Elastic Stack · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Kibana Alerting V2 API

53 actions 53 updates phrasing extends openapi/elk-stack-alerting-v2-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 53 · first 16 shown; the file carries all of them

$.info
$.paths['/api/alerting/v2/action_policies'].get
$.paths['/api/alerting/v2/action_policies'].post
$.paths['/api/alerting/v2/action_policies/_bulk_delete'].post
$.paths['/api/alerting/v2/action_policies/_bulk_disable'].post
$.paths['/api/alerting/v2/action_policies/_bulk_enable'].post
$.paths['/api/alerting/v2/action_policies/_bulk_snooze'].post
$.paths['/api/alerting/v2/action_policies/_bulk_unsnooze'].post
$.paths['/api/alerting/v2/action_policies/_bulk_update_api_key'].post
$.paths['/api/alerting/v2/action_policies/_match_for_rule'].post
$.paths['/api/alerting/v2/action_policies/{id}'].get
$.paths['/api/alerting/v2/action_policies/{id}'].put
$.paths['/api/alerting/v2/action_policies/{id}'].delete
$.paths['/api/alerting/v2/action_policies/{id}'].patch
$.paths['/api/alerting/v2/action_policies/{id}/_disable'].post
$.paths['/api/alerting/v2/action_policies/{id}/_enable'].post

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Kibana Alerting V2 API
  version: 1.0.0
extends: openapi/elk-stack-alerting-v2-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 52
- target: $.paths['/api/alerting/v2/action_policies'].get
  update:
    x-apievangelist-phrasing:
      intent: List alerting action policies
      effect: read
      questions:
      - Which action policies are set up to route my Kibana alerts to destinations?
      - Can I filter the action policy list to only the enabled ones with a given tag?
      instructions:
      - text: List all my alerting action policies.
      - text: Show enabled action policies tagged {tags}, sorted by {sort_field}.
        slots:
          tags: query.tags
          sort_field: query.sort_field
      - text: Find action policies whose name matches {search}.
        slots:
          search: query.search
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an action policy with a generated ID
      effect: write
      questions:
      - How do I create a new action policy that sends matching alerts to a destination?
      - Can a new action policy group alerts by fields before notifying?
      instructions:
      - text: Create a new action policy named {name} described as {description} that notifies {destinations}.
        slots:
          name: requestBody.name
          description: requestBody.description
          destinations: requestBody.destinations
      - text: Add an action policy {name} that only matches alerts where {matcher}, sending to {destinations} with description {description}.
        slots:
          name: requestBody.name
          matcher: requestBody.matcher
          destinations: requestBody.destinations
          description: requestBody.description
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/_bulk_delete'].post
  update:
    x-apievangelist-phrasing:
      intent: Delete several action policies at once
      effect: destructive
      questions:
      - Can I remove a batch of action policies in one request instead of one by one?
      - What happens to many obsolete action policies if I bulk delete them by ID?
      instructions:
      - text: Bulk delete the action policies with IDs {ids}.
        slots:
          ids: requestBody.ids
      - text: 'Remove all of these action policies in one call: {ids}.'
        slots:
          ids: requestBody.ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/_bulk_disable'].post
  update:
    x-apievangelist-phrasing:
      intent: Disable several action policies at once
      effect: write
      questions:
      - Is there a way to turn off a whole set of action policies in a single call?
      - Can I pause notifications from multiple action policies by listing their IDs?
      instructions:
      - text: Bulk disable the action policies {ids}.
        slots:
          ids: requestBody.ids
      - text: 'Turn off every action policy in this ID list: {ids}.'
        slots:
          ids: requestBody.ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/_bulk_enable'].post
  update:
    x-apievangelist-phrasing:
      intent: Enable several action policies at once
      effect: write
      questions:
      - Can I switch a group of disabled action policies back on together?
      - Which call re-enables multiple action policies by ID in one go?
      instructions:
      - text: Bulk enable the action policies {ids}.
        slots:
          ids: requestBody.ids
      - text: 'Turn back on every action policy in this ID list: {ids}.'
        slots:
          ids: requestBody.ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/_bulk_snooze'].post
  update:
    x-apievangelist-phrasing:
      intent: Snooze several action policies until a time
      effect: write
      questions:
      - Can I silence many action policies until a maintenance window ends?
      - How do I snooze a list of action policies until a specific date and time?
      instructions:
      - text: Snooze action policies {ids} until {snoozed_until}.
        slots:
          ids: requestBody.ids
          snoozed_until: requestBody.snoozed_until
      - text: 'Silence all of these action policies until {snoozed_until}: {ids}.'
        slots:
          snoozed_until: requestBody.snoozed_until
          ids: requestBody.ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/_bulk_unsnooze'].post
  update:
    x-apievangelist-phrasing:
      intent: Cancel the snooze on several action policies
      effect: write
      questions:
      - Can I end the snooze early on a batch of action policies?
      - What call wakes up multiple snoozed action policies at once?
      instructions:
      - text: Bulk unsnooze the action policies {ids}.
        slots:
          ids: requestBody.ids
      - text: Cancel the snooze on every action policy in {ids} so they notify again.
        slots:
          ids: requestBody.ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/_bulk_update_api_key'].post
  update:
    x-apievangelist-phrasing:
      intent: Rotate API keys for several action policies
      effect: write
      questions:
      - Can I rotate the API keys of many action policies in one request?
      - After a credential change, how do I refresh the keys on a list of action policies?
      instructions:
      - text: Rotate the API keys for action policies {ids}.
        slots:
          ids: requestBody.ids
      - text: Bulk refresh the stored API key on each action policy in {ids}.
        slots:
          ids: requestBody.ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/_match_for_rule'].post
  update:
    x-apievangelist-phrasing:
      intent: Find action policies that apply to a rule
      effect: read
      questions:
      - Which action policies would fire for a given alerting rule?
      - Can I see whether a rule is covered by direct, global or global-filtered action policies?
      instructions:
      - text: Show the action policies that match rule {rule}.
        slots:
          rule: requestBody.rule
      - text: Check which direct and global action policies apply to rule {rule}.
        slots:
          rule: requestBody.rule
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an action policy
      effect: read
      questions:
      - What destinations and matcher does a specific action policy use?
      - Can I look up one action policy's full configuration by its ID?
      instructions:
      - text: Get action policy {id}.
        slots:
          id: path.id
      - text: Show me the destinations and grouping of action policy {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/{id}'].put
  update:
    x-apievangelist-phrasing:
      intent: Create or fully replace an action policy by ID
      effect: write
      questions:
      - Can I create an action policy with my own chosen identifier?
      - How do I overwrite an existing action policy's whole configuration in one request?
      instructions:
      - text: Create or replace action policy {id} named {name}, described as {description}, sending to {destinations}.
        slots:
          id: path.id
          name: requestBody.name
          description: requestBody.description
          destinations: requestBody.destinations
      - text: Fully replace action policy {id} so it is named {name} with description {description} and destinations {destinations}.
        slots:
          id: path.id
          name: requestBody.name
          description: requestBody.description
          destinations: requestBody.destinations
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/{id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an action policy
      effect: destructive
      questions:
      - How do I permanently remove a single action policy?
      - Can I delete one action policy I no longer need by its ID?
      instructions:
      - text: Delete action policy {id}.
        slots:
          id: path.id
      - text: Remove the action policy with ID {id} permanently.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/{id}'].patch
  update:
    x-apievangelist-phrasing:
      intent: Partially update an action policy
      effect: write
      questions:
      - Can I change just one field of an action policy and leave the rest unchanged?
      - Why does a partial action policy update need the current version number?
      instructions:
      - text: Rename action policy {id} to {name}, using version {version}.
        slots:
          id: path.id
          name: requestBody.name
          version: requestBody.version
      - text: Patch action policy {id} at version {version} so its throttle is {throttle}.
        slots:
          id: path.id
          version: requestBody.version
          throttle: requestBody.throttle
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/{id}/_disable'].post
  update:
    x-apievangelist-phrasing:
      intent: Disable an action policy
      effect: write
      questions:
      - How do I turn off a single action policy without deleting it?
      - Can I stop one action policy from sending notifications for now?
      instructions:
      - text: Disable action policy {id}.
        slots:
          id: path.id
      - text: Switch off the action policy {id} but keep its configuration.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/{id}/_enable'].post
  update:
    x-apievangelist-phrasing:
      intent: Enable an action policy
      effect: write
      questions:
      - How do I turn a disabled action policy back on?
      - Can I reactivate a single action policy by ID?
      instructions:
      - text: Enable action policy {id}.
        slots:
          id: path.id
      - text: Turn the action policy {id} back on so it notifies again.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/{id}/_snooze'].post
  update:
    x-apievangelist-phrasing:
      intent: Snooze an action policy until a time
      effect: write
      questions:
      - Can I mute one action policy until a certain date?
      - How long can a single action policy stay snoozed?
      instructions:
      - text: Snooze action policy {id} until {snoozed_until}.
        slots:
          id: path.id
          snoozed_until: requestBody.snoozed_until
      - text: Quiet the action policy {id} until {snoozed_until} during maintenance.
        slots:
          id: path.id
          snoozed_until: requestBody.snoozed_until
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/{id}/_unsnooze'].post
  update:
    x-apievangelist-phrasing:
      intent: Remove the snooze from an action policy
      effect: write
      questions:
      - How do I end the snooze on one action policy early?
      - Can I unsnooze a single action policy so it resumes notifying?
      instructions:
      - text: Unsnooze action policy {id}.
        slots:
          id: path.id
      - text: Clear the snooze on the action policy {id} right now.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/{id}/_update_api_key'].post
  update:
    x-apievangelist-phrasing:
      intent: Rotate the API key of one action policy
      effect: write
      questions:
      - How do I rotate the API key for a single action policy?
      - Can I refresh the credentials one action policy runs with?
      instructions:
      - text: Rotate the API key for action policy {id}.
        slots:
          id: path.id
      - text: Update the API key used by the action policy {id} to my current credentials.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/tags'].get
  update:
    x-apievangelist-phrasing:
      intent: List tags used on action policies
      effect: read
      questions:
      - Which tags are in use across my action policies?
      - Can I search the distinct tags on action policies by prefix?
      instructions:
      - text: List the unique tags used by action policies.
      - text: Show action policy tags matching {search}.
        slots:
          search: query.search
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/alerts/_bulk_action'].post
  update:
    x-apievangelist-phrasing:
      intent: Apply actions to many alert groups at once
      effect: write
      questions:
      - Can I acknowledge or tag many alert groups in a single request?
      - Is there a bulk endpoint for creating actions across multiple alert groups?
      instructions:
      - text: Apply bulk alert actions across multiple alert groups, sending kbn-xsrf header {kbn_xsrf}.
        slots:
          kbn_xsrf: header.kbn-xsrf
      - text: Run one batch of alert group actions in a single request.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/alerts/{group_hash}/_ack'].post
  update:
    x-apievangelist-phrasing:
      intent: Acknowledge an alert group
      effect: write
      questions:
      - How do I acknowledge an alert so the team knows someone is on it?
      - Does acknowledging an alert need the episode ID?
      instructions:
      - text: Acknowledge alert group {group_hash} for episode {episode_id}.
        slots:
          group_hash: path.group_hash
          episode_id: requestBody.episode_id
      - text: Mark episode {episode_id} of alert {group_hash} as acknowledged.
        slots:
          episode_id: requestBody.episode_id
          group_hash: path.group_hash
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/alerts/{group_hash}/_activate'].post
  update:
    x-apievangelist-phrasing:
      intent: Activate an alert group with a reason
      effect: write
      questions:
      - Can I manually reactivate an alert group and record why?
      - What reason do I have to give when activating an alert?
      instructions:
      - text: Activate alert group {group_hash} because {reason}.
        slots:
          group_hash: path.group_hash
          reason: requestBody.reason
      - text: Set alert {group_hash} active again with the reason {reason}.
        slots:
          group_hash: path.group_hash
          reason: requestBody.reason
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/alerts/{group_hash}/_assign'].post
  update:
    x-apievangelist-phrasing:
      intent: Assign an alert to a user
      effect: write
      questions:
      - How do I assign an alert to a specific teammate?
      - Can I hand ownership of an alert episode to another user?
      instructions:
      - text: Assign alert group {group_hash} episode {episode_id} to user {assignee_uid}.
        slots:
          group_hash: path.group_hash
          episode_id: requestBody.episode_id
          assignee_uid: requestBody.assignee_uid
      - text: Make {assignee_uid} the owner of episode {episode_id} on alert {group_hash}.
        slots:
          assignee_uid: requestBody.assignee_uid
          episode_id: requestBody.episode_id
          group_hash: path.group_hash
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/alerts/{group_hash}/_deactivate'].post
  update:
    x-apievangelist-phrasing:
      intent: Deactivate an alert group with a reason
      effect: write
      questions:
      - Can I manually deactivate an alert group that is no longer relevant?
      - Do I need to explain why when I deactivate an alert?
      instructions:
      - text: Deactivate alert group {group_hash} because {reason}.
        slots:
          group_hash: path.group_hash
          reason: requestBody.reason
      - text: Set alert {group_hash} inactive with the reason {reason}.
        slots:
          group_hash: path.group_hash
          reason: requestBody.reason
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/alerts/{group_hash}/_snooze'].post
  update:
    x-apievangelist-phrasing:
      intent: Snooze an alert group
      effect: write
      questions:
      - Can I snooze a single noisy alert group until a set time?
      - Is an expiry optional when snoozing an alert?
      instructions:
      - text: Snooze alert group {group_hash} until {expiry}.
        slots:
          group_hash: path.group_hash
          expiry: requestBody.expiry
      - text: Snooze the alert {group_hash} with no expiry.
        slots:
          group_hash: path.group_hash
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/alerts/{group_hash}/_tag'].post
  update:
    x-apievangelist-phrasing:
      intent: Tag an alert group
      effect: write
      questions:
      - How do I label an alert with tags for triage?
      - Can I add several tags to one alert group at once?
      instructions:
      - text: Add tags {tags} to alert group {group_hash}.
        slots:
          tags: requestBody.tags
          group_hash: path.group_hash
      - text: Tag the alert {group_hash} with {tags}.
        slots:
          group_hash: path.group_hash
          tags: requestBody.tags
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/alerts/{group_hash}/_unack'].post
  update:
    x-apievangelist-phrasing:
      intent: Unacknowledge an alert group
      effect: write
      questions:
      - Can I take back an acknowledgement on an alert?
      - How do I mark an acknowledged alert episode as unhandled again?
      instructions:
      - text: Unacknowledge alert group {group_hash} for episode {episode_id}.
        slots:
          group_hash: path.group_hash
          episode_id: requestBody.episode_id
      - text: Remove my acknowledgement from episode {episode_id} of alert {group_hash}.
        slots:
          episode_id: requestBody.episode_id
          group_hash: path.group_hash
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/alerts/{group_hash}/_unsnooze'].post
  update:
    x-apievangelist-phrasing:
      intent: Unsnooze an alert group
      effect: write
      questions:
      - How do I end the snooze on one alert group early?
      - Can a snoozed alert group start notifying again before its expiry?
      instructions:
      - text: Unsnooze alert group {group_hash}.
        slots:
          group_hash: path.group_hash
      - text: Wake the snoozed alert {group_hash} back up.
        slots:
          group_hash: path.group_hash
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/execution_history/action_policies'].get
  update:
    x-apievangelist-phrasing:
      intent: List action policy execution history
      effect: read
      questions:
      - Did my action policies actually dispatch notifications recently?
      - Can I filter action policy executions by rule and outcome?
      instructions:
      - text: List action policy dispatch events in this space.
      - text: Show action policy executions for rules {rule_ids} with outcome {outcome} since {start_date}.
        slots:
          rule_ids: query.rule_ids
          outcome: query.outcome
          start_date: query.start_date
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/execution_history/rules'].get
  update:
    x-apievangelist-phrasing:
      intent: List rule execution events
      effect: read
      questions:
      - When did my alerting rules last run and did they fail?
      - Can I page through rule execution history between two dates?
      instructions:
      - text: List rule executions sorted by {sort} {sort_order}, page {page} with {per_page} per page.
        slots:
          sort: query.sort
          sort_order: query.sort_order
          page: query.page
          per_page: query.per_page
      - text: Show failed runs of rules {rule_ids} from {from} to {to}, sorted by {sort} {sort_order}, page {page} of {per_page}.
        slots:
          rule_ids: query.rule_ids
          from: query.from
          to: query.to
          sort: query.sort
          sort_order: query.sort_order
          page: query.page
          per_page: query.per_page
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules'].get
  update:
    x-apievangelist-phrasing:
      intent: List alerting rules
      effect: read
      questions:
      - What alerting rules exist in my Kibana space?
      - Can I filter and sort the rule list by a KQL filter?
      instructions:
      - text: List my alerting rules.
      - text: Find rules matching {search}, sorted by {sort_field}.
        slots:
          search: query.search
          sort_field: query.sort_field
      - text: List rules that match the filter {filter}.
        slots:
          filter: query.filter
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an alerting rule with a generated ID
      effect: write
      questions:
      - How do I create a new alerting rule that runs a query on a schedule?
      - What does a new rule need besides its query and schedule?
      instructions:
      - text: Create a new {kind} rule with metadata {metadata} that runs {query} on schedule {schedule}.
        slots:
          kind: requestBody.kind
          metadata: requestBody.metadata
          query: requestBody.query
          schedule: requestBody.schedule
      - text: Add a rule of kind {kind} running query {query} every {schedule}, metadata {metadata}, grouped by {grouping}.
        slots:
          kind: requestBody.kind
          query: requestBody.query
          schedule: requestBody.schedule
          metadata: requestBody.metadata
          grouping: requestBody.grouping
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/_bulk_delete'].post
  update:
    x-apievangelist-phrasing:
      intent: Delete several rules by ID
      effect: destructive
      questions:
      - Can I delete a list of alerting rules in one request?
      - What is the quickest way to remove many rules when I already know their IDs?
      instructions:
      - text: Bulk delete the rules {ids}.
        slots:
          ids: requestBody.ids
      - text: 'Remove every rule in this ID list: {ids}.'
        slots:
          ids: requestBody.ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/_bulk_disable'].post
  update:
    x-apievangelist-phrasing:
      intent: Disable several rules by ID
      effect: write
      questions:
      - Can I switch off a specific list of rules together?
      - Which call pauses many alerting rules when I have their IDs?
      instructions:
      - text: Bulk disable the rules {ids}.
        slots:
          ids: requestBody.ids
      - text: 'Pause every rule in this ID list: {ids}.'
        slots:
          ids: requestBody.ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/_bulk_enable'].post
  update:
    x-apievangelist-phrasing:
      intent: Enable several rules by ID
      effect: write
      questions:
      - Can I turn on a specific list of disabled rules at once?
      - Which call resumes many alerting rules when I have their IDs?
      instructions:
      - text: Bulk enable the rules {ids}.
        slots:
          ids: requestBody.ids
      - text: 'Resume every rule in this ID list: {ids}.'
        slots:
          ids: requestBody.ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/_bulk_get'].post
  update:
    x-apievangelist-phrasing:
      intent: Fetch several rules by ID
      effect: read
      questions:
      - Can I fetch the definitions of several rules in one request?
      - Is there a batch lookup for alerting rules by ID?
      instructions:
      - text: Get the rules {ids} in one request.
        slots:
          ids: requestBody.ids
      - text: Look up the configurations of rules {ids}.
        slots:
          ids: requestBody.ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/_bulk_update_api_key'].post
  update:
    x-apievangelist-phrasing:
      intent: Rotate API keys for several rules by ID
      effect: write
      questions:
      - Can I rotate the executor API keys for a list of rules at once?
      - How do I move many rules onto my current credentials?
      instructions:
      - text: Rotate the API keys for rules {ids}.
        slots:
          ids: requestBody.ids
      - text: Re-key rules {ids} with credentials derived from my user.
        slots:
          ids: requestBody.ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/_delete_by_query'].post
  update:
    x-apievangelist-phrasing:
      intent: Delete rules matching a query
      effect: destructive
      questions:
      - Can I preview which rules a KQL filter would delete before deleting them?
      - What is the cap on rules processed per delete-by-query request?
      instructions:
      - text: Dry-run deleting the rules that match filter {filter}.
        slots:
          filter: requestBody.filter
      - text: Delete for real every rule whose text matches {search}, with force set to {force}.
        slots:
          search: requestBody.search
          force: requestBody.force
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/_disable_by_query'].post
  update:
    x-apievangelist-phrasing:
      intent: Disable rules matching a query
      effect: write
      questions:
      - Can I disable every rule that matches a KQL filter?
      - Does disabling rules by query default to a dry run?
      instructions:
      - text: Preview disabling the rules that match filter {filter}.
        slots:
          filter: requestBody.filter
      - text: Disable all rules matching search {search}, force {force}.
        slots:
          search: requestBody.search
          force: requestBody.force
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/_enable_by_query'].post
  update:
    x-apievangelist-phrasing:
      intent: Enable rules matching a query
      effect: write
      questions:
      - Can I enable every rule that matches a KQL filter?
      - How do I preview which rules enabling by query would touch?
      instructions:
      - text: Preview enabling the rules that match filter {filter}.
        slots:
          filter: requestBody.filter
      - text: Enable all rules matching search {search}, force {force}.
        slots:
          search: requestBody.search
          force: requestBody.force
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/_update_api_key_by_query'].post
  update:
    x-apievangelist-phrasing:
      intent: Rotate API keys for rules matching a query
      effect: write
      questions:
      - Can I rotate executor API keys on every rule that matches a filter?
      - Is there a dry run before re-keying rules selected by a query?
      instructions:
      - text: Preview rotating API keys on rules matching filter {filter}.
        slots:
          filter: requestBody.filter
      - text: Rotate API keys on all rules, with match_all {match_all} and force {force}.
        slots:
          match_all: requestBody.match_all
          force: requestBody.force
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an alerting rule
      effect: read
      questions:
      - What query and schedule does a specific rule use?
      - Can I look up one alerting rule by its ID?
      instructions:
      - text: Get rule {id}.
        slots:
          id: path.id
      - text: Show me the current definition of alerting rule {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/{id}'].put
  update:
    x-apievangelist-phrasing:
      intent: Create or fully replace a rule by ID
      effect: write
      questions:
      - Can I create an alerting rule with an identifier I choose myself?
      - How do I overwrite a rule's entire definition in one request?
      instructions:
      - text: Create or replace rule {id} as a {kind} rule running {query} on schedule {schedule} with metadata {metadata}.
        slots:
          id: path.id
          kind: requestBody.kind
          query: requestBody.query
          schedule: requestBody.schedule
          metadata: requestBody.metadata
      - text: 'Fully replace rule {id}: kind {kind}, query {query}, schedule {schedule}, metadata {metadata}.'
        slots:
          id: path.id
          kind: requestBody.kind
          query: requestBody.query
          schedule: requestBody.schedule
          metadata: requestBody.metadata
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/{id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an alerting rule
      effect: destructive
      questions:
      - How do I permanently delete one alerting rule?
      - Can I remove a single rule I no longer need by its ID?
      instructions:
      - text: Delete rule {id}.
        slots:
          id: path.id
      - text: Permanently remove the alerting rule {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/{id}'].patch
  update:
    x-apievangelist-phrasing:
      intent: Partially update an alerting rule
      effect: write
      questions:
      - Can I change just the schedule of a rule without resending everything?
      - Which rule fields can I patch in place?
      instructions:
      - text: Change the schedule of rule {id} to {schedule}.
        slots:
          id: path.id
          schedule: requestBody.schedule
      - text: Update rule {id} to use the query {query}.
        slots:
          id: path.id
          query: requestBody.query
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/{id}/_disable'].post
  update:
    x-apievangelist-phrasing:
      intent: Disable an alerting rule
      effect: write
      questions:
      - How do I stop one rule from running without deleting it?
      - Can I disable a single alerting rule by ID?
      instructions:
      - text: Disable rule {id}.
        slots:
          id: path.id
      - text: Stop the alerting rule {id} from running for now.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'


# --- truncated at 32 KB (35 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/elk-stack/refs/heads/main/overlays/elk-stack-alerting-v2-api-phrasing-overlay.yaml