openapi: 3.1.0 info: title: Palo Alto Networks AIOps for NGFW BPA 5G Deregistered Trend Added and Cleared Mappings API description: AIOps for NGFW Best Practice Assessment (BPA) API. Provides programmatic access to submit BPA requests for Palo Alto Networks next-generation firewalls, check request processing status, and retrieve completed assessment reports. BPA reports analyze firewall configurations against Palo Alto Networks best practices and security benchmarks, identifying gaps and providing remediation guidance to improve security posture. Part of the Strata Cloud Manager platform. version: '1.0' contact: name: Palo Alto Networks Developer Support url: https://pan.dev/ license: name: Proprietary url: https://www.paloaltonetworks.com/legal servers: - url: https://api.stratacloud.paloaltonetworks.com/aiops/bpa/v1 description: AIOps for NGFW BPA API production server. security: - oauth2Bearer: [] tags: - name: Added and Cleared Mappings paths: /mt/monitor/5g/ueIp/count: post: tags: - Added and Cleared Mappings summary: Palo Alto Networks Audit Mapping Changes description: "Calculates the number of newly added and cleared User Equipment IP Address \nmappings for a designated period. System administrators trigger this \naudit to track device churn and verify lifecycle transitions within \nthe 5G management plane." requestBody: content: application/json: schema: $ref: '#/components/schemas/CountFilterRequest' example: filter: operator: AND rules: - property: event_time operator: last_n_days values: - 7 responses: '200': description: Success content: application/json: example: data: add_count: 28 delete_count: 19 header: createdAt: '2025-12-17T02:07:14Z' clientRequestId: null dataCount: 1 status: subCode: 200 '400': description: Bad Request '401': description: Permission Denied '500': description: Server Error operationId: PostMtMonitor5gUeipCount x-microcks-operation: delay: 0 dispatcher: FALLBACK components: schemas: CountFilterRequest: type: object properties: filter: type: object properties: operator: type: string example: example-operator rules: type: array items: type: object properties: property: type: string example: example-property operator: type: string example: example-operator values: type: array items: type: object example: - {} - {} example: - property: example-property operator: example-operator values: - {} - property: example-property operator: example-operator values: - {} example: operator: example-operator rules: - property: example-property operator: example-operator values: - {} - property: example-property operator: example-operator values: - {} - {} securitySchemes: oauth2Bearer: type: http scheme: bearer bearerFormat: JWT description: OAuth 2.0 Bearer token for SASE platform authentication. Obtain using the client_credentials grant with your SASE service account client ID and client secret.