Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Palo Alto Networks Alerts API
38 actions
38 updates
phrasing
extends
openapi/palo-alto-networks-alerts-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 38 · first 16 shown; the file carries all of them
$.info
$.paths['/alerts/get_alerts'].post
$.paths['/alert/v1/policy'].post
$.paths['/alert/v1/aggregate'].post
$.paths['/alert/v1/{id}/graph'].get
$.paths['/alerts/api/v1/notification/ondemand'].post
$.paths['/filter/alert/suggest'].get
$.paths['/filter/alert/suggest'].post
$.paths['/alert'].get
$.paths['/alert'].post
$.paths['/v2/alert'].get
$.paths['/v2/alert'].post
$.paths['/alert/policy'].get
$.paths['/alert/policy'].post
$.paths['/alert/{id}'].get
$.paths['/alert/dismiss'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Palo Alto Networks Alerts API
version: 1.0.0
extends: openapi/palo-alto-networks-alerts-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 37
- target: $.paths['/alerts/get_alerts'].post
update:
x-apievangelist-phrasing:
intent: Search detections across endpoint, network and cloud
effect: read
questions:
- Can I pull endpoint, network and cloud detections filtered by severity and category in one request?
- Which detections came in from my endpoints in the last day, filtered by alert ID or timestamp?
instructions:
- text: Get the endpoint, network and cloud detections that match filter {request_data}.
slots:
request_data: requestBody.request_data
- text: Pull every high-severity detection from endpoint, network and cloud sources raised since yesterday.
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/v1/policy'].post
update:
x-apievangelist-phrasing:
intent: Page through policies with their alert counts
effect: read
questions:
- Which policies have the most open alerts right now, using the newer paginated policy endpoint?
- Can I get each policy with its alert count and a next-page token for the following batch?
instructions:
- text: List policies with their alert counts for time range {time_range}, {size} per page.
slots:
time_range: requestBody.timeRange
size: requestBody.size
- text: Fetch the next page of policies with alert counts using token {next_page_token}.
slots:
next_page_token: requestBody.nextPageToken
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/v1/aggregate'].post
update:
x-apievangelist-phrasing:
intent: Group alert counts by a policy field
effect: read
questions:
- Can I bucket my alert counts by a policy field such as severity or policy type?
- What does my alert volume look like when grouped by a policy attribute of my choosing?
instructions:
- text: Aggregate alert counts grouped by policy field {group_by}.
slots:
group_by: requestBody.groupBy
- text: Group alerts by {group_by} for time range {time_range} and show the count in each group.
slots:
group_by: requestBody.groupBy
time_range: requestBody.timeRange
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/v1/{id}/graph'].get
update:
x-apievangelist-phrasing:
intent: Get an alert's evidence graph
effect: read
questions:
- Can I get the evidence behind an alert as graph data I can draw?
- Is there a way to visualise how the resources in an alert connect, in JSON Graph Format?
instructions:
- text: Get the evidence graph for alert {id}.
slots:
id: path.id
- text: Return the JSON Graph Format evidence data for alert {id} so I can render it.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/alerts/api/v1/notification/ondemand'].post
update:
x-apievangelist-phrasing:
intent: Send an on-demand notification for an alert
effect: write
questions:
- Can I push a single alert to Jira, email or Slack right now instead of waiting for a rule?
- Which channels can I send an on-demand alert notification to?
instructions:
- text: Send an on-demand notification for alert {alert_id} using config {config}.
slots:
alert_id: requestBody.alertId
config: requestBody.onDemandNotificationConfig
- text: Open a Jira ticket for alert {alert_id} with notification settings {config}.
slots:
alert_id: requestBody.alertId
config: requestBody.onDemandNotificationConfig
method: generated
generated: '2026-09-26'
- target: $.paths['/filter/alert/suggest'].get
update:
x-apievangelist-phrasing:
intent: List the available alert filters
effect: read
questions:
- What filters can I use when querying cloud alerts?
- Which alert filter keys exist and what are their default options?
instructions:
- text: Show me every alert filter key and its default or recently used options.
- text: List the alert filters I can apply to an alert search.
method: generated
generated: '2026-09-26'
- target: $.paths['/filter/alert/suggest'].post
update:
x-apievangelist-phrasing:
intent: Autocomplete values for an alert filter
effect: read
questions:
- What values can I pick for a specific alert filter like cloud.region?
- Can I type part of a value and get matching suggestions for an alert filter?
instructions:
- text: Suggest values for alert filter {filter_name}.
slots:
filter_name: requestBody.filterName
- text: Autocomplete alert filter {filter_name} with values containing {query}.
slots:
filter_name: requestBody.filterName
query: requestBody.query
method: generated
generated: '2026-09-26'
- target: $.paths['/alert'].get
update:
x-apievangelist-phrasing:
intent: List cloud alerts via query string (v1, 10k cap)
effect: read
questions:
- Can I list Prisma Cloud alerts with query-string filters using the original v1 endpoint?
- Is the original GET alert list capped at 10,000 results?
instructions:
- text: Using the v1 GET alert list, show alerts from the last {time_amount} {time_unit} with time type {time_type}, detailed {detailed}.
slots:
time_amount: query.timeAmount
time_unit: query.timeUnit
time_type: query.timeType
detailed: query.detailed
- text: 'v1 GET list: {alert_status} alerts, severity {severity}, last {time_amount} {time_unit} ({time_type}, detailed {detailed}).'
slots:
alert_status: query.alert.status
severity: query.policy.severity
time_amount: query.timeAmount
time_unit: query.timeUnit
time_type: query.timeType
detailed: query.detailed
method: generated
generated: '2026-09-26'
- target: $.paths['/alert'].post
update:
x-apievangelist-phrasing:
intent: List cloud alerts via request body (v1, 10k cap)
effect: read
questions:
- Can I post a filter body to list cloud alerts with the v1 endpoint and pick only certain fields?
- What happens when the v1 POST alert list passes 10,000 results?
instructions:
- text: Post filters {filters} to the v1 alert list and return alerts for time range {time_range}.
slots:
filters: requestBody.filters
time_range: requestBody.timeRange
- text: Using the v1 POST alert list, return only fields {fields} for alerts matching {filters}.
slots:
fields: requestBody.fields
filters: requestBody.filters
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/alert'].get
update:
x-apievangelist-phrasing:
intent: Page through cloud alerts via query string (v2)
effect: read
questions:
- Can I page past 10,000 alerts using query parameters and a page token?
- Does the v2 GET alert list include alert rules in its response?
instructions:
- text: Page through v2 alerts from the last {time_amount} {time_unit} ({time_type}, detailed {detailed}), starting at token {page_token}.
slots:
time_amount: query.timeAmount
time_unit: query.timeUnit
time_type: query.timeType
detailed: query.detailed
page_token: query.pageToken
- text: Via the v2 GET list, show alerts on cloud account {account} from the last {time_amount} {time_unit} ({time_type}, detailed {detailed}).
slots:
account: query.cloud.account
time_amount: query.timeAmount
time_unit: query.timeUnit
time_type: query.timeType
detailed: query.detailed
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/alert'].post
update:
x-apievangelist-phrasing:
intent: Page through cloud alerts via request body (v2)
effect: read
questions:
- Can I send a JSON filter body and page through more than 10,000 alerts with a page token?
- Which v2 POST alert list option lets me choose the fields returned for each alert?
instructions:
- text: Post filters {filters} to the v2 alert list and continue from page token {page_token}.
slots:
filters: requestBody.filters
page_token: requestBody.pageToken
- text: Using the v2 POST alert list, return {limit} alerts matching {filters} sorted by {sort_by}.
slots:
limit: requestBody.limit
filters: requestBody.filters
sort_by: requestBody.sortBy
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/policy'].get
update:
x-apievangelist-phrasing:
intent: Count alerts per policy via query string
effect: read
questions:
- How many alerts does each policy have, filtered with query parameters?
- Can I see alert counts per policy just for one cloud type using a GET request?
instructions:
- text: Count alerts per policy for cloud type {cloud_type} using the GET grouping.
slots:
cloud_type: query.cloud.type
- text: Show per-policy alert counts for compliance standard {standard} via query parameters.
slots:
standard: query.policy.complianceStandard
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/policy'].post
update:
x-apievangelist-phrasing:
intent: Count alerts per policy via request body
effect: read
questions:
- Can I post a filter body and get back alert counts grouped by policy?
- Which policies are generating alerts in a given time range, counted with a POST filter?
instructions:
- text: Post filters {filters} and return alert counts grouped by policy.
slots:
filters: requestBody.filters
- text: Give me per-policy alert counts for time range {time_range} using a POST body.
slots:
time_range: requestBody.timeRange
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get a cloud alert by ID
effect: read
questions:
- What are the full details of one Prisma Cloud alert when I have its ID?
- What rate limit applies when fetching a single alert's info?
instructions:
- text: Get the details of alert {id}.
slots:
id: path.id
- text: Show detailed information for alert {id} with detailed set to {detailed}.
slots:
id: path.id
detailed: query.detailed
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/dismiss'].post
update:
x-apievangelist-phrasing:
intent: Dismiss or snooze cloud alerts
effect: write
questions:
- Can I snooze alerts for a period instead of dismissing them outright?
- What do I need to send to dismiss a batch of alerts with a note?
instructions:
- text: Dismiss alerts {alerts} matching filter {filter} with note {note}.
slots:
alerts: requestBody.alerts
filter: requestBody.filter
note: requestBody.dismissalNote
- text: Snooze all alerts for policies {policies} matching {filter} for {snooze_range}.
slots:
policies: requestBody.policies
filter: requestBody.filter
snooze_range: requestBody.dismissalTimeRange
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/dismiss/require_dismissal_note'].get
update:
x-apievangelist-phrasing:
intent: Check whether dismissing requires a note
effect: read
questions:
- Do users have to give a reason when they dismiss an alert in my tenant?
- Is a dismissal note currently mandatory for alerts?
instructions:
- text: Tell me whether a dismissal note is required when dismissing alerts.
- text: Check the current dismissal-note requirement setting.
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/dismiss/require_dismissal_note'].put
update:
x-apievangelist-phrasing:
intent: Require or stop requiring a dismissal note
effect: write
questions:
- Can I force everyone to enter a reason before dismissing an alert?
- How do I turn off the mandatory dismissal note for alerts?
instructions:
- text: Set the dismissal note requirement to {required}.
slots:
required: requestBody.requireDismissalNote
- text: Make a dismissal note mandatory for every alert dismissal.
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/reopen'].post
update:
x-apievangelist-phrasing:
intent: Reopen dismissed or snoozed alerts
effect: write
questions:
- Can I set alerts I dismissed or snoozed back to open?
- What's needed to reopen every snoozed alert for a policy?
instructions:
- text: Reopen alerts {alerts} matching filter {filter}.
slots:
alerts: requestBody.alerts
filter: requestBody.filter
- text: Set every dismissed alert for policies {policies} matching {filter} back to open.
slots:
policies: requestBody.policies
filter: requestBody.filter
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/count/{status}'].get
update:
x-apievangelist-phrasing:
intent: Count alerts in a given status
effect: read
questions:
- How many open alerts do I have in total?
- Can I get just the number of dismissed or snoozed alerts without listing them?
instructions:
- text: Count my alerts with status {status}.
slots:
status: path.status
- text: Give me the total number of {status} alerts.
slots:
status: path.status
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/jobs'].post
update:
x-apievangelist-phrasing:
intent: Start a job to export alerts as JSON
effect: write
questions:
- Can I export a large alert list as a downloadable JSON file in the background?
- Do sortBy, limit and pageToken apply when I submit an alert JSON export job?
instructions:
- text: Submit a JSON export job for alerts matching {filters} in time range {time_range}.
slots:
filters: requestBody.filters
time_range: requestBody.timeRange
- text: Kick off a background job that builds a JSON alert list with fields {fields}.
slots:
fields: requestBody.fields
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/jobs/{id}/status'].get
update:
x-apievangelist-phrasing:
intent: Check an alert JSON export job's status
effect: read
questions:
- Is my alert JSON export job finished yet?
- What status is the alert list job I submitted earlier in?
instructions:
- text: Check the status of alert JSON export job {id}.
slots:
id: path.id
- text: Tell me whether alert list job {id} is ready to download.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/jobs/{id}/download'].get
update:
x-apievangelist-phrasing:
intent: Download an exported alert list as JSON
effect: read
questions:
- Where do I fetch the JSON alert list once the export job completes?
- Can I download the results of an alert list job as JSON?
instructions:
- text: Download the JSON alert list produced by job {id}.
slots:
id: path.id
- text: Fetch the finished alert export from job {id} in JSON.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/csv'].post
update:
x-apievangelist-phrasing:
intent: Start a job to export alerts as CSV
effect: write
questions:
- Can I get my alerts as a CSV file for a spreadsheet?
- How do I generate an alert CSV for a filtered set of alerts?
instructions:
- text: Submit a CSV generation job for alerts matching {filters}.
slots:
filters: requestBody.filters
- text: Start a CSV export of alerts for time range {time_range}.
slots:
time_range: requestBody.timeRange
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/csv/{id}/status'].get
update:
x-apievangelist-phrasing:
intent: Check an alert CSV export job's status
effect: read
questions:
- Has my alert CSV finished generating?
- What state is the alert CSV job I kicked off in?
instructions:
- text: Check the status of alert CSV job {id}.
slots:
id: path.id
- text: Tell me if the alert CSV for job {id} is ready.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/csv/{id}/download'].get
update:
x-apievangelist-phrasing:
intent: Download an exported alert CSV
effect: read
questions:
- Where can I download the alert CSV once it's generated?
- Can I grab the finished alert CSV file for a job?
instructions:
- text: Download the alert CSV produced by job {id}.
slots:
id: path.id
- text: Save the CSV alert list from job {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/policy/jobs'].post
update:
x-apievangelist-phrasing:
intent: Start a job listing alerts grouped by policy
effect: write
questions:
- Can I run a background job that lists alerts grouped by the policy they violated?
- Is there an async export of alerts organised per policy?
instructions:
- text: Submit a job that lists alerts grouped by violated policy for filters {filters}.
slots:
filters: requestBody.filters
- text: Start an async per-policy alert listing for time range {time_range}.
slots:
time_range: requestBody.timeRange
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/policy/jobs/{id}/status'].get
update:
x-apievangelist-phrasing:
intent: Check a per-policy alert job's status
effect: read
questions:
- Is my alerts-by-policy job done?
- What's the status of the job I submitted to group alerts by policy?
instructions:
- text: Check the status of alerts-by-policy job {id}.
slots:
id: path.id
- text: Tell me whether policy alert job {id} has completed.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/policy/jobs/{id}/download'].get
update:
x-apievangelist-phrasing:
intent: Download per-policy alert results as JSON
effect: read
questions:
- Where do I download the alerts-grouped-by-policy results?
- Can I fetch the JSON output of a per-policy alert job?
instructions:
- text: Download the per-policy alert JSON from job {id}.
slots:
id: path.id
- text: Fetch the alerts-by-policy results for job {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/remediation'].post
update:
x-apievangelist-phrasing:
intent: Generate remediation commands for alerts
effect: read
questions:
- What CLI commands would fix the misconfigurations behind these alerts?
- Can I get fully constructed remediation commands for alerts on a remediable policy?
instructions:
- text: Generate remediation commands for alerts {alerts} matching filter {filter}.
slots:
alerts: requestBody.alerts
filter: requestBody.filter
- text: Show the remediation commands for policies {policies} within filter {filter}.
slots:
policies: requestBody.policies
filter: requestBody.filter
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/remediation/{id}'].patch
update:
x-apievangelist-phrasing:
intent: Remediate an alert automatically
effect: write
questions:
- Can Prisma Cloud fix the issue behind an alert for me?
- Which alerts can be auto-remediated, and how do I trigger it?
instructions:
- text: Remediate alert {id}.
slots:
id: path.id
- text: Run the remediation for alert {id} on its remediable policy.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/policy/api/v1/fetch/remediation/{policyId}'].get
update:
x-apievangelist-phrasing:
intent: Get AI-assisted remediation for a policy
effect: read
questions:
- Is there AI-assisted guidance on how to fix a policy violation on a specific asset?
- What recommendation steps are available to mitigate a policy's finding?
instructions:
- text: Get AI-assisted remediation for policy {policy_id} on asset {asset_id} for alert {alert_id}.
slots:
policy_id: path.policyId
asset_id: query.unifiedAssetId
alert_id: query.alertId
- text: Show the recommended fix steps for policy {policy_id}, asset {asset_id}, alert {alert_id}.
slots:
policy_id: path.policyId
asset_id: query.unifiedAssetId
alert_id: query.alertId
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/alerts/id/{id}/status/{status}'].patch
update:
x-apievangelist-phrasing:
intent: Update a data detection (DDR) alert's status
effect: write
questions:
- Can I change the status of a data detection and response alert?
- What's the call to mark a DDR alert as resolved?
instructions:
- text: Set DDR alert {id} to status {status}.
slots:
id: path.id
status: path.status
- text: Mark data detection alert {id} as {status} using API key {api_key}.
slots:
id: path.id
status: path.status
api_key: header.dig-api-key
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/alerts'].get
update:
x-apievangelist-phrasing:
intent: List data detection (DDR) alerts
effect: read
questions:
- Which data detection and response alerts fired on my cloud assets this week?
- Can I filter DDR alerts by asset name, policy severity or cloud provider?
instructions:
- text: List DDR alerts with policy severity {severity}.
slots:
severity: query.policySeverity.equals
- text: Show DDR alerts on assets whose name contains {asset}, page {page}.
slots:
asset: query.assetName.contains
page: query.page
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/list'].get
update:
x-apievangelist-phrasing:
intent: List IoT Security alerts
effect: read
questions:
- What alerts has IoT Security raised about anomalous device behaviour?
- Can I list only unresolved IoT device alerts within a time window?
instructions:
- text: List IoT Security alerts for customer {customer_id}.
slots:
customer_id: query.customerid
- text: Show IoT alerts for customer {customer_id} between {start} and {end} with resolved {resolved}.
slots:
customer_id: query.customerid
start: query.stime
end: query.etime
resolved: query.resolved
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/detail'].get
update:
x-apievangelist-phrasing:
intent: Get details of an IoT Security alert
effect: read
questions:
- Which device was affected by an IoT alert, and what response is recommended?
- Can I see the timeline for a single IoT Security alert?
instructions:
- text: Get IoT alert {id} for customer {customer_id}.
slots:
id: query.id
customer_id: query.customerid
- text: Show the affected device and recommended actions for IoT alert {id} under customer {customer_id}.
slots:
id: query.id
customer_id: query.customerid
method: generated
generated: '2026-09-26'
- target: $.paths['/alert/update'].put
update:
x-apievangelist-phrasing:
intent: Resolve or unresolve an IoT Security alert
effect: write
questions:
- Can I mark an IoT device alert as resolved and record why?
- Are resolved IoT alerts kept for later analysis?
instructions:
- text: Mark IoT alert {id} for customer {customer_id} as resolved {resolved} with reason {reason}.
slots:
id: query.id
customer_id: query.customerid
resolved: query.resolved
reason: query.reason
- text: Set IoT alert {id} for customer {customer_id} to resolved {resolved}.
slots:
id: query.id
customer_id: query.customerid
resolved: query.resolved
method: generated
generated: '2026-09-26'
- target: $.paths['/dspm/api/v1/alerts'].get
update:
x-apievangelist-phrasing:
intent: List data security (DSPM) alerts
effect: read
questions:
- Which alerts flag sensitive data exposure, such as a data store that became public?
- Can I filter data security alerts by severity and cloud provider?
instructions:
- text: List data security alerts with severity {severity} and status {status}.
slots:
severity: query.severity
status: query.status
- text: Show sensitive-data exposure alerts on {cloud_provider} since {start_time}.
slots:
cloud_provider: query.cloudProvider
start_time: query.start_time
method: generated
generated: '2026-09-26'