Elastic Stack · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Kibana Security entity store API
18 actions
18 updates
phrasing
extends
openapi/elk-stack-security-entity-store-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
What the actions change
x-apievangelist-phrasing
Targets 18 · first 16 shown; the file carries all of them
$.info
$.paths['/api/security/entity_store'].put
$.paths['/api/security/entity_store/entities'].get
$.paths['/api/security/entity_store/entities/'].delete
$.paths['/api/security/entity_store/entities/{entityType}'].put
$.paths['/api/security/entity_store/entities/{entityType}'].post
$.paths['/api/security/entity_store/entities/bulk'].put
$.paths['/api/security/entity_store/install'].post
$.paths['/api/security/entity_store/resolution/group'].get
$.paths['/api/security/entity_store/resolution/link'].post
$.paths['/api/security/entity_store/resolution/rules'].get
$.paths['/api/security/entity_store/resolution/rules/{id}/disable'].put
$.paths['/api/security/entity_store/resolution/rules/{id}/enable'].put
$.paths['/api/security/entity_store/resolution/unlink'].post
$.paths['/api/security/entity_store/start'].put
$.paths['/api/security/entity_store/status'].get
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Kibana Security entity store API
version: 1.0.0
extends: openapi/elk-stack-security-entity-store-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 17
- target: $.paths['/api/security/entity_store'].put
update:
x-apievangelist-phrasing:
intent: Change Entity Store log extraction settings
effect: write
questions:
- Can I adjust how the Entity Store extracts entities from logs after it is installed?
- Where is the shared log extraction configuration for entity engines updated?
instructions:
- text: Update the Entity Store log extraction configuration to {logExtraction}.
slots:
logExtraction: requestBody.logExtraction
- text: Apply log extraction settings {logExtraction} to the installed Entity Store.
slots:
logExtraction: requestBody.logExtraction
method: generated
generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/entities'].get
update:
x-apievangelist-phrasing:
intent: List entities in the Entity Store
effect: read
questions:
- Which hosts, users and services has the Entity Store recorded?
- Can I page through entity records with a cursor instead of page numbers?
- Is it possible to filter entities to only certain entity types and sort them?
instructions:
- text: List Entity Store entities of types {entity_types}, {per_page} per page.
slots:
entity_types: query.entity_types
per_page: query.per_page
- text: Find entities matching filter {filterQuery} sorted by {sort_field}.
slots:
filterQuery: query.filterQuery
sort_field: query.sort_field
method: generated
generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/entities/'].delete
update:
x-apievangelist-phrasing:
intent: Delete an entity record
effect: destructive
questions:
- How can I remove a single host or user entity from the Entity Store?
- Is a deleted entity removed from the latest index right away?
instructions:
- text: Delete entity {entityId} from the Entity Store.
slots:
entityId: requestBody.entityId
- text: Remove the entity record with ID {entityId}.
slots:
entityId: requestBody.entityId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/entities/{entityType}'].put
update:
x-apievangelist-phrasing:
intent: Update one entity record
effect: write
questions:
- Can I edit fields on an existing host or user entity?
- How do I overwrite protected fields on an entity record?
instructions:
- text: Update an existing {entityType} entity record with these fields.
slots:
entityType: path.entityType
- text: Force-update protected fields on a {entityType} entity, force {force}.
slots:
entityType: path.entityType
force: query.force
method: generated
generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/entities/{entityType}'].post
update:
x-apievangelist-phrasing:
intent: Create an entity record
effect: write
questions:
- How do I add a new user or host entity to the Entity Store by hand?
- Which entity types can I create records for?
instructions:
- text: Create a new {entityType} entity in the Entity Store.
slots:
entityType: path.entityType
- text: Add a {entityType} entity record with the details I provide.
slots:
entityType: path.entityType
method: generated
generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/entities/bulk'].put
update:
x-apievangelist-phrasing:
intent: Update many entity records at once
effect: write
questions:
- Can I update a batch of entity records in a single request?
- Does bulk entity update support forcing changes to protected fields?
instructions:
- text: 'Bulk update these entity records: {entities}.'
slots:
entities: requestBody.entities
- text: Apply updates {entities} to multiple entities with force {force}.
slots:
entities: requestBody.entities
force: query.force
method: generated
generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/install'].post
update:
x-apievangelist-phrasing:
intent: Install the Entity Store
effect: write
questions:
- How do I turn on the Entity Store for hosts and users in Elastic Security?
- Can I enable history snapshots when installing entity engines?
instructions:
- text: Install the Entity Store with engines for {entityTypes}.
slots:
entityTypes: requestBody.entityTypes
- text: Set up Entity Store engines for {entityTypes} with history snapshot {historySnapshot}.
slots:
entityTypes: requestBody.entityTypes
historySnapshot: requestBody.historySnapshot
method: generated
generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/resolution/group'].get
update:
x-apievangelist-phrasing:
intent: Show an entity's resolution group
effect: read
questions:
- Which other entities have been linked to this one as the same identity?
- Can I see every account resolved together with a given entity?
instructions:
- text: Show the resolution group for entity {entity_id}.
slots:
entity_id: query.entity_id
- text: List all entities linked to {entity_id}.
slots:
entity_id: query.entity_id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/resolution/link'].post
update:
x-apievangelist-phrasing:
intent: Link entities as the same identity
effect: write
questions:
- How do I tell Elastic Security that several user accounts belong to the same person?
- When do newly linked entities show up in reads?
instructions:
- text: Link entities {entity_ids} to target entity {target_id}.
slots:
entity_ids: requestBody.entity_ids
target_id: requestBody.target_id
- text: Merge {entity_ids} into the resolution group of {target_id}.
slots:
entity_ids: requestBody.entity_ids
target_id: requestBody.target_id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/resolution/rules'].get
update:
x-apievangelist-phrasing:
intent: List entity resolution rules
effect: read
questions:
- What managed entity resolution rules exist in this space, and which are enabled?
- Can I see the effective state of every resolution rule?
instructions:
- text: List the entity resolution rules in this space.
- text: Show which resolution rules are currently enabled.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/resolution/rules/{id}/disable'].put
update:
x-apievangelist-phrasing:
intent: Disable an entity resolution rule
effect: write
questions:
- Can I switch off a managed resolution rule that is merging entities wrongly?
- Does disabling a resolution rule apply only to the current space?
instructions:
- text: Disable resolution rule {id}.
slots:
id: path.id
- text: Turn off entity resolution rule {id} in this space.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/resolution/rules/{id}/enable'].put
update:
x-apievangelist-phrasing:
intent: Enable an entity resolution rule
effect: write
questions:
- How do I turn a managed resolution rule back on?
- Can I activate a resolution rule for just this space?
instructions:
- text: Enable resolution rule {id}.
slots:
id: path.id
- text: Switch on entity resolution rule {id} for this space.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/resolution/unlink'].post
update:
x-apievangelist-phrasing:
intent: Unlink entities from their resolution group
effect: write
questions:
- How can I separate accounts that were wrongly linked as one identity?
- Can I pull several entities out of their resolution groups at once?
instructions:
- text: Unlink entities {entity_ids} from their resolution group.
slots:
entity_ids: requestBody.entity_ids
- text: Detach {entity_ids} so they are no longer resolved together.
slots:
entity_ids: requestBody.entity_ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/start'].put
update:
x-apievangelist-phrasing:
intent: Start stopped entity engines
effect: write
questions:
- How do I resume entity engines I paused earlier?
- Can I restart processing for only some entity types?
instructions:
- text: Start the entity engines for {entityTypes}.
slots:
entityTypes: requestBody.entityTypes
- text: Resume all stopped Entity Store engines.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/status'].get
update:
x-apievangelist-phrasing:
intent: Check Entity Store status
effect: read
questions:
- Is the Entity Store installed and are its engines running?
- Can I get component-level health details for each entity engine?
instructions:
- text: Show the Entity Store status.
- text: Get engine statuses with component health, include_components {include_components}.
slots:
include_components: query.include_components
method: generated
generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/stop'].put
update:
x-apievangelist-phrasing:
intent: Stop running entity engines
effect: write
questions:
- Can I pause entity engines without uninstalling the Entity Store?
- How do I stop data processing for one entity type?
instructions:
- text: Stop the entity engines for {entityTypes}.
slots:
entityTypes: requestBody.entityTypes
- text: Pause every running Entity Store engine.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/uninstall'].post
update:
x-apievangelist-phrasing:
intent: Uninstall the Entity Store
effect: destructive
questions:
- How do I remove the Entity Store and its engines completely?
- Can I uninstall engines for only certain entity types?
instructions:
- text: Uninstall the Entity Store engines for {entityTypes}.
slots:
entityTypes: requestBody.entityTypes
- text: Remove the Entity Store and all its resources.
method: generated
generated: '2026-09-26'