEventType represents the type of the file integrity event
shared.LambdaRuntimeType
string
LambdaRuntimeType represents the runtime type of the serverless function The constants used are taken from: https://docs.aws.amazon.com/lambda/latest/dg/APICre…
runtime.FSFileType
integer
FSFileType represents the file type
waas.Effect
string
Effect is the effect that will be used in the rule
cnnf.HostAudit
object
HostAudit represents a host network firewall audit event
14 properties
-_shared.MgmtAudit
array
shared.HostNetworkFirewallProfileAudits
object
HostNetworkFirewallProfileAudits represents the host network firewall profile audits
10 properties
-_shared.Incident
array
shared.MgmtAudit
object
MgmtAudit represents a management audit in the system
8 properties
-_shared.RuntimeAudit
array
shared.IncidentType
string
IncidentType is the type of the incident
shared.RuntimeType
string
RuntimeType represents the runtime protection type
runtime.RuleEffect
string
RuleEffect is the effect that will be used in the runtime rule
waas.HTTPFieldType
string
HTTPFieldType indicates type of http field
common.ProfileHash
integer
ProfileHash represents the profile hash It is allowed to contain up to uint32 numbers, and represented by int64 since mongodb does not support unsigned data ty…
shared.IncidentCategory
string
IncidentCategory is the incident category
waas.OWASPAPITop10
string
OWASPAPITop10 represents OWASP API top 10 attacks
vuln.Effect
string
Effect specifies relevant action for a vulnerability
shared.Audit
object
Audit represents an event in the system
17 properties
shared.TrustAudit
object
TrustAudit represents a trust audit
10 properties
-_shared.LogInspectionEvent
array
cnnf.ContainerAudit
object
ContainerAudit represents a network firewall audit event
18 properties
waas.HTTPField
object
HTTPField is used to perform checks on flags and fields
3 properties
cnnf.NetworkFirewallAttackType
string
NetworkFirewallAttackType is the network firewall type of attack
-_shared.FileIntegrityEvent
array
-_shared.Audit
array
-_types.AuditTimeslice
array
shared.RuntimeAudit
object
RuntimeAudit represents a runtime audit event (fires when a runtime policy is violated)
50 properties
cnnf.RuleID
integer
RuleID represents the ID of each container network firewall policy rule
-_kubeaudit.Audit
array
common.RuntimeResource
object
RuntimeResource represents on which resource in the system a rule applies (e.g., specific host or image) Empty resource or wildcard () represents all resources…
9 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

palo-alto-networks-audits-api-openapi.yml Raw ↑

Other APIs Palo Alto Networks publishes across the network.

PAN-OS XML API
PAN-OS OpenConfig API
Panorama API
AutoFocus API (Deprecated)
Prisma SASE Service Status API
Cross-Platform Service Status API
SASE Authentication Service API
Expedition API (Deprecated)
VM-Series Licensing API
Palo Alto Networks 5G Deregistered Trend API
Palo Alto Networks 5G Network Interconnects and Bandwidth API
Palo Alto Networks 5G Registered Trend API
Where this information came from

This is an independent, third-party profile of Palo Alto Networks Audits API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.