List Policies V2
GET/v2/policy
Returns all available policies, both system default and custom. You can apply filters to narrow the returned policy list to a subset of policies or potentially to a specific policy. For improved performance, response does not include open alert counts.
For a request to get a full list of supported filters, see List Policy Filters.
Request
Query Parameters
Policy name
Possible values: [critical
, high
, medium
, low
, informational
]
Policy severity
Policy label
Possible values: [tf
, cft
, k8s
]
Policy rule template type
Possible values: [run
, build
, run_and_build
, audit
, data_classification
, dns
, malware
, network_event
, network
, ueba
, permissions
, identity
]
Policy subtype
Possible values: [config
, network
, audit_event
]
Policy type
Policy compliance standard name
Policy compliance requirement name
Policy compliance section ID
Possible values: [true
, false
]
Policy enabled
Possible values: [custom
, redlock_default
]
Policy mode
Possible values: [true
, false
]
Policy is remediable
Possible values: [true
, false
]
Include deleted policies
Cloud type
Responses
- 200
successful operation
- application/json; charset=UTF-8
- Schema
- Example (from schema)
Schema
- Array [
- Array [
- ]
- Array [
- ]
- ]
Possible values: [ALL
, AWS
, AZURE
, GCP
, ALIBABA_CLOUD
, OCI
, IBM
]
Cloud type (Required for config policies). Not case-sensitive. Default is ALL.
complianceMetadata object[]
List of compliance data. Each item has compliance standard, requirement, and/or section information.
Compliance Section UUID
Policy ID
Requirement description
Requirement ID
Requirement name
Section name
Section Id
Section Label
Compliance standard description
Compliance standard name
Created by
Created on this timestamp
Deleted
Policy description
true=enabled. false=disabled.
Finding Type
Labels
Last modified by
Last modified on this timestamp
Policy name
Overridden
Owner
Possible values: [risk
, incident
]
PolicyCategory
PolicyClass
Policy ID
Possible values: [custom/redlock_default
]
PolicyMode
Policy subtype
Policy type. Policy type anomaly is read-only.
Policy UPI
Read Only
Remediation recommendation
isRemediable
remediation object
Model for Remediation
actions object[]
Policy Action
CLI Script Template
Description
Restrict alert dismissal
rule objectrequired
Model for Rule
API name
Cloud account
Cloud type
Saved search ID that defines the rule criteria.
dataCriteria object
Criteria for Rule
Data policy. Required for DLP rule criteria.
Possible values: [private
, public
, conditional
]
File exposure
File extensions
Name
parameters objectrequired
Parameters (e.g. {"savedSearch": "true"})
Resource ID path
Resource type
Possible values: [Config
, Network
, AuditEvent
, DLP
, IAM
, NetworkConfig
]
Type of rule or RQL query
Rule last modified on
Possible values: [high
, medium
, low
]
Severity
true = Policy is a Prisma Cloud system default policy
[
{
"cloudType": "ALL",
"complianceMetadata": [
{
"complianceId": "string",
"customAssigned": true,
"policyId": "string",
"requirementDescription": "string",
"requirementId": "string",
"requirementName": "string",
"sectionDescription": "string",
"sectionId": "string",
"sectionLabel": "string",
"standardDescription": "string",
"standardId": "string",
"standardName": "string"
}
],
"createdBy": "string",
"createdOn": 0,
"deleted": true,
"description": "string",
"enabled": true,
"findingTypes": [
"string"
],
"labels": [
"string"
],
"lastModifiedBy": "string",
"lastModifiedOn": 0,
"name": "string",
"overridden": true,
"owner": "string",
"policyCategory": "risk",
"policyClass": {},
"policyId": "string",
"policyMode": "custom/redlock_default",
"policySubTypes": [
{}
],
"policyType": {},
"policyUpi": "string",
"readOnly": true,
"recommendation": "string",
"remediable": true,
"remediation": {
"actions": [
{
"operation": "string",
"payload": "string"
}
],
"cliScriptTemplate": "string",
"description": "string"
},
"restrictAlertDismissal": true,
"rule": {
"apiName": "string",
"cloudAccount": "string",
"cloudType": "string",
"criteria": "string",
"dataCriteria": {
"classificationResult": "string",
"exposure": "private",
"extension": [
"string"
]
},
"name": "string",
"parameters": {},
"resourceIdPath": "string",
"resourceType": "string",
"type": "Config"
},
"ruleLastModifiedOn": 0,
"severity": "high",
"systemDefault": true
}
]