Elastic Stack · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Kibana Security Detections API

30 actions 30 updates phrasing extends openapi/elk-stack-security-detections-api-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 30 · first 16 shown; the file carries all of them

$.info
$.paths['/api/detection_engine/attacks/assignees'].post
$.paths['/api/detection_engine/attacks/search'].post
$.paths['/api/detection_engine/attacks/status'].post
$.paths['/api/detection_engine/attacks/tags'].post
$.paths['/api/detection_engine/index'].get
$.paths['/api/detection_engine/index'].post
$.paths['/api/detection_engine/index'].delete
$.paths['/api/detection_engine/privileges'].get
$.paths['/api/detection_engine/rules'].get
$.paths['/api/detection_engine/rules'].put
$.paths['/api/detection_engine/rules'].post
$.paths['/api/detection_engine/rules'].delete
$.paths['/api/detection_engine/rules'].patch
$.paths['/api/detection_engine/rules/_bulk_action'].post
$.paths['/api/detection_engine/rules/_export'].post

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Kibana Security Detections API
  version: 1.0.0
extends: openapi/elk-stack-security-detections-api-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 29
- target: $.paths['/api/detection_engine/attacks/assignees'].post
  update:
    x-apievangelist-phrasing:
      intent: Assign users to attack discovery alerts
      effect: write
      questions:
      - How do I assign an analyst to an attack discovery?
      - Can assigning an attack discovery also assign its related detection alerts?
      instructions:
      - text: Assign {assignees} to attack discovery alerts {ids}.
        slots:
          assignees: requestBody.assignees
          ids: requestBody.ids
      - text: Update assignees on attacks {ids} to {assignees} and cascade to their related alerts {update_related_alerts}.
        slots:
          ids: requestBody.ids
          assignees: requestBody.assignees
          update_related_alerts: requestBody.update_related_alerts
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/attacks/search'].post
  update:
    x-apievangelist-phrasing:
      intent: Search and aggregate attack discoveries
      effect: read
      questions:
      - Which attack discoveries in this space match my query?
      - Can I aggregate attack discovery alerts, for example counting them by status?
      instructions:
      - text: Search attack discovery alerts matching {query}.
        slots:
          query: requestBody.query
      - text: Aggregate attack discoveries using {aggs} and return {size} hits.
        slots:
          aggs: requestBody.aggs
          size: requestBody.size
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/attacks/status'].post
  update:
    x-apievangelist-phrasing:
      intent: Change the workflow status of attack discoveries
      effect: write
      questions:
      - How do I mark an attack discovery as acknowledged or closed?
      - Can closing an attack discovery also close the detection alerts behind it?
      instructions:
      - text: Close the attack discovery alerts I've finished investigating.
      - text: Mark these attack discoveries as acknowledged and cascade the status to their related alerts.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/attacks/tags'].post
  update:
    x-apievangelist-phrasing:
      intent: Tag or untag attack discoveries
      effect: write
      questions:
      - Can I add and remove tags on attack discoveries in a single request?
      - Will tagging an attack discovery also tag its related detection alerts?
      instructions:
      - text: Apply tag changes {tags} to attack discoveries {ids}.
        slots:
          tags: requestBody.tags
          ids: requestBody.ids
      - text: Tag attacks {ids} with {tags} and propagate to related alerts {update_related_alerts}.
        slots:
          ids: requestBody.ids
          tags: requestBody.tags
          update_related_alerts: requestBody.update_related_alerts
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/index'].get
  update:
    x-apievangelist-phrasing:
      intent: Check the security alerts index
      effect: read
      questions:
      - Which Elasticsearch index backs Elastic Security detection alerts in my space?
      - Is my alerts index mapping outdated?
      instructions:
      - text: Show the name of the detection alerts index in this space.
      - text: Check whether the security alerts index exists and if its mapping is out of date.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/index'].post
  update:
    x-apievangelist-phrasing:
      intent: Create the security alerts index
      effect: write
      questions:
      - Do I need to create an alerts index before detection rules can generate alerts?
      - How do I provision the Elastic Security alerts index for a space?
      instructions:
      - text: Create the Elastic Security alerts index for this space.
      - text: Provision the detection alerts backing index now.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/index'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete the security alerts index
      effect: destructive
      questions:
      - What happens to stored alerts if I delete the alerts backing index?
      - Can I wipe the detection alerts index for one space?
      instructions:
      - text: Delete the security alerts backing index and all alerts in it.
      - text: Permanently remove this space's detection alerts index.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/privileges'].get
  update:
    x-apievangelist-phrasing:
      intent: Check my security detection privileges
      effect: read
      questions:
      - Do I have the index privileges needed to create the security alerts index?
      - What Kibana space and index privileges does my user have for detections?
      instructions:
      - text: Show my authentication status and detection engine privileges.
      - text: Check whether I can create the alerts index in this space.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a detection rule
      effect: read
      questions:
      - How do I look up one detection rule by its rule_id?
      - What's the difference between a rule's id and rule_id when fetching it?
      instructions:
      - text: Get detection rule with rule_id {rule_id}.
        slots:
          rule_id: query.rule_id
      - text: Fetch the detection rule whose id is {id}.
        slots:
          id: query.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace a detection rule
      effect: write
      questions:
      - Does a full rule update delete the fields I leave out?
      - Can I overwrite an entire detection rule definition in one call?
      instructions:
      - text: Replace the whole definition of an existing detection rule with my new version.
      - text: Overwrite this detection rule completely, dropping any fields I don't specify.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a detection rule
      effect: write
      questions:
      - How do I create a new custom detection rule in Elastic Security?
      - Does creating a rule with an API key tie that key to the rule?
      instructions:
      - text: Create a new query detection rule for suspicious PowerShell activity.
      - text: Add a new detection rule from this definition.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a detection rule
      effect: destructive
      questions:
      - Can I remove a detection rule using its rule_id instead of its id?
      - What happens when I delete a detection rule?
      instructions:
      - text: Delete the detection rule with rule_id {rule_id}.
        slots:
          rule_id: query.rule_id
      - text: Remove detection rule {id}.
        slots:
          id: query.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules'].patch
  update:
    x-apievangelist-phrasing:
      intent: Change specific fields of a detection rule
      effect: write
      questions:
      - Can I change just a rule's severity without resending the whole rule?
      - What's the way to partially update a detection rule?
      instructions:
      - text: Patch only the severity and risk score of an existing detection rule.
      - text: Disable one detection rule by changing just its enabled field.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules/_bulk_action'].post
  update:
    x-apievangelist-phrasing:
      intent: Bulk edit, duplicate or delete detection rules
      effect: destructive
      questions:
      - Can I enable, duplicate or delete many detection rules at once?
      - Is there a dry run to see which rules a bulk action would affect?
      instructions:
      - text: Apply a bulk edit to all detection rules matching my query.
      - text: Dry-run a bulk delete of these rules first ({dry_run}).
        slots:
          dry_run: query.dry_run
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules/_export'].post
  update:
    x-apievangelist-phrasing:
      intent: Export detection rules to NDJSON
      effect: read
      questions:
      - How do I back up detection rules to an .ndjson file?
      - Are exception lists and actions included when I export rules?
      instructions:
      - text: Export detection rules {objects} to an ndjson file.
        slots:
          objects: requestBody.objects
      - text: Export rules {objects} as file {file_name} without export details.
        slots:
          objects: requestBody.objects
          file_name: query.file_name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules/_find'].get
  update:
    x-apievangelist-phrasing:
      intent: List and filter detection rules
      effect: read
      questions:
      - Which detection rules do I have, 20 per page by default?
      - Can I filter detection rules by a KQL query and sort them?
      - Which rules have execution gaps in a given time range?
      instructions:
      - text: List all my detection rules.
      - text: Find detection rules matching {filter}, sorted by {sort_field}.
        slots:
          filter: query.filter
          sort_field: query.sort_field
      - text: Show page {page} of detection rules with {per_page} per page.
        slots:
          page: query.page
          per_page: query.per_page
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules/_import'].post
  update:
    x-apievangelist-phrasing:
      intent: Import detection rules from NDJSON
      effect: write
      questions:
      - Can I import detection rules from an .ndjson export file?
      - Will importing overwrite rules that already exist with the same rule_id?
      instructions:
      - text: Import detection rules from file {file}.
        slots:
          file: requestBody.file
      - text: Import rules from {file} and overwrite existing ones ({overwrite}).
        slots:
          file: requestBody.file
          overwrite: query.overwrite
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules/prepackaged'].put
  update:
    x-apievangelist-phrasing:
      intent: Install Elastic prebuilt rules and Timelines
      effect: write
      questions:
      - How do I install all of Elastic's prebuilt detection rules?
      - Does this also update prebuilt Timeline templates?
      instructions:
      - text: Install and update all Elastic prebuilt detection rules and Timelines.
      - text: Bring my prebuilt rules and Timeline templates up to date.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules/prepackaged/_status'].get
  update:
    x-apievangelist-phrasing:
      intent: Check prebuilt rule and Timeline status
      effect: read
      questions:
      - How many prebuilt detection rules are installed versus available to update?
      - Are there any Elastic prebuilt Timelines I haven't installed yet?
      instructions:
      - text: Show the install status of Elastic prebuilt rules and Timelines.
      - text: Count my custom rules, installed prebuilt rules, and outdated prebuilt rules.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/rules/preview'].post
  update:
    x-apievangelist-phrasing:
      intent: Preview a detection rule's alerts
      effect: read
      questions:
      - Can I test a detection rule query to see what alerts it would produce without saving it?
      - Is there a way to validate a rule over a short time window before creating it?
      instructions:
      - text: Preview the alerts this draft rule would generate over the last hour.
      - text: Simulate this rule and include the logged Elasticsearch requests ({enable_logged_requests}).
        slots:
          enable_logged_requests: query.enable_logged_requests
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/signals/assignees'].post
  update:
    x-apievangelist-phrasing:
      intent: Assign users to detection alerts
      effect: write
      questions:
      - How do I assign a detection alert to someone on my team?
      - Can I add and remove the same assignee in one request?
      instructions:
      - text: Assign {assignees} to detection alerts {ids}.
        slots:
          assignees: requestBody.assignees
          ids: requestBody.ids
      - text: Change the assigned users on alerts {ids} to {assignees}.
        slots:
          ids: requestBody.ids
          assignees: requestBody.assignees
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/signals/finalize_migration'].post
  update:
    x-apievangelist-phrasing:
      intent: Finalize a legacy alert index migration
      effect: destructive
      questions:
      - How do I complete a legacy .siem-signals migration once it has finished?
      - What does finalizing an alert migration do to the read aliases?
      instructions:
      - text: Finalize alert migrations {migration_ids}.
        slots:
          migration_ids: requestBody.migration_ids
      - text: Swap read aliases to complete migrations {migration_ids}.
        slots:
          migration_ids: requestBody.migration_ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/signals/migration'].post
  update:
    x-apievangelist-phrasing:
      intent: Start a legacy alert index migration
      effect: write
      questions:
      - Can I reindex an old .siem-signals alert index to the new mapping?
      - How do I throttle a legacy alert reindex with requests per second?
      instructions:
      - text: Start a migration of alert index {index}.
        slots:
          index: requestBody.index
      - text: Migrate legacy alert indices {index} at {requests_per_second} requests per second.
        slots:
          index: requestBody.index
          requests_per_second: requestBody.requests_per_second
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/signals/migration'].delete
  update:
    x-apievangelist-phrasing:
      intent: Clean up legacy alert migrations
      effect: destructive
      questions:
      - How do I clean up old artifacts left from a signals index migration?
      - Does migration cleanup schedule the source index for deletion?
      instructions:
      - text: Clean up alert migrations {migration_ids}.
        slots:
          migration_ids: requestBody.migration_ids
      - text: Schedule deletion of the source indices for migrations {migration_ids}.
        slots:
          migration_ids: requestBody.migration_ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/signals/migration_status'].get
  update:
    x-apievangelist-phrasing:
      intent: Check legacy alert migration status
      effect: read
      questions:
      - Which old .siem-signals indices still need migrating?
      - What's the status of alert index migrations since a given date?
      instructions:
      - text: Show alert migration status for indices with alerts since {from}.
        slots:
          from: query.from
      - text: Check which legacy signal indices are outdated starting from {from}.
        slots:
          from: query.from
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/signals/search'].post
  update:
    x-apievangelist-phrasing:
      intent: Search and aggregate detection alerts
      effect: read
      questions:
      - Which detection alerts match a query I write in Elasticsearch DSL?
      - Can I aggregate detection alerts by rule name or severity?
      instructions:
      - text: Search detection alerts matching {query}.
        slots:
          query: requestBody.query
      - text: Aggregate detection alerts using {aggs}.
        slots:
          aggs: requestBody.aggs
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/signals/status'].post
  update:
    x-apievangelist-phrasing:
      intent: Open, acknowledge or close detection alerts
      effect: write
      questions:
      - How do I close a batch of detection alerts?
      - Can I set detection alerts back to open after acknowledging them?
      instructions:
      - text: Close the detection alerts I've triaged.
      - text: Mark these detection alerts as acknowledged.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/signals/tags'].post
  update:
    x-apievangelist-phrasing:
      intent: Tag or untag detection alerts
      effect: write
      questions:
      - Can I add and remove tags on detection alerts in one call?
      - Is it possible to tag detection alerts that match a query instead of by id?
      instructions:
      - text: Update tags on detection alerts {ids} with {tags}.
        slots:
          ids: requestBody.ids
          tags: requestBody.tags
      - text: Add and remove the tag changes {tags} on alerts {ids}.
        slots:
          tags: requestBody.tags
          ids: requestBody.ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/detection_engine/tags'].get
  update:
    x-apievangelist-phrasing:
      intent: List detection rule tags
      effect: read
      questions:
      - What tags are in use across all my detection rules?
      - Can I get the unique list of rule tags?
      instructions:
      - text: List all unique detection rule tags.
      - text: Show every tag used by my detection rules.
      method: generated
      generated: '2026-09-26'