Skip to main content

Create policy

Action ID: tools.pan_prisma.create_policy Add a custom policy. Calls POST /policy directly. Reference: https://pan.dev/prisma-cloud/api/cspm/add-policy/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string
required
Policy name.
string
required
Policy type, e.g. config, network, audit_event or iam. Policy type anomaly is read-only.
object
required
Policy rule. Uses criteria (a saved search ID), name, parameters and type, e.g. {“criteria”: “<saved-search-id>”, “name”: “my rule”, “parameters”: {“savedSearch”: “true”}, “type”: “Config”}.
string
required
Policy severity, e.g. low, medium or high.
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.
string | null
Cloud type. Required for config policies; other policy types default to ALL. Allowed values: ALL, AWS, AZURE, GCP, ALIBABA_CLOUD, OCI, IBM.Default: null.
array[object] | null
Compliance standard, requirement and section mappings.Default: null.
string | null
Policy description.Default: null.
boolean | null
Whether the policy is enabled. Prisma Cloud defaults to true.Default: null.
array[string] | null
Policy labels.Default: null.
string | null
Remediation recommendation.Default: null.
object | null
Remediation details, e.g. cliScriptTemplate and description.Default: null.

Delete policy

Action ID: tools.pan_prisma.delete_policy Delete a policy. Calls DELETE /policy/{id} directly. Reference: https://pan.dev/prisma-cloud/api/cspm/delete-policy/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string
required
Policy ID.
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.

Dismiss or snooze alerts

Action ID: tools.pan_prisma.dismiss_alerts Dismisses one or more alerts on the Prisma Cloud platform. If the caller specifies a dismissal time range, then alerts will snooze for that time period rather than be dismissed. Calls POST /alert/dismiss directly. Reference: https://pan.dev/prisma-cloud/api/cspm/dismiss-alerts/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string
required
Reason for dismissal.
object
required
Filter to narrow the alerts. filter.timeRange is required, e.g. {“timeRange”: {“type”: “to_now”, “value”: “epoch”}}. Can also include filters, a list of name/operator/value objects.
array[string] | null
Alert IDs.Default: null.
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.
object | null
Dismissal time range. Set this to snooze instead of dismiss, e.g. {“type”: “relative”, “value”: {“amount”: 7, “unit”: “day”}}.Default: null.
array[string] | null
Policy IDs.Default: null.

Get alert

Action ID: tools.pan_prisma.get_alert Returns information about an alert for the specified ID. Calls GET /alert/{id} directly. Reference: https://pan.dev/prisma-cloud/api/cspm/get-alert/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string
required
Alert ID.
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.
boolean | null
true = Return detailed alert data. Default is false.Default: null.

Get alert count by status

Action ID: tools.pan_prisma.get_alert_count Returns an alert count for the specified status. Calls GET /alert/count/{status} directly. Reference: https://pan.dev/prisma-cloud/api/cspm/get-alert-count/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string
required
Alert status: open, dismissed, snoozed, resolved or pending_resolution.
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.

Get alert evidence graph

Action ID: tools.pan_prisma.get_alert_evidence_graph Given an alert ID, returns the data that can be presented in a graphical format. The returned response matches the JSON Graph Format standard. Calls GET /alert/v1/{id}/graph directly. Reference: https://pan.dev/prisma-cloud/api/cspm/get-alert-evidence-graph/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string
required
The alert ID for the evidence graph.
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.

Get alert remediation commands

Action ID: tools.pan_prisma.get_alert_remediation_commands Generates and returns a list of remediation commands for the specified alerts and policies. Data returned for a successful call include fully constructed commands for remediation. Calls POST /alert/remediation directly. Reference: https://pan.dev/prisma-cloud/api/cspm/get-alerts-remediation/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

object
required
Filter to narrow or manage the search. filter.timeRange.type and filter.timeRange.value are required; other filter parameters are ignored, e.g. {“timeRange”: {“type”: “to_now”, “value”: “epoch”}}.
array[string] | null
List of alert IDs. One or more alert IDs associated with a single policy are required if no policies are specified. If a policy is specified, then all the alerts specified must belong to that policy.Default: null.
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.
array[string] | null
List of policy IDs. A single policy ID is required if no alerts are specified.Default: null.

Get asset

Action ID: tools.pan_prisma.get_asset Returns details for a unified asset, selected by the type of data to query (e.g. asset, alerts, findings, vulnerabilities, network, timeline, raw_config). Calls POST /uai/v1/asset directly. Reference: https://pan.dev/prisma-cloud/api/cspm/get-asset-details-by-id/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string
required
Unified Asset ID or RRN (Restricted Resource Name).
string
required
Asset Domain Service query type, e.g. asset, asset_lite, alerts, alert_summary, findings, vulnerabilities, network, timeline, raw_config, relationships, permissions, attack_path.
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.
integer | null
Limit number of records.Default: null.
string | null
Next page token.Default: null.

Get asset inventory

Action ID: tools.pan_prisma.get_asset_inventory Returns asset inventory pass/fail data. Calls POST /v3/inventory directly. Reference: https://pan.dev/prisma-cloud/api/cspm/post-method-for-asset-inventory-v-3/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.
array[object] | null
Filtering parameters as a list of {“name”: …, “operator”: ”=”, “value”: …} objects. For filter names and values, see the corresponding List Filters and filter suggestion APIs.Default: null.
array[string] | null
Group returned items by cloud.type, cloud.service, cloud.region, cloud.account, and/or resource.type.Default: null.
integer | null
Maximum number of items to return. When data is paginated, maximum number of items per page. The maximum cannot exceed 10,000.Default: null.
integer | null
The number of items to skip before selecting items to return. Default is zero.Default: null.
string | null
Set to the nextPageToken from a response to return the next page of data.Default: null.
array[string] | null
Sort properties. Append :asc or :desc to the key, e.g. id:asc.Default: null.

Get next config search page

Action ID: tools.pan_prisma.get_config_search_page Returns the next page of config search results, using the nextPageToken from the previous page. Calls POST /search/config/page directly. Reference: https://pan.dev/prisma-cloud/api/cspm/search-config-page/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string
required
Page token (nextPageToken from the previous response).
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.
integer | null
Results per page.Default: null.
boolean | null
true = include resource JSON.Default: null.

Get next event search page

Action ID: tools.pan_prisma.get_event_search_page Returns the next page of event search results, using the data.nextPageToken from the previous page. Calls POST /search/event/page directly. Reference: https://pan.dev/prisma-cloud/api/cspm/search-events-page/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string
required
Page token (data.nextPageToken from the previous response).
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.
integer | null
Results per page.Default: null.

Get policy

Action ID: tools.pan_prisma.get_policy Returns the policy that has the specified policy ID. Calls GET /policy/{id} directly. Reference: https://pan.dev/prisma-cloud/api/cspm/get-policy/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string
required
Policy ID.
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.

Get resource scan info

Action ID: tools.pan_prisma.get_resource_scan_info Returns a full breakdown of passed/failed statistics and associated policies for resources. Calls POST /v2/resource/scan_info directly. Reference: https://pan.dev/prisma-cloud/api/cspm/post-resource-scan-info-v-2/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.
array[object] | null
Filtering parameters as a list of {“name”: …, “operator”: ”=”, “value”: …} objects. For filter names and values, see the corresponding List Filters and filter suggestion APIs.Default: null.
integer | null
Maximum number of items to return. When data is paginated, maximum number of items per page. The maximum cannot exceed 10,000.Default: null.
integer | null
The number of items to skip before selecting items to return. Default is zero.Default: null.
string | null
Set to the nextPageToken from a response to return the next page of data.Default: null.
array[string] | null
Sort properties. Append :asc or :desc to the key, e.g. id:asc.Default: null.

List alerts for resource

Action ID: tools.pan_prisma.list_resource_alerts Get a list of alerts associated with a given resource. Calls POST /resource/alert directly. Reference: https://pan.dev/prisma-cloud/api/cspm/get-alerts-for-resource/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string
required
Restricted Resource Name, e.g. rrn::storageBucket:us-east-1:123456789012:test-bucket.
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.

List policies

Action ID: tools.pan_prisma.list_policies Returns all available policies, both system default and custom. Apply filters to narrow the returned policy list. Calls GET /v2/policy directly. Reference: https://pan.dev/prisma-cloud/api/cspm/get-policies-v-2/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.
string | null
Cloud type (cloud.type), e.g. aws, azure, gcp.Default: null.
string | null
Policy compliance standard name (policy.complianceStandard).Default: null.
string | null
Policy enabled (policy.enabled): true or false.Default: null.
string | null
Policy label (policy.label).Default: null.
string | null
Policy name (policy.name).Default: null.
string | null
Policy mode (policy.policyMode): custom or redlock_default.Default: null.
string | null
Policy is remediable (policy.remediable): true or false.Default: null.
string | null
Policy severity (policy.severity): critical, high, medium, low or informational.Default: null.
string | null
Policy subtype (policy.subtype), e.g. run, build, audit, network_event, ueba.Default: null.
string | null
Policy type (policy.type): config, network or audit_event.Default: null.

Remediate alert

Action ID: tools.pan_prisma.remediate_alert Remediates the alert with the specified ID if that alert is associated with a remediable policy. Calls PATCH /alert/remediation/{id} directly. Reference: https://pan.dev/prisma-cloud/api/cspm/perform-remediation-for-alert/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string
required
Alert ID.
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.
string | null
Finding ID.Default: null.

Reopen alerts

Action ID: tools.pan_prisma.reopen_alerts Sets the status of one or more dismissed or snoozed alerts on the Prisma Cloud platform to open. Calls POST /alert/reopen directly. Reference: https://pan.dev/prisma-cloud/api/cspm/reopen-alerts/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

object
required
Filter to narrow the alerts. filter.timeRange is required, e.g. {“timeRange”: {“type”: “to_now”, “value”: “epoch”}}. Can also include filters, a list of name/operator/value objects.
array[string] | null
Alert IDs.Default: null.
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.
array[string] | null
Policy IDs.Default: null.

Search alerts

Action ID: tools.pan_prisma.search_alerts Returns a paginated list of alerts that matches the constraints specified in the body parameters. Calls POST /v2/alert directly. Reference: https://pan.dev/prisma-cloud/api/cspm/post-alerts-v-2/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.
boolean | null
true = Return detailed alert data. Default is false.Default: null.
array[string] | null
Specific fields to return, e.g. alert.id, alert.status, alert.time, cloud.account, cloud.accountId, cloud.region, resource.id, resource.name, policy.name, policy.type, policy.severity.Default: null.
array[object] | null
Filtering parameters as a list of {“name”: …, “operator”: ”=”, “value”: …} objects. For filter names and values, see the corresponding List Filters and filter suggestion APIs. Common names include alert.status, alert.id, policy.severity, policy.name, cloud.account and resource.id.Default: null.
integer | null
Maximum number of items to return. When data is paginated, maximum number of items per page.Default: null.
string | null
Set to the nextPageToken from a previous response to return the next page of data.Default: null.
array[string] | null
Sort properties. Append :asc or :desc to the key, e.g. alertTime:desc. Valid keys are listed in the response’s sortAllowedColumns.Default: null.
object | null
Time range object, see the Prisma Cloud Time Range Model. Examples: {“type”: “relative”, “value”: {“amount”: 24, “unit”: “hour”}}, {“type”: “to_now”, “value”: “epoch”}, or {“type”: “absolute”, “value”: {“startTime”: 1700000000000, “endTime”: 1700086400000}}.Default: null.

Search audit events (RQL)

Action ID: tools.pan_prisma.search_events Returns the results of an RQL audit event query. Use event queries to detect and investigate console and API access, monitor privileged activities, and detect account compromise and unusual user behavior. Calls POST /search/event directly. Reference: https://pan.dev/prisma-cloud/api/cspm/search-events/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string
required
RQL query, e.g. event from cloud.audit_logs where operation = ‘ConsoleLogin’.
object
required
Time range object, see the Prisma Cloud Time Range Model. Examples: {“type”: “relative”, “value”: {“amount”: 24, “unit”: “hour”}}, {“type”: “to_now”, “value”: “epoch”}, or {“type”: “absolute”, “value”: {“startTime”: 1700000000000, “endTime”: 1700086400000}}.
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.
integer | null
Limit.Default: null.
array[object] | null
Sort fields, e.g. [{“field”: “time”, “direction”: “desc”}].Default: null.

Search config (RQL)

Action ID: tools.pan_prisma.search_config Returns the results of an RQL config query. Use config queries to retrieve resource information, identify misconfigurations, and uncover policy and compliance violations. Calls POST /search/api/v2/config directly. Reference: https://pan.dev/prisma-cloud/api/cspm/search-config-v-2/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string
required
RQL query, e.g. config from cloud.resource where api.name = ‘aws-ec2-describe-instances’.
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.
integer | null
Results per page. The maximum number of results is 100 items; use get_config_search_page with nextPageToken for more.Default: null.
array[object] | null
Sort field data, e.g. [{“field”: “insertTs”, “direction”: “desc”}].Default: null.
integer | null
Start time for the search in epoch milliseconds. The end time is the current system time.Default: null.
boolean | null
true = include resource JSON. Default is false.Default: null.

Search network (RQL)

Action ID: tools.pan_prisma.search_network Perform a search against flow logs with an RQL query. Calls POST /search directly. Reference: https://pan.dev/prisma-cloud/api/cspm/search-network/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string
required
RQL query, e.g. network from vpc.flow_record where dest.publicnetwork IN (‘Suspicious IPs’).
object
required
Time range object, see the Prisma Cloud Time Range Model. Examples: {“type”: “relative”, “value”: {“amount”: 24, “unit”: “hour”}}, {“type”: “to_now”, “value”: “epoch”}, or {“type”: “absolute”, “value”: {“startTime”: 1700000000000, “endTime”: 1700086400000}}.
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.
string | null
Cloud type: aws, azure, gcp, alibaba_cloud or oci.Default: null.

Update policy

Action ID: tools.pan_prisma.update_policy Update an existing policy. Calls PUT /policy/{id} directly. Reference: https://pan.dev/prisma-cloud/api/cspm/update-policy/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

string
required
Policy ID.
object
required
API-native request body containing only the fields to change; omitted fields keep their current values. Documented fields for PUT /policy/{id}: name, policyType, severity, rule, cloudType, description, recommendation, labels, enabled, complianceMetadata, remediation, findingTypes.
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.

Update policy status

Action ID: tools.pan_prisma.update_policy_status Enable or disable a policy. Calls PATCH /policy/{id}/status/{enabled} directly. Reference: https://pan.dev/prisma-cloud/api/cspm/update-policy-status/

Secrets

Required secrets:
  • pan_prisma: required values PRISMA_ACCESS_KEY_ID, PRISMA_SECRET_KEY.

Input fields

boolean
required
Policy status (true = enabled).
string
required
Policy ID.
string | null
Prisma Cloud API URL for your tenant’s stack, e.g. https://api.prismacloud.io, https://api2.prismacloud.io or https://api.eu.prismacloud.io. Falls back to the workspace variable pan_prisma.base_url.Default: null.