Cloudflare · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Cloudflare Radar API

170 actions 170 updates phrasing extends openapi/cloudflare-radar-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Cloudflare's API. It is a proposal applied on top of the contract, not a document Cloudflare publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 170 · first 16 shown; the file carries all of them

$.info
$.paths['/radar/annotations/outages'].get
$.paths['/radar/annotations/outages/locations'].get
$.paths['/radar/as112/summary/dnssec'].get
$.paths['/radar/as112/summary/edns'].get
$.paths['/radar/as112/summary/ip_version'].get
$.paths['/radar/as112/summary/protocol'].get
$.paths['/radar/as112/summary/query_type'].get
$.paths['/radar/as112/summary/response_codes'].get
$.paths['/radar/as112/timeseries'].get
$.paths['/radar/as112/timeseries_groups/dnssec'].get
$.paths['/radar/as112/timeseries_groups/edns'].get
$.paths['/radar/as112/timeseries_groups/ip_version'].get
$.paths['/radar/as112/timeseries_groups/protocol'].get
$.paths['/radar/as112/timeseries_groups/query_type'].get
$.paths['/radar/as112/timeseries_groups/response_codes'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Cloudflare Radar API
  version: 1.0.0
extends: openapi/cloudflare-radar-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 169
- target: $.paths['/radar/annotations/outages'].get
  update:
    x-apievangelist-phrasing:
      intent: List recent Internet outages and anomalies
      effect: read
      questions:
      - Where can I see the latest Internet outages Cloudflare Radar has recorded?
      - Can I list outage annotations for just one country or network?
      instructions:
      - text: List the latest Internet outages recorded in {location}.
        slots:
          location: query.location
      - text: Show outage annotations affecting AS{asn} over {dateRange}.
        slots:
          asn: query.asn
          dateRange: query.dateRange
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/annotations/outages/locations'].get
  update:
    x-apievangelist-phrasing:
      intent: Count outages per location
      effect: read
      questions:
      - Which countries have had the most Internet outages lately?
      - Is there a ranking of locations by number of outages?
      instructions:
      - text: Rank locations by how many outages they had over {dateRange}.
        slots:
          dateRange: query.dateRange
      - text: Give me the top {limit} locations by outage count.
        slots:
          limit: query.limit
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/as112/summary/dnssec'].get
  update:
    x-apievangelist-phrasing:
      intent: Summarize AS112 DNS queries by DNSSEC support
      effect: read
      questions:
      - What share of queries reaching AS112 ask for DNSSEC?
      - How much AS112 DNS traffic is DNSSEC-aware versus not, overall?
      instructions:
      - text: Summarize the DNSSEC support split of AS112 queries for {location}.
        slots:
          location: query.location
      - text: Give me the overall AS112 DNSSEC share for {dateRange}.
        slots:
          dateRange: query.dateRange
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/as112/summary/edns'].get
  update:
    x-apievangelist-phrasing:
      intent: Summarize AS112 DNS queries by EDNS support
      effect: read
      questions:
      - What percentage of AS112 queries use EDNS?
      - Can I see the EDNS support breakdown of AS112 traffic for a single country?
      instructions:
      - text: Summarize EDNS support among AS112 queries in {location}.
        slots:
          location: query.location
      - text: Report the EDNS versus non-EDNS share of AS112 lookups over {dateRange}.
        slots:
          dateRange: query.dateRange
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/as112/summary/ip_version'].get
  update:
    x-apievangelist-phrasing:
      intent: Summarize AS112 DNS queries by IP version
      effect: read
      questions:
      - How much AS112 DNS traffic arrives over IPv6 compared to IPv4?
      - What is the IPv4/IPv6 split of queries hitting AS112 in one network?
      instructions:
      - text: Summarize the IPv4 vs IPv6 share of AS112 queries from AS{asn}.
        slots:
          asn: query.asn
      - text: Show the AS112 IP version breakdown for {location}.
        slots:
          location: query.location
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/as112/summary/protocol'].get
  update:
    x-apievangelist-phrasing:
      intent: Summarize AS112 DNS queries by transport protocol
      effect: read
      questions:
      - What share of AS112 lookups travel over UDP versus TCP?
      - Which transport protocols carry DNS queries to AS112?
      instructions:
      - text: Summarize AS112 query transport protocols for {location}.
        slots:
          location: query.location
      - text: Break down AS112 lookups by UDP, TCP and other protocols for {dateRange}.
        slots:
          dateRange: query.dateRange
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/as112/summary/query_type'].get
  update:
    x-apievangelist-phrasing:
      intent: Summarize AS112 DNS queries by record type
      effect: read
      questions:
      - Which DNS record types are most commonly queried at AS112?
      - What share of AS112 queries are PTR lookups compared to A or AAAA?
      instructions:
      - text: Summarize AS112 queries by record type for {location}.
        slots:
          location: query.location
      - text: Show the query type mix hitting AS112 over {dateRange}.
        slots:
          dateRange: query.dateRange
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/as112/summary/response_codes'].get
  update:
    x-apievangelist-phrasing:
      intent: Summarize AS112 DNS responses by response code
      effect: read
      questions:
      - What share of AS112 answers are NXDOMAIN?
      - How are AS112 DNS responses distributed across response codes?
      instructions:
      - text: Summarize AS112 response codes for {location}.
        slots:
          location: query.location
      - text: Give me the NOERROR/NXDOMAIN split of AS112 replies over {dateRange}.
        slots:
          dateRange: query.dateRange
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/as112/timeseries'].get
  update:
    x-apievangelist-phrasing:
      intent: Chart AS112 DNS query volume over time
      effect: read
      questions:
      - How has the volume of queries reaching AS112 changed over time?
      - Can I get AS112 query counts at hourly or daily intervals?
      instructions:
      - text: Chart AS112 DNS query volume for {location} over {dateRange}.
        slots:
          location: query.location
          dateRange: query.dateRange
      - text: Plot AS112 query volume in {aggInterval} buckets.
        slots:
          aggInterval: query.aggInterval
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/as112/timeseries_groups/dnssec'].get
  update:
    x-apievangelist-phrasing:
      intent: Track AS112 DNSSEC support over time
      effect: read
      questions:
      - Is DNSSEC support among AS112 queries rising or falling over time?
      - Can I trend the DNSSEC-aware share of AS112 traffic day by day?
      instructions:
      - text: Trend the DNSSEC share of AS112 queries in {location} over {dateRange}.
        slots:
          location: query.location
          dateRange: query.dateRange
      - text: Plot AS112 DNSSEC support per {aggInterval} interval.
        slots:
          aggInterval: query.aggInterval
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/as112/timeseries_groups/edns'].get
  update:
    x-apievangelist-phrasing:
      intent: Track AS112 EDNS support over time
      effect: read
      questions:
      - How has EDNS usage in AS112 queries changed over the past months?
      - Can I see a time series of EDNS support for AS112 lookups?
      instructions:
      - text: Trend EDNS support in AS112 queries from {location} across {dateRange}.
        slots:
          location: query.location
          dateRange: query.dateRange
      - text: Chart the EDNS share of AS112 traffic at {aggInterval} granularity.
        slots:
          aggInterval: query.aggInterval
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/as112/timeseries_groups/ip_version'].get
  update:
    x-apievangelist-phrasing:
      intent: Track AS112 queries by IP version over time
      effect: read
      questions:
      - Is IPv6 growing as a share of AS112 DNS queries over time?
      - Can I trend the IPv4/IPv6 mix of AS112 traffic for one network?
      instructions:
      - text: Trend the IPv6 share of AS112 queries from AS{asn} over {dateRange}.
        slots:
          asn: query.asn
          dateRange: query.dateRange
      - text: Chart AS112 queries per IP version in {location} over time.
        slots:
          location: query.location
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/as112/timeseries_groups/protocol'].get
  update:
    x-apievangelist-phrasing:
      intent: Track AS112 queries by transport protocol over time
      effect: read
      questions:
      - Has the TCP share of AS112 DNS traffic changed over time?
      - Can I get a time series of AS112 queries split by transport protocol?
      instructions:
      - text: Trend AS112 transport protocol usage in {location} across {dateRange}.
        slots:
          location: query.location
          dateRange: query.dateRange
      - text: Chart AS112 UDP versus TCP usage per {aggInterval}.
        slots:
          aggInterval: query.aggInterval
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/as112/timeseries_groups/query_type'].get
  update:
    x-apievangelist-phrasing:
      intent: Track AS112 queries by record type over time
      effect: read
      questions:
      - How has the mix of record types queried at AS112 shifted over time?
      - Can I trend PTR versus other query types reaching AS112?
      instructions:
      - text: Trend AS112 query types for {location} over {dateRange}.
        slots:
          location: query.location
          dateRange: query.dateRange
      - text: Chart the AS112 record-type mix by {aggInterval}.
        slots:
          aggInterval: query.aggInterval
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/as112/timeseries_groups/response_codes'].get
  update:
    x-apievangelist-phrasing:
      intent: Track AS112 response codes over time
      effect: read
      questions:
      - Has the NXDOMAIN rate at AS112 changed over time?
      - Can I get a time series of AS112 DNS response codes?
      instructions:
      - text: Trend AS112 response codes in {location} across {dateRange}.
        slots:
          location: query.location
          dateRange: query.dateRange
      - text: Chart AS112 reply codes aggregated per {aggInterval}.
        slots:
          aggInterval: query.aggInterval
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/as112/top/locations'].get
  update:
    x-apievangelist-phrasing:
      intent: Rank locations by AS112 DNS queries
      effect: read
      questions:
      - Which countries send the most DNS queries to AS112?
      - What are the top locations by share of AS112 traffic?
      instructions:
      - text: List the top {limit} locations by AS112 query share.
        slots:
          limit: query.limit
      - text: Rank countries by AS112 DNS queries over {dateRange}.
        slots:
          dateRange: query.dateRange
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/as112/top/locations/dnssec/{dnssec}'].get
  update:
    x-apievangelist-phrasing:
      intent: Rank locations by AS112 DNSSEC support
      effect: read
      questions:
      - Which countries send the most DNSSEC-supporting queries to AS112?
      - Where do AS112 queries without DNSSEC mostly come from?
      instructions:
      - text: Rank locations by AS112 queries with DNSSEC status {dnssec}.
        slots:
          dnssec: path.dnssec
      - text: List the top {limit} countries for AS112 DNSSEC value {dnssec}.
        slots:
          limit: query.limit
          dnssec: path.dnssec
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/as112/top/locations/edns/{edns}'].get
  update:
    x-apievangelist-phrasing:
      intent: Rank locations by AS112 EDNS support
      effect: read
      questions:
      - Which countries send the most EDNS-enabled queries to AS112?
      - Where does AS112 traffic lacking EDNS originate?
      instructions:
      - text: Rank locations by AS112 queries with EDNS status {edns}.
        slots:
          edns: path.edns
      - text: Show the top {limit} countries for AS112 EDNS value {edns}.
        slots:
          limit: query.limit
          edns: path.edns
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/as112/top/locations/ip_version/{ip_version}'].get
  update:
    x-apievangelist-phrasing:
      intent: Rank locations by AS112 queries over an IP version
      effect: read
      questions:
      - Which countries send the most IPv6 queries to AS112?
      - Where does most IPv4 AS112 DNS traffic come from?
      instructions:
      - text: Rank locations by AS112 queries sent over {ip_version}.
        slots:
          ip_version: path.ip_version
      - text: List the top {limit} countries for AS112 lookups on {ip_version}.
        slots:
          limit: query.limit
          ip_version: path.ip_version
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/summary'].get
  update:
    x-apievangelist-phrasing:
      intent: Summarize layer 3/4 attacks by network protocol
      effect: read
      questions:
      - What share of network-layer DDoS attacks use UDP, TCP, ICMP or GRE?
      - Can I get an overall protocol breakdown of layer 3/4 attacks for a country?
      instructions:
      - text: Summarize layer 3/4 attacks by network protocol for {location}.
        slots:
          location: query.location
      - text: Give me the L3/4 attack protocol mix over {dateRange}.
        slots:
          dateRange: query.dateRange
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/summary/bitrate'].get
  update:
    x-apievangelist-phrasing:
      intent: Summarize layer 3/4 attacks by bitrate
      effect: read
      questions:
      - How big are most network-layer DDoS attacks in bits per second?
      - What share of layer 3 attacks exceed high bitrate bands?
      instructions:
      - text: Summarize L3/4 attack sizes by bitrate for {location}.
        slots:
          location: query.location
      - text: Break down {protocol} layer 3 attacks by bitrate band.
        slots:
          protocol: query.protocol
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/summary/duration'].get
  update:
    x-apievangelist-phrasing:
      intent: Summarize layer 3/4 attacks by duration
      effect: read
      questions:
      - How long do network-layer DDoS attacks usually last?
      - What share of layer 3 attacks run longer than an hour?
      instructions:
      - text: Summarize how long L3/4 attacks lasted in {location}.
        slots:
          location: query.location
      - text: Break down layer 3 attack durations for {dateRange}.
        slots:
          dateRange: query.dateRange
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/summary/ip_version'].get
  update:
    x-apievangelist-phrasing:
      intent: Summarize layer 3/4 attacks by IP version
      effect: read
      questions:
      - What share of network-layer attacks come over IPv6?
      - Are layer 3 attacks mostly IPv4?
      instructions:
      - text: Summarize L3/4 attacks by IPv4 vs IPv6 for {location}.
        slots:
          location: query.location
      - text: Show the IP version split of {protocol} layer 3 attacks.
        slots:
          protocol: query.protocol
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/summary/protocol'].get
  update:
    x-apievangelist-phrasing:
      intent: Summarize layer 3/4 attacks by protocol used
      effect: read
      questions:
      - Which protocol do most layer 3 attacks on IPv6 use?
      - Can I filter the layer 3 attack protocol breakdown by attack direction?
      instructions:
      - text: Show the protocol share of L3/4 attacks in {direction} direction.
        slots:
          direction: query.direction
      - text: Summarize protocols used in {ipVersion} layer 3 attacks.
        slots:
          ipVersion: query.ipVersion
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/summary/vector'].get
  update:
    x-apievangelist-phrasing:
      intent: Summarize layer 3/4 attacks by attack vector
      effect: read
      questions:
      - What are the most common network-layer attack vectors, like SYN floods?
      - Which DDoS vectors dominate layer 3 attacks against one country?
      instructions:
      - text: Summarize L3/4 attack vectors targeting {location}.
        slots:
          location: query.location
      - text: Break down layer 3 attack vectors over {dateRange}.
        slots:
          dateRange: query.dateRange
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/timeseries'].get
  update:
    x-apievangelist-phrasing:
      intent: Chart layer 3/4 attack volume over time
      effect: read
      questions:
      - How has network-layer DDoS attack volume changed over time?
      - Can I chart layer 3 attacks by bytes or by packets?
      instructions:
      - text: Chart L3/4 attack volume in {location} over {dateRange}.
        slots:
          location: query.location
          dateRange: query.dateRange
      - text: Plot layer 3 attack traffic measured by {metric}.
        slots:
          metric: query.metric
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/timeseries_groups'].get
  update:
    x-apievangelist-phrasing:
      intent: Track layer 3/4 attack protocols over time
      effect: read
      questions:
      - How has the network protocol mix of layer 3/4 attacks shifted over time?
      - Can I trend UDP versus TCP DDoS attacks week by week?
      instructions:
      - text: Trend the protocol mix of L3/4 attacks in {location} over {dateRange}.
        slots:
          location: query.location
          dateRange: query.dateRange
      - text: Chart layer 3 attack protocols per {aggInterval}.
        slots:
          aggInterval: query.aggInterval
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/timeseries_groups/bitrate'].get
  update:
    x-apievangelist-phrasing:
      intent: Track layer 3/4 attack bitrates over time
      effect: read
      questions:
      - Are network-layer attacks getting bigger in bitrate over time?
      - Can I trend DDoS attack sizes by bitrate band?
      instructions:
      - text: Trend L3/4 attack bitrates in {location} across {dateRange}.
        slots:
          location: query.location
          dateRange: query.dateRange
      - text: Chart {protocol} attack bitrate bands over time.
        slots:
          protocol: query.protocol
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/timeseries_groups/duration'].get
  update:
    x-apievangelist-phrasing:
      intent: Track layer 3/4 attack durations over time
      effect: read
      questions:
      - Are network-layer DDoS attacks getting longer or shorter over time?
      - Can I trend attack durations for a specific country?
      instructions:
      - text: Trend L3/4 attack durations in {location} over {dateRange}.
        slots:
          location: query.location
          dateRange: query.dateRange
      - text: Chart layer 3 attack length buckets per {aggInterval}.
        slots:
          aggInterval: query.aggInterval
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/timeseries_groups/industry'].get
  update:
    x-apievangelist-phrasing:
      intent: Track layer 3/4 attacks by targeted industry
      effect: read
      questions:
      - Which industries have been hit hardest by network-layer DDoS over time?
      - Can I trend layer 3 attacks against gaming or finance industries?
      instructions:
      - text: Trend L3/4 attacks by target industry over {dateRange}.
        slots:
          dateRange: query.dateRange
      - text: Chart the top {limitPerGroup} industries hit by layer 3 attacks in {location}.
        slots:
          limitPerGroup: query.limitPerGroup
          location: query.location
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/timeseries_groups/ip_version'].get
  update:
    x-apievangelist-phrasing:
      intent: Track layer 3/4 attacks by IP version over time
      effect: read
      questions:
      - Is the IPv6 share of network-layer attacks growing?
      - Can I get a time series of layer 3 attacks split by IPv4 and IPv6?
      instructions:
      - text: Trend IPv4 vs IPv6 L3/4 attacks in {location} over {dateRange}.
        slots:
          location: query.location
          dateRange: query.dateRange
      - text: Chart the IP version mix of {protocol} layer 3 attacks.
        slots:
          protocol: query.protocol
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/timeseries_groups/protocol'].get
  update:
    x-apievangelist-phrasing:
      intent: Track layer 3/4 attacks by protocol over time
      effect: read
      questions:
      - Which protocols have network attackers leaned on over the last quarter?
      - Can I trend attack protocol share for IPv6-only layer 3 attacks?
      instructions:
      - text: Trend protocols used in {ipVersion} L3/4 attacks over {dateRange}.
        slots:
          ipVersion: query.ipVersion
          dateRange: query.dateRange
      - text: Chart per-protocol layer 3 attack share with {direction} direction.
        slots:
          direction: query.direction
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/timeseries_groups/vector'].get
  update:
    x-apievangelist-phrasing:
      intent: Track layer 3/4 attack vectors over time
      effect: read
      questions:
      - How have DDoS attack vectors like SYN or DNS floods trended over time?
      - Can I see which network attack vectors are rising?
      instructions:
      - text: Trend L3/4 attack vectors against {location} over {dateRange}.
        slots:
          location: query.location
          dateRange: query.dateRange
      - text: Chart the top {limitPerGroup} layer 3 attack vectors over time.
        slots:
          limitPerGroup: query.limitPerGroup
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/timeseries_groups/vertical'].get
  update:
    x-apievangelist-phrasing:
      intent: Track layer 3/4 attacks by targeted vertical
      effect: read
      questions:
      - Which business verticals are network-layer attacks targeting over time?
      - Can I trend layer 3 DDoS by vertical for one country?
      instructions:
      - text: Trend L3/4 attacks by target vertical in {location}.
        slots:
          location: query.location
      - text: Chart the top {limitPerGroup} verticals hit by layer 3 attacks over {dateRange}.
        slots:
          limitPerGroup: query.limitPerGroup
          dateRange: query.dateRange
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/top/attacks'].get
  update:
    x-apievangelist-phrasing:
      intent: Rank origin-to-target pairs of layer 3/4 attacks
      effect: read
      questions:
      - Which country pairs see the most network-layer attacks from one to the other?
      - Where do layer 3 attacks come from and where do they land?
      instructions:
      - text: List the top {limit} origin-target location pairs for L3/4 attacks.
        slots:
          limit: query.limit
      - text: Show layer 3 attack pairs involving {location} over {dateRange}.
        slots:
          location: query.location
          dateRange: query.dateRange
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/top/industry'].get
  update:
    x-apievangelist-phrasing:
      intent: Rank industries targeted by layer 3/4 attacks
      effect: read
      questions:
      - Which industry receives the most network-layer DDoS attacks?
      - What are the top industries targeted by layer 3 attacks in a country?
      instructions:
      - text: Rank industries by L3/4 attacks received in {location}.
        slots:
          location: query.location
      - text: List the top {limit} industries hit by layer 3 attacks.
        slots:
          limit: query.limit
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/top/locations/origin'].get
  update:
    x-apievangelist-phrasing:
      intent: Rank source countries of layer 3/4 attacks
      effect: read
      questions:
      - Which countries launch the most network-layer DDoS attacks?
      - Where do most layer 3 attacks originate from?
      instructions:
      - text: List the top {limit} origin countries of L3/4 attacks.
        slots:
          limit: query.limit
      - text: Rank layer 3 attack sources for {protocol} traffic over {dateRange}.
        slots:
          protocol: query.protocol
          dateRange: query.dateRange
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/top/locations/target'].get
  update:
    x-apievangelist-phrasing:
      intent: Rank target countries of layer 3/4 attacks
      effect: read
      questions:
      - Which countries are targeted most by network-layer attacks?
      - What locations receive the most layer 3 DDoS traffic?
      instructions:
      - text: List the top {limit} targeted countries for L3/4 attacks.
        slots:
          limit: query.limit
      - text: Rank layer 3 attack targets for {ipVersion} traffic over {dateRange}.
        slots:
          ipVersion: query.ipVersion
          dateRange: query.dateRange
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer3/top/vertical'].get
  update:
    x-apievangelist-phrasing:
      intent: Rank verticals targeted by layer 3/4 attacks
      effect: read
      questions:
      - Which business verticals are most targeted by network-layer DDoS?
      - Can I rank layer 3 attack victims by vertical for one country?
      instructions:
      - text: Rank verticals by L3/4 attacks received in {location}.
        slots:
          location: query.location
      - text: List the top {limit} verticals hit by layer 3 attacks over {dateRange}.
        slots:
          limit: query.limit
          dateRange: query.dateRange
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer7/summary'].get
  update:
    x-apievangelist-phrasing:
      intent: Summarize application-layer attacks by mitigation technique
      effect: read
      questions:
      - Which mitigation techniques stop most application-layer (layer 7) attacks?
      - What share of HTTP attacks are handled by the WAF versus DDoS rules?
      instructions:
      - text: Summarize layer 7 attacks by mitigation technique for {location}.
        slots:
          location: query.location
      - text: Give me the L7 mitigation technique split over {dateRange}.
        slots:
          dateRange: query.dateRange
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer7/summary/http_method'].get
  update:
    x-apievangelist-phrasing:
      intent: Summarize layer 7 attacks by HTTP method
      effect: read
      questions:
      - Do most HTTP attacks use GET or POST requests?
      - What is the HTTP method breakdown of application-layer attacks?
      instructions:
      - text: Summarize layer 7 attacks by HTTP method in {location}.
        slots:
          location: query.location
      - text: Break down HTTP methods in attacks caught by {mitigationProduct}.
        slots:
          mitigationProduct: query.mitigationProduct
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer7/summary/http_version'].get
  update:
    x-apievangelist-phrasing:
      intent: Summarize layer 7 attacks by HTTP version
      effect: read
      questions:
      - Are application-layer attacks mostly over HTTP/1.1, HTTP/2 or HTTP/3?
      - What share of web attacks use HTTP/2?
      instructions:
      - text: Summarize layer 7 attacks by HTTP version for {location}.
        slots:
          location: query.location
      - text: Break down {httpMethod} attacks by HTTP version.
        slots:
          httpMethod: query.httpMethod
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer7/summary/ip_version'].get
  update:
    x-apievangelist-phrasing:
      intent: Summarize layer 7 attacks by IP version
      effect: read
      questions:
      - What share of HTTP-layer attacks arrive over IPv6?
      - Is the IPv4/IPv6 mix of web attacks different for one mitigation product?
      instructions:
      - text: Summarize application-layer attacks by IPv4 vs IPv6 in {location}.
        slots:
          location: query.location
      - text: Show the IP version split of web attacks mitigated by {mitigationProduct}.
        slots:
          mitigationProduct: query.mitigationProduct
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer7/summary/managed_rules'].get
  update:
    x-apievangelist-phrasing:
      intent: Summarize layer 7 attacks by managed rule
      effect: read
      questions:
      - Which WAF managed rule categories catch the most web attacks?
      - What share of HTTP attacks are blocked by managed rules like SQL injection or XSS?
      instructions:
      - text: Summarize layer 7 attacks by managed rule for {location}.
        slots:
          location: query.location
      - text: Break down managed rule hits in attacks over {dateRange}.
        slots:
          dateRange: query.dateRange
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer7/summary/mitigation_product'].get
  update:
    x-apievangelist-phrasing:
      intent: Summarize layer 7 attacks by mitigation product
      effect: read
      questions:
      - Which Cloudflare product mitigates the largest share of HTTP attacks?
      - What percentage of web attacks are stopped by bot management versus the WAF?
      instructions:
      - text: Summarize layer 7 attacks by mitigation product in {location}.
        slots:
          location: query.location
      - text: Break down {httpMethod} attacks by the product that mitigated them.
        slots:
          httpMethod: query.httpMethod
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer7/timeseries'].get
  update:
    x-apievangelist-phrasing:
      intent: Chart application-layer attack volume over time
      effect: read
      questions:
      - How has the volume of HTTP-layer attacks changed over time?
      - Can I chart layer 7 attack requests normalized over a date range?
      instructions:
      - text: Chart layer 7 attack volume in {location} over {dateRange}.
        slots:
          location: query.location
          dateRange: query.dateRange
      - text: Plot application-layer attack requests using {normalization} normalization.
        slots:
          normalization: query.normalization
      method: generated
      generated: '2026-09-26'
- target: $.paths['/radar/attacks/layer7/timeseries_groups'].get
  update:
    x-apievangelist-phrasing:
      intent: Track layer 7 mitigation techniques over time
      effect: read
      questions:
      - How has the mix of layer 7 mitigation techniques changed over time?
      - Can I trend WAF versus DDoS mitigation of HTTP attacks?
      instructions:
      - text: Trend layer 7 mitigation techniques in {location} over {dateRange}.
        slots:
          location: query.location
          dateRange: query.dateRange
      - text: Chart L7 mitigation technique shares per {aggInterval}.
        slots:
          aggInterval: query.aggInterval
      method: generated
      generated: '2026-09-26'


# --- truncated at 32 KB (110 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cloudflare/refs/heads/main/overlays/cloudflare-radar-api-phrasing-overlay.yaml