Elastic Stack · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Kibana Security Osquery API

22 actions 22 updates phrasing extends openapi/elk-stack-security-osquery-api-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 22 · first 16 shown; the file carries all of them

$.info
$.paths['/api/osquery/history'].get
$.paths['/api/osquery/live_queries'].get
$.paths['/api/osquery/live_queries'].post
$.paths['/api/osquery/live_queries/{id}'].get
$.paths['/api/osquery/live_queries/{id}/results/{actionId}'].get
$.paths['/api/osquery/live_queries/{id}/results/{actionId}/_export'].post
$.paths['/api/osquery/packs'].get
$.paths['/api/osquery/packs'].post
$.paths['/api/osquery/packs/{id}'].get
$.paths['/api/osquery/packs/{id}'].put
$.paths['/api/osquery/packs/{id}'].delete
$.paths['/api/osquery/packs/{id}/copy'].post
$.paths['/api/osquery/saved_queries'].get
$.paths['/api/osquery/saved_queries'].post
$.paths['/api/osquery/saved_queries/{id}'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Kibana Security Osquery API
  version: 1.0.0
extends: openapi/elk-stack-security-osquery-api-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 21
- target: $.paths['/api/osquery/history'].get
  update:
    x-apievangelist-phrasing:
      intent: View combined osquery execution history
      effect: read
      questions:
      - Can I see live, rule-triggered and scheduled osquery runs in one timeline?
      - Which osquery executions ran between two dates?
      - Is it possible to filter osquery history to queries a specific user ran?
      instructions:
      - text: Show my unified osquery history from {startDate} to {endDate}.
        slots:
          startDate: query.startDate
          endDate: query.endDate
      - text: List osquery executions run by users {userIds}.
        slots:
          userIds: query.userIds
      - text: Get the next page of osquery history using cursor {nextPage}.
        slots:
          nextPage: query.nextPage
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/live_queries'].get
  update:
    x-apievangelist-phrasing:
      intent: List live osquery queries
      effect: read
      questions:
      - Which live queries have been run against my hosts?
      - Can I filter the list of live queries with KQL?
      instructions:
      - text: List all live osquery queries.
      - text: Find live queries matching {kuery}, sorted by {sort}.
        slots:
          kuery: query.kuery
          sort: query.sort
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/live_queries'].post
  update:
    x-apievangelist-phrasing:
      intent: Run a live osquery query on hosts
      effect: write
      questions:
      - How do I run an osquery SQL query on my endpoints right now?
      - Can I target a live query at a specific agent policy or platform?
      - Is it possible to run a saved query or a whole pack as a live query?
      instructions:
      - text: Run live query {query} on agents {agent_ids}.
        slots:
          query: requestBody.query
          agent_ids: requestBody.agent_ids
      - text: Run live query {query} on every agent in policies {agent_policy_ids}.
        slots:
          query: requestBody.query
          agent_policy_ids: requestBody.agent_policy_ids
      - text: Launch saved query {saved_query_id} live on all {agent_platforms} hosts.
        slots:
          saved_query_id: requestBody.saved_query_id
          agent_platforms: requestBody.agent_platforms
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/live_queries/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a live query's details
      effect: read
      questions:
      - What queries and agents were part of a specific live query run?
      - Can I check the status of a live query I launched?
      instructions:
      - text: Get the details of live query {id}.
        slots:
          id: path.id
      - text: Show which agents live query {id} targeted.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/live_queries/{id}/results/{actionId}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the result rows of a live query
      effect: read
      questions:
      - Where do I see the rows my live osquery query returned?
      - Can I page through live query results and filter them?
      instructions:
      - text: Show results of action {actionId} in live query {id}.
        slots:
          actionId: path.actionId
          id: path.id
      - text: Page {page} of live query {id} action {actionId} results filtered by {kuery}.
        slots:
          page: query.page
          id: path.id
          actionId: path.actionId
          kuery: query.kuery
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/live_queries/{id}/results/{actionId}/_export'].post
  update:
    x-apievangelist-phrasing:
      intent: Download live query results as a file
      effect: read
      questions:
      - Can I download a live query's results as a file?
      - Which file formats can live osquery results be exported in?
      instructions:
      - text: Export live query {id} action {actionId} results as {format}.
        slots:
          id: path.id
          actionId: path.actionId
          format: query.format
      - text: Download {format} results of live query {id} action {actionId} for agents {agentIds}.
        slots:
          format: query.format
          id: path.id
          actionId: path.actionId
          agentIds: requestBody.agentIds
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/packs'].get
  update:
    x-apievangelist-phrasing:
      intent: List osquery packs
      effect: read
      questions:
      - What osquery query packs do I have?
      - Can I sort my query packs by name?
      instructions:
      - text: List all osquery packs.
      - text: Show page {page} of query packs sorted by {sort}.
        slots:
          page: query.page
          sort: query.sort
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/packs'].post
  update:
    x-apievangelist-phrasing:
      intent: Create an osquery pack
      effect: write
      questions:
      - How do I bundle several scheduled osquery queries into a pack?
      - Can I assign a new pack to specific agent policies?
      instructions:
      - text: Create pack {name} with queries {queries}.
        slots:
          name: requestBody.name
          queries: requestBody.queries
      - text: Create an enabled pack {name} assigned to policies {policy_ids}.
        slots:
          name: requestBody.name
          policy_ids: requestBody.policy_ids
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/packs/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an osquery pack
      effect: read
      questions:
      - Which queries are inside a given osquery pack?
      - What schedule and policies does a pack use?
      instructions:
      - text: Get the details of pack {id}.
        slots:
          id: path.id
      - text: Show the queries in osquery pack {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/packs/{id}'].put
  update:
    x-apievangelist-phrasing:
      intent: Update an osquery pack
      effect: write
      questions:
      - Can I change the queries or schedule of an existing pack?
      - Why can't I edit a prebuilt osquery pack?
      instructions:
      - text: Update pack {id} with queries {queries}.
        slots:
          id: path.id
          queries: requestBody.queries
      - text: Disable pack {id} by setting enabled to {enabled}.
        slots:
          id: path.id
          enabled: requestBody.enabled
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/packs/{id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete an osquery pack
      effect: destructive
      questions:
      - How do I remove a query pack I no longer use?
      - Does deleting a pack stop its scheduled queries?
      instructions:
      - text: Delete osquery pack {id}.
        slots:
          id: path.id
      - text: Remove pack {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/packs/{id}/copy'].post
  update:
    x-apievangelist-phrasing:
      intent: Duplicate an osquery pack
      effect: write
      questions:
      - Can I clone a query pack so I can edit the copy?
      - What name does a copied pack get, and is it enabled?
      instructions:
      - text: Copy pack {id}.
        slots:
          id: path.id
      - text: Make a disabled duplicate of osquery pack {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/saved_queries'].get
  update:
    x-apievangelist-phrasing:
      intent: List saved osquery queries
      effect: read
      questions:
      - What saved osquery queries are available to reuse?
      - Can I page through saved queries sorted by a field?
      instructions:
      - text: List all saved osquery queries.
      - text: Show page {page} of saved queries, {pageSize} per page.
        slots:
          page: query.page
          pageSize: query.pageSize
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/saved_queries'].post
  update:
    x-apievangelist-phrasing:
      intent: Save an osquery query for reuse
      effect: write
      questions:
      - How do I save an osquery SQL statement so I can run it later?
      - Can a saved query be limited to one platform?
      instructions:
      - text: Save query {query} with id {id}.
        slots:
          query: requestBody.query
          id: requestBody.id
      - text: Save osquery {query} for platform {platform} as {id}.
        slots:
          query: requestBody.query
          platform: requestBody.platform
          id: requestBody.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/saved_queries/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a saved osquery query
      effect: read
      questions:
      - What SQL and ECS mapping does a particular saved query use?
      - Can I look up one saved query by id?
      instructions:
      - text: Get saved query {id}.
        slots:
          id: path.id
      - text: Show the SQL of saved query {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/saved_queries/{id}'].put
  update:
    x-apievangelist-phrasing:
      intent: Update a saved osquery query
      effect: write
      questions:
      - Can I edit the SQL of a query I saved earlier?
      - Are prebuilt saved queries editable?
      instructions:
      - text: Change saved query {id} to run {query}.
        slots:
          id: path.id
          query: requestBody.query
      - text: Update the interval of saved query {id} to {interval}.
        slots:
          id: path.id
          interval: requestBody.interval
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/saved_queries/{id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a saved osquery query
      effect: destructive
      questions:
      - How do I delete a saved osquery query?
      - Is removing a saved query permanent?
      instructions:
      - text: Delete saved query {id}.
        slots:
          id: path.id
      - text: Remove the saved osquery query {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/saved_queries/{id}/copy'].post
  update:
    x-apievangelist-phrasing:
      intent: Duplicate a saved osquery query
      effect: write
      questions:
      - Can I clone a saved query as a starting point for a new one?
      - What suffix is added to a copied saved query's name?
      instructions:
      - text: Copy saved query {id}.
        slots:
          id: path.id
      - text: Make a duplicate of saved osquery query {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/scheduled_results/{scheduleId}/{executionCount}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get per-agent status of a scheduled query run
      effect: read
      questions:
      - Which agents succeeded or failed on a particular scheduled osquery execution?
      - Can I see success and failure counts for one scheduled query run?
      instructions:
      - text: Show per-agent results for schedule {scheduleId} execution {executionCount}.
        slots:
          scheduleId: path.scheduleId
          executionCount: path.executionCount
      - text: List failing agents in scheduled run {executionCount} of {scheduleId}.
        slots:
          executionCount: path.executionCount
          scheduleId: path.scheduleId
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/scheduled_results/{scheduleId}/{executionCount}/_export'].post
  update:
    x-apievangelist-phrasing:
      intent: Download scheduled query results as a file
      effect: read
      questions:
      - Can I export every row from a scheduled osquery execution to a file?
      - Which formats can scheduled query results be downloaded in?
      instructions:
      - text: Export schedule {scheduleId} run {executionCount} results as {format}.
        slots:
          scheduleId: path.scheduleId
          executionCount: path.executionCount
          format: query.format
      - text: Download {format} rows of scheduled run {executionCount} of {scheduleId} filtered by {kuery}.
        slots:
          format: query.format
          executionCount: path.executionCount
          scheduleId: path.scheduleId
          kuery: requestBody.kuery
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/osquery/scheduled_results/{scheduleId}/{executionCount}/results'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the data rows of a scheduled query run
      effect: read
      questions:
      - What actual osquery output did a scheduled query return on one run?
      - Can I page through scheduled query result rows from a start date?
      instructions:
      - text: Show the result rows of schedule {scheduleId} execution {executionCount}.
        slots:
          scheduleId: path.scheduleId
          executionCount: path.executionCount
      - text: Get page {page} of output rows for scheduled run {executionCount} of {scheduleId}.
        slots:
          page: query.page
          executionCount: path.executionCount
          scheduleId: path.scheduleId
      method: generated
      generated: '2026-09-26'