Skip to main content

Add address group members

Action ID: tools.pan_strata.add_address_group_members Add members of a static address group in the candidate configuration. Reads the group by ID or by name with GET /config/objects/v1/address-groups, and writes it with PUT /config/objects/v1/address-groups/{id} only when membership changes, so repeated calls are idempotent. Push the candidate configuration to apply the change. Reference: https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

array[string]
required
Names of address objects or address groups.
string | null
Address group UUID.Default: null.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Address group name. Requires exactly one of folder, snippet, or device. Ignored when address_group_id is set.Default: null.
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.

Block CIDR

Action ID: tools.pan_strata.block_cidr Block a CIDR range by adding an address object to a static address group referenced by a deny rule. Looks up the address object by name, creates it with POST /config/objects/v1/addresses if missing, then adds it to the group with PUT /config/objects/v1/address-groups/{id} if it is not already a member, so repeated calls do not create duplicates. Changes stay in the candidate configuration; run push_candidate_config to enforce them. Reference: https://pan.dev/scm/api/config/ngfw/objects/create-addresses/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Static address group that a deny rule references, e.g. tracecat-blocklist.
string
required
IPv4 or IPv6 network in CIDR notation to block, e.g. 198.51.100.0/24.
string | null
Address object name to use instead of the generated name.Default: null.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Description for a newly created address object, e.g. the case ID.Default: null.
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
string
Prefix for generated address object names.Default: "tc-block-".
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
array[string] | null
Tags for a newly created address object.Default: null.

Block FQDN

Action ID: tools.pan_strata.block_fqdn Block an FQDN by adding an address object to a static address group referenced by a deny rule. Looks up the address object by name, creates it with POST /config/objects/v1/addresses if missing, then adds it to the group with PUT /config/objects/v1/address-groups/{id} if it is not already a member, so repeated calls do not create duplicates. Changes stay in the candidate configuration; run push_candidate_config to enforce them. Reference: https://pan.dev/scm/api/config/ngfw/objects/create-addresses/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Static address group that a deny rule references, e.g. tracecat-blocklist.
string
required
Fully qualified domain name to block.
string | null
Address object name to use instead of the generated name.Default: null.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Description for a newly created address object, e.g. the case ID.Default: null.
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
string
Prefix for generated address object names.Default: "tc-block-".
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
array[string] | null
Tags for a newly created address object.Default: null.

Block IP

Action ID: tools.pan_strata.block_ip Block an IP address by adding an address object to a static address group referenced by a deny rule. Looks up the address object by name, creates it with POST /config/objects/v1/addresses if missing, then adds it to the group with PUT /config/objects/v1/address-groups/{id} if it is not already a member, so repeated calls do not create duplicates. Changes stay in the candidate configuration; run push_candidate_config to enforce them. Reference: https://pan.dev/scm/api/config/ngfw/objects/create-addresses/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Static address group that a deny rule references, e.g. tracecat-blocklist.
string
required
IPv4 or IPv6 address to block.
string | null
Address object name to use instead of the generated name.Default: null.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Description for a newly created address object, e.g. the case ID.Default: null.
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
string
Prefix for generated address object names.Default: "tc-block-".
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
array[string] | null
Tags for a newly created address object.Default: null.

Create address

Action ID: tools.pan_strata.create_address Create an address object in the candidate configuration with POST /config/objects/v1/addresses. Provide exactly one of ip_netmask, ip_range, ip_wildcard, or fqdn. Push the candidate configuration to apply the change. Reference: https://pan.dev/scm/api/config/ngfw/objects/create-addresses/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Address object name (max 63 characters).
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Address object description.Default: null.
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Fully qualified domain name, e.g. malicious.example.com.Default: null.
string | null
IP address with or without CIDR mask, e.g. 203.0.113.10 or 10.0.0.0/24.Default: null.
string | null
IP range, e.g. 10.0.0.1-10.0.0.20.Default: null.
string | null
IP wildcard mask, e.g. 10.20.1.0/0.0.248.255.Default: null.
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
array[string] | null
Tags to apply. Tags must already exist in the container.Default: null.

Create address group

Action ID: tools.pan_strata.create_address_group Create a static or dynamic address group in the candidate configuration with POST /config/objects/v1/address-groups. Provide exactly one of static_members or dynamic_filter. Push the candidate configuration to apply the change. Reference: https://pan.dev/scm/api/config/ngfw/objects/create-address-groups/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Address group name (max 63 characters).
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Address group description.Default: null.
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Tag filter for a dynamic group, e.g. ‘quarantine’ or ‘malicious’ and ‘external’.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
array[string] | null
Names of address objects or groups for a static group.Default: null.
array[string] | null
Tags to apply to the group.Default: null.

Create security rule

Action ID: tools.pan_strata.create_security_rule Create a security rule in the candidate configuration with POST /config/security/v1/security-rules?position=. The rule is added at the bottom of the rulebase; use move_security_rule to place it. Push the candidate configuration to apply the change. Reference: https://pan.dev/scm/api/config/ngfw/security/create-security-rules/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Action to take when the rule matches. Allowed values: allow, deny, drop, reset-client, reset-server, reset-both.
string
required
Security rule name.
array[string]
Applications. Defaults to any.Default: [ "any" ].
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
array[string]
URL categories. Defaults to any.Default: [ "any" ].
string | null
Rule description.Default: null.
array[string]
Destination addresses, address groups, or EDLs. Defaults to any.Default: [ "any" ].
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
boolean
Create the rule disabled.Default: false.
object | null
Additional API-native rule fields, e.g. negate_source or schedule.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
array[string]
Source zones. Defaults to any.Default: [ "any" ].
string | null
Log forwarding profile.Default: null.
string
Rulebase position of the rule. Allowed values: pre, post.Default: "pre".
string | null
Security profile group to attach.Default: null.
array[string]
Services, e.g. application-default or any. Defaults to any.Default: [ "any" ].
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
array[string]
Source addresses, address groups, or EDLs. Defaults to any.Default: [ "any" ].
array[string]
Source users or groups. Defaults to any.Default: [ "any" ].
array[string] | null
Tags to apply to the rule.Default: null.
array[string]
Destination zones. Defaults to any.Default: [ "any" ].

Create tag

Action ID: tools.pan_strata.create_tag Create a tag in the candidate configuration with POST /config/objects/v1/tags. Tags drive dynamic address group membership. Push the candidate configuration to apply the change. Reference: https://pan.dev/scm/api/config/ngfw/objects/create-tags/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Tag name (max 127 characters).
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Tag color name, e.g. Red or Orange.Default: null.
string | null
Tag comments.Default: null.
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.

Delete address

Action ID: tools.pan_strata.delete_address Delete a address object from the candidate configuration with DELETE /config/objects/v1/addresses/{id}. Push the candidate configuration to apply the change. Reference: https://pan.dev/scm/api/config/ngfw/objects/delete-addresses-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Address object UUID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.

Delete address group

Action ID: tools.pan_strata.delete_address_group Delete a address group from the candidate configuration with DELETE /config/objects/v1/address-groups/{id}. Push the candidate configuration to apply the change. Reference: https://pan.dev/scm/api/config/ngfw/objects/delete-address-groups-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Address group UUID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.

Delete security rule

Action ID: tools.pan_strata.delete_security_rule Delete a security rule from the candidate configuration with DELETE /config/security/v1/security-rules/{id}. Push the candidate configuration to apply the change. Reference: https://pan.dev/scm/api/config/ngfw/security/delete-security-rules-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Security rule UUID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string
Rulebase position of the rule. Allowed values: pre, post.Default: "pre".

Disable security rule

Action ID: tools.pan_strata.disable_security_rule Disable a security rule in the candidate configuration. Reads it with GET /config/security/v1/security-rules/{id} and writes it with PUT /config/security/v1/security-rules/{id} only when the state changes, so repeated calls are idempotent. Push the candidate configuration to apply the change. Reference: https://pan.dev/scm/api/config/ngfw/security/update-security-rules-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Security rule UUID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string
Rulebase position of the rule. Allowed values: pre, post.Default: "pre".

Enable security rule

Action ID: tools.pan_strata.enable_security_rule Enable a security rule in the candidate configuration. Reads it with GET /config/security/v1/security-rules/{id} and writes it with PUT /config/security/v1/security-rules/{id} only when the state changes, so repeated calls are idempotent. Push the candidate configuration to apply the change. Reference: https://pan.dev/scm/api/config/ngfw/security/update-security-rules-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Security rule UUID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string
Rulebase position of the rule. Allowed values: pre, post.Default: "pre".

Get address

Action ID: tools.pan_strata.get_address Get a address object by ID with GET /config/objects/v1/addresses/{id}, or by name and container with GET /config/objects/v1/addresses?name=. Reference: https://pan.dev/scm/api/config/ngfw/objects/get-addresses-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string | null
Address object UUID.Default: null.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Name of the address object. Requires exactly one of folder, snippet, or device. Ignored when the ID is set.Default: null.
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.

Get address group

Action ID: tools.pan_strata.get_address_group Get a address group by ID with GET /config/objects/v1/address-groups/{id}, or by name and container with GET /config/objects/v1/address-groups?name=. Reference: https://pan.dev/scm/api/config/ngfw/objects/get-address-groups-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string | null
Address group UUID.Default: null.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Name of the address group. Requires exactly one of folder, snippet, or device. Ignored when the ID is set.Default: null.
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.

Get device

Action ID: tools.pan_strata.get_device Get a device onboarded to Strata Cloud Manager with GET /config/setup/v1/devices/{id}. Reference: https://pan.dev/scm/api/config/ngfw/setup/get-device-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Device ID (serial number).
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.

Get incident

Action ID: tools.pan_strata.get_incident Get the details of a Strata Cloud Manager incident with GET /incidents/v1/details/{incident-id}. Reference: https://pan.dev/scm/api/config/incidents/get-incident-details/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Incident ID.
string
required
Tenant region sent as the X-PANW-Region header, e.g. americas, europe, uk, or au.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.

Get job

Action ID: tools.pan_strata.get_job Get a configuration job with GET /config/operations/v1/jobs/{id}. Returns normalized status, result, done, and succeeded fields along with the raw job. Reference: https://pan.dev/scm/api/config/ngfw/operations/get-jobs-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Job ID, e.g. the job_id returned by push_candidate_config.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.

Get security rule

Action ID: tools.pan_strata.get_security_rule Get a security rule by ID with GET /config/security/v1/security-rules/{id}, or by name and container with GET /config/security/v1/security-rules?name=. Reference: https://pan.dev/scm/api/config/ngfw/security/get-security-rules-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Name of the security rule. Requires exactly one of folder, snippet, or device. Ignored when the ID is set.Default: null.
string
Rulebase position of the rule. Allowed values: pre, post.Default: "pre".
string | null
Security rule UUID.Default: null.
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.

List address groups

Action ID: tools.pan_strata.list_address_groups List address groups. Calls GET /config/objects/v1/address-groups directly; page with limit and offset. Reference: https://pan.dev/scm/api/config/ngfw/objects/list-address-groups/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
integer | null
Maximum number of results per page. SCM defaults to 200.Default: null.
integer | null
Number of results to skip before the first returned result. Use the response’s total to page.Default: null.
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.

List addresses

Action ID: tools.pan_strata.list_addresses List address objects. Calls GET /config/objects/v1/addresses directly; page with limit and offset. Reference: https://pan.dev/scm/api/config/ngfw/objects/list-addresses/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
integer | null
Maximum number of results per page. SCM defaults to 200.Default: null.
integer | null
Number of results to skip before the first returned result. Use the response’s total to page.Default: null.
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.

List devices

Action ID: tools.pan_strata.list_devices List devices onboarded to Strata Cloud Manager. Calls GET /config/setup/v1/devices directly; page with limit and offset. Reference: https://pan.dev/scm/api/config/ngfw/setup/list-devices/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
integer | null
Maximum number of results per page. SCM defaults to 200.Default: null.
integer | null
Number of results to skip before the first returned result. Use the response’s total to page.Default: null.

List external dynamic lists

Action ID: tools.pan_strata.list_external_dynamic_lists List external dynamic lists. Calls GET /config/objects/v1/external-dynamic-lists directly; page with limit and offset. Reference: https://pan.dev/scm/api/config/ngfw/objects/list-external-dynamic-lists/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
integer | null
Maximum number of results per page. SCM defaults to 200.Default: null.
integer | null
Number of results to skip before the first returned result. Use the response’s total to page.Default: null.
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.

List folders

Action ID: tools.pan_strata.list_folders List folders. Calls GET /config/setup/v1/folders directly; page with limit and offset. Reference: https://pan.dev/scm/api/config/ngfw/setup/list-folders/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
integer | null
Maximum number of results per page. SCM defaults to 200.Default: null.
integer | null
Number of results to skip before the first returned result. Use the response’s total to page.Default: null.

List jobs

Action ID: tools.pan_strata.list_jobs List configuration jobs. Calls GET /config/operations/v1/jobs directly; page with limit and offset. Reference: https://pan.dev/scm/api/config/ngfw/operations/list-jobs/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
integer | null
Maximum number of results per page. SCM defaults to 200.Default: null.
integer | null
Number of results to skip before the first returned result. Use the response’s total to page.Default: null.

List quarantined devices

Action ID: tools.pan_strata.list_quarantined_devices List GlobalProtect devices on the quarantine list with GET /config/objects/v1/quarantined-devices, optionally filtered by host ID or serial number. Reference: https://pan.dev/scm/api/config/ngfw/objects/list-quarantined-devices/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Filter by device host ID.Default: null.
string | null
Filter by device serial number.Default: null.

List security rules

Action ID: tools.pan_strata.list_security_rules List security rules. Calls GET /config/security/v1/security-rules directly; page with limit and offset. Reference: https://pan.dev/scm/api/config/ngfw/security/list-rules/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
integer | null
Maximum number of results per page. SCM defaults to 200.Default: null.
integer | null
Number of results to skip before the first returned result. Use the response’s total to page.Default: null.
string
Rulebase position of the rule. Allowed values: pre, post.Default: "pre".
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.

List snippets

Action ID: tools.pan_strata.list_snippets List snippets. Calls GET /config/setup/v1/snippets directly; page with limit and offset. Reference: https://pan.dev/scm/api/config/ngfw/setup/list-snippets/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
integer | null
Maximum number of results per page. SCM defaults to 200.Default: null.
integer | null
Number of results to skip before the first returned result. Use the response’s total to page.Default: null.

List tags

Action ID: tools.pan_strata.list_tags List tags. Calls GET /config/objects/v1/tags directly; page with limit and offset. Reference: https://pan.dev/scm/api/config/ngfw/objects/list-tags/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
integer | null
Maximum number of results per page. SCM defaults to 200.Default: null.
integer | null
Number of results to skip before the first returned result. Use the response’s total to page.Default: null.
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.

Move security rule

Action ID: tools.pan_strata.move_security_rule Move a security rule within its rulebase with POST /config/security/v1/security-rules/{id}:move. Push the candidate configuration to apply the change. Reference: https://pan.dev/scm/api/config/ngfw/security/move-security-rules-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Where to move the rule. Allowed values: top, bottom, before, after.
string
required
Security rule UUID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
UUID of the reference rule. Required when destination is before or after.Default: null.
string
Rulebase of the rule. Allowed values: pre, post.Default: "pre".

Push candidate configuration

Action ID: tools.pan_strata.push_candidate_config Push the candidate configuration of one or more folders to devices with POST /config/operations/v1/config-versions/candidate:push. Returns the job ID; use wait_for_job to wait for completion. Put this behind an approval step in containment workflows. Reference: https://pan.dev/scm/api/config/ngfw/operations/push-candidate-config-versions/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

array[string]
required
Folders to push, e.g. [“All Firewalls”] or [“Mobile Users”, “Remote Networks”].
array[string] | null
Push only changes made by these administrators or service accounts, e.g. the client ID of this integration. Omit to push all changes in the folders.Default: null.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Description of the change, e.g. the case or incident ID.Default: null.

Quarantine device

Action ID: tools.pan_strata.create_quarantined_device Add a GlobalProtect device to the quarantine list with POST /config/objects/v1/quarantined-devices. Quarantined devices can be blocked by security rules that match the quarantine list. Reference: https://pan.dev/scm/api/config/ngfw/objects/create-quarantined-devices/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Device host ID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Device serial number.Default: null.

Remove address group members

Action ID: tools.pan_strata.remove_address_group_members Remove members of a static address group in the candidate configuration. Reads the group by ID or by name with GET /config/objects/v1/address-groups, and writes it with PUT /config/objects/v1/address-groups/{id} only when membership changes, so repeated calls are idempotent. Push the candidate configuration to apply the change. Reference: https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

array[string]
required
Names of address objects or address groups.
string | null
Address group UUID.Default: null.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Address group name. Requires exactly one of folder, snippet, or device. Ignored when address_group_id is set.Default: null.
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.

Remove device from quarantine

Action ID: tools.pan_strata.delete_quarantined_device Remove a GlobalProtect device from the quarantine list with DELETE /config/objects/v1/quarantined-devices?host_id=. Reference: https://pan.dev/scm/api/config/ngfw/objects/delete-quarantined-devices/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Device host ID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.

Search incidents

Action ID: tools.pan_strata.search_incidents Search Strata Cloud Manager incidents with POST /incidents/v1/search. Filter rules use property, operator, and values, e.g. {“property”: “status”, “operator”: “in”, “values”: [“Raised”]}. Reference: https://pan.dev/scm/api/config/incidents/search-incidents/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Tenant region sent as the X-PANW-Region header, e.g. americas, europe, uk, or au.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
array[object] | null
Filter rules with property, operator, and values.Default: null.
array[object] | null
Sort order, e.g. [{“property”: “updated_time”, “order”: “desc”}].Default: null.
integer
Page number, starting at 1.Default: 1.
integer
Number of incidents per page.Default: 25.

Unblock FQDN

Action ID: tools.pan_strata.unblock_fqdn Unblock an FQDN blocked with the matching block action. Removes the address object from the static address group with PUT /config/objects/v1/address-groups/{id} if it is a member, then deletes the address object with DELETE /config/objects/v1/addresses/{id} if it exists. Repeated calls are no-ops. Changes stay in the candidate configuration; run push_candidate_config to enforce them. Reference: https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Static address group that a deny rule references, e.g. tracecat-blocklist.
string
required
Fully qualified domain name to unblock.
string | null
Address object name to use instead of the generated name.Default: null.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
boolean
Delete the address object after removing it from the group. Fails if other rules or groups still reference it.Default: true.
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
string
Prefix for generated address object names.Default: "tc-block-".
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.

Unblock IP

Action ID: tools.pan_strata.unblock_ip Unblock an IP address or CIDR range blocked with the matching block action. Removes the address object from the static address group with PUT /config/objects/v1/address-groups/{id} if it is a member, then deletes the address object with DELETE /config/objects/v1/addresses/{id} if it exists. Repeated calls are no-ops. Changes stay in the candidate configuration; run push_candidate_config to enforce them. Reference: https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Static address group that a deny rule references, e.g. tracecat-blocklist.
string
required
IPv4 or IPv6 address, or CIDR range, to unblock.
string | null
Address object name to use instead of the generated name.Default: null.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
boolean
Delete the address object after removing it from the group. Fails if other rules or groups still reference it.Default: true.
string | null
Device (serial number) that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.
string | null
Folder that contains the configuration, e.g. Shared or All Firewalls. Provide exactly one of folder, snippet, or device.Default: null.
string
Prefix for generated address object names.Default: "tc-block-".
string | null
Snippet that contains the configuration. Provide exactly one of folder, snippet, or device.Default: null.

Update address

Action ID: tools.pan_strata.update_address Update an address object in the candidate configuration. Reads it with GET /config/objects/v1/addresses/{id}, applies only the provided fields, and writes it with PUT /config/objects/v1/addresses/{id}. Push the candidate configuration to apply the change. Reference: https://pan.dev/scm/api/config/ngfw/objects/update-addresses-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Address object UUID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
New description.Default: null.
string | null
Fully qualified domain name, e.g. malicious.example.com.Default: null.
string | null
IP address with or without CIDR mask, e.g. 203.0.113.10 or 10.0.0.0/24.Default: null.
string | null
IP range, e.g. 10.0.0.1-10.0.0.20.Default: null.
string | null
IP wildcard mask, e.g. 10.20.1.0/0.0.248.255.Default: null.
string | null
New name.Default: null.
array[string] | null
Replacement tag list.Default: null.

Update address group

Action ID: tools.pan_strata.update_address_group Update an address group in the candidate configuration. Reads it with GET /config/objects/v1/address-groups/{id}, applies only the provided fields, and writes it with PUT /config/objects/v1/address-groups/{id}. static_members replaces the whole member list; use add_address_group_members or remove_address_group_members for incremental changes. Reference: https://pan.dev/scm/api/config/ngfw/objects/update-address-groups-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Address group UUID.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string | null
New description.Default: null.
string | null
Tag filter for a dynamic group, e.g. ‘quarantine’ or ‘malicious’ and ‘external’.Default: null.
string | null
New name.Default: null.
array[string] | null
Names of address objects or groups for a static group.Default: null.
array[string] | null
Replacement tag list.Default: null.

Update security rule

Action ID: tools.pan_strata.update_security_rule Update a security rule in the candidate configuration. Reads it with GET /config/security/v1/security-rules/{id}, merges the provided API-native fields, and writes it with PUT /config/security/v1/security-rules/{id}. Push the candidate configuration to apply the change. Reference: https://pan.dev/scm/api/config/ngfw/security/update-security-rules-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Security rule UUID.
object
required
API-native fields to replace, e.g. {“action”: “deny”, “source”: [“blocked-ips”]}.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
string
Rulebase position of the rule. Allowed values: pre, post.Default: "pre".

Wait for job

Action ID: tools.pan_strata.wait_for_job Poll GET /config/operations/v1/jobs/{id} until the job finishes, then return normalized status, result, done, and succeeded fields. Fails when the job fails, unless raise_on_failure is false, or when it does not finish within poll_max_attempts. Reference: https://pan.dev/scm/api/config/ngfw/operations/get-jobs-by-id/

Secrets

Required secrets:
  • pan_strata_oauth: OAuth token PAN_STRATA_SERVICE_TOKEN.

Input fields

string
required
Job ID, e.g. the job_id returned by push_candidate_config.
string | null
SCM API base URL. Falls back to the workspace variable pan_strata.base_url, then https://api.strata.paloaltonetworks.com. Set this for FedRAMP tenants.Default: null.
number
Seconds between polls.Default: 10.
integer
Maximum number of polls.Default: 60.
boolean
Fail the action when the job finishes unsuccessfully.Default: true.