Elastic Stack · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Kibana Significant Events API

6 actions 6 updates phrasing extends openapi/elk-stack-significant-events-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Elastic Stack's API. It is a proposal applied on top of the contract, not a document Elastic Stack publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 6

$.info
$.paths['/api/streams/{name}/queries'].get
$.paths['/api/streams/{name}/queries/_bulk'].post
$.paths['/api/streams/{name}/queries/{queryId}'].put
$.paths['/api/streams/{name}/queries/{queryId}'].delete
$.paths['/api/streams/{name}/significant_events'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Kibana Significant Events API
  version: 1.0.0
extends: openapi/elk-stack-significant-events-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 5
- target: $.paths['/api/streams/{name}/queries'].get
  update:
    x-apievangelist-phrasing:
      intent: List significant-event queries on a stream
      effect: read
      questions:
      - Which significant-event queries are attached to a stream?
      - How do I see the detection queries defined for one stream?
      instructions:
      - text: List the queries linked to stream {name}.
        slots:
          name: path.name
      - text: Show every significant-event query on stream {name}.
        slots:
          name: path.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/streams/{name}/queries/_bulk'].post
  update:
    x-apievangelist-phrasing:
      intent: Bulk add and remove stream queries
      effect: write
      questions:
      - How do I add and delete several significant-event queries on a stream in one call?
      - Can I replace a stream's queries in bulk?
      instructions:
      - text: Apply query operations {operations} to stream {name}.
        slots:
          operations: requestBody.operations
          name: path.name
      - text: Bulk update the significant-event queries on stream {name} with {operations}.
        slots:
          name: path.name
          operations: requestBody.operations
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/streams/{name}/queries/{queryId}'].put
  update:
    x-apievangelist-phrasing:
      intent: Add a significant-event query to a stream
      effect: write
      questions:
      - How do I add an ES|QL query that flags significant events on a stream?
      - Can I give a significant-event query a severity score and an expiry date?
      instructions:
      - text: Add query {queryId} titled {title} with ES|QL {esql} to stream {name}.
        slots:
          queryId: path.queryId
          title: requestBody.title
          esql: requestBody.esql
          name: path.name
      - text: Upsert query {queryId} on stream {name} titled {title} using {esql} with severity {severity_score}.
        slots:
          queryId: path.queryId
          name: path.name
          title: requestBody.title
          esql: requestBody.esql
          severity_score: requestBody.severity_score
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/streams/{name}/queries/{queryId}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Remove a significant-event query from a stream
      effect: destructive
      questions:
      - How do I remove a detection query from a stream?
      - Is removing a query that isn't on the stream an error?
      instructions:
      - text: Remove query {queryId} from stream {name}.
        slots:
          queryId: path.queryId
          name: path.name
      - text: Delete significant-event query {queryId} on stream {name}.
        slots:
          queryId: path.queryId
          name: path.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/streams/{name}/significant_events'].get
  update:
    x-apievangelist-phrasing:
      intent: Read a stream's significant events over time
      effect: read
      questions:
      - What significant events happened on a stream during a time range?
      - Can I search significant events using semantic or hybrid search?
      - How do I bucket significant events by hour?
      instructions:
      - text: Show significant events on stream {name} from {from} to {to} in {bucketSize} buckets.
        slots:
          name: path.name
          from: query.from
          to: query.to
          bucketSize: query.bucketSize
      - text: Find significant events on stream {name} matching {query} between {from} and {to}, bucketed by {bucketSize}.
        slots:
          name: path.name
          query: query.query
          from: query.from
          to: query.to
          bucketSize: query.bucketSize
      method: generated
      generated: '2026-09-26'