Elastic Stack · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Kibana Security Endpoint Management API

30 actions 30 updates phrasing extends openapi/elk-stack-security-endpoint-management-api-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 30 · first 16 shown; the file carries all of them

$.info
$.paths['/api/endpoint/action'].get
$.paths['/api/endpoint/action_status'].get
$.paths['/api/endpoint/action/{action_id}'].get
$.paths['/api/endpoint/action/{action_id}/file/{file_id}'].get
$.paths['/api/endpoint/action/{action_id}/file/{file_id}/download'].get
$.paths['/api/endpoint/action/cancel'].post
$.paths['/api/endpoint/action/execute'].post
$.paths['/api/endpoint/action/get_file'].post
$.paths['/api/endpoint/action/isolate'].post
$.paths['/api/endpoint/action/kill_process'].post
$.paths['/api/endpoint/action/memory_dump'].post
$.paths['/api/endpoint/action/run_script'].post
$.paths['/api/endpoint/action/running_procs'].post
$.paths['/api/endpoint/action/scan'].post
$.paths['/api/endpoint/action/state'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Kibana Security Endpoint Management API
  version: 1.0.0
extends: openapi/elk-stack-security-endpoint-management-api-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 29
- target: $.paths['/api/endpoint/action'].get
  update:
    x-apievangelist-phrasing:
      intent: List endpoint response actions
      effect: read
      questions:
      - What response actions have been run against my endpoints?
      - Can I filter response action history by user or date range?
      - Which isolate or kill-process commands were issued on a given agent?
      instructions:
      - text: List all endpoint response actions.
      - text: Show response actions run on agents {agent_ids}.
        slots:
          agent_ids: query.agentIds
      - text: List {commands} response actions issued between {start} and {end}.
        slots:
          commands: query.commands
          start: query.startDate
          end: query.endDate
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/action_status'].get
  update:
    x-apievangelist-phrasing:
      intent: Get pending response action status for agents
      effect: read
      questions:
      - Do any of my agents have response actions still pending?
      - What is the response action status for a set of endpoint agents?
      instructions:
      - text: Check the response action status for agents {agent_ids}.
        slots:
          agent_ids: query.agent_ids
      - text: Show pending action counts for agent {agent_ids}.
        slots:
          agent_ids: query.agent_ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/{action_id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get details of a response action
      effect: read
      questions:
      - Did a specific response action complete successfully?
      - What output did one particular response action return?
      instructions:
      - text: Show the details of response action {action_id}.
        slots:
          action_id: path.action_id
      - text: Check whether action {action_id} finished.
        slots:
          action_id: path.action_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/{action_id}/file/{file_id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get info about a response action file
      effect: read
      questions:
      - What file was collected by a get-file response action, and how big is it?
      - Is a retrieved endpoint file ready for download yet?
      instructions:
      - text: Show information for file {file_id} from action {action_id}.
        slots:
          file_id: path.file_id
          action_id: path.action_id
      - text: Check the status of file {file_id} retrieved by action {action_id}.
        slots:
          file_id: path.file_id
          action_id: path.action_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/{action_id}/file/{file_id}/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download a file from a response action
      effect: read
      questions:
      - How can I download a file that was pulled from an endpoint?
      - What password opens the zip archive of a retrieved endpoint file?
      instructions:
      - text: Download file {file_id} from response action {action_id}.
        slots:
          file_id: path.file_id
          action_id: path.action_id
      - text: Save the zipped file {file_id} collected by action {action_id}.
        slots:
          file_id: path.file_id
          action_id: path.action_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/cancel'].post
  update:
    x-apievangelist-phrasing:
      intent: Cancel a pending response action
      effect: destructive
      questions:
      - Can I cancel a response action that is still pending on a host?
      - Is cancelling a running response action supported for every agent type?
      instructions:
      - text: Cancel the pending response action on endpoint {endpoint_ids}.
        slots:
          endpoint_ids: requestBody.endpoint_ids
      - text: Cancel the running action on {endpoint_ids} with comment {comment}.
        slots:
          endpoint_ids: requestBody.endpoint_ids
          comment: requestBody.comment
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/execute'].post
  update:
    x-apievangelist-phrasing:
      intent: Run a shell command on an endpoint
      effect: write
      questions:
      - Can I run a shell command remotely on a compromised host?
      - How do I execute a command on an endpoint and capture its output?
      instructions:
      - text: Run the shell command {parameters} on endpoint {endpoint_ids}.
        slots:
          parameters: requestBody.parameters
          endpoint_ids: requestBody.endpoint_ids
      - text: Execute a command on {endpoint_ids} and link it to case {case_ids}.
        slots:
          endpoint_ids: requestBody.endpoint_ids
          case_ids: requestBody.case_ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/get_file'].post
  update:
    x-apievangelist-phrasing:
      intent: Retrieve a file from an endpoint
      effect: write
      questions:
      - Can I pull a suspicious file off a host for analysis?
      - What do I need to collect a file from an endpoint by path?
      instructions:
      - text: Retrieve the file at {parameters} from endpoint {endpoint_ids}.
        slots:
          parameters: requestBody.parameters
          endpoint_ids: requestBody.endpoint_ids
      - text: Collect a file from host {endpoint_ids} for alert {alert_ids}.
        slots:
          endpoint_ids: requestBody.endpoint_ids
          alert_ids: requestBody.alert_ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/isolate'].post
  update:
    x-apievangelist-phrasing:
      intent: Isolate an endpoint from the network
      effect: write
      questions:
      - How do I cut a compromised host off from the network?
      - Does an isolated endpoint stay isolated until someone releases it?
      instructions:
      - text: Isolate endpoint {endpoint_ids} from the network.
        slots:
          endpoint_ids: requestBody.endpoint_ids
      - text: Network-isolate host {endpoint_ids} with the note {comment}.
        slots:
          endpoint_ids: requestBody.endpoint_ids
          comment: requestBody.comment
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/kill_process'].post
  update:
    x-apievangelist-phrasing:
      intent: Terminate a process on an endpoint
      effect: destructive
      questions:
      - Can I kill a malicious process running on a host?
      - What details do I need to terminate a process by PID on an endpoint?
      instructions:
      - text: Kill process {parameters} on endpoint {endpoint_ids}.
        slots:
          parameters: requestBody.parameters
          endpoint_ids: requestBody.endpoint_ids
      - text: Terminate the running process on {endpoint_ids} tied to alert {alert_ids}.
        slots:
          endpoint_ids: requestBody.endpoint_ids
          alert_ids: requestBody.alert_ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/memory_dump'].post
  update:
    x-apievangelist-phrasing:
      intent: Capture a memory dump from a host
      effect: write
      questions:
      - Can I capture a memory dump from a host under investigation?
      - Is a memory dump taken of the whole machine or a single process?
      instructions:
      - text: Generate a memory dump on endpoint {endpoint_ids}.
        slots:
          endpoint_ids: requestBody.endpoint_ids
      - text: Capture memory from {endpoint_ids} using options {parameters}.
        slots:
          endpoint_ids: requestBody.endpoint_ids
          parameters: requestBody.parameters
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/run_script'].post
  update:
    x-apievangelist-phrasing:
      intent: Run a script on a host
      effect: write
      questions:
      - Can I run a remediation script on a host remotely?
      - Which agent types support running a script as a response action?
      instructions:
      - text: Run script {parameters} on endpoint {endpoint_ids}.
        slots:
          parameters: requestBody.parameters
          endpoint_ids: requestBody.endpoint_ids
      - text: Run a script on {endpoint_ids} for agent type {agent_type}.
        slots:
          endpoint_ids: requestBody.endpoint_ids
          agent_type: requestBody.agent_type
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/running_procs'].post
  update:
    x-apievangelist-phrasing:
      intent: List processes running on an endpoint
      effect: write
      questions:
      - What processes are running on a suspicious host right now?
      - Can I pull a live process list from an endpoint?
      instructions:
      - text: Get the running processes on endpoint {endpoint_ids}.
        slots:
          endpoint_ids: requestBody.endpoint_ids
      - text: Pull a process list from {endpoint_ids} for case {case_ids}.
        slots:
          endpoint_ids: requestBody.endpoint_ids
          case_ids: requestBody.case_ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/scan'].post
  update:
    x-apievangelist-phrasing:
      intent: Scan a file or folder for malware
      effect: write
      questions:
      - Can I trigger a malware scan of a folder on a host?
      - Is it possible to scan one specific file on an endpoint?
      instructions:
      - text: Scan the path {parameters} on endpoint {endpoint_ids} for malware.
        slots:
          parameters: requestBody.parameters
          endpoint_ids: requestBody.endpoint_ids
      - text: Run a malware scan on {endpoint_ids}.
        slots:
          endpoint_ids: requestBody.endpoint_ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/state'].get
  update:
    x-apievangelist-phrasing:
      intent: Check whether response action encryption is on
      effect: read
      questions:
      - Is encryption enabled for endpoint response actions?
      - What is the overall state of the response actions feature?
      instructions:
      - text: Check the response actions state.
      - text: Tell me if response action encryption is enabled.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/suspend_process'].post
  update:
    x-apievangelist-phrasing:
      intent: Suspend a process on an endpoint
      effect: write
      questions:
      - Can I pause a suspicious process without killing it?
      - What do I need to suspend a running process on a host?
      instructions:
      - text: Suspend process {parameters} on endpoint {endpoint_ids}.
        slots:
          parameters: requestBody.parameters
          endpoint_ids: requestBody.endpoint_ids
      - text: Freeze the running process on {endpoint_ids} with note {comment}.
        slots:
          endpoint_ids: requestBody.endpoint_ids
          comment: requestBody.comment
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/unisolate'].post
  update:
    x-apievangelist-phrasing:
      intent: Release an isolated endpoint
      effect: write
      questions:
      - How do I bring an isolated host back onto the network?
      - Can I release several isolated endpoints at once?
      instructions:
      - text: Release endpoint {endpoint_ids} from isolation.
        slots:
          endpoint_ids: requestBody.endpoint_ids
      - text: Unisolate host {endpoint_ids} and note {comment}.
        slots:
          endpoint_ids: requestBody.endpoint_ids
          comment: requestBody.comment
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/upload'].post
  update:
    x-apievangelist-phrasing:
      intent: Upload a file to an endpoint
      effect: write
      questions:
      - Can I push a file onto a host during an investigation?
      - Where does a file uploaded to an endpoint end up?
      instructions:
      - text: Upload {file} to endpoint {endpoint_ids}.
        slots:
          file: requestBody.file
          endpoint_ids: requestBody.endpoint_ids
      - text: Send the file {file} to host {endpoint_ids} with options {parameters}.
        slots:
          file: requestBody.file
          endpoint_ids: requestBody.endpoint_ids
          parameters: requestBody.parameters
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/metadata'].get
  update:
    x-apievangelist-phrasing:
      intent: List endpoint host metadata
      effect: read
      questions:
      - Which endpoints are enrolled and what is their host status?
      - Can I list only unhealthy or offline endpoints?
      instructions:
      - text: List endpoint hosts with status {host_statuses}.
        slots:
          host_statuses: query.hostStatuses
      - text: Show endpoints matching {kuery} with status {host_statuses}.
        slots:
          kuery: query.kuery
          host_statuses: query.hostStatuses
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/metadata/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get host metadata for one endpoint
      effect: read
      questions:
      - What OS and agent version is a specific endpoint running?
      - Which policy is applied to one particular host?
      instructions:
      - text: Show host metadata for endpoint {id}.
        slots:
          id: path.id
      - text: Get the details of endpoint {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/policy_response'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an endpoint's latest policy response
      effect: read
      questions:
      - Did the endpoint security policy apply successfully on a host?
      - Why is a policy failing on a particular agent?
      instructions:
      - text: Show the latest policy response for agent {agent_id}.
        slots:
          agent_id: query.agentId
      - text: Check policy application status on agent {agent_id}.
        slots:
          agent_id: query.agentId
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/protection_updates_note/{package_policy_id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a protection updates note
      effect: read
      questions:
      - What note is recorded about protection updates for a policy?
      - Why were protection updates pinned on a package policy?
      instructions:
      - text: Show the protection updates note for policy {package_policy_id}.
        slots:
          package_policy_id: path.package_policy_id
      - text: Read the protection note on {package_policy_id}.
        slots:
          package_policy_id: path.package_policy_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/protection_updates_note/{package_policy_id}'].post
  update:
    x-apievangelist-phrasing:
      intent: Write the protection updates note for a policy
      effect: write
      questions:
      - Can I record why protection updates were paused on a policy?
      - How do I change the protection updates note on a package policy?
      instructions:
      - text: Set the protection updates note on policy {package_policy_id} to {note}.
        slots:
          package_policy_id: path.package_policy_id
          note: requestBody.note
      - text: Save the note {note} for protection updates on {package_policy_id}.
        slots:
          note: requestBody.note
          package_policy_id: path.package_policy_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/scripts_library'].get
  update:
    x-apievangelist-phrasing:
      intent: List scripts in the script library
      effect: read
      questions:
      - What scripts are in my endpoint script library?
      - Can I search the script library by name or platform?
      instructions:
      - text: List all scripts in the script library.
      - text: Find library scripts matching {kuery}.
        slots:
          kuery: query.kuery
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/scripts_library'].post
  update:
    x-apievangelist-phrasing:
      intent: Add a script to the script library
      effect: write
      questions:
      - How do I add a new script to the endpoint script library?
      - Which platforms can a library script target?
      instructions:
      - text: Upload {file} as script {name} for platform {platform} as {file_type}.
        slots:
          file: requestBody.file
          name: requestBody.name
          platform: requestBody.platform
          file_type: requestBody.fileType
      - text: Create library script {name} from {file} ({file_type}) for {platform}, tagged {tags}.
        slots:
          name: requestBody.name
          file: requestBody.file
          file_type: requestBody.fileType
          platform: requestBody.platform
          tags: requestBody.tags
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/scripts_library/{script_id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a script from the library
      effect: read
      questions:
      - What does a specific script in the library do and which platform is it for?
      - Does one library script require input when it runs?
      instructions:
      - text: Show library script {script_id}.
        slots:
          script_id: path.script_id
      - text: Get the details and instructions of script {script_id}.
        slots:
          script_id: path.script_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/scripts_library/{script_id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a script from the library
      effect: destructive
      questions:
      - Can I remove an outdated script from the script library?
      - Is deleting a library script permanent?
      instructions:
      - text: Delete library script {script_id}.
        slots:
          script_id: path.script_id
      - text: Remove script {script_id} from the script library.
        slots:
          script_id: path.script_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/scripts_library/{script_id}'].patch
  update:
    x-apievangelist-phrasing:
      intent: Update a script in the library
      effect: write
      questions:
      - Can I change just the description of a library script?
      - How do I replace the file behind an existing library script?
      instructions:
      - text: Rename library script {script_id} to {name}.
        slots:
          script_id: path.script_id
          name: requestBody.name
      - text: Replace the file of script {script_id} with {file}.
        slots:
          script_id: path.script_id
          file: requestBody.file
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/endpoint/scripts_library/{script_id}/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download a library script file
      effect: read
      questions:
      - Can I download the file behind a script in the library?
      - Where do I get the source of a library script to review it?
      instructions:
      - text: Download the file for library script {script_id}.
        slots:
          script_id: path.script_id
      - text: Fetch the script source of {script_id}.
        slots:
          script_id: path.script_id
      method: generated
      generated: '2026-09-26'