Add address group members
Action ID:tools.pan_os.add_address_group_members
Add members of a static address group in the candidate configuration. Reads the group with GET /restapi/{version}/Objects/AddressGroups?name= and writes it with PUT only when membership changes, so repeated calls are idempotent. Commit to apply the change.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
array[string]
required
Address objects or address groups.
string
required
Address group name.
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Block CIDR
Action ID:tools.pan_os.block_cidr
Block a CIDR range by adding an address object to a static address group referenced by a deny rule. Looks up the address object by name, creates it with POST /restapi/{version}/Objects/Addresses if missing, then adds it to the group with PUT /restapi/{version}/Objects/AddressGroups if it is not already a member, so repeated calls do not create duplicates. Changes stay in the candidate configuration; run commit (and commit_all on Panorama) to enforce them. For temporary blocks without a commit, use register_ip_tags with a dynamic address group.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Static address group that a deny rule references, e.g. tracecat-blocklist.
string
required
IPv4 or IPv6 network in CIDR notation to block.
string | null
Address object name to use instead of the generated name.Default:
null.string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Description for a newly created address object, e.g. the case ID.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".string
Prefix for generated address object names.Default:
"tc-block-".array[string] | null
Tags for a newly created address object.Default:
null.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Block FQDN
Action ID:tools.pan_os.block_fqdn
Block an FQDN by adding an address object to a static address group referenced by a deny rule. Looks up the address object by name, creates it with POST /restapi/{version}/Objects/Addresses if missing, then adds it to the group with PUT /restapi/{version}/Objects/AddressGroups if it is not already a member, so repeated calls do not create duplicates. Changes stay in the candidate configuration; run commit (and commit_all on Panorama) to enforce them. For temporary blocks without a commit, use register_ip_tags with a dynamic address group.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Static address group that a deny rule references, e.g. tracecat-blocklist.
string
required
Fully qualified domain name to block.
string | null
Address object name to use instead of the generated name.Default:
null.string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Description for a newly created address object, e.g. the case ID.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".string
Prefix for generated address object names.Default:
"tc-block-".array[string] | null
Tags for a newly created address object.Default:
null.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Block IP
Action ID:tools.pan_os.block_ip
Block an IP address by adding an address object to a static address group referenced by a deny rule. Looks up the address object by name, creates it with POST /restapi/{version}/Objects/Addresses if missing, then adds it to the group with PUT /restapi/{version}/Objects/AddressGroups if it is not already a member, so repeated calls do not create duplicates. Changes stay in the candidate configuration; run commit (and commit_all on Panorama) to enforce them. For temporary blocks without a commit, use register_ip_tags with a dynamic address group.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Static address group that a deny rule references, e.g. tracecat-blocklist.
string
required
IPv4 or IPv6 address to block.
string | null
Address object name to use instead of the generated name.Default:
null.string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Description for a newly created address object, e.g. the case ID.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".string
Prefix for generated address object names.Default:
"tc-block-".array[string] | null
Tags for a newly created address object.Default:
null.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Commit
Action ID:tools.pan_os.commit
Commit the candidate configuration on a firewall or Panorama with the XML API (type=commit). Optionally commit only changes made by specific administrators. Returns the job ID, or no job ID when there is nothing to commit; use wait_for_job to wait for completion.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/commit-configuration-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
array[string] | null
Commit only changes made by these administrators (partial commit).Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Commit description, e.g. the case or incident ID.Default:
null.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.Create address
Action ID:tools.pan_os.create_address
Create an address object in the candidate configuration with POST /restapi/{version}/Objects/Addresses?name=. Provide exactly one of ip_netmask, ip_range, ip_wildcard, or fqdn. Commit to apply the change.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Address object name (max 63 characters).
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Address object description.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string | null
Fully qualified domain name.Default:
null.string | null
IP address with or without CIDR mask, e.g. 203.0.113.10 or 10.0.0.0/24.Default:
null.string | null
IP range, e.g. 10.0.0.1-10.0.0.20.Default:
null.string | null
IP wildcard mask, e.g. 10.20.1.0/0.0.248.255.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".array[string] | null
Tags to apply. Tags must already exist.Default:
null.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Create address group
Action ID:tools.pan_os.create_address_group
Create a static or dynamic address group in the candidate configuration with POST /restapi/{version}/Objects/AddressGroups?name=. Provide exactly one of static_members or dynamic_filter. Commit to apply the change.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Address group name (max 63 characters).
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Address group description.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string | null
Tag filter for a dynamic address group, e.g. ‘tracecat-block’.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".array[string] | null
Address objects or groups for a static group.Default:
null.array[string] | null
Tags to apply to the group.Default:
null.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Create security rule
Action ID:tools.pan_os.create_security_rule
Create a security rule in the candidate configuration with POST /restapi/{version}/Policies/SecurityRules?name= (SecurityPreRules or SecurityPostRules on Panorama). The rule is added at the bottom; use move_security_rule to place it. Commit to apply the change.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Action to take when the rule matches. Allowed values: allow, deny, drop, reset-client, reset-server, reset-both.
string
required
Security rule name.
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.array[string]
Applications. Defaults to any.Default:
[ "any" ].string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.array[string]
URL categories. Defaults to any.Default:
[ "any" ].string | null
Rule description.Default:
null.array[string]
Destination addresses, address groups, or EDLs. Defaults to any.Default:
[ "any" ].string | null
Panorama device group when location is device-group.Default:
null.boolean
Create the rule disabled.Default:
false.object | null
Additional API-native entry fields, e.g. {“negate-source”: “yes”}.Default:
null.array[string]
Source zones. Defaults to any.Default:
[ "any" ].string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".string | null
Log forwarding profile.Default:
null.string | null
Security profile group to attach.Default:
null.string
Rulebase. Use security on firewalls; pre or post on Panorama, with location shared or device-group. Allowed values: security, pre, post.Default:
"security".array[string]
Services, e.g. application-default or any. Defaults to any.Default:
[ "any" ].array[string]
Source addresses, address groups, or EDLs. Defaults to any.Default:
[ "any" ].array[string]
Source users or groups. Defaults to any.Default:
[ "any" ].array[string] | null
Tags to apply to the rule.Default:
null.array[string]
Destination zones. Defaults to any.Default:
[ "any" ].boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Create tag
Action ID:tools.pan_os.create_tag
Create a tag in the candidate configuration with POST /restapi/{version}/Objects/Tags?name=. Commit to apply the change.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-a-tag-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Tag name.
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Tag color ID, e.g. color1 (red).Default:
null.string | null
Tag comments.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Delete address
Action ID:tools.pan_os.delete_address
Delete a address object from the candidate configuration with DELETE /restapi/{version}/Objects/Addresses?name=. Commit to apply the change.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Name of the address object.
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Delete address group
Action ID:tools.pan_os.delete_address_group
Delete a address group from the candidate configuration with DELETE /restapi/{version}/Objects/AddressGroups?name=. Commit to apply the change.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Name of the address group.
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Delete security rule
Action ID:tools.pan_os.delete_security_rule
Delete a security rule from the candidate configuration with DELETE /restapi/{version}/Policies/${{ “SecurityPreRules” if inputs.rulebase == “pre” else (“SecurityPostRules” if inputs.rulebase == “post” else “SecurityRules”) }}?name=. Commit to apply the change.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Name of the security rule.
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".string
Rulebase. Use security on firewalls; pre or post on Panorama, with location shared or device-group. Allowed values: security, pre, post.Default:
"security".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Disable security rule
Action ID:tools.pan_os.disable_security_rule
Disable a security rule in the candidate configuration. Reads it with GET /restapi/{version}/Policies/SecurityRules?name= and writes it with PUT only when the state changes, so repeated calls are idempotent. Commit to apply the change.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Security rule name.
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".string
Rulebase. Use security on firewalls; pre or post on Panorama, with location shared or device-group. Allowed values: security, pre, post.Default:
"security".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Enable security rule
Action ID:tools.pan_os.enable_security_rule
Enable a security rule in the candidate configuration. Reads it with GET /restapi/{version}/Policies/SecurityRules?name= and writes it with PUT only when the state changes, so repeated calls are idempotent. Commit to apply the change.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Security rule name.
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".string
Rulebase. Use security on firewalls; pre or post on Panorama, with location shared or device-group. Allowed values: security, pre, post.Default:
"security".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Get address
Action ID:tools.pan_os.get_address
Get a address object by name with GET /restapi/{version}/Objects/Addresses?name=.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Name of the address object.
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Get address group
Action ID:tools.pan_os.get_address_group
Get a address group by name with GET /restapi/{version}/Objects/AddressGroups?name=.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Name of the address group.
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Get job
Action ID:tools.pan_os.get_job
Get a job (commit, push, content install) with the XML API operational command show jobs id. Returns normalized status, result, done, and succeeded fields.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Job ID, e.g. the job_id returned by commit.
string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.Get security rule
Action ID:tools.pan_os.get_security_rule
Get a security rule by name with GET /restapi/{version}/Policies/${{ “SecurityPreRules” if inputs.rulebase == “pre” else (“SecurityPostRules” if inputs.rulebase == “post” else “SecurityRules”) }}?name=.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Name of the security rule.
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".string
Rulebase. Use security on firewalls; pre or post on Panorama, with location shared or device-group. Allowed values: security, pre, post.Default:
"security".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Get system info
Action ID:tools.pan_os.get_system_info
Get hostname, model, serial, PAN-OS version, and content versions with the XML API operational command show system info.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Managed firewall serial number when calling through Panorama.Default:
null.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.List address groups
Action ID:tools.pan_os.list_address_groups
List address groups with GET /restapi/{version}/Objects/AddressGroups.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".List addresses
Action ID:tools.pan_os.list_addresses
List address objects with GET /restapi/{version}/Objects/Addresses.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".List device groups
Action ID:tools.pan_os.list_device_groups
List Panorama device groups and their member firewalls with the XML API operational command show devicegroups. Use the names as device_group with location device-group in object and security rule actions, and with commit_all.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.List external dynamic lists
Action ID:tools.pan_os.list_external_dynamic_lists
List external dynamic lists with GET /restapi/{version}/Objects/ExternalDynamicLists.
Reference: https://pan.dev/panos/docs/restapi/
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".List managed firewalls
Action ID:tools.pan_os.list_managed_devices
List firewalls managed by Panorama with the XML API operational command show devices all (or show devices connected). Returns serial, hostname, management IP, model, PAN-OS version, connection state, and the remaining API-native fields for each firewall.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.boolean
Only return firewalls currently connected to Panorama.Default:
false.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.List registered IPs
Action ID:tools.pan_os.list_registered_ips
List IP addresses registered with tags for dynamic address groups with the XML API operational command show object registered-ip, optionally filtered by IP or tag.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Filter by IP address.Default:
null.string | null
Filter by tag.Default:
null.string | null
Managed firewall serial number when calling through Panorama.Default:
null.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string | null
Virtual system on multi-vsys firewalls.Default:
null.List security rules
Action ID:tools.pan_os.list_security_rules
List security rules with GET /restapi/{version}/Policies/${{ “SecurityPreRules” if inputs.rulebase == “pre” else (“SecurityPostRules” if inputs.rulebase == “post” else “SecurityRules”) }}.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".string
Rulebase. Use security on firewalls; pre or post on Panorama, with location shared or device-group. Allowed values: security, pre, post.Default:
"security".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".List tags
Action ID:tools.pan_os.list_tags
List tags with GET /restapi/{version}/Objects/Tags.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-a-tag-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".List template stacks
Action ID:tools.pan_os.list_template_stacks
List Panorama template stacks with the XML API (type=config, action=get) for /config/devices/entry[@name=‘localhost.localdomain’]/template-stack. Returns each name, description, member templates (stacks only), and assigned firewall serial numbers.
Reference: https://docs.paloaltonetworks.com/ngfw/api/pan-os-xml-api-request-types-and-actions/configuration-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.List templates
Action ID:tools.pan_os.list_templates
List Panorama templates with the XML API (type=config, action=get) for /config/devices/entry[@name=‘localhost.localdomain’]/template. Returns each name, description, member templates (stacks only), and assigned firewall serial numbers.
Reference: https://docs.paloaltonetworks.com/ngfw/api/pan-os-xml-api-request-types-and-actions/configuration-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.Move security rule
Action ID:tools.pan_os.move_security_rule
Move a security rule with POST /restapi/{version}/Policies/SecurityRules:move?where=&dst= (SecurityPreRules or SecurityPostRules on Panorama). Commit to apply the change.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Where to move the rule. Allowed values: top, bottom, before, after.
string
required
Security rule name.
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Reference rule name. Required when destination is before or after.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".string
Rulebase. Use security on firewalls; pre or post on Panorama, with location shared or device-group. Allowed values: security, pre, post.Default:
"security".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Push template
Action ID:tools.pan_os.push_template
Push template configuration from Panorama to its firewalls with the XML API (type=commit, action=all, commit-all template). Optionally limit the push to specific firewall serial numbers. Commit on Panorama first. Returns the job ID; use wait_for_job to wait for completion.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/commit-configuration-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Template name.
string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Push description, e.g. the case or incident ID.Default:
null.array[string] | null
Limit the push to these firewall serial numbers.Default:
null.boolean
Overwrite local firewall values with template values.Default:
false.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.Push template stack
Action ID:tools.pan_os.push_template_stack
Push template stack configuration from Panorama to its firewalls with the XML API (type=commit, action=all, commit-all template-stack). Optionally limit the push to specific firewall serial numbers. Commit on Panorama first. Returns the job ID; use wait_for_job to wait for completion.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/commit-configuration-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Template stack name.
string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Push description, e.g. the case or incident ID.Default:
null.array[string] | null
Limit the push to these firewall serial numbers.Default:
null.boolean
Overwrite local firewall values with template values.Default:
false.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.Push to device groups (Panorama)
Action ID:tools.pan_os.commit_all
Push committed Panorama configuration to the firewalls in one or more device groups with the XML API (type=commit, action=all, commit-all shared-policy). Optionally limit the push to specific firewall serial numbers. Commit on Panorama first. Returns the job ID; use wait_for_job to wait for completion.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/commit-configuration-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
array[string]
required
Device groups to push to.
string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Push description, e.g. the case or incident ID.Default:
null.array[string] | null
Limit the push to these firewall serial numbers in each device group.Default:
null.boolean
Overwrite local firewall values with template values.Default:
false.boolean
Also push the template and template stack configuration.Default:
false.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.Query logs
Action ID:tools.pan_os.query_logs
Search firewall or Panorama logs with the XML API log retrieval (type=log). Submits the query, polls the log job until it finishes, and returns the log entries.
Reference: https://pan.dev/panos/docs/xmlapi/
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Log type to search. Allowed values: traffic, threat, url, wildfire, data, auth, decryption, userid, gtp, tunnel, sctp, system, config, hipmatch, globalprotect.
string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string
backward returns newest first. Allowed values: backward, forward.Default:
"backward".integer
Number of logs to return (max 5000).Default:
100.number
Seconds between log job polls.Default:
2.integer
Maximum number of log job polls.Default:
30.string | null
Log filter, e.g. (addr.src in 203.0.113.10) and (severity geq high).Default:
null.integer
Number of logs to skip.Default:
0.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.Refresh external dynamic list
Action ID:tools.pan_os.refresh_external_dynamic_list
Refresh an external dynamic list now instead of waiting for its schedule, with the XML API operational command request system external-list refresh. Use after updating an EDL feed with new indicators.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
External dynamic list name.
string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string
External dynamic list type. Allowed values: ip, domain, url.Default:
"ip".string | null
Managed firewall serial number when calling through Panorama.Default:
null.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string | null
Virtual system on multi-vsys firewalls.Default:
null.Register IP tags
Action ID:tools.pan_os.register_ip_tags
Tag IP addresses with the User-ID XML API (type=user-id, uid-message register) so dynamic address groups that match the tags pick them up without a commit. Set timeout for temporary containment; PAN-OS removes the tag when it expires.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/apply-user-id-mapping-and-populate-dynamic-address-groups-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
array[string]
required
IP addresses to tag.
array[string]
required
Tags to register, e.g. tracecat-block.
string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.boolean
Keep the registration across reboots.Default:
true.string | null
Managed firewall serial number when calling through Panorama.Default:
null.integer | null
Seconds until the tag expires (PAN-OS 9.0 or later). Omit for no expiry.Default:
null.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string | null
Virtual system on multi-vsys firewalls.Default:
null.Remove address group members
Action ID:tools.pan_os.remove_address_group_members
Remove members of a static address group in the candidate configuration. Reads the group with GET /restapi/{version}/Objects/AddressGroups?name= and writes it with PUT only when membership changes, so repeated calls are idempotent. Commit to apply the change.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
array[string]
required
Address objects or address groups.
string
required
Address group name.
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Run operational command
Action ID:tools.pan_os.run_op_command
Run an operational command with the XML API (type=op) and return the parsed response, e.g. <show><session><all><filter><source>203.0.113.10</source></filter></all></session></show>.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Operational command in XML form.
string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Managed firewall serial number when calling through Panorama.Default:
null.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string | null
Virtual system on multi-vsys firewalls.Default:
null.Test security policy match
Action ID:tools.pan_os.test_security_policy_match
Find the security rule that matches a traffic tuple with the XML API operational command test security-policy-match. Use it to confirm a block is effective or to explain why traffic was allowed.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Destination IP address.
string
required
Source IP address.
string | null
Application, e.g. ssl.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.integer | null
Destination port.Default:
null.string | null
Source zone.Default:
null.integer
IP protocol number, e.g. 6 for TCP or 17 for UDP.Default:
6.string | null
Source user.Default:
null.string | null
Managed firewall serial number when calling through Panorama.Default:
null.string | null
Destination zone.Default:
null.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.Unblock FQDN
Action ID:tools.pan_os.unblock_fqdn
Unblock an FQDN blocked with the matching block action. Removes the address object from the static address group with PUT /restapi/{version}/Objects/AddressGroups if it is a member, then deletes the address object with DELETE /restapi/{version}/Objects/Addresses if it exists. Repeated calls are no-ops. Changes stay in the candidate configuration; run commit (and commit_all on Panorama) to enforce them.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Static address group that a deny rule references, e.g. tracecat-blocklist.
string
required
Fully qualified domain name to unblock.
string | null
Address object name to use instead of the generated name.Default:
null.string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.boolean
Delete the address object after removing it from the group. Fails if other rules or groups still reference it.Default:
true.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".string
Prefix for generated address object names.Default:
"tc-block-".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Unblock IP
Action ID:tools.pan_os.unblock_ip
Unblock an IP address or CIDR range blocked with the matching block action. Removes the address object from the static address group with PUT /restapi/{version}/Objects/AddressGroups if it is a member, then deletes the address object with DELETE /restapi/{version}/Objects/Addresses if it exists. Repeated calls are no-ops. Changes stay in the candidate configuration; run commit (and commit_all on Panorama) to enforce them.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Static address group that a deny rule references, e.g. tracecat-blocklist.
string
required
IPv4 or IPv6 address, or CIDR range, to unblock.
string | null
Address object name to use instead of the generated name.Default:
null.string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.boolean
Delete the address object after removing it from the group. Fails if other rules or groups still reference it.Default:
true.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".string
Prefix for generated address object names.Default:
"tc-block-".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Unregister IP tags
Action ID:tools.pan_os.unregister_ip_tags
Remove tags from IP addresses with the User-ID XML API (type=user-id, uid-message unregister), which removes them from dynamic address groups that match the tags.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/apply-user-id-mapping-and-populate-dynamic-address-groups-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
array[string]
required
IP addresses to untag.
array[string]
required
Tags to unregister.
string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Managed firewall serial number when calling through Panorama.Default:
null.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string | null
Virtual system on multi-vsys firewalls.Default:
null.Update address
Action ID:tools.pan_os.update_address
Update a address object in the candidate configuration. Reads it with GET /restapi/{version}/Objects/Addresses?name=, applies only the provided fields, and writes it with PUT. Commit to apply the change.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Name of the address object.
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
New description.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string | null
Fully qualified domain name.Default:
null.string | null
IP address with or without CIDR mask, e.g. 203.0.113.10 or 10.0.0.0/24.Default:
null.string | null
IP range, e.g. 10.0.0.1-10.0.0.20.Default:
null.string | null
IP wildcard mask, e.g. 10.20.1.0/0.0.248.255.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".array[string] | null
Replacement tag list.Default:
null.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Update security rule
Action ID:tools.pan_os.update_security_rule
Update a security rule in the candidate configuration. Reads it with GET /restapi/{version}/Policies/${{ “SecurityPreRules” if inputs.rulebase == “pre” else (“SecurityPostRules” if inputs.rulebase == “post” else “SecurityRules”) }}?name=, applies only the provided fields, and writes it with PUT. Commit to apply the change.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Name of the security rule.
object
required
API-native entry fields to replace, e.g. {“action”: “deny”, “source”: {“member”: [“blocked-ips”]}}.
string | null
PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan_os.api_version, then v11.1.Default:
null.string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.string | null
Panorama device group when location is device-group.Default:
null.string
Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.Default:
"vsys".string
Rulebase. Use security on firewalls; pre or post on Panorama, with location shared or device-group. Allowed values: security, pre, post.Default:
"security".boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.string
Virtual system when location is vsys.Default:
"vsys1".Wait for job
Action ID:tools.pan_os.wait_for_job
Poll a job with the XML API operational command show jobs id until it finishes, then return normalized status, result, done, and succeeded fields. Fails when the job fails, unless raise_on_failure is false, or when it does not finish within poll_max_attempts.
Reference: https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api
Secrets
Required secrets:pan_os: required valuesPANOS_API_KEY.
Input fields
string
required
Job ID, e.g. the job_id returned by commit.
string | null
Firewall or Panorama management URL, e.g. https://fw.example.com. Falls back to the workspace variable pan_os.base_url.Default:
null.number
Seconds between polls.Default:
10.integer
Maximum number of polls.Default:
60.boolean
Fail the action when the job finishes unsuccessfully.Default:
true.boolean
Verify the management TLS certificate. Prefer adding a CA_CERTIFICATE secret over disabling this.Default:
true.