Elastic Stack · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Kibana Security Endpoint Exceptions API

7 actions 7 updates phrasing extends openapi/elk-stack-security-endpoint-exceptions-api-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 7

$.info
$.paths['/api/endpoint_list'].post
$.paths['/api/endpoint_list/items'].get
$.paths['/api/endpoint_list/items'].put
$.paths['/api/endpoint_list/items'].post
$.paths['/api/endpoint_list/items'].delete
$.paths['/api/endpoint_list/items/_find'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Kibana Security Endpoint Exceptions API
  version: 1.0.0
extends: openapi/elk-stack-security-endpoint-exceptions-api-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 6
- target: $.paths['/api/endpoint_list'].post
  update:
    x-apievangelist-phrasing:
      intent: Create the Elastic Endpoint exception list
      effect: write
      questions:
      - How do I set up the exception list that Elastic Endpoint rules use?
      - What happens if the Endpoint exception list already exists when I create it?
      instructions:
      - text: Create the Elastic Endpoint exception list.
      - text: Initialize the endpoint_list container for Endpoint rule exceptions.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint_list/items'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an Endpoint exception item
      effect: read
      questions:
      - What conditions does a specific Endpoint exception item contain?
      - Can I look up an Endpoint exception by its human item_id instead of the ID?
      instructions:
      - text: Show Endpoint exception item {item_id}.
        slots:
          item_id: query.item_id
      - text: Get the Endpoint exception with ID {id}.
        slots:
          id: query.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint_list/items'].put
  update:
    x-apievangelist-phrasing:
      intent: Update an Endpoint exception item
      effect: write
      questions:
      - How do I edit the entries of an existing Endpoint exception?
      - Can I change which operating systems an Endpoint exception applies to?
      instructions:
      - text: 'Update Endpoint exception {item_id}: name {name}, description {description}, type {type}, entries {entries}.'
        slots:
          item_id: requestBody.item_id
          name: requestBody.name
          description: requestBody.description
          type: requestBody.type
          entries: requestBody.entries
      - text: Change OS types to {os_types} on exception {id} ({name}, {description}, {type}, {entries}).
        slots:
          os_types: requestBody.os_types
          id: requestBody.id
          name: requestBody.name
          description: requestBody.description
          type: requestBody.type
          entries: requestBody.entries
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint_list/items'].post
  update:
    x-apievangelist-phrasing:
      intent: Add an Endpoint exception item
      effect: write
      questions:
      - How do I stop Elastic Endpoint from alerting on a trusted process?
      - Can a new Endpoint exception target only Windows or macOS?
      instructions:
      - text: Add Endpoint exception {name} ({description}) of type {type} with entries {entries}.
        slots:
          name: requestBody.name
          description: requestBody.description
          type: requestBody.type
          entries: requestBody.entries
      - text: 'Create a {type} Endpoint exception {name} for OS {os_types}: {description}, entries {entries}.'
        slots:
          name: requestBody.name
          description: requestBody.description
          type: requestBody.type
          entries: requestBody.entries
          os_types: requestBody.os_types
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint_list/items'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an Endpoint exception item
      effect: destructive
      questions:
      - How can I remove an Endpoint exception so those events alert again?
      - Can I delete an Endpoint exception using its item_id?
      instructions:
      - text: Delete Endpoint exception item {item_id}.
        slots:
          item_id: query.item_id
      - text: Remove the Endpoint exception with ID {id}.
        slots:
          id: query.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint_list/items/_find'].get
  update:
    x-apievangelist-phrasing:
      intent: List Endpoint exception items
      effect: read
      questions:
      - Which exceptions are currently on the Elastic Endpoint list?
      - Can I filter and sort the Endpoint exception items?
      instructions:
      - text: List all Endpoint exception items.
      - text: Find Endpoint exceptions matching {filter} sorted by {sort_field}.
        slots:
          filter: query.filter
          sort_field: query.sort_field
      method: generated
      generated: '2026-09-26'