Elastic Stack · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Kibana Security entity store API

18 actions 18 updates phrasing extends openapi/elk-stack-security-entity-store-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 18 · first 16 shown; the file carries all of them

$.info
$.paths['/api/security/entity_store'].put
$.paths['/api/security/entity_store/entities'].get
$.paths['/api/security/entity_store/entities/'].delete
$.paths['/api/security/entity_store/entities/{entityType}'].put
$.paths['/api/security/entity_store/entities/{entityType}'].post
$.paths['/api/security/entity_store/entities/bulk'].put
$.paths['/api/security/entity_store/install'].post
$.paths['/api/security/entity_store/resolution/group'].get
$.paths['/api/security/entity_store/resolution/link'].post
$.paths['/api/security/entity_store/resolution/rules'].get
$.paths['/api/security/entity_store/resolution/rules/{id}/disable'].put
$.paths['/api/security/entity_store/resolution/rules/{id}/enable'].put
$.paths['/api/security/entity_store/resolution/unlink'].post
$.paths['/api/security/entity_store/start'].put
$.paths['/api/security/entity_store/status'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Kibana Security entity store API
  version: 1.0.0
extends: openapi/elk-stack-security-entity-store-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 17
- target: $.paths['/api/security/entity_store'].put
  update:
    x-apievangelist-phrasing:
      intent: Change Entity Store log extraction settings
      effect: write
      questions:
      - Can I adjust how the Entity Store extracts entities from logs after it is installed?
      - Where is the shared log extraction configuration for entity engines updated?
      instructions:
      - text: Update the Entity Store log extraction configuration to {logExtraction}.
        slots:
          logExtraction: requestBody.logExtraction
      - text: Apply log extraction settings {logExtraction} to the installed Entity Store.
        slots:
          logExtraction: requestBody.logExtraction
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/entities'].get
  update:
    x-apievangelist-phrasing:
      intent: List entities in the Entity Store
      effect: read
      questions:
      - Which hosts, users and services has the Entity Store recorded?
      - Can I page through entity records with a cursor instead of page numbers?
      - Is it possible to filter entities to only certain entity types and sort them?
      instructions:
      - text: List Entity Store entities of types {entity_types}, {per_page} per page.
        slots:
          entity_types: query.entity_types
          per_page: query.per_page
      - text: Find entities matching filter {filterQuery} sorted by {sort_field}.
        slots:
          filterQuery: query.filterQuery
          sort_field: query.sort_field
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/entities/'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an entity record
      effect: destructive
      questions:
      - How can I remove a single host or user entity from the Entity Store?
      - Is a deleted entity removed from the latest index right away?
      instructions:
      - text: Delete entity {entityId} from the Entity Store.
        slots:
          entityId: requestBody.entityId
      - text: Remove the entity record with ID {entityId}.
        slots:
          entityId: requestBody.entityId
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/entities/{entityType}'].put
  update:
    x-apievangelist-phrasing:
      intent: Update one entity record
      effect: write
      questions:
      - Can I edit fields on an existing host or user entity?
      - How do I overwrite protected fields on an entity record?
      instructions:
      - text: Update an existing {entityType} entity record with these fields.
        slots:
          entityType: path.entityType
      - text: Force-update protected fields on a {entityType} entity, force {force}.
        slots:
          entityType: path.entityType
          force: query.force
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/entities/{entityType}'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an entity record
      effect: write
      questions:
      - How do I add a new user or host entity to the Entity Store by hand?
      - Which entity types can I create records for?
      instructions:
      - text: Create a new {entityType} entity in the Entity Store.
        slots:
          entityType: path.entityType
      - text: Add a {entityType} entity record with the details I provide.
        slots:
          entityType: path.entityType
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/entities/bulk'].put
  update:
    x-apievangelist-phrasing:
      intent: Update many entity records at once
      effect: write
      questions:
      - Can I update a batch of entity records in a single request?
      - Does bulk entity update support forcing changes to protected fields?
      instructions:
      - text: 'Bulk update these entity records: {entities}.'
        slots:
          entities: requestBody.entities
      - text: Apply updates {entities} to multiple entities with force {force}.
        slots:
          entities: requestBody.entities
          force: query.force
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/install'].post
  update:
    x-apievangelist-phrasing:
      intent: Install the Entity Store
      effect: write
      questions:
      - How do I turn on the Entity Store for hosts and users in Elastic Security?
      - Can I enable history snapshots when installing entity engines?
      instructions:
      - text: Install the Entity Store with engines for {entityTypes}.
        slots:
          entityTypes: requestBody.entityTypes
      - text: Set up Entity Store engines for {entityTypes} with history snapshot {historySnapshot}.
        slots:
          entityTypes: requestBody.entityTypes
          historySnapshot: requestBody.historySnapshot
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/resolution/group'].get
  update:
    x-apievangelist-phrasing:
      intent: Show an entity's resolution group
      effect: read
      questions:
      - Which other entities have been linked to this one as the same identity?
      - Can I see every account resolved together with a given entity?
      instructions:
      - text: Show the resolution group for entity {entity_id}.
        slots:
          entity_id: query.entity_id
      - text: List all entities linked to {entity_id}.
        slots:
          entity_id: query.entity_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/resolution/link'].post
  update:
    x-apievangelist-phrasing:
      intent: Link entities as the same identity
      effect: write
      questions:
      - How do I tell Elastic Security that several user accounts belong to the same person?
      - When do newly linked entities show up in reads?
      instructions:
      - text: Link entities {entity_ids} to target entity {target_id}.
        slots:
          entity_ids: requestBody.entity_ids
          target_id: requestBody.target_id
      - text: Merge {entity_ids} into the resolution group of {target_id}.
        slots:
          entity_ids: requestBody.entity_ids
          target_id: requestBody.target_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/resolution/rules'].get
  update:
    x-apievangelist-phrasing:
      intent: List entity resolution rules
      effect: read
      questions:
      - What managed entity resolution rules exist in this space, and which are enabled?
      - Can I see the effective state of every resolution rule?
      instructions:
      - text: List the entity resolution rules in this space.
      - text: Show which resolution rules are currently enabled.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/resolution/rules/{id}/disable'].put
  update:
    x-apievangelist-phrasing:
      intent: Disable an entity resolution rule
      effect: write
      questions:
      - Can I switch off a managed resolution rule that is merging entities wrongly?
      - Does disabling a resolution rule apply only to the current space?
      instructions:
      - text: Disable resolution rule {id}.
        slots:
          id: path.id
      - text: Turn off entity resolution rule {id} in this space.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/resolution/rules/{id}/enable'].put
  update:
    x-apievangelist-phrasing:
      intent: Enable an entity resolution rule
      effect: write
      questions:
      - How do I turn a managed resolution rule back on?
      - Can I activate a resolution rule for just this space?
      instructions:
      - text: Enable resolution rule {id}.
        slots:
          id: path.id
      - text: Switch on entity resolution rule {id} for this space.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/resolution/unlink'].post
  update:
    x-apievangelist-phrasing:
      intent: Unlink entities from their resolution group
      effect: write
      questions:
      - How can I separate accounts that were wrongly linked as one identity?
      - Can I pull several entities out of their resolution groups at once?
      instructions:
      - text: Unlink entities {entity_ids} from their resolution group.
        slots:
          entity_ids: requestBody.entity_ids
      - text: Detach {entity_ids} so they are no longer resolved together.
        slots:
          entity_ids: requestBody.entity_ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/start'].put
  update:
    x-apievangelist-phrasing:
      intent: Start stopped entity engines
      effect: write
      questions:
      - How do I resume entity engines I paused earlier?
      - Can I restart processing for only some entity types?
      instructions:
      - text: Start the entity engines for {entityTypes}.
        slots:
          entityTypes: requestBody.entityTypes
      - text: Resume all stopped Entity Store engines.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/status'].get
  update:
    x-apievangelist-phrasing:
      intent: Check Entity Store status
      effect: read
      questions:
      - Is the Entity Store installed and are its engines running?
      - Can I get component-level health details for each entity engine?
      instructions:
      - text: Show the Entity Store status.
      - text: Get engine statuses with component health, include_components {include_components}.
        slots:
          include_components: query.include_components
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/stop'].put
  update:
    x-apievangelist-phrasing:
      intent: Stop running entity engines
      effect: write
      questions:
      - Can I pause entity engines without uninstalling the Entity Store?
      - How do I stop data processing for one entity type?
      instructions:
      - text: Stop the entity engines for {entityTypes}.
        slots:
          entityTypes: requestBody.entityTypes
      - text: Pause every running Entity Store engine.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/security/entity_store/uninstall'].post
  update:
    x-apievangelist-phrasing:
      intent: Uninstall the Entity Store
      effect: destructive
      questions:
      - How do I remove the Entity Store and its engines completely?
      - Can I uninstall engines for only certain entity types?
      instructions:
      - text: Uninstall the Entity Store engines for {entityTypes}.
        slots:
          entityTypes: requestBody.entityTypes
      - text: Remove the Entity Store and all its resources.
      method: generated
      generated: '2026-09-26'