Elastic Stack · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Kibana Security Endpoint Management API
30 actions
30 updates
phrasing
extends
openapi/elk-stack-security-endpoint-management-api-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
What the actions change
x-apievangelist-phrasing
Targets 30 · first 16 shown; the file carries all of them
$.info
$.paths['/api/endpoint/action'].get
$.paths['/api/endpoint/action_status'].get
$.paths['/api/endpoint/action/{action_id}'].get
$.paths['/api/endpoint/action/{action_id}/file/{file_id}'].get
$.paths['/api/endpoint/action/{action_id}/file/{file_id}/download'].get
$.paths['/api/endpoint/action/cancel'].post
$.paths['/api/endpoint/action/execute'].post
$.paths['/api/endpoint/action/get_file'].post
$.paths['/api/endpoint/action/isolate'].post
$.paths['/api/endpoint/action/kill_process'].post
$.paths['/api/endpoint/action/memory_dump'].post
$.paths['/api/endpoint/action/run_script'].post
$.paths['/api/endpoint/action/running_procs'].post
$.paths['/api/endpoint/action/scan'].post
$.paths['/api/endpoint/action/state'].get
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Kibana Security Endpoint Management API
version: 1.0.0
extends: openapi/elk-stack-security-endpoint-management-api-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 29
- target: $.paths['/api/endpoint/action'].get
update:
x-apievangelist-phrasing:
intent: List endpoint response actions
effect: read
questions:
- What response actions have been run against my endpoints?
- Can I filter response action history by user or date range?
- Which isolate or kill-process commands were issued on a given agent?
instructions:
- text: List all endpoint response actions.
- text: Show response actions run on agents {agent_ids}.
slots:
agent_ids: query.agentIds
- text: List {commands} response actions issued between {start} and {end}.
slots:
commands: query.commands
start: query.startDate
end: query.endDate
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/action_status'].get
update:
x-apievangelist-phrasing:
intent: Get pending response action status for agents
effect: read
questions:
- Do any of my agents have response actions still pending?
- What is the response action status for a set of endpoint agents?
instructions:
- text: Check the response action status for agents {agent_ids}.
slots:
agent_ids: query.agent_ids
- text: Show pending action counts for agent {agent_ids}.
slots:
agent_ids: query.agent_ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/{action_id}'].get
update:
x-apievangelist-phrasing:
intent: Get details of a response action
effect: read
questions:
- Did a specific response action complete successfully?
- What output did one particular response action return?
instructions:
- text: Show the details of response action {action_id}.
slots:
action_id: path.action_id
- text: Check whether action {action_id} finished.
slots:
action_id: path.action_id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/{action_id}/file/{file_id}'].get
update:
x-apievangelist-phrasing:
intent: Get info about a response action file
effect: read
questions:
- What file was collected by a get-file response action, and how big is it?
- Is a retrieved endpoint file ready for download yet?
instructions:
- text: Show information for file {file_id} from action {action_id}.
slots:
file_id: path.file_id
action_id: path.action_id
- text: Check the status of file {file_id} retrieved by action {action_id}.
slots:
file_id: path.file_id
action_id: path.action_id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/{action_id}/file/{file_id}/download'].get
update:
x-apievangelist-phrasing:
intent: Download a file from a response action
effect: read
questions:
- How can I download a file that was pulled from an endpoint?
- What password opens the zip archive of a retrieved endpoint file?
instructions:
- text: Download file {file_id} from response action {action_id}.
slots:
file_id: path.file_id
action_id: path.action_id
- text: Save the zipped file {file_id} collected by action {action_id}.
slots:
file_id: path.file_id
action_id: path.action_id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/cancel'].post
update:
x-apievangelist-phrasing:
intent: Cancel a pending response action
effect: destructive
questions:
- Can I cancel a response action that is still pending on a host?
- Is cancelling a running response action supported for every agent type?
instructions:
- text: Cancel the pending response action on endpoint {endpoint_ids}.
slots:
endpoint_ids: requestBody.endpoint_ids
- text: Cancel the running action on {endpoint_ids} with comment {comment}.
slots:
endpoint_ids: requestBody.endpoint_ids
comment: requestBody.comment
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/execute'].post
update:
x-apievangelist-phrasing:
intent: Run a shell command on an endpoint
effect: write
questions:
- Can I run a shell command remotely on a compromised host?
- How do I execute a command on an endpoint and capture its output?
instructions:
- text: Run the shell command {parameters} on endpoint {endpoint_ids}.
slots:
parameters: requestBody.parameters
endpoint_ids: requestBody.endpoint_ids
- text: Execute a command on {endpoint_ids} and link it to case {case_ids}.
slots:
endpoint_ids: requestBody.endpoint_ids
case_ids: requestBody.case_ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/get_file'].post
update:
x-apievangelist-phrasing:
intent: Retrieve a file from an endpoint
effect: write
questions:
- Can I pull a suspicious file off a host for analysis?
- What do I need to collect a file from an endpoint by path?
instructions:
- text: Retrieve the file at {parameters} from endpoint {endpoint_ids}.
slots:
parameters: requestBody.parameters
endpoint_ids: requestBody.endpoint_ids
- text: Collect a file from host {endpoint_ids} for alert {alert_ids}.
slots:
endpoint_ids: requestBody.endpoint_ids
alert_ids: requestBody.alert_ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/isolate'].post
update:
x-apievangelist-phrasing:
intent: Isolate an endpoint from the network
effect: write
questions:
- How do I cut a compromised host off from the network?
- Does an isolated endpoint stay isolated until someone releases it?
instructions:
- text: Isolate endpoint {endpoint_ids} from the network.
slots:
endpoint_ids: requestBody.endpoint_ids
- text: Network-isolate host {endpoint_ids} with the note {comment}.
slots:
endpoint_ids: requestBody.endpoint_ids
comment: requestBody.comment
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/kill_process'].post
update:
x-apievangelist-phrasing:
intent: Terminate a process on an endpoint
effect: destructive
questions:
- Can I kill a malicious process running on a host?
- What details do I need to terminate a process by PID on an endpoint?
instructions:
- text: Kill process {parameters} on endpoint {endpoint_ids}.
slots:
parameters: requestBody.parameters
endpoint_ids: requestBody.endpoint_ids
- text: Terminate the running process on {endpoint_ids} tied to alert {alert_ids}.
slots:
endpoint_ids: requestBody.endpoint_ids
alert_ids: requestBody.alert_ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/memory_dump'].post
update:
x-apievangelist-phrasing:
intent: Capture a memory dump from a host
effect: write
questions:
- Can I capture a memory dump from a host under investigation?
- Is a memory dump taken of the whole machine or a single process?
instructions:
- text: Generate a memory dump on endpoint {endpoint_ids}.
slots:
endpoint_ids: requestBody.endpoint_ids
- text: Capture memory from {endpoint_ids} using options {parameters}.
slots:
endpoint_ids: requestBody.endpoint_ids
parameters: requestBody.parameters
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/run_script'].post
update:
x-apievangelist-phrasing:
intent: Run a script on a host
effect: write
questions:
- Can I run a remediation script on a host remotely?
- Which agent types support running a script as a response action?
instructions:
- text: Run script {parameters} on endpoint {endpoint_ids}.
slots:
parameters: requestBody.parameters
endpoint_ids: requestBody.endpoint_ids
- text: Run a script on {endpoint_ids} for agent type {agent_type}.
slots:
endpoint_ids: requestBody.endpoint_ids
agent_type: requestBody.agent_type
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/running_procs'].post
update:
x-apievangelist-phrasing:
intent: List processes running on an endpoint
effect: write
questions:
- What processes are running on a suspicious host right now?
- Can I pull a live process list from an endpoint?
instructions:
- text: Get the running processes on endpoint {endpoint_ids}.
slots:
endpoint_ids: requestBody.endpoint_ids
- text: Pull a process list from {endpoint_ids} for case {case_ids}.
slots:
endpoint_ids: requestBody.endpoint_ids
case_ids: requestBody.case_ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/scan'].post
update:
x-apievangelist-phrasing:
intent: Scan a file or folder for malware
effect: write
questions:
- Can I trigger a malware scan of a folder on a host?
- Is it possible to scan one specific file on an endpoint?
instructions:
- text: Scan the path {parameters} on endpoint {endpoint_ids} for malware.
slots:
parameters: requestBody.parameters
endpoint_ids: requestBody.endpoint_ids
- text: Run a malware scan on {endpoint_ids}.
slots:
endpoint_ids: requestBody.endpoint_ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/state'].get
update:
x-apievangelist-phrasing:
intent: Check whether response action encryption is on
effect: read
questions:
- Is encryption enabled for endpoint response actions?
- What is the overall state of the response actions feature?
instructions:
- text: Check the response actions state.
- text: Tell me if response action encryption is enabled.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/suspend_process'].post
update:
x-apievangelist-phrasing:
intent: Suspend a process on an endpoint
effect: write
questions:
- Can I pause a suspicious process without killing it?
- What do I need to suspend a running process on a host?
instructions:
- text: Suspend process {parameters} on endpoint {endpoint_ids}.
slots:
parameters: requestBody.parameters
endpoint_ids: requestBody.endpoint_ids
- text: Freeze the running process on {endpoint_ids} with note {comment}.
slots:
endpoint_ids: requestBody.endpoint_ids
comment: requestBody.comment
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/unisolate'].post
update:
x-apievangelist-phrasing:
intent: Release an isolated endpoint
effect: write
questions:
- How do I bring an isolated host back onto the network?
- Can I release several isolated endpoints at once?
instructions:
- text: Release endpoint {endpoint_ids} from isolation.
slots:
endpoint_ids: requestBody.endpoint_ids
- text: Unisolate host {endpoint_ids} and note {comment}.
slots:
endpoint_ids: requestBody.endpoint_ids
comment: requestBody.comment
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/action/upload'].post
update:
x-apievangelist-phrasing:
intent: Upload a file to an endpoint
effect: write
questions:
- Can I push a file onto a host during an investigation?
- Where does a file uploaded to an endpoint end up?
instructions:
- text: Upload {file} to endpoint {endpoint_ids}.
slots:
file: requestBody.file
endpoint_ids: requestBody.endpoint_ids
- text: Send the file {file} to host {endpoint_ids} with options {parameters}.
slots:
file: requestBody.file
endpoint_ids: requestBody.endpoint_ids
parameters: requestBody.parameters
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/metadata'].get
update:
x-apievangelist-phrasing:
intent: List endpoint host metadata
effect: read
questions:
- Which endpoints are enrolled and what is their host status?
- Can I list only unhealthy or offline endpoints?
instructions:
- text: List endpoint hosts with status {host_statuses}.
slots:
host_statuses: query.hostStatuses
- text: Show endpoints matching {kuery} with status {host_statuses}.
slots:
kuery: query.kuery
host_statuses: query.hostStatuses
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/metadata/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get host metadata for one endpoint
effect: read
questions:
- What OS and agent version is a specific endpoint running?
- Which policy is applied to one particular host?
instructions:
- text: Show host metadata for endpoint {id}.
slots:
id: path.id
- text: Get the details of endpoint {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/policy_response'].get
update:
x-apievangelist-phrasing:
intent: Get an endpoint's latest policy response
effect: read
questions:
- Did the endpoint security policy apply successfully on a host?
- Why is a policy failing on a particular agent?
instructions:
- text: Show the latest policy response for agent {agent_id}.
slots:
agent_id: query.agentId
- text: Check policy application status on agent {agent_id}.
slots:
agent_id: query.agentId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/protection_updates_note/{package_policy_id}'].get
update:
x-apievangelist-phrasing:
intent: Get a protection updates note
effect: read
questions:
- What note is recorded about protection updates for a policy?
- Why were protection updates pinned on a package policy?
instructions:
- text: Show the protection updates note for policy {package_policy_id}.
slots:
package_policy_id: path.package_policy_id
- text: Read the protection note on {package_policy_id}.
slots:
package_policy_id: path.package_policy_id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/protection_updates_note/{package_policy_id}'].post
update:
x-apievangelist-phrasing:
intent: Write the protection updates note for a policy
effect: write
questions:
- Can I record why protection updates were paused on a policy?
- How do I change the protection updates note on a package policy?
instructions:
- text: Set the protection updates note on policy {package_policy_id} to {note}.
slots:
package_policy_id: path.package_policy_id
note: requestBody.note
- text: Save the note {note} for protection updates on {package_policy_id}.
slots:
note: requestBody.note
package_policy_id: path.package_policy_id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/scripts_library'].get
update:
x-apievangelist-phrasing:
intent: List scripts in the script library
effect: read
questions:
- What scripts are in my endpoint script library?
- Can I search the script library by name or platform?
instructions:
- text: List all scripts in the script library.
- text: Find library scripts matching {kuery}.
slots:
kuery: query.kuery
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/scripts_library'].post
update:
x-apievangelist-phrasing:
intent: Add a script to the script library
effect: write
questions:
- How do I add a new script to the endpoint script library?
- Which platforms can a library script target?
instructions:
- text: Upload {file} as script {name} for platform {platform} as {file_type}.
slots:
file: requestBody.file
name: requestBody.name
platform: requestBody.platform
file_type: requestBody.fileType
- text: Create library script {name} from {file} ({file_type}) for {platform}, tagged {tags}.
slots:
name: requestBody.name
file: requestBody.file
file_type: requestBody.fileType
platform: requestBody.platform
tags: requestBody.tags
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/scripts_library/{script_id}'].get
update:
x-apievangelist-phrasing:
intent: Get a script from the library
effect: read
questions:
- What does a specific script in the library do and which platform is it for?
- Does one library script require input when it runs?
instructions:
- text: Show library script {script_id}.
slots:
script_id: path.script_id
- text: Get the details and instructions of script {script_id}.
slots:
script_id: path.script_id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/scripts_library/{script_id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a script from the library
effect: destructive
questions:
- Can I remove an outdated script from the script library?
- Is deleting a library script permanent?
instructions:
- text: Delete library script {script_id}.
slots:
script_id: path.script_id
- text: Remove script {script_id} from the script library.
slots:
script_id: path.script_id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/scripts_library/{script_id}'].patch
update:
x-apievangelist-phrasing:
intent: Update a script in the library
effect: write
questions:
- Can I change just the description of a library script?
- How do I replace the file behind an existing library script?
instructions:
- text: Rename library script {script_id} to {name}.
slots:
script_id: path.script_id
name: requestBody.name
- text: Replace the file of script {script_id} with {file}.
slots:
script_id: path.script_id
file: requestBody.file
method: generated
generated: '2026-09-26'
- target: $.paths['/api/endpoint/scripts_library/{script_id}/download'].get
update:
x-apievangelist-phrasing:
intent: Download a library script file
effect: read
questions:
- Can I download the file behind a script in the library?
- Where do I get the source of a library script to review it?
instructions:
- text: Download the file for library script {script_id}.
slots:
script_id: path.script_id
- text: Fetch the script source of {script_id}.
slots:
script_id: path.script_id
method: generated
generated: '2026-09-26'