Get Incident Details
GET/v2/api/incidents/:incidentID
Similarly to how you can view DLP Incidents on Panorama, you can view your DLP incidents programatically. The API retrieves all DLP incidents which you can filter using the query parameters. When using the API note:
- If you are using multiple filtering parameters such as report ID, user ID, file SHA, and channel, all are combined via an "AND" operation
- All filters are exact matches
- Fields with null values are not included in the response.
Request
Path Parameters
- IncidentID Example
The incident ID to filter.
Example: 3fb38abe-a83b-44e5-99d5-4bec3765bba6
Query Parameters
Possible values: [us
, eu
, uk
, jp
, in
, ap
, ca
, au
, par
]
region(default to us)
Responses
- 200
- 400
- 401
- 403
- 404
- 500
OK
- application/json
- Schema
- Example (from schema)
- incident detail
Schema
Possible values: [alert
, block
]
Action taken on the incident.
Palo Alto Networks assigned Application ID.
The name of the application.
Automatically assigned ID of the assignee.
Possible values: [ngfw
, prisma-access
]
The Palo Alto Networks channel that identified the incident.
The UUID profile descriptor used to characterize the incident.
The data profile descriptor used to characterize the incident.
The analyzed file name.
The analyzed file SHA hash.
The analyzed file type.
The time the incident first occurred.
Current status of the feedback assosicated with the incident.
The Palo Alto Networks automatically assigned incident ID.
User defined notes for the incident.
match_info object
Possible values: [document_fingerprint
, edm
, file_property
, ml
, ml_document
, regex
, titus_tag
, trainable_classifier
, weighted_regex
]
One of several techniques used to identify the incident.
Exact Data Matching (EDM) is a method of detecting and protecting your most sensitive content. Unlike data patterns, EDM uses specific data—such as a patient’s first and last name or a patient’s social security number or a customer’s bank account number—to identify matches.
The indicator for high confidence freqeuncy.
The indicator for low confidence frequency.
Indicator for medium confidence frequency.
The name of the pattern.
The unique high confidence frequency pattern.
The unique low confidence freqeuncy pattern.
The unique medium confidence frequency pattern.
Data pattern version.
The Palo Alto Networks automatically assigned report ID that you can use to retrieve reports.
Resolution status from Enterprise DLP status.
Specifies a session key assosciated with the incident.
A JSON structure containing snippet data, if snippets are not enabled, the field returns as null.
The Palo Alto Networks source that identified the incident.
The TSG enabled tenant used to identify the Incident.
The user assosciated with te incident.
{
"action": "alert",
"assignee_id": "00d53ebf-c386-4b95-ad05-6819517c3450",
"channel": "prisma-access",
"data_profile_id": 11995590,
"data_profile_name": "PatricksDPwEDM",
"file_name": "100_rows_10_cols_tail.csv",
"file_sha": "9d8ce237eff10b5ac4b4c8fed0d7988ca6cc4f090f90230acd8dad36fb7da636",
"incident_creation_time": "2024-Jan-11 17:14:30 UTC",
"incident_id": "4adeefe4-8358-411e-8ba7-5f45e5625c58",
"incident_notes": "test notes",
"match_info": {
"65a0209ce36cd3480011d677": {
"detection_technique": "edm",
"edm_columns": [
"credit_card_number",
"social_security_number"
],
"hcf": 10,
"lcf": 10,
"mcf": 0,
"name": "EDM - PatricksDataSet20240111",
"uhcf": 10,
"ulcf": 10,
"umcf": 0,
"version": 1
}
},
"report_id": "530470823",
"resolution_status": "Assigned",
"source": "prisma-access",
"tenant_id": "5886928188517009408"
}
{
"action": "alert",
"channel": "ngfw",
"data_profile_id": 11995044,
"data_profile_name": "PII",
"file_name": "SSNpattern",
"file_sha": "a4d58aa3caeb73b56028f597de2b3263d64e2835f277f31c97be53bc76a29e47",
"incident_creation_time": "2024-Jan-18 21:46:54 UTC",
"incident_id": "1a762308-3735-4d29-8edd-4595d4e3f982",
"match_info": {
"6374e1b4dee31d91c40b1705": {
"detection_technique": "regex",
"hcf": 0,
"lcf": 5,
"mcf": 0,
"name": "Driver License - Slovenia",
"uhcf": 0,
"ulcf": 5,
"umcf": 0,
"version": 1
},
"6374e1b4dee31d91c40b1708": {
"detection_technique": "regex",
"hcf": 0,
"lcf": 13,
"mcf": 0,
"name": "Driver License - Canada",
"uhcf": 0,
"ulcf": 13,
"umcf": 0,
"version": 1
},
"6374e1b4dee31d91c40b1709": {
"detection_technique": "regex",
"hcf": 0,
"lcf": 17,
"mcf": 0,
"name": "Driver License - US",
"uhcf": 0,
"ulcf": 17,
"umcf": 0,
"version": 1
}
},
"report_id": "1107089697",
"snippets": {
"6374e1b4dee31d91c40b1705": {
"low_confidence_detections": [
{
"detection": "*******00",
"left": "\n\n\n\n\n\n tax id number ***-**-**99 abs cupp\nIBAN CH9300762011623852957 cusip ",
"origOffSet": 75,
"original_text": "*******00",
"right": " | *****0BG4 DEA *****3839 | *****5341 CLIA 24C3872984 | 05D0911402\nHETU number ******-856E | *******0490
\nCPF | **************1-30 CNPJ
\n*-****-****-6246 SHAKAI HOSHŌ ZEI BANGŌ SEIDO MAINANBA ****-**",
"textLength": 0
},
{
"detection": "*******55",
"left": "HOSHŌ ZEI BANGŌ SEIDO MAINANBA ****-****-6333\nUK Tax UTR ******1030 ******1031 NINO GP 32 76 63 *****280B Germany Tax ID *******1827 *******8911 *******8796 visa 4556501518562241 4929091695478411 aba ",
"origOffSet": 446,
"original_text": "*******55",
"right": " *****3532 ssn 098-07-33 16 480-33-1945 Canada SIN *** *** 425 *****3197 Australia Tax ID 45322 1716 98754015 Access Key ID 022QF06E7MXBSH9DHM02 AWS Secret Key kWcrlUX5JEDGM/LtmEENI/ aVmYvHNif5zB+d9+c",
"textLength": 0
},
{
"detection": "*****3532",
"left": "BANGŌ SEIDO MAINANBA ****-****-6333\nUK Tax UTR ******1030 ******1031 NINO GP 32 76 63 *****280B Germany Tax ID *******1827 *******8911 *******8796 visa 4556501518562241 4929091695478411 aba *******55 ",
"origOffSet": 456,
"original_text": "*****3532",
"right": " ssn 098-07-33 16 480-33-1945 Canada SIN *** *** 425 *****3197 Australia Tax ID 45322 1716 98754015 Access Key ID 022QF06E7MXBSH9DHM02 AWS Secret Key kWcrlUX5JEDGM/LtmEENI/ aVmYvHNif5zB+d9+ct ;5301250",
"textLength": 0
}
],
"version": 1
},
"6374e1b4dee31d91c40b1708": {
"low_confidence_detections": [
{
"detection": "*******00",
"left": "\n\n\n\n\n\n tax id number ***-**-**99 abs cupp\nIBAN CH9300762011623852957 cusip ",
"origOffSet": 75,
"original_text": "*******00",
"right": " | *****0BG4 DEA *****3839 | *****5341 CLIA 24C3872984 | 05D0911402\nHETU number ******-856E | *******0490
\nCPF | **************1-30 CNPJ
\n*-****-****-6246 SHAKAI HOSHŌ ZEI BANGŌ SEIDO MAINANBA ****-**",
"textLength": 0
},
{
"detection": "*****5341",
"left": "\n\n\n\n\n\n tax id number ***-**-**99 abs cupp\nIBAN CH9300762011623852957 cusip *******00 | *****0BG4 DEA *****3839 | ",
"origOffSet": 113,
"original_text": "*****5341",
"right": " CLIA 24C3872984 | 05D0911402\nHETU number ******-856E | *******0490
\nCPF | **************1-30 CNPJ
\n*-****-****-6246 SHAKAI HOSHŌ ZEI BANGŌ SEIDO MAINANBA ****-****-6333\nUK Tax UTR ******1030 ******10",
"textLength": 0
},
{
"detection": "*****3839",
"left": "\n\n\n\n\n\n tax id number ***-**-**99 abs cupp\nIBAN CH9300762011623852957 cusip *******00 | *****0BG4 DEA ",
"origOffSet": 101,
"original_text": "*****3839",
"right": " | *****5341 CLIA 24C3872984 | 05D0911402\nHETU number ******-856E | *******0490
\nCPF | **************1-30 CNPJ
\n*-****-****-6246 SHAKAI HOSHŌ ZEI BANGŌ SEIDO MAINANBA ****-****-6333\nUK Tax UTR ******1",
"textLength": 0
}
],
"version": 1
},
"6374e1b4dee31d91c40b1709": {
"low_confidence_detections": [
{
"detection": "*******00",
"left": "\n\n\n\n\n\n tax id number ***-**-**99 abs cupp\nIBAN CH9300762011623852957 cusip ",
"origOffSet": 75,
"original_text": "*******00",
"right": " | *****0BG4 DEA *****3839 | *****5341 CLIA 24C3872984 | 05D0911402\nHETU number ******-856E | *******0490
\nCPF | **************1-30 CNPJ
\n*-****-****-6246 SHAKAI HOSHŌ ZEI BANGŌ SEIDO MAINANBA ****-**",
"textLength": 0
},
{
"detection": "******",
"left": "\n\n\n\n\n\n tax id number ***-**-**99 abs cupp\nIBAN CH9300762011623852957 cusip *******00 | *****0BG4 DEA *****3839 | *****5341 CLIA 24C3872984 | 05D0911402\nHETU number ",
"origOffSet": 164,
"original_text": "******",
"right": "-856E | *******0490
\nCPF | **************1-30 CNPJ
\n*-****-****-6246 SHAKAI HOSHŌ ZEI BANGŌ SEIDO MAINANBA ****-****-6333\nUK Tax UTR ******1030 ******1031 NINO GP 32 76 63 *****280B Germany Tax ID ***",
"textLength": 0
},
{
"detection": "***-**-**99",
"left": "\n\n\n\n\n\n tax id number ",
"origOffSet": 21,
"original_text": "***-**-**99",
"right": " abs cupp\nIBAN CH9300762011623852957 cusip *******00 | *****0BG4 DEA *****3839 | *****5341 CLIA 24C3872984 | 05D0911402\nHETU number ******-856E | *******0490
\nCPF | **************1-30 CNPJ
\n*-****-***",
"textLength": 0
}
],
"version": 1
}
},
"source": "ngfw",
"tenant_id": "5886928188517009408"
}
Bad Request
Unauthorized
Forbidden
Not Found
Internal server error