Skip to main content

runtime dashboard

CLI 5.0.0, using SDK 0.26.0, exposes the supplied SCM application dashboard routes. All commands are read-only and use Management OAuth. These undocumented APIs may change; only the supplied and live-tested windows are claimed verified.

CommandRequired identityDefault windowResponse
applicationsNone1 dayitems, pagination; --limit 25 --offset 0
application--app-id, --app-name30 daysApplication, profiles, session/token statistics
application-violations--app-id, --app-name30 daysDetector/severity breakdown
top-applicationsNone1 dayapplications ranked subset
violations-trendNone1 dayviolations time buckets
apps-listNone30 daysapplications identity pairs; no verified pagination
airs-cli runtime dashboard applications --interval 1 --unit day --output json
airs-cli runtime dashboard apps-list --output yaml
airs-cli runtime dashboard application --app-id APPLICATION_ID --app-name 'Exact name'
airs-cli runtime dashboard application-violations --app-id APPLICATION_ID --app-name 'Exact name'
airs-cli runtime dashboard top-applications --output json
airs-cli runtime dashboard violations-trend --output json

All support --interval, --unit, and --output pretty|json|yaml. Pretty output is readable JSON; JSON/YAML preserve the SDK response envelope. Application detail and breakdown require 7, 30, or 60 days; their metrics must not be labeled daily. Overview accepts the SDK's 1/7/30/60 and day/days/hour options; arbitrary combinations are not guaranteed by the service. Rankings, trends, and apps-list accept hour, hours, day, or days as units. In CLI 5.0.1, unsupported units fail locally with exit code 2. Express one week as --interval 7 --unit days; week is not a supported unit, and units are not silently converted.

Keep application ID and exact name together: IDs can repeat across names, and names across IDs. Preserve scaled token units. Detector violations may exceed violating sessions; overview bucket totals may not reconcile with top-level counters.

The dashboard host defaults to https://api.apps.paloaltonetworks.com/aisec. Override it with PANW_MGMT_DASHBOARD_ENDPOINT or config mgmtDashboardEndpoint; mgmtEndpoint remains separate for other Management resources. Credentials are the existing mgmtClientId, mgmtClientSecret, mgmtTsgId in the selected tenant file. No Scanner key, browser token, Origin or Referer is needed. Debug files in CWD omit dashboard bodies; explicitly displayed JSON/YAML may still contain confidential metadata.

See sessions for drill-down and the daily report for a shareable, allowlisted projection.