Elastic Stack · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Kibana Security Detections API
30 actions
30 updates
phrasing
extends
openapi/elk-stack-security-detections-api-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
What the actions change
x-apievangelist-phrasing
Targets 30 · first 16 shown; the file carries all of them
$.info
$.paths['/api/detection_engine/attacks/assignees'].post
$.paths['/api/detection_engine/attacks/search'].post
$.paths['/api/detection_engine/attacks/status'].post
$.paths['/api/detection_engine/attacks/tags'].post
$.paths['/api/detection_engine/index'].get
$.paths['/api/detection_engine/index'].post
$.paths['/api/detection_engine/index'].delete
$.paths['/api/detection_engine/privileges'].get
$.paths['/api/detection_engine/rules'].get
$.paths['/api/detection_engine/rules'].put
$.paths['/api/detection_engine/rules'].post
$.paths['/api/detection_engine/rules'].delete
$.paths['/api/detection_engine/rules'].patch
$.paths['/api/detection_engine/rules/_bulk_action'].post
$.paths['/api/detection_engine/rules/_export'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Kibana Security Detections API
version: 1.0.0
extends: openapi/elk-stack-security-detections-api-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 29
- target: $.paths['/api/detection_engine/attacks/assignees'].post
update:
x-apievangelist-phrasing:
intent: Assign users to attack discovery alerts
effect: write
questions:
- How do I assign an analyst to an attack discovery?
- Can assigning an attack discovery also assign its related detection alerts?
instructions:
- text: Assign {assignees} to attack discovery alerts {ids}.
slots:
assignees: requestBody.assignees
ids: requestBody.ids
- text: Update assignees on attacks {ids} to {assignees} and cascade to their related alerts {update_related_alerts}.
slots:
ids: requestBody.ids
assignees: requestBody.assignees
update_related_alerts: requestBody.update_related_alerts
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/attacks/search'].post
update:
x-apievangelist-phrasing:
intent: Search and aggregate attack discoveries
effect: read
questions:
- Which attack discoveries in this space match my query?
- Can I aggregate attack discovery alerts, for example counting them by status?
instructions:
- text: Search attack discovery alerts matching {query}.
slots:
query: requestBody.query
- text: Aggregate attack discoveries using {aggs} and return {size} hits.
slots:
aggs: requestBody.aggs
size: requestBody.size
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/attacks/status'].post
update:
x-apievangelist-phrasing:
intent: Change the workflow status of attack discoveries
effect: write
questions:
- How do I mark an attack discovery as acknowledged or closed?
- Can closing an attack discovery also close the detection alerts behind it?
instructions:
- text: Close the attack discovery alerts I've finished investigating.
- text: Mark these attack discoveries as acknowledged and cascade the status to their related alerts.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/attacks/tags'].post
update:
x-apievangelist-phrasing:
intent: Tag or untag attack discoveries
effect: write
questions:
- Can I add and remove tags on attack discoveries in a single request?
- Will tagging an attack discovery also tag its related detection alerts?
instructions:
- text: Apply tag changes {tags} to attack discoveries {ids}.
slots:
tags: requestBody.tags
ids: requestBody.ids
- text: Tag attacks {ids} with {tags} and propagate to related alerts {update_related_alerts}.
slots:
ids: requestBody.ids
tags: requestBody.tags
update_related_alerts: requestBody.update_related_alerts
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/index'].get
update:
x-apievangelist-phrasing:
intent: Check the security alerts index
effect: read
questions:
- Which Elasticsearch index backs Elastic Security detection alerts in my space?
- Is my alerts index mapping outdated?
instructions:
- text: Show the name of the detection alerts index in this space.
- text: Check whether the security alerts index exists and if its mapping is out of date.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/index'].post
update:
x-apievangelist-phrasing:
intent: Create the security alerts index
effect: write
questions:
- Do I need to create an alerts index before detection rules can generate alerts?
- How do I provision the Elastic Security alerts index for a space?
instructions:
- text: Create the Elastic Security alerts index for this space.
- text: Provision the detection alerts backing index now.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/index'].delete
update:
x-apievangelist-phrasing:
intent: Delete the security alerts index
effect: destructive
questions:
- What happens to stored alerts if I delete the alerts backing index?
- Can I wipe the detection alerts index for one space?
instructions:
- text: Delete the security alerts backing index and all alerts in it.
- text: Permanently remove this space's detection alerts index.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/privileges'].get
update:
x-apievangelist-phrasing:
intent: Check my security detection privileges
effect: read
questions:
- Do I have the index privileges needed to create the security alerts index?
- What Kibana space and index privileges does my user have for detections?
instructions:
- text: Show my authentication status and detection engine privileges.
- text: Check whether I can create the alerts index in this space.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules'].get
update:
x-apievangelist-phrasing:
intent: Get a detection rule
effect: read
questions:
- How do I look up one detection rule by its rule_id?
- What's the difference between a rule's id and rule_id when fetching it?
instructions:
- text: Get detection rule with rule_id {rule_id}.
slots:
rule_id: query.rule_id
- text: Fetch the detection rule whose id is {id}.
slots:
id: query.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules'].put
update:
x-apievangelist-phrasing:
intent: Replace a detection rule
effect: write
questions:
- Does a full rule update delete the fields I leave out?
- Can I overwrite an entire detection rule definition in one call?
instructions:
- text: Replace the whole definition of an existing detection rule with my new version.
- text: Overwrite this detection rule completely, dropping any fields I don't specify.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules'].post
update:
x-apievangelist-phrasing:
intent: Create a detection rule
effect: write
questions:
- How do I create a new custom detection rule in Elastic Security?
- Does creating a rule with an API key tie that key to the rule?
instructions:
- text: Create a new query detection rule for suspicious PowerShell activity.
- text: Add a new detection rule from this definition.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules'].delete
update:
x-apievangelist-phrasing:
intent: Delete a detection rule
effect: destructive
questions:
- Can I remove a detection rule using its rule_id instead of its id?
- What happens when I delete a detection rule?
instructions:
- text: Delete the detection rule with rule_id {rule_id}.
slots:
rule_id: query.rule_id
- text: Remove detection rule {id}.
slots:
id: query.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules'].patch
update:
x-apievangelist-phrasing:
intent: Change specific fields of a detection rule
effect: write
questions:
- Can I change just a rule's severity without resending the whole rule?
- What's the way to partially update a detection rule?
instructions:
- text: Patch only the severity and risk score of an existing detection rule.
- text: Disable one detection rule by changing just its enabled field.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules/_bulk_action'].post
update:
x-apievangelist-phrasing:
intent: Bulk edit, duplicate or delete detection rules
effect: destructive
questions:
- Can I enable, duplicate or delete many detection rules at once?
- Is there a dry run to see which rules a bulk action would affect?
instructions:
- text: Apply a bulk edit to all detection rules matching my query.
- text: Dry-run a bulk delete of these rules first ({dry_run}).
slots:
dry_run: query.dry_run
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules/_export'].post
update:
x-apievangelist-phrasing:
intent: Export detection rules to NDJSON
effect: read
questions:
- How do I back up detection rules to an .ndjson file?
- Are exception lists and actions included when I export rules?
instructions:
- text: Export detection rules {objects} to an ndjson file.
slots:
objects: requestBody.objects
- text: Export rules {objects} as file {file_name} without export details.
slots:
objects: requestBody.objects
file_name: query.file_name
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules/_find'].get
update:
x-apievangelist-phrasing:
intent: List and filter detection rules
effect: read
questions:
- Which detection rules do I have, 20 per page by default?
- Can I filter detection rules by a KQL query and sort them?
- Which rules have execution gaps in a given time range?
instructions:
- text: List all my detection rules.
- text: Find detection rules matching {filter}, sorted by {sort_field}.
slots:
filter: query.filter
sort_field: query.sort_field
- text: Show page {page} of detection rules with {per_page} per page.
slots:
page: query.page
per_page: query.per_page
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules/_import'].post
update:
x-apievangelist-phrasing:
intent: Import detection rules from NDJSON
effect: write
questions:
- Can I import detection rules from an .ndjson export file?
- Will importing overwrite rules that already exist with the same rule_id?
instructions:
- text: Import detection rules from file {file}.
slots:
file: requestBody.file
- text: Import rules from {file} and overwrite existing ones ({overwrite}).
slots:
file: requestBody.file
overwrite: query.overwrite
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules/prepackaged'].put
update:
x-apievangelist-phrasing:
intent: Install Elastic prebuilt rules and Timelines
effect: write
questions:
- How do I install all of Elastic's prebuilt detection rules?
- Does this also update prebuilt Timeline templates?
instructions:
- text: Install and update all Elastic prebuilt detection rules and Timelines.
- text: Bring my prebuilt rules and Timeline templates up to date.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules/prepackaged/_status'].get
update:
x-apievangelist-phrasing:
intent: Check prebuilt rule and Timeline status
effect: read
questions:
- How many prebuilt detection rules are installed versus available to update?
- Are there any Elastic prebuilt Timelines I haven't installed yet?
instructions:
- text: Show the install status of Elastic prebuilt rules and Timelines.
- text: Count my custom rules, installed prebuilt rules, and outdated prebuilt rules.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules/preview'].post
update:
x-apievangelist-phrasing:
intent: Preview a detection rule's alerts
effect: read
questions:
- Can I test a detection rule query to see what alerts it would produce without saving it?
- Is there a way to validate a rule over a short time window before creating it?
instructions:
- text: Preview the alerts this draft rule would generate over the last hour.
- text: Simulate this rule and include the logged Elasticsearch requests ({enable_logged_requests}).
slots:
enable_logged_requests: query.enable_logged_requests
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/signals/assignees'].post
update:
x-apievangelist-phrasing:
intent: Assign users to detection alerts
effect: write
questions:
- How do I assign a detection alert to someone on my team?
- Can I add and remove the same assignee in one request?
instructions:
- text: Assign {assignees} to detection alerts {ids}.
slots:
assignees: requestBody.assignees
ids: requestBody.ids
- text: Change the assigned users on alerts {ids} to {assignees}.
slots:
ids: requestBody.ids
assignees: requestBody.assignees
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/signals/finalize_migration'].post
update:
x-apievangelist-phrasing:
intent: Finalize a legacy alert index migration
effect: destructive
questions:
- How do I complete a legacy .siem-signals migration once it has finished?
- What does finalizing an alert migration do to the read aliases?
instructions:
- text: Finalize alert migrations {migration_ids}.
slots:
migration_ids: requestBody.migration_ids
- text: Swap read aliases to complete migrations {migration_ids}.
slots:
migration_ids: requestBody.migration_ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/signals/migration'].post
update:
x-apievangelist-phrasing:
intent: Start a legacy alert index migration
effect: write
questions:
- Can I reindex an old .siem-signals alert index to the new mapping?
- How do I throttle a legacy alert reindex with requests per second?
instructions:
- text: Start a migration of alert index {index}.
slots:
index: requestBody.index
- text: Migrate legacy alert indices {index} at {requests_per_second} requests per second.
slots:
index: requestBody.index
requests_per_second: requestBody.requests_per_second
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/signals/migration'].delete
update:
x-apievangelist-phrasing:
intent: Clean up legacy alert migrations
effect: destructive
questions:
- How do I clean up old artifacts left from a signals index migration?
- Does migration cleanup schedule the source index for deletion?
instructions:
- text: Clean up alert migrations {migration_ids}.
slots:
migration_ids: requestBody.migration_ids
- text: Schedule deletion of the source indices for migrations {migration_ids}.
slots:
migration_ids: requestBody.migration_ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/signals/migration_status'].get
update:
x-apievangelist-phrasing:
intent: Check legacy alert migration status
effect: read
questions:
- Which old .siem-signals indices still need migrating?
- What's the status of alert index migrations since a given date?
instructions:
- text: Show alert migration status for indices with alerts since {from}.
slots:
from: query.from
- text: Check which legacy signal indices are outdated starting from {from}.
slots:
from: query.from
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/signals/search'].post
update:
x-apievangelist-phrasing:
intent: Search and aggregate detection alerts
effect: read
questions:
- Which detection alerts match a query I write in Elasticsearch DSL?
- Can I aggregate detection alerts by rule name or severity?
instructions:
- text: Search detection alerts matching {query}.
slots:
query: requestBody.query
- text: Aggregate detection alerts using {aggs}.
slots:
aggs: requestBody.aggs
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/signals/status'].post
update:
x-apievangelist-phrasing:
intent: Open, acknowledge or close detection alerts
effect: write
questions:
- How do I close a batch of detection alerts?
- Can I set detection alerts back to open after acknowledging them?
instructions:
- text: Close the detection alerts I've triaged.
- text: Mark these detection alerts as acknowledged.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/signals/tags'].post
update:
x-apievangelist-phrasing:
intent: Tag or untag detection alerts
effect: write
questions:
- Can I add and remove tags on detection alerts in one call?
- Is it possible to tag detection alerts that match a query instead of by id?
instructions:
- text: Update tags on detection alerts {ids} with {tags}.
slots:
ids: requestBody.ids
tags: requestBody.tags
- text: Add and remove the tag changes {tags} on alerts {ids}.
slots:
tags: requestBody.tags
ids: requestBody.ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/detection_engine/tags'].get
update:
x-apievangelist-phrasing:
intent: List detection rule tags
effect: read
questions:
- What tags are in use across all my detection rules?
- Can I get the unique list of rule tags?
instructions:
- text: List all unique detection rule tags.
- text: Show every tag used by my detection rules.
method: generated
generated: '2026-09-26'