openapi: 3.1.0 info: title: Palo Alto Networks AIOps for NGFW BPA 5G Deregistered Trend Incidents by Severity API description: AIOps for NGFW Best Practice Assessment (BPA) API. Provides programmatic access to submit BPA requests for Palo Alto Networks next-generation firewalls, check request processing status, and retrieve completed assessment reports. BPA reports analyze firewall configurations against Palo Alto Networks best practices and security benchmarks, identifying gaps and providing remediation guidance to improve security posture. Part of the Strata Cloud Manager platform. version: '1.0' contact: name: Palo Alto Networks Developer Support url: https://pan.dev/ license: name: Proprietary url: https://www.paloaltonetworks.com/legal servers: - url: https://api.stratacloud.paloaltonetworks.com/aiops/bpa/v1 description: AIOps for NGFW BPA API production server. security: - oauth2Bearer: [] tags: - name: Incidents by Severity paths: /mt/monitor/5g/incidents/count: post: tags: - Incidents by Severity summary: Palo Alto Networks Categorize Incident Severities description: "Aggregates active 5G service incidents based on critical, warning, or \ninformational severity levels. NOC engineers use this data during \nincident response windows to prioritize remediation efforts across \nthe global 5G fabric." parameters: - name: agg_by in: query schema: type: string enum: - tenant description: Aggregation parameter example: tenant requestBody: content: application/json: schema: $ref: '#/components/schemas/IncidentsCountRequest' example: properties: - property: total_count - property: critical_count - property: warning_count filter: rules: - property: raised_time operator: last_n_days values: - 7 - property: status operator: equals values: - Raised responses: '200': description: Success content: application/json: example: data: - total_count: 680 critical_count: 340 warning_count: 0 '400': description: Bad Request '401': description: Permission Denied '500': description: Server Error operationId: PostMtMonitor5gIncidentsCount x-microcks-operation: delay: 0 dispatcher: FALLBACK components: schemas: IncidentsCountRequest: type: object properties: properties: type: array items: type: object properties: property: type: string example: example-property example: - property: example-property - property: example-property filter: type: object properties: rules: type: array items: type: object properties: property: type: string example: example-property operator: type: string example: example-operator values: type: array items: type: object example: - {} example: - property: example-property operator: example-operator values: - {} - property: example-property operator: example-operator values: - {} example: rules: - property: example-property operator: example-operator values: - {} - property: example-property operator: example-operator values: - {} - {} securitySchemes: oauth2Bearer: type: http scheme: bearer bearerFormat: JWT description: OAuth 2.0 Bearer token for SASE platform authentication. Obtain using the client_credentials grant with your SASE service account client ID and client secret.