Elastic Stack · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Kibana Alerting V2 API
53 actions
53 updates
phrasing
extends
openapi/elk-stack-alerting-v2-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
What the actions change
x-apievangelist-phrasing
Targets 53 · first 16 shown; the file carries all of them
$.info
$.paths['/api/alerting/v2/action_policies'].get
$.paths['/api/alerting/v2/action_policies'].post
$.paths['/api/alerting/v2/action_policies/_bulk_delete'].post
$.paths['/api/alerting/v2/action_policies/_bulk_disable'].post
$.paths['/api/alerting/v2/action_policies/_bulk_enable'].post
$.paths['/api/alerting/v2/action_policies/_bulk_snooze'].post
$.paths['/api/alerting/v2/action_policies/_bulk_unsnooze'].post
$.paths['/api/alerting/v2/action_policies/_bulk_update_api_key'].post
$.paths['/api/alerting/v2/action_policies/_match_for_rule'].post
$.paths['/api/alerting/v2/action_policies/{id}'].get
$.paths['/api/alerting/v2/action_policies/{id}'].put
$.paths['/api/alerting/v2/action_policies/{id}'].delete
$.paths['/api/alerting/v2/action_policies/{id}'].patch
$.paths['/api/alerting/v2/action_policies/{id}/_disable'].post
$.paths['/api/alerting/v2/action_policies/{id}/_enable'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Kibana Alerting V2 API
version: 1.0.0
extends: openapi/elk-stack-alerting-v2-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 52
- target: $.paths['/api/alerting/v2/action_policies'].get
update:
x-apievangelist-phrasing:
intent: List alerting action policies
effect: read
questions:
- Which action policies are set up to route my Kibana alerts to destinations?
- Can I filter the action policy list to only the enabled ones with a given tag?
instructions:
- text: List all my alerting action policies.
- text: Show enabled action policies tagged {tags}, sorted by {sort_field}.
slots:
tags: query.tags
sort_field: query.sort_field
- text: Find action policies whose name matches {search}.
slots:
search: query.search
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies'].post
update:
x-apievangelist-phrasing:
intent: Create an action policy with a generated ID
effect: write
questions:
- How do I create a new action policy that sends matching alerts to a destination?
- Can a new action policy group alerts by fields before notifying?
instructions:
- text: Create a new action policy named {name} described as {description} that notifies {destinations}.
slots:
name: requestBody.name
description: requestBody.description
destinations: requestBody.destinations
- text: Add an action policy {name} that only matches alerts where {matcher}, sending to {destinations} with description {description}.
slots:
name: requestBody.name
matcher: requestBody.matcher
destinations: requestBody.destinations
description: requestBody.description
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/_bulk_delete'].post
update:
x-apievangelist-phrasing:
intent: Delete several action policies at once
effect: destructive
questions:
- Can I remove a batch of action policies in one request instead of one by one?
- What happens to many obsolete action policies if I bulk delete them by ID?
instructions:
- text: Bulk delete the action policies with IDs {ids}.
slots:
ids: requestBody.ids
- text: 'Remove all of these action policies in one call: {ids}.'
slots:
ids: requestBody.ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/_bulk_disable'].post
update:
x-apievangelist-phrasing:
intent: Disable several action policies at once
effect: write
questions:
- Is there a way to turn off a whole set of action policies in a single call?
- Can I pause notifications from multiple action policies by listing their IDs?
instructions:
- text: Bulk disable the action policies {ids}.
slots:
ids: requestBody.ids
- text: 'Turn off every action policy in this ID list: {ids}.'
slots:
ids: requestBody.ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/_bulk_enable'].post
update:
x-apievangelist-phrasing:
intent: Enable several action policies at once
effect: write
questions:
- Can I switch a group of disabled action policies back on together?
- Which call re-enables multiple action policies by ID in one go?
instructions:
- text: Bulk enable the action policies {ids}.
slots:
ids: requestBody.ids
- text: 'Turn back on every action policy in this ID list: {ids}.'
slots:
ids: requestBody.ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/_bulk_snooze'].post
update:
x-apievangelist-phrasing:
intent: Snooze several action policies until a time
effect: write
questions:
- Can I silence many action policies until a maintenance window ends?
- How do I snooze a list of action policies until a specific date and time?
instructions:
- text: Snooze action policies {ids} until {snoozed_until}.
slots:
ids: requestBody.ids
snoozed_until: requestBody.snoozed_until
- text: 'Silence all of these action policies until {snoozed_until}: {ids}.'
slots:
snoozed_until: requestBody.snoozed_until
ids: requestBody.ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/_bulk_unsnooze'].post
update:
x-apievangelist-phrasing:
intent: Cancel the snooze on several action policies
effect: write
questions:
- Can I end the snooze early on a batch of action policies?
- What call wakes up multiple snoozed action policies at once?
instructions:
- text: Bulk unsnooze the action policies {ids}.
slots:
ids: requestBody.ids
- text: Cancel the snooze on every action policy in {ids} so they notify again.
slots:
ids: requestBody.ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/_bulk_update_api_key'].post
update:
x-apievangelist-phrasing:
intent: Rotate API keys for several action policies
effect: write
questions:
- Can I rotate the API keys of many action policies in one request?
- After a credential change, how do I refresh the keys on a list of action policies?
instructions:
- text: Rotate the API keys for action policies {ids}.
slots:
ids: requestBody.ids
- text: Bulk refresh the stored API key on each action policy in {ids}.
slots:
ids: requestBody.ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/_match_for_rule'].post
update:
x-apievangelist-phrasing:
intent: Find action policies that apply to a rule
effect: read
questions:
- Which action policies would fire for a given alerting rule?
- Can I see whether a rule is covered by direct, global or global-filtered action policies?
instructions:
- text: Show the action policies that match rule {rule}.
slots:
rule: requestBody.rule
- text: Check which direct and global action policies apply to rule {rule}.
slots:
rule: requestBody.rule
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get an action policy
effect: read
questions:
- What destinations and matcher does a specific action policy use?
- Can I look up one action policy's full configuration by its ID?
instructions:
- text: Get action policy {id}.
slots:
id: path.id
- text: Show me the destinations and grouping of action policy {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/{id}'].put
update:
x-apievangelist-phrasing:
intent: Create or fully replace an action policy by ID
effect: write
questions:
- Can I create an action policy with my own chosen identifier?
- How do I overwrite an existing action policy's whole configuration in one request?
instructions:
- text: Create or replace action policy {id} named {name}, described as {description}, sending to {destinations}.
slots:
id: path.id
name: requestBody.name
description: requestBody.description
destinations: requestBody.destinations
- text: Fully replace action policy {id} so it is named {name} with description {description} and destinations {destinations}.
slots:
id: path.id
name: requestBody.name
description: requestBody.description
destinations: requestBody.destinations
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete an action policy
effect: destructive
questions:
- How do I permanently remove a single action policy?
- Can I delete one action policy I no longer need by its ID?
instructions:
- text: Delete action policy {id}.
slots:
id: path.id
- text: Remove the action policy with ID {id} permanently.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/{id}'].patch
update:
x-apievangelist-phrasing:
intent: Partially update an action policy
effect: write
questions:
- Can I change just one field of an action policy and leave the rest unchanged?
- Why does a partial action policy update need the current version number?
instructions:
- text: Rename action policy {id} to {name}, using version {version}.
slots:
id: path.id
name: requestBody.name
version: requestBody.version
- text: Patch action policy {id} at version {version} so its throttle is {throttle}.
slots:
id: path.id
version: requestBody.version
throttle: requestBody.throttle
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/{id}/_disable'].post
update:
x-apievangelist-phrasing:
intent: Disable an action policy
effect: write
questions:
- How do I turn off a single action policy without deleting it?
- Can I stop one action policy from sending notifications for now?
instructions:
- text: Disable action policy {id}.
slots:
id: path.id
- text: Switch off the action policy {id} but keep its configuration.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/{id}/_enable'].post
update:
x-apievangelist-phrasing:
intent: Enable an action policy
effect: write
questions:
- How do I turn a disabled action policy back on?
- Can I reactivate a single action policy by ID?
instructions:
- text: Enable action policy {id}.
slots:
id: path.id
- text: Turn the action policy {id} back on so it notifies again.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/{id}/_snooze'].post
update:
x-apievangelist-phrasing:
intent: Snooze an action policy until a time
effect: write
questions:
- Can I mute one action policy until a certain date?
- How long can a single action policy stay snoozed?
instructions:
- text: Snooze action policy {id} until {snoozed_until}.
slots:
id: path.id
snoozed_until: requestBody.snoozed_until
- text: Quiet the action policy {id} until {snoozed_until} during maintenance.
slots:
id: path.id
snoozed_until: requestBody.snoozed_until
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/{id}/_unsnooze'].post
update:
x-apievangelist-phrasing:
intent: Remove the snooze from an action policy
effect: write
questions:
- How do I end the snooze on one action policy early?
- Can I unsnooze a single action policy so it resumes notifying?
instructions:
- text: Unsnooze action policy {id}.
slots:
id: path.id
- text: Clear the snooze on the action policy {id} right now.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/{id}/_update_api_key'].post
update:
x-apievangelist-phrasing:
intent: Rotate the API key of one action policy
effect: write
questions:
- How do I rotate the API key for a single action policy?
- Can I refresh the credentials one action policy runs with?
instructions:
- text: Rotate the API key for action policy {id}.
slots:
id: path.id
- text: Update the API key used by the action policy {id} to my current credentials.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/action_policies/tags'].get
update:
x-apievangelist-phrasing:
intent: List tags used on action policies
effect: read
questions:
- Which tags are in use across my action policies?
- Can I search the distinct tags on action policies by prefix?
instructions:
- text: List the unique tags used by action policies.
- text: Show action policy tags matching {search}.
slots:
search: query.search
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/alerts/_bulk_action'].post
update:
x-apievangelist-phrasing:
intent: Apply actions to many alert groups at once
effect: write
questions:
- Can I acknowledge or tag many alert groups in a single request?
- Is there a bulk endpoint for creating actions across multiple alert groups?
instructions:
- text: Apply bulk alert actions across multiple alert groups, sending kbn-xsrf header {kbn_xsrf}.
slots:
kbn_xsrf: header.kbn-xsrf
- text: Run one batch of alert group actions in a single request.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/alerts/{group_hash}/_ack'].post
update:
x-apievangelist-phrasing:
intent: Acknowledge an alert group
effect: write
questions:
- How do I acknowledge an alert so the team knows someone is on it?
- Does acknowledging an alert need the episode ID?
instructions:
- text: Acknowledge alert group {group_hash} for episode {episode_id}.
slots:
group_hash: path.group_hash
episode_id: requestBody.episode_id
- text: Mark episode {episode_id} of alert {group_hash} as acknowledged.
slots:
episode_id: requestBody.episode_id
group_hash: path.group_hash
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/alerts/{group_hash}/_activate'].post
update:
x-apievangelist-phrasing:
intent: Activate an alert group with a reason
effect: write
questions:
- Can I manually reactivate an alert group and record why?
- What reason do I have to give when activating an alert?
instructions:
- text: Activate alert group {group_hash} because {reason}.
slots:
group_hash: path.group_hash
reason: requestBody.reason
- text: Set alert {group_hash} active again with the reason {reason}.
slots:
group_hash: path.group_hash
reason: requestBody.reason
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/alerts/{group_hash}/_assign'].post
update:
x-apievangelist-phrasing:
intent: Assign an alert to a user
effect: write
questions:
- How do I assign an alert to a specific teammate?
- Can I hand ownership of an alert episode to another user?
instructions:
- text: Assign alert group {group_hash} episode {episode_id} to user {assignee_uid}.
slots:
group_hash: path.group_hash
episode_id: requestBody.episode_id
assignee_uid: requestBody.assignee_uid
- text: Make {assignee_uid} the owner of episode {episode_id} on alert {group_hash}.
slots:
assignee_uid: requestBody.assignee_uid
episode_id: requestBody.episode_id
group_hash: path.group_hash
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/alerts/{group_hash}/_deactivate'].post
update:
x-apievangelist-phrasing:
intent: Deactivate an alert group with a reason
effect: write
questions:
- Can I manually deactivate an alert group that is no longer relevant?
- Do I need to explain why when I deactivate an alert?
instructions:
- text: Deactivate alert group {group_hash} because {reason}.
slots:
group_hash: path.group_hash
reason: requestBody.reason
- text: Set alert {group_hash} inactive with the reason {reason}.
slots:
group_hash: path.group_hash
reason: requestBody.reason
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/alerts/{group_hash}/_snooze'].post
update:
x-apievangelist-phrasing:
intent: Snooze an alert group
effect: write
questions:
- Can I snooze a single noisy alert group until a set time?
- Is an expiry optional when snoozing an alert?
instructions:
- text: Snooze alert group {group_hash} until {expiry}.
slots:
group_hash: path.group_hash
expiry: requestBody.expiry
- text: Snooze the alert {group_hash} with no expiry.
slots:
group_hash: path.group_hash
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/alerts/{group_hash}/_tag'].post
update:
x-apievangelist-phrasing:
intent: Tag an alert group
effect: write
questions:
- How do I label an alert with tags for triage?
- Can I add several tags to one alert group at once?
instructions:
- text: Add tags {tags} to alert group {group_hash}.
slots:
tags: requestBody.tags
group_hash: path.group_hash
- text: Tag the alert {group_hash} with {tags}.
slots:
group_hash: path.group_hash
tags: requestBody.tags
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/alerts/{group_hash}/_unack'].post
update:
x-apievangelist-phrasing:
intent: Unacknowledge an alert group
effect: write
questions:
- Can I take back an acknowledgement on an alert?
- How do I mark an acknowledged alert episode as unhandled again?
instructions:
- text: Unacknowledge alert group {group_hash} for episode {episode_id}.
slots:
group_hash: path.group_hash
episode_id: requestBody.episode_id
- text: Remove my acknowledgement from episode {episode_id} of alert {group_hash}.
slots:
episode_id: requestBody.episode_id
group_hash: path.group_hash
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/alerts/{group_hash}/_unsnooze'].post
update:
x-apievangelist-phrasing:
intent: Unsnooze an alert group
effect: write
questions:
- How do I end the snooze on one alert group early?
- Can a snoozed alert group start notifying again before its expiry?
instructions:
- text: Unsnooze alert group {group_hash}.
slots:
group_hash: path.group_hash
- text: Wake the snoozed alert {group_hash} back up.
slots:
group_hash: path.group_hash
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/execution_history/action_policies'].get
update:
x-apievangelist-phrasing:
intent: List action policy execution history
effect: read
questions:
- Did my action policies actually dispatch notifications recently?
- Can I filter action policy executions by rule and outcome?
instructions:
- text: List action policy dispatch events in this space.
- text: Show action policy executions for rules {rule_ids} with outcome {outcome} since {start_date}.
slots:
rule_ids: query.rule_ids
outcome: query.outcome
start_date: query.start_date
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/execution_history/rules'].get
update:
x-apievangelist-phrasing:
intent: List rule execution events
effect: read
questions:
- When did my alerting rules last run and did they fail?
- Can I page through rule execution history between two dates?
instructions:
- text: List rule executions sorted by {sort} {sort_order}, page {page} with {per_page} per page.
slots:
sort: query.sort
sort_order: query.sort_order
page: query.page
per_page: query.per_page
- text: Show failed runs of rules {rule_ids} from {from} to {to}, sorted by {sort} {sort_order}, page {page} of {per_page}.
slots:
rule_ids: query.rule_ids
from: query.from
to: query.to
sort: query.sort
sort_order: query.sort_order
page: query.page
per_page: query.per_page
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules'].get
update:
x-apievangelist-phrasing:
intent: List alerting rules
effect: read
questions:
- What alerting rules exist in my Kibana space?
- Can I filter and sort the rule list by a KQL filter?
instructions:
- text: List my alerting rules.
- text: Find rules matching {search}, sorted by {sort_field}.
slots:
search: query.search
sort_field: query.sort_field
- text: List rules that match the filter {filter}.
slots:
filter: query.filter
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules'].post
update:
x-apievangelist-phrasing:
intent: Create an alerting rule with a generated ID
effect: write
questions:
- How do I create a new alerting rule that runs a query on a schedule?
- What does a new rule need besides its query and schedule?
instructions:
- text: Create a new {kind} rule with metadata {metadata} that runs {query} on schedule {schedule}.
slots:
kind: requestBody.kind
metadata: requestBody.metadata
query: requestBody.query
schedule: requestBody.schedule
- text: Add a rule of kind {kind} running query {query} every {schedule}, metadata {metadata}, grouped by {grouping}.
slots:
kind: requestBody.kind
query: requestBody.query
schedule: requestBody.schedule
metadata: requestBody.metadata
grouping: requestBody.grouping
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/_bulk_delete'].post
update:
x-apievangelist-phrasing:
intent: Delete several rules by ID
effect: destructive
questions:
- Can I delete a list of alerting rules in one request?
- What is the quickest way to remove many rules when I already know their IDs?
instructions:
- text: Bulk delete the rules {ids}.
slots:
ids: requestBody.ids
- text: 'Remove every rule in this ID list: {ids}.'
slots:
ids: requestBody.ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/_bulk_disable'].post
update:
x-apievangelist-phrasing:
intent: Disable several rules by ID
effect: write
questions:
- Can I switch off a specific list of rules together?
- Which call pauses many alerting rules when I have their IDs?
instructions:
- text: Bulk disable the rules {ids}.
slots:
ids: requestBody.ids
- text: 'Pause every rule in this ID list: {ids}.'
slots:
ids: requestBody.ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/_bulk_enable'].post
update:
x-apievangelist-phrasing:
intent: Enable several rules by ID
effect: write
questions:
- Can I turn on a specific list of disabled rules at once?
- Which call resumes many alerting rules when I have their IDs?
instructions:
- text: Bulk enable the rules {ids}.
slots:
ids: requestBody.ids
- text: 'Resume every rule in this ID list: {ids}.'
slots:
ids: requestBody.ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/_bulk_get'].post
update:
x-apievangelist-phrasing:
intent: Fetch several rules by ID
effect: read
questions:
- Can I fetch the definitions of several rules in one request?
- Is there a batch lookup for alerting rules by ID?
instructions:
- text: Get the rules {ids} in one request.
slots:
ids: requestBody.ids
- text: Look up the configurations of rules {ids}.
slots:
ids: requestBody.ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/_bulk_update_api_key'].post
update:
x-apievangelist-phrasing:
intent: Rotate API keys for several rules by ID
effect: write
questions:
- Can I rotate the executor API keys for a list of rules at once?
- How do I move many rules onto my current credentials?
instructions:
- text: Rotate the API keys for rules {ids}.
slots:
ids: requestBody.ids
- text: Re-key rules {ids} with credentials derived from my user.
slots:
ids: requestBody.ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/_delete_by_query'].post
update:
x-apievangelist-phrasing:
intent: Delete rules matching a query
effect: destructive
questions:
- Can I preview which rules a KQL filter would delete before deleting them?
- What is the cap on rules processed per delete-by-query request?
instructions:
- text: Dry-run deleting the rules that match filter {filter}.
slots:
filter: requestBody.filter
- text: Delete for real every rule whose text matches {search}, with force set to {force}.
slots:
search: requestBody.search
force: requestBody.force
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/_disable_by_query'].post
update:
x-apievangelist-phrasing:
intent: Disable rules matching a query
effect: write
questions:
- Can I disable every rule that matches a KQL filter?
- Does disabling rules by query default to a dry run?
instructions:
- text: Preview disabling the rules that match filter {filter}.
slots:
filter: requestBody.filter
- text: Disable all rules matching search {search}, force {force}.
slots:
search: requestBody.search
force: requestBody.force
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/_enable_by_query'].post
update:
x-apievangelist-phrasing:
intent: Enable rules matching a query
effect: write
questions:
- Can I enable every rule that matches a KQL filter?
- How do I preview which rules enabling by query would touch?
instructions:
- text: Preview enabling the rules that match filter {filter}.
slots:
filter: requestBody.filter
- text: Enable all rules matching search {search}, force {force}.
slots:
search: requestBody.search
force: requestBody.force
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/_update_api_key_by_query'].post
update:
x-apievangelist-phrasing:
intent: Rotate API keys for rules matching a query
effect: write
questions:
- Can I rotate executor API keys on every rule that matches a filter?
- Is there a dry run before re-keying rules selected by a query?
instructions:
- text: Preview rotating API keys on rules matching filter {filter}.
slots:
filter: requestBody.filter
- text: Rotate API keys on all rules, with match_all {match_all} and force {force}.
slots:
match_all: requestBody.match_all
force: requestBody.force
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get an alerting rule
effect: read
questions:
- What query and schedule does a specific rule use?
- Can I look up one alerting rule by its ID?
instructions:
- text: Get rule {id}.
slots:
id: path.id
- text: Show me the current definition of alerting rule {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/{id}'].put
update:
x-apievangelist-phrasing:
intent: Create or fully replace a rule by ID
effect: write
questions:
- Can I create an alerting rule with an identifier I choose myself?
- How do I overwrite a rule's entire definition in one request?
instructions:
- text: Create or replace rule {id} as a {kind} rule running {query} on schedule {schedule} with metadata {metadata}.
slots:
id: path.id
kind: requestBody.kind
query: requestBody.query
schedule: requestBody.schedule
metadata: requestBody.metadata
- text: 'Fully replace rule {id}: kind {kind}, query {query}, schedule {schedule}, metadata {metadata}.'
slots:
id: path.id
kind: requestBody.kind
query: requestBody.query
schedule: requestBody.schedule
metadata: requestBody.metadata
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete an alerting rule
effect: destructive
questions:
- How do I permanently delete one alerting rule?
- Can I remove a single rule I no longer need by its ID?
instructions:
- text: Delete rule {id}.
slots:
id: path.id
- text: Permanently remove the alerting rule {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/{id}'].patch
update:
x-apievangelist-phrasing:
intent: Partially update an alerting rule
effect: write
questions:
- Can I change just the schedule of a rule without resending everything?
- Which rule fields can I patch in place?
instructions:
- text: Change the schedule of rule {id} to {schedule}.
slots:
id: path.id
schedule: requestBody.schedule
- text: Update rule {id} to use the query {query}.
slots:
id: path.id
query: requestBody.query
method: generated
generated: '2026-09-26'
- target: $.paths['/api/alerting/v2/rules/{id}/_disable'].post
update:
x-apievangelist-phrasing:
intent: Disable an alerting rule
effect: write
questions:
- How do I stop one rule from running without deleting it?
- Can I disable a single alerting rule by ID?
instructions:
- text: Disable rule {id}.
slots:
id: path.id
- text: Stop the alerting rule {id} from running for now.
slots:
id: path.id
method: generated
generated: '2026-09-26'
# --- truncated at 32 KB (35 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/elk-stack/refs/heads/main/overlays/elk-stack-alerting-v2-api-phrasing-overlay.yaml