Palo Alto Networks · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Palo Alto Networks Audits API

97 actions 97 updates phrasing extends openapi/palo-alto-networks-audits-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 97 · first 16 shown; the file carries all of them

$.info
$.paths['/api/v34.03/audits/access'].get
$.paths['/api/v34.03/audits/access/download'].get
$.paths['/api/v34.03/audits/admission'].get
$.paths['/api/v34.03/audits/admission/download'].get
$.paths['/api/v34.03/audits/firewall/app/agentless'].get
$.paths['/api/v34.03/audits/firewall/app/agentless/download'].get
$.paths['/api/v34.03/audits/firewall/app/agentless/timeslice'].get
$.paths['/api/v34.03/audits/firewall/app/app-embedded'].get
$.paths['/api/v34.03/audits/firewall/app/app-embedded/download'].get
$.paths['/api/v34.03/audits/firewall/app/app-embedded/timeslice'].get
$.paths['/api/v34.03/audits/firewall/app/container'].get
$.paths['/api/v34.03/audits/firewall/app/container/download'].get
$.paths['/api/v34.03/audits/firewall/app/container/timeslice'].get
$.paths['/api/v34.03/audits/firewall/app/host'].get
$.paths['/api/v34.03/audits/firewall/app/host/download'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Palo Alto Networks Audits API
  version: 1.0.0
extends: openapi/palo-alto-networks-audits-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 96
- target: $.paths['/api/v34.03/audits/access'].get
  update:
    x-apievangelist-phrasing:
      intent: List Docker access audit events (v34.03)
      effect: read
      questions:
      - Which Docker commands were allowed or blocked on my hosts, according to the v34.03 audits API?
      - Can I filter v34.03 Docker access audits by user and hostname?
      instructions:
      - text: List v34.03 Docker access audit events on host {hostname} for user {user}.
        slots:
          hostname: query.hostname
          user: query.user
      - text: Show v34.03 Docker access audits triggered by rule {ruleName} between {from} and {to}.
        slots:
          ruleName: query.ruleName
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/access/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download Docker access audit events (v34.03)
      effect: read
      questions:
      - Can I export Docker access audit events to a file using the v34.03 API?
      - Is there a way to download v34.03 Docker access audits for one cluster?
      instructions:
      - text: Download the v34.03 Docker access audit file for cluster {cluster}.
        slots:
          cluster: query.cluster
      - text: Export v34.03 Docker access audits from {from} to {to} as a download.
        slots:
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/admission'].get
  update:
    x-apievangelist-phrasing:
      intent: List Kubernetes admission audit events (v34.03)
      effect: read
      questions:
      - Which admission control decisions were audited in a namespace under v34.03?
      - Can I find v34.03 admission audits tied to a MITRE attack technique?
      instructions:
      - text: List v34.03 admission audit events in namespace {namespace}.
        slots:
          namespace: query.namespace
      - text: Show v34.03 admission audits for operation {operation} on cluster {cluster}.
        slots:
          operation: query.operation
          cluster: query.cluster
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/admission/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download admission audit events (v34.03)
      effect: read
      questions:
      - Can I download admission controller audits as a file from the v34.03 API?
      - Is it possible to export v34.03 admission audits for a single namespace?
      instructions:
      - text: Download v34.03 admission audit events for namespace {namespace}.
        slots:
          namespace: query.namespace
      - text: Export the v34.03 admission audit file between {from} and {to}.
        slots:
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/agentless'].get
  update:
    x-apievangelist-phrasing:
      intent: List WAAS agentless audit events (v34.03)
      effect: read
      questions:
      - What web attacks did WAAS agentless protection record under the v34.03 API?
      - Can I narrow v34.03 WAAS agentless audits to OWASP Top 10 findings or one country?
      instructions:
      - text: List v34.03 WAAS agentless audit events on host {hostname}.
        slots:
          hostname: query.hostname
      - text: Show v34.03 WAAS agentless audits from country {country} for URL path {urlPath}.
        slots:
          country: query.country
          urlPath: query.urlPath
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/agentless/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download WAAS agentless audit events (v34.03)
      effect: read
      questions:
      - Can I export WAAS agentless firewall audits to a file in v34.03?
      - Is there a download of v34.03 WAAS agentless events for one rule?
      instructions:
      - text: Download v34.03 WAAS agentless audits for rule {ruleName}.
        slots:
          ruleName: query.ruleName
      - text: Export the v34.03 WAAS agentless audit file for {from} to {to}.
        slots:
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/agentless/timeslice'].get
  update:
    x-apievangelist-phrasing:
      intent: Chart WAAS agentless audits over time (v34.03)
      effect: read
      questions:
      - How are WAAS agentless audit events spread across a timeframe in v34.03?
      - Can I bucket v34.03 WAAS agentless events into a set number of time slices?
      instructions:
      - text: Split v34.03 WAAS agentless audits from {from} to {to} into {buckets} time buckets.
        slots:
          from: query.from
          to: query.to
          buckets: query.buckets
      - text: Get the v34.03 WAAS agentless audit timeline for host {hostname}.
        slots:
          hostname: query.hostname
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/app-embedded'].get
  update:
    x-apievangelist-phrasing:
      intent: List WAAS app-embedded audit events (v34.03)
      effect: read
      questions:
      - What attacks did app-embedded WAAS defenders block, per the v34.03 audits API?
      - Can I filter v34.03 app-embedded WAAS audits by app ID or effect?
      instructions:
      - text: List v34.03 WAAS app-embedded audit events for app {appID}.
        slots:
          appID: query.appID
      - text: Show v34.03 app-embedded WAAS audits with effect {effect} since {from}.
        slots:
          effect: query.effect
          from: query.from
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/app-embedded/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download WAAS app-embedded audit events (v34.03)
      effect: read
      questions:
      - Can I download app-embedded WAAS audits as a file in v34.03?
      - Is there an export of v34.03 app-embedded WAAS events for one app?
      instructions:
      - text: Download v34.03 WAAS app-embedded audits for app {appID}.
        slots:
          appID: query.appID
      - text: Export the v34.03 app-embedded WAAS audit file from {from} to {to}.
        slots:
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/app-embedded/timeslice'].get
  update:
    x-apievangelist-phrasing:
      intent: Chart WAAS app-embedded audits over time (v34.03)
      effect: read
      questions:
      - How did app-embedded WAAS audit volume change over a timeframe in v34.03?
      - Can I get v34.03 app-embedded WAAS event counts per time bucket?
      instructions:
      - text: Bucket v34.03 WAAS app-embedded audits from {from} to {to} into {buckets} slices.
        slots:
          from: query.from
          to: query.to
          buckets: query.buckets
      - text: Get the v34.03 app-embedded WAAS audit timeline for app {appID}.
        slots:
          appID: query.appID
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/container'].get
  update:
    x-apievangelist-phrasing:
      intent: List WAAS container audit events (v34.03)
      effect: read
      questions:
      - Which web attacks against my containers did WAAS log in v34.03?
      - Can I filter v34.03 WAAS container audits by image or container name?
      instructions:
      - text: List v34.03 WAAS container audit events for image {imageName}.
        slots:
          imageName: query.imageName
      - text: Show v34.03 WAAS container audits for container {containerName} on cluster {cluster}.
        slots:
          containerName: query.containerName
          cluster: query.cluster
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/container/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download WAAS container audit events (v34.03)
      effect: read
      questions:
      - Can I pull a v34.03 file export of the web application firewall events for my containers?
      - Is there a v34.03 download of WAAS container audits for one image?
      instructions:
      - text: Download v34.03 WAAS container audits for image {imageName}.
        slots:
          imageName: query.imageName
      - text: Export the v34.03 WAAS container audit file between {from} and {to}.
        slots:
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/container/timeslice'].get
  update:
    x-apievangelist-phrasing:
      intent: Chart WAAS container audits over time (v34.03)
      effect: read
      questions:
      - How are WAAS container audit events distributed over time in v34.03?
      - Can I split v34.03 WAAS container events into time buckets for a chart?
      instructions:
      - text: Bucket v34.03 WAAS container audits from {from} to {to} into {buckets} slices.
        slots:
          from: query.from
          to: query.to
          buckets: query.buckets
      - text: Get the v34.03 WAAS container audit timeslice for image {imageName}.
        slots:
          imageName: query.imageName
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/host'].get
  update:
    x-apievangelist-phrasing:
      intent: List WAAS host audit events (v34.03)
      effect: read
      questions:
      - What web attacks on host-based apps did WAAS record in v34.03?
      - Can I filter v34.03 WAAS host audits by the connecting IP or user agent?
      instructions:
      - text: List v34.03 WAAS audits for web apps running directly on host {hostname}.
        slots:
          hostname: query.hostname
      - text: Show v34.03 WAAS host audits from connecting IPs {connectingIPs}.
        slots:
          connectingIPs: query.connectingIPs
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/host/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download WAAS host audit events (v34.03)
      effect: read
      questions:
      - Can I download WAAS host firewall audits as a file with v34.03?
      - Is there an export of v34.03 WAAS host audits for one hostname?
      instructions:
      - text: Download v34.03 WAAS host audits for host {hostname}.
        slots:
          hostname: query.hostname
      - text: Export the v34.03 WAAS host audit file from {from} to {to}.
        slots:
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/host/timeslice'].get
  update:
    x-apievangelist-phrasing:
      intent: Chart WAAS host audits over time (v34.03)
      effect: read
      questions:
      - How did WAAS host audit activity trend across a period in v34.03?
      - Can I get v34.03 WAAS host audit counts grouped into time buckets?
      instructions:
      - text: Bucket v34.03 WAAS host audits from {from} to {to} into {buckets} slices.
        slots:
          from: query.from
          to: query.to
          buckets: query.buckets
      - text: Get the v34.03 WAAS host audit timeslice for host {hostname}.
        slots:
          hostname: query.hostname
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/serverless'].get
  update:
    x-apievangelist-phrasing:
      intent: List WAAS serverless audit events (v34.03)
      effect: read
      questions:
      - Which attacks on my serverless functions did WAAS log in v34.03?
      - Can I filter v34.03 WAAS serverless audits by function or runtime?
      instructions:
      - text: List v34.03 WAAS serverless audit events for function {function}.
        slots:
          function: query.function
      - text: Show v34.03 WAAS serverless audits on runtime {runtime}.
        slots:
          runtime: query.runtime
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/serverless/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download WAAS serverless audit events (v34.03)
      effect: read
      questions:
      - Can I get a v34.03 downloadable file of firewall events for my serverless functions?
      - Is there a v34.03 download of WAAS serverless events for one function?
      instructions:
      - text: Download v34.03 WAAS serverless audits for function {function}.
        slots:
          function: query.function
      - text: Export the v34.03 WAAS serverless audit file from {from} to {to}.
        slots:
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/serverless/timeslice'].get
  update:
    x-apievangelist-phrasing:
      intent: Chart WAAS serverless audits over time (v34.03)
      effect: read
      questions:
      - How are WAAS serverless audit events spread over a timeframe in v34.03?
      - Can I bucket v34.03 WAAS serverless events by time for a trend view?
      instructions:
      - text: Bucket v34.03 WAAS serverless audits from {from} to {to} into {buckets} slices.
        slots:
          from: query.from
          to: query.to
          buckets: query.buckets
      - text: Get the v34.03 WAAS serverless audit timeline for function {function}.
        slots:
          function: query.function
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/network/container'].get
  update:
    x-apievangelist-phrasing:
      intent: List CNNS container network audits (v34.03)
      effect: read
      questions:
      - Which container-to-container connections did cloud native network security flag in v34.03?
      - Can I see only blocked v34.03 CNNS container connections between two images?
      instructions:
      - text: List v34.03 CNNS container audits from image {srcImageName} to image {dstImageName}.
        slots:
          srcImageName: query.srcImageName
          dstImageName: query.dstImageName
      - text: Show v34.03 CNNS container network audits with block filter {block}.
        slots:
          block: query.block
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/network/container/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download CNNS container network audits (v34.03)
      effect: read
      questions:
      - Can I export CNNS container network audits as a file in v34.03?
      - Is there a v34.03 download of container network audits for one source image?
      instructions:
      - text: Download v34.03 CNNS container audits for source image {srcImageName}.
        slots:
          srcImageName: query.srcImageName
      - text: Export the v34.03 CNNS container audit file from {from} to {to}.
        slots:
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/network/host'].get
  update:
    x-apievangelist-phrasing:
      intent: List CNNS host network audits (v34.03)
      effect: read
      questions:
      - Which host-to-host connections did CNNS audit in v34.03?
      - Can I filter v34.03 CNNS host audits by source and destination hostnames?
      instructions:
      - text: List v34.03 CNNS host audits from {srcHostnames} to {dstHostnames}.
        slots:
          srcHostnames: query.srcHostnames
          dstHostnames: query.dstHostnames
      - text: Show v34.03 CNNS host network audits since {from}.
        slots:
          from: query.from
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/network/host/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download CNNS host network audits (v34.03)
      effect: read
      questions:
      - Can I download CNNS host network audits as a file in v34.03?
      - Is there a v34.03 export of host network audits for specific source hosts?
      instructions:
      - text: Download v34.03 CNNS host audits for source hosts {srcHostnames}.
        slots:
          srcHostnames: query.srcHostnames
      - text: Export the v34.03 CNNS host audit file between {from} and {to}.
        slots:
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/incidents'].get
  update:
    x-apievangelist-phrasing:
      intent: List incident audit events (v34.03)
      effect: read
      questions:
      - What security incidents has Prisma Cloud Compute recorded, per the v34.03 API?
      - Can I list only unacknowledged v34.03 incidents in one category?
      instructions:
      - text: List v34.03 incidents in category {category} on host {hostname}.
        slots:
          category: query.category
          hostname: query.hostname
      - text: Show v34.03 incident audits with acknowledged set to {acknowledged}.
        slots:
          acknowledged: query.acknowledged
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/incidents/acknowledge/{id}'].patch
  update:
    x-apievangelist-phrasing:
      intent: Archive an incident (v34.03)
      effect: write
      questions:
      - How do I acknowledge and archive an incident through the v34.03 API?
      - Can I mark a v34.03 incident as acknowledged so it leaves the active list?
      instructions:
      - text: Archive incident {id} using the v34.03 API.
        slots:
          id: path.id
      - text: Set acknowledged to {acknowledged} on v34.03 incident {id}.
        slots:
          acknowledged: requestBody.acknowledged
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/incidents/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download incident audit events (v34.03)
      effect: read
      questions:
      - Can I export incident audits to a file with the v34.03 API?
      - Is there a v34.03 download of incidents for one cluster?
      instructions:
      - text: Download v34.03 incident audits for cluster {cluster}.
        slots:
          cluster: query.cluster
      - text: Export the v34.03 incident file from {from} to {to}.
        slots:
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/kubernetes'].get
  update:
    x-apievangelist-phrasing:
      intent: List Kubernetes audit events (v34.03)
      effect: read
      questions:
      - Which Kubernetes API activity was flagged in the v34.03 audits?
      - Can I filter v34.03 Kubernetes audits by user or cluster?
      instructions:
      - text: List v34.03 Kubernetes audit events for user {user}.
        slots:
          user: query.user
      - text: Show v34.03 Kubernetes audits on cluster {cluster} since {from}.
        slots:
          cluster: query.cluster
          from: query.from
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/kubernetes/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download Kubernetes audit events (v34.03)
      effect: read
      questions:
      - Can I download Kubernetes audit events as a file in v34.03?
      - Is there a v34.03 export of Kubernetes audits for one cluster?
      instructions:
      - text: Download v34.03 Kubernetes audits for cluster {cluster}.
        slots:
          cluster: query.cluster
      - text: Export the v34.03 Kubernetes audit file from {from} to {to}.
        slots:
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/mgmt'].get
  update:
    x-apievangelist-phrasing:
      intent: List management audit events (v34.03)
      effect: read
      questions:
      - Who changed settings in the Console, according to the v34.03 management audits?
      - Can I see v34.03 management audit events for one admin username?
      instructions:
      - text: List v34.03 management audit events by user {username}.
        slots:
          username: query.username
      - text: Show v34.03 management audits of type {type} between {from} and {to}.
        slots:
          type: query.type
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/mgmt/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download management audit events (v34.03)
      effect: read
      questions:
      - Can I export Console management audits to a file in v34.03?
      - Is there a v34.03 download of admin activity for one username?
      instructions:
      - text: Download v34.03 management audits for user {username}.
        slots:
          username: query.username
      - text: Export the v34.03 management audit file from {from} to {to}.
        slots:
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/mgmt/filters'].get
  update:
    x-apievangelist-phrasing:
      intent: Get management audit filter values (v34.03)
      effect: read
      questions:
      - What filter values can I use when searching management audits in v34.03?
      - Which usernames and audit types appear as v34.03 management audit filters?
      instructions:
      - text: Get the v34.03 management audit filter options.
      - text: Show the v34.03 management audit filters available for type {type}.
        slots:
          type: query.type
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/app-embedded'].get
  update:
    x-apievangelist-phrasing:
      intent: List runtime app-embedded audit events (v34.03)
      effect: read
      questions:
      - What runtime alerts did app-embedded defenders raise in v34.03?
      - Can I filter v34.03 app-embedded runtime audits by attack type or process path?
      instructions:
      - text: List v34.03 runtime app-embedded audits for app {appID}.
        slots:
          appID: query.appID
      - text: Show v34.03 app-embedded runtime audits with attack type {attackType}.
        slots:
          attackType: query.attackType
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/app-embedded/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download runtime app-embedded audits (v34.03)
      effect: read
      questions:
      - Can I grab a v34.03 file of runtime (not WAAS) alerts from app-embedded defenders?
      - Is there a v34.03 export of runtime app-embedded events for one app?
      instructions:
      - text: Download v34.03 runtime app-embedded audits for app {appID}.
        slots:
          appID: query.appID
      - text: Export the v34.03 runtime app-embedded audit file from {from} to {to}.
        slots:
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/container'].get
  update:
    x-apievangelist-phrasing:
      intent: List runtime container audit events (v34.03)
      effect: read
      questions:
      - What suspicious process, network or file activity did runtime defense see in containers in v34.03?
      - Can I filter v34.03 container runtime audits by image and namespace?
      instructions:
      - text: List v34.03 runtime container audits for image {imageName} in namespace {namespace}.
        slots:
          imageName: query.imageName
          namespace: query.namespace
      - text: Show v34.03 container runtime audits for container {container}.
        slots:
          container: query.container
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/container/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download runtime container audits (v34.03)
      effect: read
      questions:
      - Can I export container runtime audits to a file in v34.03?
      - Is there a v34.03 download of runtime container events for one image?
      instructions:
      - text: Download v34.03 runtime container audits for image {imageName}.
        slots:
          imageName: query.imageName
      - text: Export the v34.03 runtime container audit file between {from} and {to}.
        slots:
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/container/timeslice'].get
  update:
    x-apievangelist-phrasing:
      intent: Chart runtime container audits over time (v34.03)
      effect: read
      questions:
      - How did container runtime audit volume trend across a timeframe in v34.03?
      - Can I bucket v34.03 runtime container events into time slices?
      instructions:
      - text: Bucket v34.03 runtime container audits from {from} to {to} into {buckets} slices.
        slots:
          from: query.from
          to: query.to
          buckets: query.buckets
      - text: Get the v34.03 runtime container audit timeline for image {imageName}.
        slots:
          imageName: query.imageName
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/file-integrity'].get
  update:
    x-apievangelist-phrasing:
      intent: List file integrity audit events (v34.03)
      effect: read
      questions:
      - Which monitored files were changed on my hosts, per v34.03 file integrity audits?
      - Can I filter v34.03 file integrity events by path or event type?
      instructions:
      - text: List v34.03 file integrity audits on host {hostname} for path {path}.
        slots:
          hostname: query.hostname
          path: query.path
      - text: Show v34.03 file integrity events of type {eventType}.
        slots:
          eventType: query.eventType
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/file-integrity/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download file integrity audit events (v34.03)
      effect: read
      questions:
      - Can I download file integrity monitoring audits as a file in v34.03?
      - Is there a v34.03 export of file integrity events for one host?
      instructions:
      - text: Download v34.03 file integrity audits for host {hostname}.
        slots:
          hostname: query.hostname
      - text: Export the v34.03 file integrity audit file from {from} to {to}.
        slots:
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/host'].get
  update:
    x-apievangelist-phrasing:
      intent: List runtime host audit events (v34.03)
      effect: read
      questions:
      - What runtime alerts did host defenders raise in the v34.03 audits?
      - Can I filter v34.03 host runtime audits by user or process path?
      instructions:
      - text: List v34.03 runtime host audits on host {hostname}.
        slots:
          hostname: query.hostname
      - text: Show v34.03 host runtime audits for process path {processPath} run by {user}.
        slots:
          processPath: query.processPath
          user: query.user
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/host/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download runtime host audits (v34.03)
      effect: read
      questions:
      - Can I export host runtime audits to a file in v34.03?
      - Is there a v34.03 download of runtime host events for one hostname?
      instructions:
      - text: Download v34.03 runtime host audits for host {hostname}.
        slots:
          hostname: query.hostname
      - text: Export the v34.03 runtime host audit file from {from} to {to}.
        slots:
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/host/timeslice'].get
  update:
    x-apievangelist-phrasing:
      intent: Chart runtime host audits over time (v34.03)
      effect: read
      questions:
      - How are host runtime audit events distributed over time in v34.03?
      - Can I get v34.03 runtime host audit counts per time bucket?
      instructions:
      - text: Bucket v34.03 runtime host audits from {from} to {to} into {buckets} slices.
        slots:
          from: query.from
          to: query.to
          buckets: query.buckets
      - text: Get the v34.03 runtime host audit timeline for host {hostname}.
        slots:
          hostname: query.hostname
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/log-inspection'].get
  update:
    x-apievangelist-phrasing:
      intent: List log inspection audit events (v34.03)
      effect: read
      questions:
      - Which log inspection rules matched lines in my host logs, per v34.03?
      - Can I filter v34.03 log inspection audits by log file?
      instructions:
      - text: List v34.03 log inspection audits for log file {logfile}.
        slots:
          logfile: query.logfile
      - text: Show v34.03 log inspection events on host {hostname}.
        slots:
          hostname: query.hostname
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/log-inspection/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download log inspection audit events (v34.03)
      effect: read
      questions:
      - Can I download log inspection audits as a file in v34.03?
      - Is there a v34.03 export of log inspection events for one host?
      instructions:
      - text: Download v34.03 log inspection audits for host {hostname}.
        slots:
          hostname: query.hostname
      - text: Export the v34.03 log inspection audit file from {from} to {to}.
        slots:
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/serverless'].get
  update:
    x-apievangelist-phrasing:
      intent: List runtime serverless audit events (v34.03)
      effect: read
      questions:
      - What runtime alerts fired for my serverless functions in v34.03?
      - Can I filter v34.03 serverless runtime audits by function and effect?
      instructions:
      - text: List v34.03 runtime serverless audits for function {function}.
        slots:
          function: query.function
      - text: Show v34.03 serverless runtime audits with effect {effect} on runtime {runtime}.
        slots:
          effect: query.effect
          runtime: query.runtime
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/serverless/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download runtime serverless audits (v34.03)
      effect: read
      questions:
      - Can I export serverless runtime audits to a file in v34.03?
      - Is there a v34.03 file export of runtime defense alerts for one serverless function?
      instructions:
      - text: Download v34.03 runtime serverless audits for function {function}.
        slots:
          function: query.function
      - text: Export the v34.03 runtime serverless audit file from {from} to {to}.
        slots:
          from: query.from
          to: query.to
      method: generated
      generated: '2026-09-26'


# --- truncated at 32 KB (66 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/overlays/palo-alto-networks-audits-api-phrasing-overlay.yaml