Elastic Stack · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Kibana Security Osquery API
22 actions
22 updates
phrasing
extends
openapi/elk-stack-security-osquery-api-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
What the actions change
x-apievangelist-phrasing
Targets 22 · first 16 shown; the file carries all of them
$.info
$.paths['/api/osquery/history'].get
$.paths['/api/osquery/live_queries'].get
$.paths['/api/osquery/live_queries'].post
$.paths['/api/osquery/live_queries/{id}'].get
$.paths['/api/osquery/live_queries/{id}/results/{actionId}'].get
$.paths['/api/osquery/live_queries/{id}/results/{actionId}/_export'].post
$.paths['/api/osquery/packs'].get
$.paths['/api/osquery/packs'].post
$.paths['/api/osquery/packs/{id}'].get
$.paths['/api/osquery/packs/{id}'].put
$.paths['/api/osquery/packs/{id}'].delete
$.paths['/api/osquery/packs/{id}/copy'].post
$.paths['/api/osquery/saved_queries'].get
$.paths['/api/osquery/saved_queries'].post
$.paths['/api/osquery/saved_queries/{id}'].get
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Kibana Security Osquery API
version: 1.0.0
extends: openapi/elk-stack-security-osquery-api-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 21
- target: $.paths['/api/osquery/history'].get
update:
x-apievangelist-phrasing:
intent: View combined osquery execution history
effect: read
questions:
- Can I see live, rule-triggered and scheduled osquery runs in one timeline?
- Which osquery executions ran between two dates?
- Is it possible to filter osquery history to queries a specific user ran?
instructions:
- text: Show my unified osquery history from {startDate} to {endDate}.
slots:
startDate: query.startDate
endDate: query.endDate
- text: List osquery executions run by users {userIds}.
slots:
userIds: query.userIds
- text: Get the next page of osquery history using cursor {nextPage}.
slots:
nextPage: query.nextPage
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/live_queries'].get
update:
x-apievangelist-phrasing:
intent: List live osquery queries
effect: read
questions:
- Which live queries have been run against my hosts?
- Can I filter the list of live queries with KQL?
instructions:
- text: List all live osquery queries.
- text: Find live queries matching {kuery}, sorted by {sort}.
slots:
kuery: query.kuery
sort: query.sort
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/live_queries'].post
update:
x-apievangelist-phrasing:
intent: Run a live osquery query on hosts
effect: write
questions:
- How do I run an osquery SQL query on my endpoints right now?
- Can I target a live query at a specific agent policy or platform?
- Is it possible to run a saved query or a whole pack as a live query?
instructions:
- text: Run live query {query} on agents {agent_ids}.
slots:
query: requestBody.query
agent_ids: requestBody.agent_ids
- text: Run live query {query} on every agent in policies {agent_policy_ids}.
slots:
query: requestBody.query
agent_policy_ids: requestBody.agent_policy_ids
- text: Launch saved query {saved_query_id} live on all {agent_platforms} hosts.
slots:
saved_query_id: requestBody.saved_query_id
agent_platforms: requestBody.agent_platforms
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/live_queries/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get a live query's details
effect: read
questions:
- What queries and agents were part of a specific live query run?
- Can I check the status of a live query I launched?
instructions:
- text: Get the details of live query {id}.
slots:
id: path.id
- text: Show which agents live query {id} targeted.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/live_queries/{id}/results/{actionId}'].get
update:
x-apievangelist-phrasing:
intent: Get the result rows of a live query
effect: read
questions:
- Where do I see the rows my live osquery query returned?
- Can I page through live query results and filter them?
instructions:
- text: Show results of action {actionId} in live query {id}.
slots:
actionId: path.actionId
id: path.id
- text: Page {page} of live query {id} action {actionId} results filtered by {kuery}.
slots:
page: query.page
id: path.id
actionId: path.actionId
kuery: query.kuery
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/live_queries/{id}/results/{actionId}/_export'].post
update:
x-apievangelist-phrasing:
intent: Download live query results as a file
effect: read
questions:
- Can I download a live query's results as a file?
- Which file formats can live osquery results be exported in?
instructions:
- text: Export live query {id} action {actionId} results as {format}.
slots:
id: path.id
actionId: path.actionId
format: query.format
- text: Download {format} results of live query {id} action {actionId} for agents {agentIds}.
slots:
format: query.format
id: path.id
actionId: path.actionId
agentIds: requestBody.agentIds
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/packs'].get
update:
x-apievangelist-phrasing:
intent: List osquery packs
effect: read
questions:
- What osquery query packs do I have?
- Can I sort my query packs by name?
instructions:
- text: List all osquery packs.
- text: Show page {page} of query packs sorted by {sort}.
slots:
page: query.page
sort: query.sort
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/packs'].post
update:
x-apievangelist-phrasing:
intent: Create an osquery pack
effect: write
questions:
- How do I bundle several scheduled osquery queries into a pack?
- Can I assign a new pack to specific agent policies?
instructions:
- text: Create pack {name} with queries {queries}.
slots:
name: requestBody.name
queries: requestBody.queries
- text: Create an enabled pack {name} assigned to policies {policy_ids}.
slots:
name: requestBody.name
policy_ids: requestBody.policy_ids
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/packs/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get an osquery pack
effect: read
questions:
- Which queries are inside a given osquery pack?
- What schedule and policies does a pack use?
instructions:
- text: Get the details of pack {id}.
slots:
id: path.id
- text: Show the queries in osquery pack {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/packs/{id}'].put
update:
x-apievangelist-phrasing:
intent: Update an osquery pack
effect: write
questions:
- Can I change the queries or schedule of an existing pack?
- Why can't I edit a prebuilt osquery pack?
instructions:
- text: Update pack {id} with queries {queries}.
slots:
id: path.id
queries: requestBody.queries
- text: Disable pack {id} by setting enabled to {enabled}.
slots:
id: path.id
enabled: requestBody.enabled
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/packs/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete an osquery pack
effect: destructive
questions:
- How do I remove a query pack I no longer use?
- Does deleting a pack stop its scheduled queries?
instructions:
- text: Delete osquery pack {id}.
slots:
id: path.id
- text: Remove pack {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/packs/{id}/copy'].post
update:
x-apievangelist-phrasing:
intent: Duplicate an osquery pack
effect: write
questions:
- Can I clone a query pack so I can edit the copy?
- What name does a copied pack get, and is it enabled?
instructions:
- text: Copy pack {id}.
slots:
id: path.id
- text: Make a disabled duplicate of osquery pack {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/saved_queries'].get
update:
x-apievangelist-phrasing:
intent: List saved osquery queries
effect: read
questions:
- What saved osquery queries are available to reuse?
- Can I page through saved queries sorted by a field?
instructions:
- text: List all saved osquery queries.
- text: Show page {page} of saved queries, {pageSize} per page.
slots:
page: query.page
pageSize: query.pageSize
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/saved_queries'].post
update:
x-apievangelist-phrasing:
intent: Save an osquery query for reuse
effect: write
questions:
- How do I save an osquery SQL statement so I can run it later?
- Can a saved query be limited to one platform?
instructions:
- text: Save query {query} with id {id}.
slots:
query: requestBody.query
id: requestBody.id
- text: Save osquery {query} for platform {platform} as {id}.
slots:
query: requestBody.query
platform: requestBody.platform
id: requestBody.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/saved_queries/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get a saved osquery query
effect: read
questions:
- What SQL and ECS mapping does a particular saved query use?
- Can I look up one saved query by id?
instructions:
- text: Get saved query {id}.
slots:
id: path.id
- text: Show the SQL of saved query {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/saved_queries/{id}'].put
update:
x-apievangelist-phrasing:
intent: Update a saved osquery query
effect: write
questions:
- Can I edit the SQL of a query I saved earlier?
- Are prebuilt saved queries editable?
instructions:
- text: Change saved query {id} to run {query}.
slots:
id: path.id
query: requestBody.query
- text: Update the interval of saved query {id} to {interval}.
slots:
id: path.id
interval: requestBody.interval
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/saved_queries/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a saved osquery query
effect: destructive
questions:
- How do I delete a saved osquery query?
- Is removing a saved query permanent?
instructions:
- text: Delete saved query {id}.
slots:
id: path.id
- text: Remove the saved osquery query {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/saved_queries/{id}/copy'].post
update:
x-apievangelist-phrasing:
intent: Duplicate a saved osquery query
effect: write
questions:
- Can I clone a saved query as a starting point for a new one?
- What suffix is added to a copied saved query's name?
instructions:
- text: Copy saved query {id}.
slots:
id: path.id
- text: Make a duplicate of saved osquery query {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/scheduled_results/{scheduleId}/{executionCount}'].get
update:
x-apievangelist-phrasing:
intent: Get per-agent status of a scheduled query run
effect: read
questions:
- Which agents succeeded or failed on a particular scheduled osquery execution?
- Can I see success and failure counts for one scheduled query run?
instructions:
- text: Show per-agent results for schedule {scheduleId} execution {executionCount}.
slots:
scheduleId: path.scheduleId
executionCount: path.executionCount
- text: List failing agents in scheduled run {executionCount} of {scheduleId}.
slots:
executionCount: path.executionCount
scheduleId: path.scheduleId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/scheduled_results/{scheduleId}/{executionCount}/_export'].post
update:
x-apievangelist-phrasing:
intent: Download scheduled query results as a file
effect: read
questions:
- Can I export every row from a scheduled osquery execution to a file?
- Which formats can scheduled query results be downloaded in?
instructions:
- text: Export schedule {scheduleId} run {executionCount} results as {format}.
slots:
scheduleId: path.scheduleId
executionCount: path.executionCount
format: query.format
- text: Download {format} rows of scheduled run {executionCount} of {scheduleId} filtered by {kuery}.
slots:
format: query.format
executionCount: path.executionCount
scheduleId: path.scheduleId
kuery: requestBody.kuery
method: generated
generated: '2026-09-26'
- target: $.paths['/api/osquery/scheduled_results/{scheduleId}/{executionCount}/results'].get
update:
x-apievangelist-phrasing:
intent: Get the data rows of a scheduled query run
effect: read
questions:
- What actual osquery output did a scheduled query return on one run?
- Can I page through scheduled query result rows from a start date?
instructions:
- text: Show the result rows of schedule {scheduleId} execution {executionCount}.
slots:
scheduleId: path.scheduleId
executionCount: path.executionCount
- text: Get page {page} of output rows for scheduled run {executionCount} of {scheduleId}.
slots:
page: query.page
executionCount: path.executionCount
scheduleId: path.scheduleId
method: generated
generated: '2026-09-26'