Elastic Stack · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Kibana Security Attack discovery API
17 actions
17 updates
phrasing
extends
openapi/elk-stack-security-attack-discovery-api-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
What the actions change
x-apievangelist-phrasing
Targets 17 · first 16 shown; the file carries all of them
$.info
$.paths['/api/attack_discovery/_bulk'].post
$.paths['/api/attack_discovery/_find'].get
$.paths['/api/attack_discovery/_generate'].post
$.paths['/api/attack_discovery/generations'].get
$.paths['/api/attack_discovery/generations/{execution_uuid}'].get
$.paths['/api/attack_discovery/generations/{execution_uuid}/_dismiss'].post
$.paths['/api/attack_discovery/schedules'].post
$.paths['/api/attack_discovery/schedules/_bulk_delete'].post
$.paths['/api/attack_discovery/schedules/_bulk_disable'].post
$.paths['/api/attack_discovery/schedules/_bulk_enable'].post
$.paths['/api/attack_discovery/schedules/_find'].get
$.paths['/api/attack_discovery/schedules/{id}'].get
$.paths['/api/attack_discovery/schedules/{id}'].put
$.paths['/api/attack_discovery/schedules/{id}'].delete
$.paths['/api/attack_discovery/schedules/{id}/_disable'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Kibana Security Attack discovery API
version: 1.0.0
extends: openapi/elk-stack-security-attack-discovery-api-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 16
- target: $.paths['/api/attack_discovery/_bulk'].post
update:
x-apievangelist-phrasing:
intent: Bulk update Attack discoveries
effect: write
questions:
- Can I change the workflow status of many Attack discoveries at once?
- How do I mark a batch of attack findings as acknowledged or shared in one request?
instructions:
- text: Apply the bulk Attack discovery update {update}.
slots:
update: requestBody.update
- text: Change the workflow status and visibility of discoveries using {update}.
slots:
update: requestBody.update
method: generated
generated: '2026-09-26'
- target: $.paths['/api/attack_discovery/_find'].get
update:
x-apievangelist-phrasing:
intent: Search Attack discoveries
effect: read
questions:
- Which Attack discoveries were found in the last day?
- Can I filter discoveries by status, connector or the alerts they reference?
instructions:
- text: Find Attack discoveries matching {search}.
slots:
search: query.search
- text: List discoveries with status {status} between {start} and {end}.
slots:
status: query.status
start: query.start
end: query.end
- text: Show discoveries that include alert {alert_ids}.
slots:
alert_ids: query.alert_ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/attack_discovery/_generate'].post
update:
x-apievangelist-phrasing:
intent: Generate attack discoveries from alerts with AI
effect: write
questions:
- How do I have an AI connector analyse my security alerts for attack chains?
- Can I limit how many alerts Attack Discovery analyses in one run?
instructions:
- text: Generate attack discoveries from alerts in {alertsIndexPattern}, analysing up to {size} alerts with connector config {apiConfig}.
slots:
alertsIndexPattern: requestBody.alertsIndexPattern
size: requestBody.size
apiConfig: requestBody.apiConfig
- text: Run Attack Discovery on {alertsIndexPattern} from {start} to {end} using connector {connectorName}.
slots:
alertsIndexPattern: requestBody.alertsIndexPattern
start: requestBody.start
end: requestBody.end
connectorName: requestBody.connectorName
method: generated
generated: '2026-09-26'
- target: $.paths['/api/attack_discovery/generations'].get
update:
x-apievangelist-phrasing:
intent: List my recent Attack Discovery generations
effect: read
questions:
- What is the status of my recent Attack Discovery runs?
- Can I see only the scheduled generations and their statistics?
instructions:
- text: List my latest Attack Discovery generations.
- text: Show the last {size} generations between {start} and {end}.
slots:
size: query.size
start: query.start
end: query.end
method: generated
generated: '2026-09-26'
- target: $.paths['/api/attack_discovery/generations/{execution_uuid}'].get
update:
x-apievangelist-phrasing:
intent: Get one Attack Discovery generation
effect: read
questions:
- Which attack discoveries did a particular generation run produce?
- Can I retrieve a generation's results with anonymized values replaced?
instructions:
- text: Get Attack Discovery generation {execution_uuid}.
slots:
execution_uuid: path.execution_uuid
- text: Show the discoveries from run {execution_uuid} with replacements set to {with_replacements}.
slots:
execution_uuid: path.execution_uuid
with_replacements: query.with_replacements
method: generated
generated: '2026-09-26'
- target: $.paths['/api/attack_discovery/generations/{execution_uuid}/_dismiss'].post
update:
x-apievangelist-phrasing:
intent: Dismiss an Attack Discovery generation
effect: write
questions:
- How do I stop a finished generation from showing in the UI?
- What does dismissing an Attack Discovery generation change?
instructions:
- text: Dismiss Attack Discovery generation {execution_uuid}.
slots:
execution_uuid: path.execution_uuid
- text: Hide the generation {execution_uuid} from my status view.
slots:
execution_uuid: path.execution_uuid
method: generated
generated: '2026-09-26'
- target: $.paths['/api/attack_discovery/schedules'].post
update:
x-apievangelist-phrasing:
intent: Create an Attack Discovery schedule
effect: write
questions:
- Can Attack Discovery run automatically on an interval?
- How do I set up recurring AI analysis of alerts with actions when findings appear?
instructions:
- text: Create an Attack Discovery schedule {name} running every {schedule} with params {params}.
slots:
name: requestBody.name
schedule: requestBody.schedule
params: requestBody.params
- text: Schedule {name} on interval {schedule} with params {params} and notify via {actions}.
slots:
name: requestBody.name
schedule: requestBody.schedule
params: requestBody.params
actions: requestBody.actions
method: generated
generated: '2026-09-26'
- target: $.paths['/api/attack_discovery/schedules/_bulk_delete'].post
update:
x-apievangelist-phrasing:
intent: Delete several Attack Discovery schedules
effect: destructive
questions:
- Can I delete multiple Attack Discovery schedules at once?
- What removes a list of discovery schedules by ID?
instructions:
- text: Bulk delete Attack Discovery schedules {ids}.
slots:
ids: requestBody.ids
- text: 'Remove all of these discovery schedules: {ids}.'
slots:
ids: requestBody.ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/attack_discovery/schedules/_bulk_disable'].post
update:
x-apievangelist-phrasing:
intent: Disable several Attack Discovery schedules
effect: write
questions:
- Can I pause a set of Attack Discovery schedules together?
- Which call disables multiple discovery schedules by ID?
instructions:
- text: Bulk disable Attack Discovery schedules {ids}.
slots:
ids: requestBody.ids
- text: 'Pause all of these discovery schedules: {ids}.'
slots:
ids: requestBody.ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/attack_discovery/schedules/_bulk_enable'].post
update:
x-apievangelist-phrasing:
intent: Enable several Attack Discovery schedules
effect: write
questions:
- Can I resume a group of paused Attack Discovery schedules together?
- Which call enables multiple discovery schedules by ID?
instructions:
- text: Bulk enable Attack Discovery schedules {ids}.
slots:
ids: requestBody.ids
- text: 'Resume all of these discovery schedules: {ids}.'
slots:
ids: requestBody.ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/attack_discovery/schedules/_find'].get
update:
x-apievangelist-phrasing:
intent: List Attack Discovery schedules
effect: read
questions:
- What Attack Discovery schedules are configured?
- Can I sort discovery schedules by a field and page through them?
instructions:
- text: List my Attack Discovery schedules.
- text: Show discovery schedules sorted by {sort_field} {sort_direction}, page {page}.
slots:
sort_field: query.sort_field
sort_direction: query.sort_direction
page: query.page
method: generated
generated: '2026-09-26'
- target: $.paths['/api/attack_discovery/schedules/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get an Attack Discovery schedule
effect: read
questions:
- What interval, parameters and actions does one discovery schedule have?
- Can I see a schedule's execution history?
instructions:
- text: Get Attack Discovery schedule {id}.
slots:
id: path.id
- text: Show the configuration and run history of discovery schedule {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/attack_discovery/schedules/{id}'].put
update:
x-apievangelist-phrasing:
intent: Replace an Attack Discovery schedule's settings
effect: write
questions:
- How do I change the interval or connector of an existing discovery schedule?
- Does updating a discovery schedule replace its whole configuration?
instructions:
- text: 'Update discovery schedule {id}: name {name}, interval {schedule}, params {params}, actions {actions}.'
slots:
id: path.id
name: requestBody.name
schedule: requestBody.schedule
params: requestBody.params
actions: requestBody.actions
- text: Reconfigure schedule {id} to run every {schedule} as {name} with params {params} and actions {actions}.
slots:
id: path.id
schedule: requestBody.schedule
name: requestBody.name
params: requestBody.params
actions: requestBody.actions
method: generated
generated: '2026-09-26'
- target: $.paths['/api/attack_discovery/schedules/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete an Attack Discovery schedule
effect: destructive
questions:
- How do I permanently remove one Attack Discovery schedule?
- Is deleting a discovery schedule reversible?
instructions:
- text: Delete Attack Discovery schedule {id}.
slots:
id: path.id
- text: Permanently remove discovery schedule {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/attack_discovery/schedules/{id}/_disable'].post
update:
x-apievangelist-phrasing:
intent: Disable an Attack Discovery schedule
effect: write
questions:
- How do I pause one discovery schedule but keep its settings?
- Will a running execution finish if I disable its schedule?
instructions:
- text: Disable Attack Discovery schedule {id}.
slots:
id: path.id
- text: Stop discovery schedule {id} from starting new runs.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/attack_discovery/schedules/{id}/_enable'].post
update:
x-apievangelist-phrasing:
intent: Enable an Attack Discovery schedule
effect: write
questions:
- How do I turn a disabled discovery schedule back on?
- When does a re-enabled discovery schedule run next?
instructions:
- text: Enable Attack Discovery schedule {id}.
slots:
id: path.id
- text: Resume discovery schedule {id} on its interval.
slots:
id: path.id
method: generated
generated: '2026-09-26'