Elastic Stack · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Kibana Cases API
30 actions
30 updates
phrasing
extends
openapi/elk-stack-cases-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
What the actions change
x-apievangelist-phrasing
Targets 30 · first 16 shown; the file carries all of them
$.info
$.paths['/api/cases'].post
$.paths['/api/cases'].delete
$.paths['/api/cases'].patch
$.paths['/api/cases/_find'].get
$.paths['/api/cases/{caseId}'].get
$.paths['/api/cases/{caseId}/alerts'].get
$.paths['/api/cases/{caseId}/comments'].post
$.paths['/api/cases/{caseId}/comments'].delete
$.paths['/api/cases/{caseId}/comments'].patch
$.paths['/api/cases/{caseId}/comments/_find'].get
$.paths['/api/cases/{caseId}/comments/{commentId}'].get
$.paths['/api/cases/{caseId}/comments/{commentId}'].delete
$.paths['/api/cases/{caseId}/connector/{connectorId}/_push'].post
$.paths['/api/cases/{caseId}/fields'].get
$.paths['/api/cases/{caseId}/files'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Kibana Cases API
version: 1.0.0
extends: openapi/elk-stack-cases-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 29
- target: $.paths['/api/cases'].post
update:
x-apievangelist-phrasing:
intent: Open a new case
effect: write
questions:
- How do I open a new security or observability case in Kibana from a script?
- Can I set severity, assignees and tags when I first create a case?
instructions:
- text: Open a case titled {title} described as {description}, owned by {owner}, tagged {tags}.
slots:
title: requestBody.title
description: requestBody.description
owner: requestBody.owner
tags: requestBody.tags
- text: Create a {severity} severity case {title} and assign it to {assignees}.
slots:
severity: requestBody.severity
title: requestBody.title
assignees: requestBody.assignees
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases'].delete
update:
x-apievangelist-phrasing:
intent: Delete one or more cases
effect: destructive
questions:
- How do I permanently delete several Kibana cases at once?
- Does deleting a case also remove its comments and attachments?
instructions:
- text: Delete cases {ids}.
slots:
ids: query.ids
- text: Permanently remove the case with ID {ids}.
slots:
ids: query.ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases'].patch
update:
x-apievangelist-phrasing:
intent: Update fields on existing cases
effect: write
questions:
- How do I close a case or change its status programmatically?
- Can I bulk-update severity or title on several existing cases in one call?
instructions:
- text: Apply these case updates {cases}.
slots:
cases: requestBody.cases
- text: Mark the existing cases in {cases} as closed.
slots:
cases: requestBody.cases
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/_find'].get
update:
x-apievangelist-phrasing:
intent: Search and filter cases
effect: read
questions:
- Which open cases are assigned to me?
- Can I find critical-severity cases created in the last week?
- What cases carry a particular tag?
instructions:
- text: Find cases with status {status} and severity {severity}.
slots:
status: query.status
severity: query.severity
- text: Search cases for {search} tagged {tags}.
slots:
search: query.search
tags: query.tags
- text: List cases assigned to {assignees} opened between {from} and {to}.
slots:
assignees: query.assignees
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/{caseId}'].get
update:
x-apievangelist-phrasing:
intent: Get a case's details
effect: read
questions:
- What's the current status and description of a specific case?
- Who opened a given case and when?
instructions:
- text: Show me the details of case {caseId}.
slots:
caseId: path.caseId
- text: Fetch case {caseId} with its title, status and severity.
slots:
caseId: path.caseId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/{caseId}/alerts'].get
update:
x-apievangelist-phrasing:
intent: List alerts attached to a case
effect: read
questions:
- Which detection alerts have been attached to this case?
- How can I see every alert linked to one case?
instructions:
- text: List all alerts attached to case {caseId}.
slots:
caseId: path.caseId
- text: Get the alert IDs linked to case {caseId}.
slots:
caseId: path.caseId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/{caseId}/comments'].post
update:
x-apievangelist-phrasing:
intent: Add a comment or alert to a case
effect: write
questions:
- How do I post a note on a case?
- Can I attach an alert to a case as a new case attachment?
instructions:
- text: Add a new comment to case {caseId}.
slots:
caseId: path.caseId
- text: Attach an alert to case {caseId}.
slots:
caseId: path.caseId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/{caseId}/comments'].delete
update:
x-apievangelist-phrasing:
intent: Delete every comment and alert on a case
effect: destructive
questions:
- How do I wipe all comments and attached alerts from a case in one go?
- Can I clear a case's entire comment history?
instructions:
- text: Delete all comments and alerts from case {caseId}.
slots:
caseId: path.caseId
- text: Clear the whole comment history on case {caseId}.
slots:
caseId: path.caseId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/{caseId}/comments'].patch
update:
x-apievangelist-phrasing:
intent: Edit an existing case comment or alert
effect: write
questions:
- How do I fix a typo in a comment I already posted on a case?
- Can I change an existing alert attachment on a case?
instructions:
- text: Edit an existing comment on case {caseId}.
slots:
caseId: path.caseId
- text: Update the text of a comment I already posted to case {caseId}.
slots:
caseId: path.caseId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/{caseId}/comments/_find'].get
update:
x-apievangelist-phrasing:
intent: Page through a case's comments
effect: read
questions:
- What comments have been left on this case, newest first?
- Can I paginate through a long comment thread on a case?
instructions:
- text: Find comments on case {caseId}, sorted {sortOrder}.
slots:
caseId: path.caseId
sortOrder: query.sortOrder
- text: Show page {page} of comments on case {caseId}, {perPage} per page.
slots:
page: query.page
caseId: path.caseId
perPage: query.perPage
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/{caseId}/comments/{commentId}'].get
update:
x-apievangelist-phrasing:
intent: Get one case comment or alert
effect: read
questions:
- How do I read a single comment on a case by its ID?
- What does a specific alert attachment on a case contain?
instructions:
- text: Get comment {commentId} on case {caseId}.
slots:
commentId: path.commentId
caseId: path.caseId
- text: Show the attachment {commentId} from case {caseId}.
slots:
commentId: path.commentId
caseId: path.caseId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/{caseId}/comments/{commentId}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a single case comment or alert
effect: destructive
questions:
- How do I remove just one comment from a case?
- Can I detach a single alert from a case without touching the other comments?
instructions:
- text: Delete comment {commentId} from case {caseId}.
slots:
commentId: path.commentId
caseId: path.caseId
- text: Remove only attachment {commentId} on case {caseId}.
slots:
commentId: path.commentId
caseId: path.caseId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/{caseId}/connector/{connectorId}/_push'].post
update:
x-apievangelist-phrasing:
intent: Push a case to an external ticketing system
effect: write
questions:
- How do I send a case to an external incident system like Jira or ServiceNow through its connector?
- Can I sync the latest case updates to the external service it's linked to?
instructions:
- text: Push case {caseId} through connector {connectorId}.
slots:
caseId: path.caseId
connectorId: path.connectorId
- text: Sync case {caseId} to the external service behind connector {connectorId}.
slots:
caseId: path.caseId
connectorId: path.connectorId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/{caseId}/fields'].get
update:
x-apievangelist-phrasing:
intent: Get fields applicable to an existing case
effect: read
questions:
- Which custom fields apply to a case that's already open?
- What fields can I fill in on this particular case?
instructions:
- text: Get the applicable fields for existing case {caseId}.
slots:
caseId: path.caseId
- text: List the custom fields that apply to case {caseId}.
slots:
caseId: path.caseId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/{caseId}/files'].post
update:
x-apievangelist-phrasing:
intent: Attach a file to a case
effect: write
questions:
- How do I upload a screenshot or log file to a case?
- Can I set a custom filename when attaching a file to a case?
instructions:
- text: Attach file {file} to case {caseId}.
slots:
file: requestBody.file
caseId: path.caseId
- text: Upload {file} to case {caseId} named {filename}.
slots:
file: requestBody.file
caseId: path.caseId
filename: requestBody.filename
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/{caseId}/user_actions/_find'].get
update:
x-apievangelist-phrasing:
intent: Review a case's activity history
effect: read
questions:
- Who changed what on this case and when?
- Can I filter a case's activity log to only status changes or comments?
instructions:
- text: Show the activity history for case {caseId}.
slots:
caseId: path.caseId
- text: Find user actions of types {types} on case {caseId}.
slots:
types: query.types
caseId: path.caseId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/alerts/{alertId}'].get
update:
x-apievangelist-phrasing:
intent: Find cases that contain an alert
effect: read
questions:
- Which cases is this alert already attached to?
- Has a given alert been added to any security case yet?
instructions:
- text: Find the cases that include alert {alertId}.
slots:
alertId: path.alertId
- text: List {owner} cases containing alert {alertId}.
slots:
owner: query.owner
alertId: path.alertId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/configure'].get
update:
x-apievangelist-phrasing:
intent: Get case settings
effect: read
questions:
- How are cases configured to close and which connector do they use by default?
- What custom fields and templates are set up in case settings?
instructions:
- text: Show the case settings for {owner}.
slots:
owner: query.owner
- text: Get the current case configuration, including default connector and closure type.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/configure'].post
update:
x-apievangelist-phrasing:
intent: Create case settings
effect: write
questions:
- How do I set up the default connector and closure behaviour for cases the first time?
- Can I make cases close automatically when they're pushed to an external system?
instructions:
- text: Create case settings for {owner} with closure type {closure_type} and connector {connector}.
slots:
owner: requestBody.owner
closure_type: requestBody.closure_type
connector: requestBody.connector
- text: Add initial case settings for {owner} with custom fields {customFields}.
slots:
owner: requestBody.owner
customFields: requestBody.customFields
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/configure/{configurationId}'].patch
update:
x-apievangelist-phrasing:
intent: Change existing case settings
effect: write
questions:
- How do I switch the default connector on case settings I already created?
- Why do I need to pass a version when editing case settings?
instructions:
- text: Update case settings {configurationId} at version {version} to closure type {closure_type}.
slots:
configurationId: path.configurationId
version: requestBody.version
closure_type: requestBody.closure_type
- text: Change the connector on configuration {configurationId} (version {version}) to {connector}.
slots:
configurationId: path.configurationId
version: requestBody.version
connector: requestBody.connector
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/configure/connectors/_find'].get
update:
x-apievangelist-phrasing:
intent: List connectors usable by cases
effect: read
questions:
- Which external connectors can cases be pushed to?
- What case connectors are available in this space?
instructions:
- text: List the connectors available for cases.
- text: Show which ticketing connectors I can attach to cases.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/fields'].get
update:
x-apievangelist-phrasing:
intent: Get fields available to new cases
effect: read
questions:
- What fields would a new case have for a given solution before I open it?
- Which fields does a case template add?
instructions:
- text: Get the fields applicable to {owner} cases.
slots:
owner: query.owner
- text: Show fields a new {owner} case would get from template {templateId}.
slots:
owner: query.owner
templateId: query.templateId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/reporters'].get
update:
x-apievangelist-phrasing:
intent: List users who opened cases
effect: read
questions:
- Who has been opening cases?
- Can I see the list of case creators for just security cases?
instructions:
- text: List the users who opened cases.
- text: Show case reporters for {owner}.
slots:
owner: query.owner
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/tags'].get
update:
x-apievangelist-phrasing:
intent: List tags used on cases
effect: read
questions:
- What tags are in use across all my cases?
- Which case tags exist for observability cases?
instructions:
- text: List every tag used on cases.
- text: Get the case tags for {owner}.
slots:
owner: query.owner
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/templates'].get
update:
x-apievangelist-phrasing:
intent: List case templates
effect: read
questions:
- What case templates have been defined?
- Can I list only enabled case templates by a certain author?
instructions:
- text: List all case templates.
- text: Search case templates for {search} where enabled is {isEnabled}.
slots:
search: query.search
isEnabled: query.isEnabled
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/templates'].post
update:
x-apievangelist-phrasing:
intent: Create a case template
effect: write
questions:
- How do I create a reusable template for new cases?
- Can I validate a case template with a dry run before saving it?
instructions:
- text: Create a case template {name} for {owner} with definition {definition}.
slots:
name: requestBody.name
owner: requestBody.owner
definition: requestBody.definition
- text: Dry-run a new case template for {owner} using definition {definition}.
slots:
owner: requestBody.owner
definition: requestBody.definition
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/templates/{template_id}'].get
update:
x-apievangelist-phrasing:
intent: Get a case template
effect: read
questions:
- What does a specific case template define?
- Can I fetch an older version of a case template?
instructions:
- text: Get case template {template_id}.
slots:
template_id: path.template_id
- text: Show version {version} of case template {template_id}.
slots:
version: query.version
template_id: path.template_id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/templates/{template_id}'].put
update:
x-apievangelist-phrasing:
intent: Update a case template
effect: write
questions:
- How do I change the definition of an existing case template?
- Can I disable a case template without deleting it?
instructions:
- text: Replace case template {template_id} for {owner} with definition {definition}.
slots:
template_id: path.template_id
owner: requestBody.owner
definition: requestBody.definition
- text: Set isEnabled to {isEnabled} on case template {template_id}.
slots:
isEnabled: requestBody.isEnabled
template_id: path.template_id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/cases/templates/{template_id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a case template
effect: destructive
questions:
- How do I delete a case template I no longer use?
- Can I remove a case template by its ID?
instructions:
- text: Delete case template {template_id}.
slots:
template_id: path.template_id
- text: Remove the case template with ID {template_id}.
slots:
template_id: path.template_id
method: generated
generated: '2026-09-26'