Elastic Stack · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Kibana Security Lists API
19 actions
19 updates
phrasing
extends
openapi/elk-stack-security-lists-api-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
What the actions change
x-apievangelist-phrasing
Targets 19 · first 16 shown; the file carries all of them
$.info
$.paths['/api/lists'].get
$.paths['/api/lists'].put
$.paths['/api/lists'].post
$.paths['/api/lists'].delete
$.paths['/api/lists'].patch
$.paths['/api/lists/_find'].get
$.paths['/api/lists/index'].get
$.paths['/api/lists/index'].post
$.paths['/api/lists/index'].delete
$.paths['/api/lists/items'].get
$.paths['/api/lists/items'].put
$.paths['/api/lists/items'].post
$.paths['/api/lists/items'].delete
$.paths['/api/lists/items'].patch
$.paths['/api/lists/items/_export'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Kibana Security Lists API
version: 1.0.0
extends: openapi/elk-stack-security-lists-api-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 18
- target: $.paths['/api/lists'].get
update:
x-apievangelist-phrasing:
intent: Get a value list's details
effect: read
questions:
- Can I look up one value list by its ID?
- What name, type and description does a given value list have?
instructions:
- text: Get the value list {id}.
slots:
id: query.id
- text: Show the details of security value list {id}.
slots:
id: query.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/lists'].put
update:
x-apievangelist-phrasing:
intent: Replace a value list's name and description
effect: write
questions:
- Can I fully replace a value list, knowing unspecified fields get deleted?
- How do I overwrite a value list's name and description together?
instructions:
- text: Replace value list {id} with name {name} and description {description}.
slots:
id: requestBody.id
name: requestBody.name
description: requestBody.description
- text: Overwrite the whole value list {id}, setting description to {description} and name to {name}.
slots:
id: requestBody.id
description: requestBody.description
name: requestBody.name
method: generated
generated: '2026-09-26'
- target: $.paths['/api/lists'].post
update:
x-apievangelist-phrasing:
intent: Create a value list
effect: write
questions:
- How do I create a new value list of IP addresses for exceptions?
- Which list types can a new value list use, like ip or keyword?
instructions:
- text: Create a {type} value list named {name} described as {description}.
slots:
type: requestBody.type
name: requestBody.name
description: requestBody.description
- text: Make a new value list with ID {id}, name {name}, type {type} and description {description}.
slots:
id: requestBody.id
name: requestBody.name
type: requestBody.type
description: requestBody.description
method: generated
generated: '2026-09-26'
- target: $.paths['/api/lists'].delete
update:
x-apievangelist-phrasing:
intent: Delete a value list and its items
effect: destructive
questions:
- Does deleting a value list also delete all of its items?
- How do I delete a value list even if exception items still reference it?
instructions:
- text: Delete value list {id}.
slots:
id: query.id
- text: Delete value list {id} and remove the exception references to it.
slots:
id: query.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/lists'].patch
update:
x-apievangelist-phrasing:
intent: Change specific fields of a value list
effect: write
questions:
- Can I change just the name of a value list without replacing the rest?
- How do I partially update an existing value list?
instructions:
- text: Patch value list {id} so its name is {name}.
slots:
id: requestBody.id
name: requestBody.name
- text: Change only the description of value list {id} to {description}.
slots:
id: requestBody.id
description: requestBody.description
method: generated
generated: '2026-09-26'
- target: $.paths['/api/lists/_find'].get
update:
x-apievangelist-phrasing:
intent: Browse and filter value lists
effect: read
questions:
- What value lists exist in this Kibana space?
- Can I page through value lists 20 at a time and sort them?
instructions:
- text: List all my value lists.
- text: Find value lists matching filter {filter}, sorted by {sort_field}.
slots:
filter: query.filter
sort_field: query.sort_field
- text: Show page {page} of value lists with {per_page} per page.
slots:
page: query.page
per_page: query.per_page
method: generated
generated: '2026-09-26'
- target: $.paths['/api/lists/index'].get
update:
x-apievangelist-phrasing:
intent: Check that value list data streams exist
effect: read
questions:
- Do the .lists and .items data streams exist in this space?
- How can I verify value list storage is set up before importing?
instructions:
- text: Check the status of the value list data streams.
- text: Verify that the .lists and .items data streams are present.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/lists/index'].post
update:
x-apievangelist-phrasing:
intent: Create value list data streams (deprecated)
effect: write
questions:
- Do I still need to create the .lists and .items data streams by hand?
- Is the call that creates value list backing storage deprecated?
instructions:
- text: Create the .lists and .items data streams for this space.
- text: Provision value list backing data streams with the deprecated endpoint.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/lists/index'].delete
update:
x-apievangelist-phrasing:
intent: Delete the value list data streams
effect: destructive
questions:
- How do I remove the .lists and .items data streams entirely?
- Can I delete all value list storage for a space?
instructions:
- text: Delete the .lists and .items data streams.
- text: Tear down value list storage in this space.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/lists/items'].get
update:
x-apievangelist-phrasing:
intent: Get a value list item
effect: read
questions:
- How do I check whether a specific value is in a value list?
- Can I fetch one list item by its ID?
instructions:
- text: Get value list item {id}.
slots:
id: query.id
- text: Look up value {value} in value list {list_id}.
slots:
value: query.value
list_id: query.list_id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/lists/items'].put
update:
x-apievangelist-phrasing:
intent: Replace a value list item
effect: write
questions:
- Can I fully replace a list item's value, dropping fields I leave out?
- How do I overwrite a value list item by its ID?
instructions:
- text: Replace list item {id} with value {value}.
slots:
id: requestBody.id
value: requestBody.value
- text: Overwrite the entire value list item {id} so it holds {value}.
slots:
id: requestBody.id
value: requestBody.value
method: generated
generated: '2026-09-26'
- target: $.paths['/api/lists/items'].post
update:
x-apievangelist-phrasing:
intent: Add an item to a value list
effect: write
questions:
- How do I add an IP address to an existing value list?
- Must every item in a value list be the same type?
instructions:
- text: Add {value} to value list {list_id}.
slots:
value: requestBody.value
list_id: requestBody.list_id
- text: Create a list item {value} in list {list_id} and refresh right away.
slots:
value: requestBody.value
list_id: requestBody.list_id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/lists/items'].delete
update:
x-apievangelist-phrasing:
intent: Remove an item from a value list
effect: destructive
questions:
- What call removes a single value from a value list?
- Can I delete a list item by its value instead of its ID?
instructions:
- text: Delete value list item {id}.
slots:
id: query.id
- text: Remove {value} from value list {list_id}.
slots:
value: query.value
list_id: query.list_id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/lists/items'].patch
update:
x-apievangelist-phrasing:
intent: Change specific fields of a value list item
effect: write
questions:
- Can I change just a list item's value without replacing its metadata?
- How do I partially update one value list item?
instructions:
- text: Patch list item {id} so its value becomes {value}.
slots:
id: requestBody.id
value: requestBody.value
- text: Update only the metadata of value list item {id} to {meta}.
slots:
id: requestBody.id
meta: requestBody.meta
method: generated
generated: '2026-09-26'
- target: $.paths['/api/lists/items/_export'].post
update:
x-apievangelist-phrasing:
intent: Export the values in a value list
effect: read
questions:
- How do I download all the values stored in a value list?
- Can I export a value list's items to a file?
instructions:
- text: Export the items of value list {list_id}.
slots:
list_id: query.list_id
- text: Download every value in list {list_id} as a file.
slots:
list_id: query.list_id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/lists/items/_find'].get
update:
x-apievangelist-phrasing:
intent: Browse the items in a value list
effect: read
questions:
- What values are in a given value list?
- Can I page and filter through the items of one list?
instructions:
- text: List the items in value list {list_id}.
slots:
list_id: query.list_id
- text: Find items in list {list_id} matching {filter}.
slots:
list_id: query.list_id
filter: query.filter
- text: Show page {page} of list {list_id} items, {per_page} at a time.
slots:
page: query.page
list_id: query.list_id
per_page: query.per_page
method: generated
generated: '2026-09-26'
- target: $.paths['/api/lists/items/_import'].post
update:
x-apievangelist-phrasing:
intent: Import value list items from a TXT or CSV file
effect: write
questions:
- How do I bulk load IP addresses into a value list from a CSV?
- What is the maximum file size for a value list import?
instructions:
- text: Import the values in {file} into value list {list_id}.
slots:
file: requestBody.file
list_id: query.list_id
- text: Upload {file} as a new {type} value list.
slots:
file: requestBody.file
type: query.type
method: generated
generated: '2026-09-26'
- target: $.paths['/api/lists/privileges'].get
update:
x-apievangelist-phrasing:
intent: Check my privileges on value lists
effect: read
questions:
- Am I allowed to create or import value lists in this space?
- Which cluster and index privileges do I hold for the value list data streams?
instructions:
- text: Show my value list privileges.
- text: Check whether I have read or all access to .lists and .items.
method: generated
generated: '2026-09-26'