> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tracecat.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Palo Alto Networks (PAN-OS)

> Reference for the Tracecat Palo Alto Networks (PAN-OS) integration: registered actions, required secrets, expected inputs, and example workflow usage.

## Add address group members

Action ID: `tools.pan_os.add_address_group_members`

Add members of a static address group in the candidate configuration. Reads the group with GET /restapi/\{version}/Objects/AddressGroups?name= and writes it with PUT only when membership changes, so repeated calls are idempotent. Commit to apply the change.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="members" type="array[string]" required>
  Address objects or address groups.
</ParamField>

<ParamField path="name" type="string" required>
  Address group name.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Block CIDR

Action ID: `tools.pan_os.block_cidr`

Block a CIDR range by adding an address object to a static address group referenced by a deny rule. Looks up the address object by name, creates it with POST /restapi/\{version}/Objects/Addresses if missing, then adds it to the group with PUT /restapi/\{version}/Objects/AddressGroups if it is not already a member, so repeated calls do not create duplicates. Changes stay in the candidate configuration; run commit (and commit\_all on Panorama) to enforce them. For temporary blocks without a commit, use register\_ip\_tags with a dynamic address group.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="address_group" type="string" required>
  Static address group that a deny rule references, e.g. tracecat-blocklist.
</ParamField>

<ParamField path="value" type="string" required>
  IPv4 or IPv6 network in CIDR notation to block.
</ParamField>

<ParamField path="address_name" type="string | null">
  Address object name to use instead of the generated name.

  Default: `null`.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="description" type="string | null">
  Description for a newly created address object, e.g. the case ID.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="name_prefix" type="string">
  Prefix for generated address object names.

  Default: `"tc-block-"`.
</ParamField>

<ParamField path="tags" type="array[string] | null">
  Tags for a newly created address object.

  Default: `null`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Block FQDN

Action ID: `tools.pan_os.block_fqdn`

Block an FQDN by adding an address object to a static address group referenced by a deny rule. Looks up the address object by name, creates it with POST /restapi/\{version}/Objects/Addresses if missing, then adds it to the group with PUT /restapi/\{version}/Objects/AddressGroups if it is not already a member, so repeated calls do not create duplicates. Changes stay in the candidate configuration; run commit (and commit\_all on Panorama) to enforce them. For temporary blocks without a commit, use register\_ip\_tags with a dynamic address group.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="address_group" type="string" required>
  Static address group that a deny rule references, e.g. tracecat-blocklist.
</ParamField>

<ParamField path="value" type="string" required>
  Fully qualified domain name to block.
</ParamField>

<ParamField path="address_name" type="string | null">
  Address object name to use instead of the generated name.

  Default: `null`.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="description" type="string | null">
  Description for a newly created address object, e.g. the case ID.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="name_prefix" type="string">
  Prefix for generated address object names.

  Default: `"tc-block-"`.
</ParamField>

<ParamField path="tags" type="array[string] | null">
  Tags for a newly created address object.

  Default: `null`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Block IP

Action ID: `tools.pan_os.block_ip`

Block an IP address by adding an address object to a static address group referenced by a deny rule. Looks up the address object by name, creates it with POST /restapi/\{version}/Objects/Addresses if missing, then adds it to the group with PUT /restapi/\{version}/Objects/AddressGroups if it is not already a member, so repeated calls do not create duplicates. Changes stay in the candidate configuration; run commit (and commit\_all on Panorama) to enforce them. For temporary blocks without a commit, use register\_ip\_tags with a dynamic address group.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="address_group" type="string" required>
  Static address group that a deny rule references, e.g. tracecat-blocklist.
</ParamField>

<ParamField path="value" type="string" required>
  IPv4 or IPv6 address to block.
</ParamField>

<ParamField path="address_name" type="string | null">
  Address object name to use instead of the generated name.

  Default: `null`.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="description" type="string | null">
  Description for a newly created address object, e.g. the case ID.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="name_prefix" type="string">
  Prefix for generated address object names.

  Default: `"tc-block-"`.
</ParamField>

<ParamField path="tags" type="array[string] | null">
  Tags for a newly created address object.

  Default: `null`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Commit

Action ID: `tools.pan_os.commit`

Commit the candidate configuration on a firewall or Panorama with the XML API (type=commit). Optionally commit only changes made by specific administrators. Returns the job ID, or no job ID when there is nothing to commit; use wait\_for\_job to wait for completion.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/commit-configuration-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/commit-configuration-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="admins" type="array[string] | null">
  Commit only changes made by these administrators (partial commit).

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="description" type="string | null">
  Commit description, e.g. the case or incident ID.

  Default: `null`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

## Create address

Action ID: `tools.pan_os.create_address`

Create an address object in the candidate configuration with POST /restapi/\{version}/Objects/Addresses?name=. Provide exactly one of ip\_netmask, ip\_range, ip\_wildcard, or fqdn. Commit to apply the change.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="name" type="string" required>
  Address object name (max 63 characters).
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="description" type="string | null">
  Address object description.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="fqdn" type="string | null">
  Fully qualified domain name.

  Default: `null`.
</ParamField>

<ParamField path="ip_netmask" type="string | null">
  IP address with or without CIDR mask, e.g. 203.0.113.10 or 10.0.0.0/24.

  Default: `null`.
</ParamField>

<ParamField path="ip_range" type="string | null">
  IP range, e.g. 10.0.0.1-10.0.0.20.

  Default: `null`.
</ParamField>

<ParamField path="ip_wildcard" type="string | null">
  IP wildcard mask, e.g. 10.20.1.0/0.0.248.255.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="tags" type="array[string] | null">
  Tags to apply. Tags must already exist.

  Default: `null`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Create address group

Action ID: `tools.pan_os.create_address_group`

Create a static or dynamic address group in the candidate configuration with POST /restapi/\{version}/Objects/AddressGroups?name=. Provide exactly one of static\_members or dynamic\_filter. Commit to apply the change.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="name" type="string" required>
  Address group name (max 63 characters).
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="description" type="string | null">
  Address group description.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="dynamic_filter" type="string | null">
  Tag filter for a dynamic address group, e.g. 'tracecat-block'.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="static_members" type="array[string] | null">
  Address objects or groups for a static group.

  Default: `null`.
</ParamField>

<ParamField path="tags" type="array[string] | null">
  Tags to apply to the group.

  Default: `null`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Create security rule

Action ID: `tools.pan_os.create_security_rule`

Create a security rule in the candidate configuration with POST /restapi/\{version}/Policies/SecurityRules?name= (SecurityPreRules or SecurityPostRules on Panorama). The rule is added at the bottom; use move\_security\_rule to place it. Commit to apply the change.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="action" type="string" required>
  Action to take when the rule matches. Allowed values: allow, deny, drop, reset-client, reset-server, reset-both.
</ParamField>

<ParamField path="name" type="string" required>
  Security rule name.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="application" type="array[string]">
  Applications. Defaults to any.

  Default: `[
      "any"
    ]`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="category" type="array[string]">
  URL categories. Defaults to any.

  Default: `[
      "any"
    ]`.
</ParamField>

<ParamField path="description" type="string | null">
  Rule description.

  Default: `null`.
</ParamField>

<ParamField path="destination" type="array[string]">
  Destination addresses, address groups, or EDLs. Defaults to any.

  Default: `[
      "any"
    ]`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="disabled" type="boolean">
  Create the rule disabled.

  Default: `false`.
</ParamField>

<ParamField path="extra_fields" type="object | null">
  Additional API-native entry fields, e.g. \{"negate-source": "yes"}.

  Default: `null`.
</ParamField>

<ParamField path="from_zones" type="array[string]">
  Source zones. Defaults to any.

  Default: `[
      "any"
    ]`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="log_setting" type="string | null">
  Log forwarding profile.

  Default: `null`.
</ParamField>

<ParamField path="profile_group" type="string | null">
  Security profile group to attach.

  Default: `null`.
</ParamField>

<ParamField path="rulebase" type="string">
  Rulebase. Use security on firewalls; pre or post on Panorama, with location shared or device-group. Allowed values: security, pre, post.

  Default: `"security"`.
</ParamField>

<ParamField path="service" type="array[string]">
  Services, e.g. application-default or any. Defaults to any.

  Default: `[
      "any"
    ]`.
</ParamField>

<ParamField path="source" type="array[string]">
  Source addresses, address groups, or EDLs. Defaults to any.

  Default: `[
      "any"
    ]`.
</ParamField>

<ParamField path="source_user" type="array[string]">
  Source users or groups. Defaults to any.

  Default: `[
      "any"
    ]`.
</ParamField>

<ParamField path="tags" type="array[string] | null">
  Tags to apply to the rule.

  Default: `null`.
</ParamField>

<ParamField path="to_zones" type="array[string]">
  Destination zones. Defaults to any.

  Default: `[
      "any"
    ]`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Create tag

Action ID: `tools.pan_os.create_tag`

Create a tag in the candidate configuration with POST /restapi/\{version}/Objects/Tags?name=. Commit to apply the change.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-a-tag-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-a-tag-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="name" type="string" required>
  Tag name.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="color" type="string | null">
  Tag color ID, e.g. color1 (red).

  Default: `null`.
</ParamField>

<ParamField path="comments" type="string | null">
  Tag comments.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Delete address

Action ID: `tools.pan_os.delete_address`

Delete a address object from the candidate configuration with DELETE /restapi/\{version}/Objects/Addresses?name=. Commit to apply the change.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="name" type="string" required>
  Name of the address object.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Delete address group

Action ID: `tools.pan_os.delete_address_group`

Delete a address group from the candidate configuration with DELETE /restapi/\{version}/Objects/AddressGroups?name=. Commit to apply the change.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="name" type="string" required>
  Name of the address group.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Delete security rule

Action ID: `tools.pan_os.delete_security_rule`

Delete a security rule from the candidate configuration with DELETE /restapi/\{version}/Policies/\$\{\{ "SecurityPreRules" if inputs.rulebase == "pre" else ("SecurityPostRules" if inputs.rulebase == "post" else "SecurityRules") }}?name=. Commit to apply the change.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="name" type="string" required>
  Name of the security rule.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="rulebase" type="string">
  Rulebase. Use security on firewalls; pre or post on Panorama, with location shared or device-group. Allowed values: security, pre, post.

  Default: `"security"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Disable security rule

Action ID: `tools.pan_os.disable_security_rule`

Disable a security rule in the candidate configuration. Reads it with GET /restapi/\{version}/Policies/SecurityRules?name= and writes it with PUT only when the state changes, so repeated calls are idempotent. Commit to apply the change.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="name" type="string" required>
  Security rule name.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="rulebase" type="string">
  Rulebase. Use security on firewalls; pre or post on Panorama, with location shared or device-group. Allowed values: security, pre, post.

  Default: `"security"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Enable security rule

Action ID: `tools.pan_os.enable_security_rule`

Enable a security rule in the candidate configuration. Reads it with GET /restapi/\{version}/Policies/SecurityRules?name= and writes it with PUT only when the state changes, so repeated calls are idempotent. Commit to apply the change.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="name" type="string" required>
  Security rule name.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="rulebase" type="string">
  Rulebase. Use security on firewalls; pre or post on Panorama, with location shared or device-group. Allowed values: security, pre, post.

  Default: `"security"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Get address

Action ID: `tools.pan_os.get_address`

Get a address object by name with GET /restapi/\{version}/Objects/Addresses?name=.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="name" type="string" required>
  Name of the address object.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Get address group

Action ID: `tools.pan_os.get_address_group`

Get a address group by name with GET /restapi/\{version}/Objects/AddressGroups?name=.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="name" type="string" required>
  Name of the address group.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Get job

Action ID: `tools.pan_os.get_job`

Get a job (commit, push, content install) with the XML API operational command show jobs id. Returns normalized status, result, done, and succeeded fields.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="job_id" type="string" required>
  Job ID, e.g. the job\_id returned by commit.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

## Get security rule

Action ID: `tools.pan_os.get_security_rule`

Get a security rule by name with GET /restapi/\{version}/Policies/\$\{\{ "SecurityPreRules" if inputs.rulebase == "pre" else ("SecurityPostRules" if inputs.rulebase == "post" else "SecurityRules") }}?name=.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="name" type="string" required>
  Name of the security rule.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="rulebase" type="string">
  Rulebase. Use security on firewalls; pre or post on Panorama, with location shared or device-group. Allowed values: security, pre, post.

  Default: `"security"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Get system info

Action ID: `tools.pan_os.get_system_info`

Get hostname, model, serial, PAN-OS version, and content versions with the XML API operational command show system info.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="target" type="string | null">
  Managed firewall serial number when calling through Panorama.

  Default: `null`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

## List address groups

Action ID: `tools.pan_os.list_address_groups`

List address groups with GET /restapi/\{version}/Objects/AddressGroups.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## List addresses

Action ID: `tools.pan_os.list_addresses`

List address objects with GET /restapi/\{version}/Objects/Addresses.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## List device groups

Action ID: `tools.pan_os.list_device_groups`

List Panorama device groups and their member firewalls with the XML API operational command show devicegroups. Use the names as device\_group with location device-group in object and security rule actions, and with commit\_all.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

## List external dynamic lists

Action ID: `tools.pan_os.list_external_dynamic_lists`

List external dynamic lists with GET /restapi/\{version}/Objects/ExternalDynamicLists.

Reference: [https://pan.dev/panos/docs/restapi/](https://pan.dev/panos/docs/restapi/)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## List managed firewalls

Action ID: `tools.pan_os.list_managed_devices`

List firewalls managed by Panorama with the XML API operational command show devices all (or show devices connected). Returns serial, hostname, management IP, model, PAN-OS version, connection state, and the remaining API-native fields for each firewall.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="connected_only" type="boolean">
  Only return firewalls currently connected to Panorama.

  Default: `false`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

## List registered IPs

Action ID: `tools.pan_os.list_registered_ips`

List IP addresses registered with tags for dynamic address groups with the XML API operational command show object registered-ip, optionally filtered by IP or tag.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="ip" type="string | null">
  Filter by IP address.

  Default: `null`.
</ParamField>

<ParamField path="tag" type="string | null">
  Filter by tag.

  Default: `null`.
</ParamField>

<ParamField path="target" type="string | null">
  Managed firewall serial number when calling through Panorama.

  Default: `null`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string | null">
  Virtual system on multi-vsys firewalls.

  Default: `null`.
</ParamField>

## List security rules

Action ID: `tools.pan_os.list_security_rules`

List security rules with GET /restapi/\{version}/Policies/\$\{\{ "SecurityPreRules" if inputs.rulebase == "pre" else ("SecurityPostRules" if inputs.rulebase == "post" else "SecurityRules") }}.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="rulebase" type="string">
  Rulebase. Use security on firewalls; pre or post on Panorama, with location shared or device-group. Allowed values: security, pre, post.

  Default: `"security"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## List tags

Action ID: `tools.pan_os.list_tags`

List tags with GET /restapi/\{version}/Objects/Tags.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-a-tag-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-a-tag-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## List template stacks

Action ID: `tools.pan_os.list_template_stacks`

List Panorama template stacks with the XML API (type=config, action=get) for /config/devices/entry\[@name='localhost.localdomain']/template-stack. Returns each name, description, member templates (stacks only), and assigned firewall serial numbers.

Reference: [https://docs.paloaltonetworks.com/ngfw/api/pan-os-xml-api-request-types-and-actions/configuration-api](https://docs.paloaltonetworks.com/ngfw/api/pan-os-xml-api-request-types-and-actions/configuration-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

## List templates

Action ID: `tools.pan_os.list_templates`

List Panorama templates with the XML API (type=config, action=get) for /config/devices/entry\[@name='localhost.localdomain']/template. Returns each name, description, member templates (stacks only), and assigned firewall serial numbers.

Reference: [https://docs.paloaltonetworks.com/ngfw/api/pan-os-xml-api-request-types-and-actions/configuration-api](https://docs.paloaltonetworks.com/ngfw/api/pan-os-xml-api-request-types-and-actions/configuration-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

## Move security rule

Action ID: `tools.pan_os.move_security_rule`

Move a security rule with POST /restapi/\{version}/Policies/SecurityRules:move?where=\&dst= (SecurityPreRules or SecurityPostRules on Panorama). Commit to apply the change.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="destination" type="string" required>
  Where to move the rule. Allowed values: top, bottom, before, after.
</ParamField>

<ParamField path="name" type="string" required>
  Security rule name.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="destination_rule" type="string | null">
  Reference rule name. Required when destination is before or after.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="rulebase" type="string">
  Rulebase. Use security on firewalls; pre or post on Panorama, with location shared or device-group. Allowed values: security, pre, post.

  Default: `"security"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Push template

Action ID: `tools.pan_os.push_template`

Push template configuration from Panorama to its firewalls with the XML API (type=commit, action=all, commit-all template). Optionally limit the push to specific firewall serial numbers. Commit on Panorama first. Returns the job ID; use wait\_for\_job to wait for completion.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/commit-configuration-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/commit-configuration-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="name" type="string" required>
  Template name.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="description" type="string | null">
  Push description, e.g. the case or incident ID.

  Default: `null`.
</ParamField>

<ParamField path="devices" type="array[string] | null">
  Limit the push to these firewall serial numbers.

  Default: `null`.
</ParamField>

<ParamField path="force_template_values" type="boolean">
  Overwrite local firewall values with template values.

  Default: `false`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

## Push template stack

Action ID: `tools.pan_os.push_template_stack`

Push template stack configuration from Panorama to its firewalls with the XML API (type=commit, action=all, commit-all template-stack). Optionally limit the push to specific firewall serial numbers. Commit on Panorama first. Returns the job ID; use wait\_for\_job to wait for completion.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/commit-configuration-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/commit-configuration-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="name" type="string" required>
  Template stack name.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="description" type="string | null">
  Push description, e.g. the case or incident ID.

  Default: `null`.
</ParamField>

<ParamField path="devices" type="array[string] | null">
  Limit the push to these firewall serial numbers.

  Default: `null`.
</ParamField>

<ParamField path="force_template_values" type="boolean">
  Overwrite local firewall values with template values.

  Default: `false`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

## Push to device groups (Panorama)

Action ID: `tools.pan_os.commit_all`

Push committed Panorama configuration to the firewalls in one or more device groups with the XML API (type=commit, action=all, commit-all shared-policy). Optionally limit the push to specific firewall serial numbers. Commit on Panorama first. Returns the job ID; use wait\_for\_job to wait for completion.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/commit-configuration-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/commit-configuration-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="device_groups" type="array[string]" required>
  Device groups to push to.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="description" type="string | null">
  Push description, e.g. the case or incident ID.

  Default: `null`.
</ParamField>

<ParamField path="devices" type="array[string] | null">
  Limit the push to these firewall serial numbers in each device group.

  Default: `null`.
</ParamField>

<ParamField path="force_template_values" type="boolean">
  Overwrite local firewall values with template values.

  Default: `false`.
</ParamField>

<ParamField path="include_template" type="boolean">
  Also push the template and template stack configuration.

  Default: `false`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

## Query logs

Action ID: `tools.pan_os.query_logs`

Search firewall or Panorama logs with the XML API log retrieval (type=log). Submits the query, polls the log job until it finishes, and returns the log entries.

Reference: [https://pan.dev/panos/docs/xmlapi/](https://pan.dev/panos/docs/xmlapi/)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="log_type" type="string" required>
  Log type to search. Allowed values: traffic, threat, url, wildfire, data, auth, decryption, userid, gtp, tunnel, sctp, system, config, hipmatch, globalprotect.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="direction" type="string">
  backward returns newest first. Allowed values: backward, forward.

  Default: `"backward"`.
</ParamField>

<ParamField path="nlogs" type="integer">
  Number of logs to return (max 5000).

  Default: `100`.
</ParamField>

<ParamField path="poll_interval" type="number">
  Seconds between log job polls.

  Default: `2`.
</ParamField>

<ParamField path="poll_max_attempts" type="integer">
  Maximum number of log job polls.

  Default: `30`.
</ParamField>

<ParamField path="query" type="string | null">
  Log filter, e.g. (addr.src in 203.0.113.10) and (severity geq high).

  Default: `null`.
</ParamField>

<ParamField path="skip" type="integer">
  Number of logs to skip.

  Default: `0`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

## Refresh external dynamic list

Action ID: `tools.pan_os.refresh_external_dynamic_list`

Refresh an external dynamic list now instead of waiting for its schedule, with the XML API operational command request system external-list refresh. Use after updating an EDL feed with new indicators.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="name" type="string" required>
  External dynamic list name.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="list_type" type="string">
  External dynamic list type. Allowed values: ip, domain, url.

  Default: `"ip"`.
</ParamField>

<ParamField path="target" type="string | null">
  Managed firewall serial number when calling through Panorama.

  Default: `null`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string | null">
  Virtual system on multi-vsys firewalls.

  Default: `null`.
</ParamField>

## Register IP tags

Action ID: `tools.pan_os.register_ip_tags`

Tag IP addresses with the User-ID XML API (type=user-id, uid-message register) so dynamic address groups that match the tags pick them up without a commit. Set timeout for temporary containment; PAN-OS removes the tag when it expires.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/apply-user-id-mapping-and-populate-dynamic-address-groups-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/apply-user-id-mapping-and-populate-dynamic-address-groups-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="ips" type="array[string]" required>
  IP addresses to tag.
</ParamField>

<ParamField path="tags" type="array[string]" required>
  Tags to register, e.g. tracecat-block.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="persistent" type="boolean">
  Keep the registration across reboots.

  Default: `true`.
</ParamField>

<ParamField path="target" type="string | null">
  Managed firewall serial number when calling through Panorama.

  Default: `null`.
</ParamField>

<ParamField path="timeout" type="integer | null">
  Seconds until the tag expires (PAN-OS 9.0 or later). Omit for no expiry.

  Default: `null`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string | null">
  Virtual system on multi-vsys firewalls.

  Default: `null`.
</ParamField>

## Remove address group members

Action ID: `tools.pan_os.remove_address_group_members`

Remove members of a static address group in the candidate configuration. Reads the group with GET /restapi/\{version}/Objects/AddressGroups?name= and writes it with PUT only when membership changes, so repeated calls are idempotent. Commit to apply the change.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="members" type="array[string]" required>
  Address objects or address groups.
</ParamField>

<ParamField path="name" type="string" required>
  Address group name.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Run operational command

Action ID: `tools.pan_os.run_op_command`

Run an operational command with the XML API (type=op) and return the parsed response, e.g. \<show>\<session>\<all>\<filter>\<source>203.0.113.10\</source>\</filter>\</all>\</session>\</show>.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="cmd" type="string" required>
  Operational command in XML form.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="target" type="string | null">
  Managed firewall serial number when calling through Panorama.

  Default: `null`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string | null">
  Virtual system on multi-vsys firewalls.

  Default: `null`.
</ParamField>

## Test security policy match

Action ID: `tools.pan_os.test_security_policy_match`

Find the security rule that matches a traffic tuple with the XML API operational command test security-policy-match. Use it to confirm a block is effective or to explain why traffic was allowed.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="destination" type="string" required>
  Destination IP address.
</ParamField>

<ParamField path="source" type="string" required>
  Source IP address.
</ParamField>

<ParamField path="application" type="string | null">
  Application, e.g. ssl.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="destination_port" type="integer | null">
  Destination port.

  Default: `null`.
</ParamField>

<ParamField path="from_zone" type="string | null">
  Source zone.

  Default: `null`.
</ParamField>

<ParamField path="protocol" type="integer">
  IP protocol number, e.g. 6 for TCP or 17 for UDP.

  Default: `6`.
</ParamField>

<ParamField path="source_user" type="string | null">
  Source user.

  Default: `null`.
</ParamField>

<ParamField path="target" type="string | null">
  Managed firewall serial number when calling through Panorama.

  Default: `null`.
</ParamField>

<ParamField path="to_zone" type="string | null">
  Destination zone.

  Default: `null`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

## Unblock FQDN

Action ID: `tools.pan_os.unblock_fqdn`

Unblock an FQDN blocked with the matching block action. Removes the address object from the static address group with PUT /restapi/\{version}/Objects/AddressGroups if it is a member, then deletes the address object with DELETE /restapi/\{version}/Objects/Addresses if it exists. Repeated calls are no-ops. Changes stay in the candidate configuration; run commit (and commit\_all on Panorama) to enforce them.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="address_group" type="string" required>
  Static address group that a deny rule references, e.g. tracecat-blocklist.
</ParamField>

<ParamField path="value" type="string" required>
  Fully qualified domain name to unblock.
</ParamField>

<ParamField path="address_name" type="string | null">
  Address object name to use instead of the generated name.

  Default: `null`.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="delete_address" type="boolean">
  Delete the address object after removing it from the group. Fails if other rules or groups still reference it.

  Default: `true`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="name_prefix" type="string">
  Prefix for generated address object names.

  Default: `"tc-block-"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Unblock IP

Action ID: `tools.pan_os.unblock_ip`

Unblock an IP address or CIDR range blocked with the matching block action. Removes the address object from the static address group with PUT /restapi/\{version}/Objects/AddressGroups if it is a member, then deletes the address object with DELETE /restapi/\{version}/Objects/Addresses if it exists. Repeated calls are no-ops. Changes stay in the candidate configuration; run commit (and commit\_all on Panorama) to enforce them.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="address_group" type="string" required>
  Static address group that a deny rule references, e.g. tracecat-blocklist.
</ParamField>

<ParamField path="value" type="string" required>
  IPv4 or IPv6 address, or CIDR range, to unblock.
</ParamField>

<ParamField path="address_name" type="string | null">
  Address object name to use instead of the generated name.

  Default: `null`.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="delete_address" type="boolean">
  Delete the address object after removing it from the group. Fails if other rules or groups still reference it.

  Default: `true`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="name_prefix" type="string">
  Prefix for generated address object names.

  Default: `"tc-block-"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Unregister IP tags

Action ID: `tools.pan_os.unregister_ip_tags`

Remove tags from IP addresses with the User-ID XML API (type=user-id, uid-message unregister), which removes them from dynamic address groups that match the tags.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/apply-user-id-mapping-and-populate-dynamic-address-groups-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/apply-user-id-mapping-and-populate-dynamic-address-groups-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="ips" type="array[string]" required>
  IP addresses to untag.
</ParamField>

<ParamField path="tags" type="array[string]" required>
  Tags to unregister.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="target" type="string | null">
  Managed firewall serial number when calling through Panorama.

  Default: `null`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string | null">
  Virtual system on multi-vsys firewalls.

  Default: `null`.
</ParamField>

## Update address

Action ID: `tools.pan_os.update_address`

Update a address object in the candidate configuration. Reads it with GET /restapi/\{version}/Objects/Addresses?name=, applies only the provided fields, and writes it with PUT. Commit to apply the change.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="name" type="string" required>
  Name of the address object.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="description" type="string | null">
  New description.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="fqdn" type="string | null">
  Fully qualified domain name.

  Default: `null`.
</ParamField>

<ParamField path="ip_netmask" type="string | null">
  IP address with or without CIDR mask, e.g. 203.0.113.10 or 10.0.0.0/24.

  Default: `null`.
</ParamField>

<ParamField path="ip_range" type="string | null">
  IP range, e.g. 10.0.0.1-10.0.0.20.

  Default: `null`.
</ParamField>

<ParamField path="ip_wildcard" type="string | null">
  IP wildcard mask, e.g. 10.20.1.0/0.0.248.255.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="tags" type="array[string] | null">
  Replacement tag list.

  Default: `null`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Update security rule

Action ID: `tools.pan_os.update_security_rule`

Update a security rule in the candidate configuration. Reads it with GET /restapi/\{version}/Policies/\$\{\{ "SecurityPreRules" if inputs.rulebase == "pre" else ("SecurityPostRules" if inputs.rulebase == "post" else "SecurityRules") }}?name=, applies only the provided fields, and writes it with PUT. Commit to apply the change.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/create-security-policy-rule-rest-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="name" type="string" required>
  Name of the security rule.
</ParamField>

<ParamField path="updates" type="object" required>
  API-native entry fields to replace, e.g. \{"action": "deny", "source": \{"member": \["blocked-ips"]}}.
</ParamField>

<ParamField path="api_version" type="string | null">
  PAN-OS REST API version, e.g. v11.1 or v10.2. Falls back to the workspace variable pan\_os.api\_version, then v11.1.

  Default: `null`.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="device_group" type="string | null">
  Panorama device group when location is device-group.

  Default: `null`.
</ParamField>

<ParamField path="location" type="string">
  Configuration location. Use vsys on firewalls, device-group or shared on Panorama. Allowed values: vsys, shared, device-group.

  Default: `"vsys"`.
</ParamField>

<ParamField path="rulebase" type="string">
  Rulebase. Use security on firewalls; pre or post on Panorama, with location shared or device-group. Allowed values: security, pre, post.

  Default: `"security"`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>

<ParamField path="vsys" type="string">
  Virtual system when location is vsys.

  Default: `"vsys1"`.
</ParamField>

## Wait for job

Action ID: `tools.pan_os.wait_for_job`

Poll a job with the XML API operational command show jobs id until it finishes, then return normalized status, result, done, and succeeded fields. Fails when the job fails, unless raise\_on\_failure is false, or when it does not finish within poll\_max\_attempts.

Reference: [https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api](https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-panorama-api/pan-os-xml-api-request-types/run-operational-mode-commands-api)

### Secrets

Required secrets:

* `pan_os`: required values `PANOS_API_KEY`.

### Input fields

<ParamField path="job_id" type="string" required>
  Job ID, e.g. the job\_id returned by commit.
</ParamField>

<ParamField path="base_url" type="string | null">
  Firewall or Panorama management URL, e.g. [https://fw.example.com](https://fw.example.com). Falls back to the workspace variable pan\_os.base\_url.

  Default: `null`.
</ParamField>

<ParamField path="poll_interval" type="number">
  Seconds between polls.

  Default: `10`.
</ParamField>

<ParamField path="poll_max_attempts" type="integer">
  Maximum number of polls.

  Default: `60`.
</ParamField>

<ParamField path="raise_on_failure" type="boolean">
  Fail the action when the job finishes unsuccessfully.

  Default: `true`.
</ParamField>

<ParamField path="verify_ssl" type="boolean">
  Verify the management TLS certificate. Prefer adding a CA\_CERTIFICATE secret over disabling this.

  Default: `true`.
</ParamField>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.