Elastic Stack · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Kibana Security Exceptions API
17 actions
17 updates
phrasing
extends
openapi/elk-stack-security-exceptions-api-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
What the actions change
x-apievangelist-phrasing
Targets 17 · first 16 shown; the file carries all of them
$.info
$.paths['/api/detection_engine/rules/{id}/exceptions'].post
$.paths['/api/exception_lists'].get
$.paths['/api/exception_lists'].put
$.paths['/api/exception_lists'].post
$.paths['/api/exception_lists'].delete
$.paths['/api/exception_lists/_duplicate'].post
$.paths['/api/exception_lists/_export'].post
$.paths['/api/exception_lists/_find'].get
$.paths['/api/exception_lists/_import'].post
$.paths['/api/exception_lists/items'].get
$.paths['/api/exception_lists/items'].put
$.paths['/api/exception_lists/items'].post
$.paths['/api/exception_lists/items'].delete
$.paths['/api/exception_lists/items/_find'].get
$.paths['/api/exception_lists/summary'].get
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Kibana Security Exceptions API
version: 1.0.0
extends: openapi/elk-stack-security-exceptions-api-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 16
- target: $.paths['/api/detection_engine/rules/{id}/exceptions'].post
update:
x-apievangelist-phrasing:
intent: Add exception items to a detection rule
effect: write
questions:
- How do I add an exception directly to one detection rule so it stops alerting on known-good activity?
- Can I attach several exception items to a rule in one request?
instructions:
- text: Add exception items {items} to detection rule {id}.
slots:
id: path.id
items: requestBody.items
- text: Create rule exceptions {items} on rule {id} to suppress false positives.
slots:
id: path.id
items: requestBody.items
method: generated
generated: '2026-09-26'
- target: $.paths['/api/exception_lists'].get
update:
x-apievangelist-phrasing:
intent: Get an exception list's details
effect: read
questions:
- What are the details of a specific exception list?
- Can I look up an exception list by its human-readable list_id?
instructions:
- text: Get exception list {list_id}.
slots:
list_id: query.list_id
- text: Show the details of exception list with id {id} in namespace {namespace_type}.
slots:
id: query.id
namespace_type: query.namespace_type
method: generated
generated: '2026-09-26'
- target: $.paths['/api/exception_lists'].put
update:
x-apievangelist-phrasing:
intent: Update an exception list
effect: write
questions:
- How do I rename an existing exception list or change its description?
- Can I change the OS types or tags on an exception list I already made?
instructions:
- text: Update exception list {list_id} with name {name}, description {description} and type {type}.
slots:
list_id: requestBody.list_id
name: requestBody.name
description: requestBody.description
type: requestBody.type
- text: Retag existing exception list {list_id} with {tags}, keeping name {name}, description {description}, type {type}.
slots:
list_id: requestBody.list_id
tags: requestBody.tags
name: requestBody.name
description: requestBody.description
type: requestBody.type
method: generated
generated: '2026-09-26'
- target: $.paths['/api/exception_lists'].post
update:
x-apievangelist-phrasing:
intent: Create an exception list
effect: write
questions:
- How do I create a new exception list for my detection rules?
- Can I make an exception list that applies only to Windows endpoints?
instructions:
- text: Create an exception list named {name} of type {type} described as {description}.
slots:
name: requestBody.name
type: requestBody.type
description: requestBody.description
- text: Create exception list {list_id} called {name}, type {type}, description {description}, for OS types {os_types}.
slots:
list_id: requestBody.list_id
name: requestBody.name
type: requestBody.type
description: requestBody.description
os_types: requestBody.os_types
method: generated
generated: '2026-09-26'
- target: $.paths['/api/exception_lists'].delete
update:
x-apievangelist-phrasing:
intent: Delete an exception list
effect: destructive
questions:
- How do I permanently delete an exception list?
- Does deleting an exception list remove it from the rules that use it?
instructions:
- text: Delete exception list {list_id}.
slots:
list_id: query.list_id
- text: Delete the exception list with id {id} in namespace {namespace_type}.
slots:
id: query.id
namespace_type: query.namespace_type
method: generated
generated: '2026-09-26'
- target: $.paths['/api/exception_lists/_duplicate'].post
update:
x-apievangelist-phrasing:
intent: Duplicate an exception list
effect: write
questions:
- Can I make a copy of an existing exception list?
- Is it possible to leave out expired exceptions when copying a list?
instructions:
- text: 'Duplicate exception list {list_id} in namespace {namespace_type}, including expired items: {include_expired_exceptions}.'
slots:
list_id: query.list_id
namespace_type: query.namespace_type
include_expired_exceptions: query.include_expired_exceptions
- text: Copy list {list_id} ({namespace_type}) and include_expired_exceptions {include_expired_exceptions}.
slots:
list_id: query.list_id
namespace_type: query.namespace_type
include_expired_exceptions: query.include_expired_exceptions
method: generated
generated: '2026-09-26'
- target: $.paths['/api/exception_lists/_export'].post
update:
x-apievangelist-phrasing:
intent: Export an exception list to a file
effect: read
questions:
- How do I export an exception list and its items as NDJSON?
- Can I back up an exception list without its expired items?
instructions:
- text: Export exception list {list_id} with id {id} in namespace {namespace_type}, include expired {include_expired_exceptions}.
slots:
list_id: query.list_id
id: query.id
namespace_type: query.namespace_type
include_expired_exceptions: query.include_expired_exceptions
- text: Download list {list_id} (id {id}, {namespace_type}) as a file, expired items {include_expired_exceptions}.
slots:
list_id: query.list_id
id: query.id
namespace_type: query.namespace_type
include_expired_exceptions: query.include_expired_exceptions
method: generated
generated: '2026-09-26'
- target: $.paths['/api/exception_lists/_find'].get
update:
x-apievangelist-phrasing:
intent: Search and list exception lists
effect: read
questions:
- Which exception lists exist in my Kibana space?
- Can I filter and sort exception lists and page through them?
instructions:
- text: List all exception lists.
- text: Find exception lists matching {filter}, {per_page} per page.
slots:
filter: query.filter
per_page: query.per_page
- text: List exception lists sorted by {sort_field} in {sort_order} order.
slots:
sort_field: query.sort_field
sort_order: query.sort_order
method: generated
generated: '2026-09-26'
- target: $.paths['/api/exception_lists/_import'].post
update:
x-apievangelist-phrasing:
intent: Import an exception list from a file
effect: write
questions:
- How do I import exception lists from an exported NDJSON file?
- Can I import a list as a new copy rather than overwriting the existing one?
instructions:
- text: Import exception lists from file {file}.
slots:
file: requestBody.file
- text: Import {file} and overwrite existing lists when overwrite is {overwrite}.
slots:
file: requestBody.file
overwrite: query.overwrite
- text: Import {file} as a new list with as_new_list {as_new_list}.
slots:
file: requestBody.file
as_new_list: query.as_new_list
method: generated
generated: '2026-09-26'
- target: $.paths['/api/exception_lists/items'].get
update:
x-apievangelist-phrasing:
intent: Get an exception list item
effect: read
questions:
- What does a single exception item contain?
- Can I look up an exception item by its item_id?
instructions:
- text: Get exception item {item_id}.
slots:
item_id: query.item_id
- text: Show exception list item with id {id} in namespace {namespace_type}.
slots:
id: query.id
namespace_type: query.namespace_type
method: generated
generated: '2026-09-26'
- target: $.paths['/api/exception_lists/items'].put
update:
x-apievangelist-phrasing:
intent: Update an exception list item
effect: write
questions:
- How do I change the conditions on an existing exception item?
- Can I edit an exception item I already added to a list?
instructions:
- text: Update an existing exception list item.
- text: Edit the entries of an exception item that's already in a list.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/exception_lists/items'].post
update:
x-apievangelist-phrasing:
intent: Add an item to an exception list
effect: write
questions:
- How do I add a new exception item to a shared exception list?
- Can I add an entry to an existing list rather than to one rule?
instructions:
- text: Create a new item in an exception list.
- text: Add an exception entry to a shared list.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/exception_lists/items'].delete
update:
x-apievangelist-phrasing:
intent: Delete an exception list item
effect: destructive
questions:
- How do I remove one exception item from a list?
- Can I delete an exception item using its item_id?
instructions:
- text: Delete exception item {item_id}.
slots:
item_id: query.item_id
- text: Remove the exception list item with id {id} in namespace {namespace_type}.
slots:
id: query.id
namespace_type: query.namespace_type
method: generated
generated: '2026-09-26'
- target: $.paths['/api/exception_lists/items/_find'].get
update:
x-apievangelist-phrasing:
intent: List the items in an exception list
effect: read
questions:
- What exceptions are inside a particular exception list?
- Can I search within one list's exception items and page the results?
instructions:
- text: List the items in exception list {list_id}.
slots:
list_id: query.list_id
- text: Search exception list {list_id} items for {search}.
slots:
list_id: query.list_id
search: query.search
- text: List items of {list_id} sorted by {sort_field}, {per_page} per page.
slots:
list_id: query.list_id
sort_field: query.sort_field
per_page: query.per_page
method: generated
generated: '2026-09-26'
- target: $.paths['/api/exception_lists/summary'].get
update:
x-apievangelist-phrasing:
intent: Summarize an exception list by OS
effect: read
questions:
- How many exception items in a list apply to Windows, Linux or macOS?
- Can I get item counts per operating system for an exception list?
instructions:
- text: Summarize exception list {list_id}.
slots:
list_id: query.list_id
- text: Give me the per-OS item counts for list {list_id} filtered by {filter}.
slots:
list_id: query.list_id
filter: query.filter
method: generated
generated: '2026-09-26'
- target: $.paths['/api/exceptions/shared'].post
update:
x-apievangelist-phrasing:
intent: Create a shared exception list
effect: write
questions:
- How do I create a shared exception list that many rules can reference?
- What do I need to provide to set up a shared exception list?
instructions:
- text: Create a shared exception list named {name} described as {description}.
slots:
name: requestBody.name
description: requestBody.description
- text: Set up shared list {name} for reuse across rules, description {description}.
slots:
name: requestBody.name
description: requestBody.description
method: generated
generated: '2026-09-26'