openapi: 3.1.0 info: title: Palo Alto Networks AIOps for NGFW BPA 5G Deregistered Trend API description: AIOps for NGFW Best Practice Assessment (BPA) API. Provides programmatic access to submit BPA requests for Palo Alto Networks next-generation firewalls, check request processing status, and retrieve completed assessment reports. BPA reports analyze firewall configurations against Palo Alto Networks best practices and security benchmarks, identifying gaps and providing remediation guidance to improve security posture. Part of the Strata Cloud Manager platform. version: '1.0' contact: name: Palo Alto Networks Developer Support url: https://pan.dev/ license: name: Proprietary url: https://www.paloaltonetworks.com/legal servers: - url: https://api.stratacloud.paloaltonetworks.com/aiops/bpa/v1 description: AIOps for NGFW BPA API production server. security: - oauth2Bearer: [] tags: - name: 5G Deregistered Trend paths: /mt/monitor/5g/ueIp/deregistered/trend: post: tags: - 5G Deregistered Trend summary: Palo Alto Networks Track Deregistration Trends description: "Monitors the frequency and volume of User Equipment session terminations \nover time. Security analysts use this telemetry to detect anomalous \ndisconnect patterns or regional connectivity drops during active \nmonitoring windows." requestBody: content: application/json: schema: $ref: '#/components/schemas/TrendRequest' example: properties: - property: imei function: count alias: deregistered_count filter: operator: AND rules: - property: event_time operator: last_n_days values: - 7 - property: compute_region operator: in values: - us-central1 histogram: property: event_time range: day enableEmptyInterval: false value: '1' responses: '200': description: Success content: application/json: example: data: - event_time: 1765324800000 deregistered_count: 3 - event_time: 1765411200000 deregistered_count: 3 header: createdAt: '2025-12-17T02:05:42Z' clientRequestId: null dataCount: 7 status: subCode: 200 '400': description: Bad Request '401': description: Permission Denied '500': description: Server Error operationId: PostMtMonitor5gUeipDeregisteredTrend x-microcks-operation: delay: 0 dispatcher: FALLBACK components: schemas: TrendRequest: type: object properties: properties: type: array items: type: object properties: property: type: string example: example-property function: type: string example: example-function alias: type: string example: example-alias example: - property: example-property function: example-function alias: example-alias - property: example-property function: example-function alias: example-alias filter: type: object properties: operator: type: string example: example-operator rules: type: array items: type: object properties: property: type: string example: example-property operator: type: string example: example-operator values: type: array items: type: object example: - {} - {} example: - property: example-property operator: example-operator values: - {} - {} example: operator: example-operator rules: - property: example-property operator: example-operator values: - {} - property: example-property operator: example-operator values: - {} - {} histogram: type: object properties: property: type: string example: example-property range: type: string example: example-range enableEmptyInterval: type: boolean example: true value: type: string example: example-value example: property: example-property range: example-range enableEmptyInterval: true value: example-value securitySchemes: oauth2Bearer: type: http scheme: bearer bearerFormat: JWT description: OAuth 2.0 Bearer token for SASE platform authentication. Obtain using the client_credentials grant with your SASE service account client ID and client secret.