openapi: 3.1.0 info: title: Palo Alto Networks AIOps for NGFW BPA 5G Deregistered Trend 5G Unknown IPs Trend API description: AIOps for NGFW Best Practice Assessment (BPA) API. Provides programmatic access to submit BPA requests for Palo Alto Networks next-generation firewalls, check request processing status, and retrieve completed assessment reports. BPA reports analyze firewall configurations against Palo Alto Networks best practices and security benchmarks, identifying gaps and providing remediation guidance to improve security posture. Part of the Strata Cloud Manager platform. version: '1.0' contact: name: Palo Alto Networks Developer Support url: https://pan.dev/ license: name: Proprietary url: https://www.paloaltonetworks.com/legal servers: - url: https://api.stratacloud.paloaltonetworks.com/aiops/bpa/v1 description: AIOps for NGFW BPA API production server. security: - oauth2Bearer: [] tags: - name: 5G Unknown IPs Trend paths: /mt/monitor/5g/unknownIp/trend: post: tags: - 5G Unknown IPs Trend summary: Palo Alto Networks Monitor Unknown Trends description: "Tracks the volume of unknown IP Address address detections over a historical \ntime range. Network engineers monitor these trends to troubleshoot \ndiscovery gaps and improve the accuracy of subscriber mapping across \nregional interconnects." requestBody: content: application/json: schema: $ref: '#/components/schemas/TrendRequest' example: properties: - property: ip_address function: distinct_count alias: count - property: compute_region alias: region filter: operator: AND rules: - property: event_time operator: last_n_days values: - 7 - property: compute_region operator: in values: - us-central1 histogram: property: event_time range: day enableEmptyInterval: false value: '1' responses: '200': description: Success content: application/json: example: data: - region: us-central1 event_time: 1765324800000 count: 13 - region: us-central1 event_time: 1765411200000 count: 7 header: createdAt: '2025-12-17T02:05:04Z' clientRequestId: null dataCount: 8 status: subCode: 200 '400': description: Bad Request '401': description: Permission Denied '500': description: Server Error operationId: PostMtMonitor5gUnknownipTrend x-microcks-operation: delay: 0 dispatcher: FALLBACK components: schemas: TrendRequest: type: object properties: properties: type: array items: type: object properties: property: type: string example: example-property function: type: string example: example-function alias: type: string example: example-alias example: - property: example-property function: example-function alias: example-alias - property: example-property function: example-function alias: example-alias filter: type: object properties: operator: type: string example: example-operator rules: type: array items: type: object properties: property: type: string example: example-property operator: type: string example: example-operator values: type: array items: type: object example: - {} - {} example: - property: example-property operator: example-operator values: - {} - {} example: operator: example-operator rules: - property: example-property operator: example-operator values: - {} - property: example-property operator: example-operator values: - {} - {} histogram: type: object properties: property: type: string example: example-property range: type: string example: example-range enableEmptyInterval: type: boolean example: true value: type: string example: example-value example: property: example-property range: example-range enableEmptyInterval: true value: example-value securitySchemes: oauth2Bearer: type: http scheme: bearer bearerFormat: JWT description: OAuth 2.0 Bearer token for SASE platform authentication. Obtain using the client_credentials grant with your SASE service account client ID and client secret.