Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Palo Alto Networks Audits API
97 actions
97 updates
phrasing
extends
openapi/palo-alto-networks-audits-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 97 · first 16 shown; the file carries all of them
$.info
$.paths['/api/v34.03/audits/access'].get
$.paths['/api/v34.03/audits/access/download'].get
$.paths['/api/v34.03/audits/admission'].get
$.paths['/api/v34.03/audits/admission/download'].get
$.paths['/api/v34.03/audits/firewall/app/agentless'].get
$.paths['/api/v34.03/audits/firewall/app/agentless/download'].get
$.paths['/api/v34.03/audits/firewall/app/agentless/timeslice'].get
$.paths['/api/v34.03/audits/firewall/app/app-embedded'].get
$.paths['/api/v34.03/audits/firewall/app/app-embedded/download'].get
$.paths['/api/v34.03/audits/firewall/app/app-embedded/timeslice'].get
$.paths['/api/v34.03/audits/firewall/app/container'].get
$.paths['/api/v34.03/audits/firewall/app/container/download'].get
$.paths['/api/v34.03/audits/firewall/app/container/timeslice'].get
$.paths['/api/v34.03/audits/firewall/app/host'].get
$.paths['/api/v34.03/audits/firewall/app/host/download'].get
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Palo Alto Networks Audits API
version: 1.0.0
extends: openapi/palo-alto-networks-audits-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 96
- target: $.paths['/api/v34.03/audits/access'].get
update:
x-apievangelist-phrasing:
intent: List Docker access audit events (v34.03)
effect: read
questions:
- Which Docker commands were allowed or blocked on my hosts, according to the v34.03 audits API?
- Can I filter v34.03 Docker access audits by user and hostname?
instructions:
- text: List v34.03 Docker access audit events on host {hostname} for user {user}.
slots:
hostname: query.hostname
user: query.user
- text: Show v34.03 Docker access audits triggered by rule {ruleName} between {from} and {to}.
slots:
ruleName: query.ruleName
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/access/download'].get
update:
x-apievangelist-phrasing:
intent: Download Docker access audit events (v34.03)
effect: read
questions:
- Can I export Docker access audit events to a file using the v34.03 API?
- Is there a way to download v34.03 Docker access audits for one cluster?
instructions:
- text: Download the v34.03 Docker access audit file for cluster {cluster}.
slots:
cluster: query.cluster
- text: Export v34.03 Docker access audits from {from} to {to} as a download.
slots:
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/admission'].get
update:
x-apievangelist-phrasing:
intent: List Kubernetes admission audit events (v34.03)
effect: read
questions:
- Which admission control decisions were audited in a namespace under v34.03?
- Can I find v34.03 admission audits tied to a MITRE attack technique?
instructions:
- text: List v34.03 admission audit events in namespace {namespace}.
slots:
namespace: query.namespace
- text: Show v34.03 admission audits for operation {operation} on cluster {cluster}.
slots:
operation: query.operation
cluster: query.cluster
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/admission/download'].get
update:
x-apievangelist-phrasing:
intent: Download admission audit events (v34.03)
effect: read
questions:
- Can I download admission controller audits as a file from the v34.03 API?
- Is it possible to export v34.03 admission audits for a single namespace?
instructions:
- text: Download v34.03 admission audit events for namespace {namespace}.
slots:
namespace: query.namespace
- text: Export the v34.03 admission audit file between {from} and {to}.
slots:
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/agentless'].get
update:
x-apievangelist-phrasing:
intent: List WAAS agentless audit events (v34.03)
effect: read
questions:
- What web attacks did WAAS agentless protection record under the v34.03 API?
- Can I narrow v34.03 WAAS agentless audits to OWASP Top 10 findings or one country?
instructions:
- text: List v34.03 WAAS agentless audit events on host {hostname}.
slots:
hostname: query.hostname
- text: Show v34.03 WAAS agentless audits from country {country} for URL path {urlPath}.
slots:
country: query.country
urlPath: query.urlPath
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/agentless/download'].get
update:
x-apievangelist-phrasing:
intent: Download WAAS agentless audit events (v34.03)
effect: read
questions:
- Can I export WAAS agentless firewall audits to a file in v34.03?
- Is there a download of v34.03 WAAS agentless events for one rule?
instructions:
- text: Download v34.03 WAAS agentless audits for rule {ruleName}.
slots:
ruleName: query.ruleName
- text: Export the v34.03 WAAS agentless audit file for {from} to {to}.
slots:
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/agentless/timeslice'].get
update:
x-apievangelist-phrasing:
intent: Chart WAAS agentless audits over time (v34.03)
effect: read
questions:
- How are WAAS agentless audit events spread across a timeframe in v34.03?
- Can I bucket v34.03 WAAS agentless events into a set number of time slices?
instructions:
- text: Split v34.03 WAAS agentless audits from {from} to {to} into {buckets} time buckets.
slots:
from: query.from
to: query.to
buckets: query.buckets
- text: Get the v34.03 WAAS agentless audit timeline for host {hostname}.
slots:
hostname: query.hostname
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/app-embedded'].get
update:
x-apievangelist-phrasing:
intent: List WAAS app-embedded audit events (v34.03)
effect: read
questions:
- What attacks did app-embedded WAAS defenders block, per the v34.03 audits API?
- Can I filter v34.03 app-embedded WAAS audits by app ID or effect?
instructions:
- text: List v34.03 WAAS app-embedded audit events for app {appID}.
slots:
appID: query.appID
- text: Show v34.03 app-embedded WAAS audits with effect {effect} since {from}.
slots:
effect: query.effect
from: query.from
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/app-embedded/download'].get
update:
x-apievangelist-phrasing:
intent: Download WAAS app-embedded audit events (v34.03)
effect: read
questions:
- Can I download app-embedded WAAS audits as a file in v34.03?
- Is there an export of v34.03 app-embedded WAAS events for one app?
instructions:
- text: Download v34.03 WAAS app-embedded audits for app {appID}.
slots:
appID: query.appID
- text: Export the v34.03 app-embedded WAAS audit file from {from} to {to}.
slots:
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/app-embedded/timeslice'].get
update:
x-apievangelist-phrasing:
intent: Chart WAAS app-embedded audits over time (v34.03)
effect: read
questions:
- How did app-embedded WAAS audit volume change over a timeframe in v34.03?
- Can I get v34.03 app-embedded WAAS event counts per time bucket?
instructions:
- text: Bucket v34.03 WAAS app-embedded audits from {from} to {to} into {buckets} slices.
slots:
from: query.from
to: query.to
buckets: query.buckets
- text: Get the v34.03 app-embedded WAAS audit timeline for app {appID}.
slots:
appID: query.appID
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/container'].get
update:
x-apievangelist-phrasing:
intent: List WAAS container audit events (v34.03)
effect: read
questions:
- Which web attacks against my containers did WAAS log in v34.03?
- Can I filter v34.03 WAAS container audits by image or container name?
instructions:
- text: List v34.03 WAAS container audit events for image {imageName}.
slots:
imageName: query.imageName
- text: Show v34.03 WAAS container audits for container {containerName} on cluster {cluster}.
slots:
containerName: query.containerName
cluster: query.cluster
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/container/download'].get
update:
x-apievangelist-phrasing:
intent: Download WAAS container audit events (v34.03)
effect: read
questions:
- Can I pull a v34.03 file export of the web application firewall events for my containers?
- Is there a v34.03 download of WAAS container audits for one image?
instructions:
- text: Download v34.03 WAAS container audits for image {imageName}.
slots:
imageName: query.imageName
- text: Export the v34.03 WAAS container audit file between {from} and {to}.
slots:
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/container/timeslice'].get
update:
x-apievangelist-phrasing:
intent: Chart WAAS container audits over time (v34.03)
effect: read
questions:
- How are WAAS container audit events distributed over time in v34.03?
- Can I split v34.03 WAAS container events into time buckets for a chart?
instructions:
- text: Bucket v34.03 WAAS container audits from {from} to {to} into {buckets} slices.
slots:
from: query.from
to: query.to
buckets: query.buckets
- text: Get the v34.03 WAAS container audit timeslice for image {imageName}.
slots:
imageName: query.imageName
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/host'].get
update:
x-apievangelist-phrasing:
intent: List WAAS host audit events (v34.03)
effect: read
questions:
- What web attacks on host-based apps did WAAS record in v34.03?
- Can I filter v34.03 WAAS host audits by the connecting IP or user agent?
instructions:
- text: List v34.03 WAAS audits for web apps running directly on host {hostname}.
slots:
hostname: query.hostname
- text: Show v34.03 WAAS host audits from connecting IPs {connectingIPs}.
slots:
connectingIPs: query.connectingIPs
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/host/download'].get
update:
x-apievangelist-phrasing:
intent: Download WAAS host audit events (v34.03)
effect: read
questions:
- Can I download WAAS host firewall audits as a file with v34.03?
- Is there an export of v34.03 WAAS host audits for one hostname?
instructions:
- text: Download v34.03 WAAS host audits for host {hostname}.
slots:
hostname: query.hostname
- text: Export the v34.03 WAAS host audit file from {from} to {to}.
slots:
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/host/timeslice'].get
update:
x-apievangelist-phrasing:
intent: Chart WAAS host audits over time (v34.03)
effect: read
questions:
- How did WAAS host audit activity trend across a period in v34.03?
- Can I get v34.03 WAAS host audit counts grouped into time buckets?
instructions:
- text: Bucket v34.03 WAAS host audits from {from} to {to} into {buckets} slices.
slots:
from: query.from
to: query.to
buckets: query.buckets
- text: Get the v34.03 WAAS host audit timeslice for host {hostname}.
slots:
hostname: query.hostname
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/serverless'].get
update:
x-apievangelist-phrasing:
intent: List WAAS serverless audit events (v34.03)
effect: read
questions:
- Which attacks on my serverless functions did WAAS log in v34.03?
- Can I filter v34.03 WAAS serverless audits by function or runtime?
instructions:
- text: List v34.03 WAAS serverless audit events for function {function}.
slots:
function: query.function
- text: Show v34.03 WAAS serverless audits on runtime {runtime}.
slots:
runtime: query.runtime
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/serverless/download'].get
update:
x-apievangelist-phrasing:
intent: Download WAAS serverless audit events (v34.03)
effect: read
questions:
- Can I get a v34.03 downloadable file of firewall events for my serverless functions?
- Is there a v34.03 download of WAAS serverless events for one function?
instructions:
- text: Download v34.03 WAAS serverless audits for function {function}.
slots:
function: query.function
- text: Export the v34.03 WAAS serverless audit file from {from} to {to}.
slots:
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/app/serverless/timeslice'].get
update:
x-apievangelist-phrasing:
intent: Chart WAAS serverless audits over time (v34.03)
effect: read
questions:
- How are WAAS serverless audit events spread over a timeframe in v34.03?
- Can I bucket v34.03 WAAS serverless events by time for a trend view?
instructions:
- text: Bucket v34.03 WAAS serverless audits from {from} to {to} into {buckets} slices.
slots:
from: query.from
to: query.to
buckets: query.buckets
- text: Get the v34.03 WAAS serverless audit timeline for function {function}.
slots:
function: query.function
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/network/container'].get
update:
x-apievangelist-phrasing:
intent: List CNNS container network audits (v34.03)
effect: read
questions:
- Which container-to-container connections did cloud native network security flag in v34.03?
- Can I see only blocked v34.03 CNNS container connections between two images?
instructions:
- text: List v34.03 CNNS container audits from image {srcImageName} to image {dstImageName}.
slots:
srcImageName: query.srcImageName
dstImageName: query.dstImageName
- text: Show v34.03 CNNS container network audits with block filter {block}.
slots:
block: query.block
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/network/container/download'].get
update:
x-apievangelist-phrasing:
intent: Download CNNS container network audits (v34.03)
effect: read
questions:
- Can I export CNNS container network audits as a file in v34.03?
- Is there a v34.03 download of container network audits for one source image?
instructions:
- text: Download v34.03 CNNS container audits for source image {srcImageName}.
slots:
srcImageName: query.srcImageName
- text: Export the v34.03 CNNS container audit file from {from} to {to}.
slots:
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/network/host'].get
update:
x-apievangelist-phrasing:
intent: List CNNS host network audits (v34.03)
effect: read
questions:
- Which host-to-host connections did CNNS audit in v34.03?
- Can I filter v34.03 CNNS host audits by source and destination hostnames?
instructions:
- text: List v34.03 CNNS host audits from {srcHostnames} to {dstHostnames}.
slots:
srcHostnames: query.srcHostnames
dstHostnames: query.dstHostnames
- text: Show v34.03 CNNS host network audits since {from}.
slots:
from: query.from
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/firewall/network/host/download'].get
update:
x-apievangelist-phrasing:
intent: Download CNNS host network audits (v34.03)
effect: read
questions:
- Can I download CNNS host network audits as a file in v34.03?
- Is there a v34.03 export of host network audits for specific source hosts?
instructions:
- text: Download v34.03 CNNS host audits for source hosts {srcHostnames}.
slots:
srcHostnames: query.srcHostnames
- text: Export the v34.03 CNNS host audit file between {from} and {to}.
slots:
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/incidents'].get
update:
x-apievangelist-phrasing:
intent: List incident audit events (v34.03)
effect: read
questions:
- What security incidents has Prisma Cloud Compute recorded, per the v34.03 API?
- Can I list only unacknowledged v34.03 incidents in one category?
instructions:
- text: List v34.03 incidents in category {category} on host {hostname}.
slots:
category: query.category
hostname: query.hostname
- text: Show v34.03 incident audits with acknowledged set to {acknowledged}.
slots:
acknowledged: query.acknowledged
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/incidents/acknowledge/{id}'].patch
update:
x-apievangelist-phrasing:
intent: Archive an incident (v34.03)
effect: write
questions:
- How do I acknowledge and archive an incident through the v34.03 API?
- Can I mark a v34.03 incident as acknowledged so it leaves the active list?
instructions:
- text: Archive incident {id} using the v34.03 API.
slots:
id: path.id
- text: Set acknowledged to {acknowledged} on v34.03 incident {id}.
slots:
acknowledged: requestBody.acknowledged
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/incidents/download'].get
update:
x-apievangelist-phrasing:
intent: Download incident audit events (v34.03)
effect: read
questions:
- Can I export incident audits to a file with the v34.03 API?
- Is there a v34.03 download of incidents for one cluster?
instructions:
- text: Download v34.03 incident audits for cluster {cluster}.
slots:
cluster: query.cluster
- text: Export the v34.03 incident file from {from} to {to}.
slots:
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/kubernetes'].get
update:
x-apievangelist-phrasing:
intent: List Kubernetes audit events (v34.03)
effect: read
questions:
- Which Kubernetes API activity was flagged in the v34.03 audits?
- Can I filter v34.03 Kubernetes audits by user or cluster?
instructions:
- text: List v34.03 Kubernetes audit events for user {user}.
slots:
user: query.user
- text: Show v34.03 Kubernetes audits on cluster {cluster} since {from}.
slots:
cluster: query.cluster
from: query.from
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/kubernetes/download'].get
update:
x-apievangelist-phrasing:
intent: Download Kubernetes audit events (v34.03)
effect: read
questions:
- Can I download Kubernetes audit events as a file in v34.03?
- Is there a v34.03 export of Kubernetes audits for one cluster?
instructions:
- text: Download v34.03 Kubernetes audits for cluster {cluster}.
slots:
cluster: query.cluster
- text: Export the v34.03 Kubernetes audit file from {from} to {to}.
slots:
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/mgmt'].get
update:
x-apievangelist-phrasing:
intent: List management audit events (v34.03)
effect: read
questions:
- Who changed settings in the Console, according to the v34.03 management audits?
- Can I see v34.03 management audit events for one admin username?
instructions:
- text: List v34.03 management audit events by user {username}.
slots:
username: query.username
- text: Show v34.03 management audits of type {type} between {from} and {to}.
slots:
type: query.type
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/mgmt/download'].get
update:
x-apievangelist-phrasing:
intent: Download management audit events (v34.03)
effect: read
questions:
- Can I export Console management audits to a file in v34.03?
- Is there a v34.03 download of admin activity for one username?
instructions:
- text: Download v34.03 management audits for user {username}.
slots:
username: query.username
- text: Export the v34.03 management audit file from {from} to {to}.
slots:
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/mgmt/filters'].get
update:
x-apievangelist-phrasing:
intent: Get management audit filter values (v34.03)
effect: read
questions:
- What filter values can I use when searching management audits in v34.03?
- Which usernames and audit types appear as v34.03 management audit filters?
instructions:
- text: Get the v34.03 management audit filter options.
- text: Show the v34.03 management audit filters available for type {type}.
slots:
type: query.type
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/app-embedded'].get
update:
x-apievangelist-phrasing:
intent: List runtime app-embedded audit events (v34.03)
effect: read
questions:
- What runtime alerts did app-embedded defenders raise in v34.03?
- Can I filter v34.03 app-embedded runtime audits by attack type or process path?
instructions:
- text: List v34.03 runtime app-embedded audits for app {appID}.
slots:
appID: query.appID
- text: Show v34.03 app-embedded runtime audits with attack type {attackType}.
slots:
attackType: query.attackType
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/app-embedded/download'].get
update:
x-apievangelist-phrasing:
intent: Download runtime app-embedded audits (v34.03)
effect: read
questions:
- Can I grab a v34.03 file of runtime (not WAAS) alerts from app-embedded defenders?
- Is there a v34.03 export of runtime app-embedded events for one app?
instructions:
- text: Download v34.03 runtime app-embedded audits for app {appID}.
slots:
appID: query.appID
- text: Export the v34.03 runtime app-embedded audit file from {from} to {to}.
slots:
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/container'].get
update:
x-apievangelist-phrasing:
intent: List runtime container audit events (v34.03)
effect: read
questions:
- What suspicious process, network or file activity did runtime defense see in containers in v34.03?
- Can I filter v34.03 container runtime audits by image and namespace?
instructions:
- text: List v34.03 runtime container audits for image {imageName} in namespace {namespace}.
slots:
imageName: query.imageName
namespace: query.namespace
- text: Show v34.03 container runtime audits for container {container}.
slots:
container: query.container
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/container/download'].get
update:
x-apievangelist-phrasing:
intent: Download runtime container audits (v34.03)
effect: read
questions:
- Can I export container runtime audits to a file in v34.03?
- Is there a v34.03 download of runtime container events for one image?
instructions:
- text: Download v34.03 runtime container audits for image {imageName}.
slots:
imageName: query.imageName
- text: Export the v34.03 runtime container audit file between {from} and {to}.
slots:
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/container/timeslice'].get
update:
x-apievangelist-phrasing:
intent: Chart runtime container audits over time (v34.03)
effect: read
questions:
- How did container runtime audit volume trend across a timeframe in v34.03?
- Can I bucket v34.03 runtime container events into time slices?
instructions:
- text: Bucket v34.03 runtime container audits from {from} to {to} into {buckets} slices.
slots:
from: query.from
to: query.to
buckets: query.buckets
- text: Get the v34.03 runtime container audit timeline for image {imageName}.
slots:
imageName: query.imageName
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/file-integrity'].get
update:
x-apievangelist-phrasing:
intent: List file integrity audit events (v34.03)
effect: read
questions:
- Which monitored files were changed on my hosts, per v34.03 file integrity audits?
- Can I filter v34.03 file integrity events by path or event type?
instructions:
- text: List v34.03 file integrity audits on host {hostname} for path {path}.
slots:
hostname: query.hostname
path: query.path
- text: Show v34.03 file integrity events of type {eventType}.
slots:
eventType: query.eventType
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/file-integrity/download'].get
update:
x-apievangelist-phrasing:
intent: Download file integrity audit events (v34.03)
effect: read
questions:
- Can I download file integrity monitoring audits as a file in v34.03?
- Is there a v34.03 export of file integrity events for one host?
instructions:
- text: Download v34.03 file integrity audits for host {hostname}.
slots:
hostname: query.hostname
- text: Export the v34.03 file integrity audit file from {from} to {to}.
slots:
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/host'].get
update:
x-apievangelist-phrasing:
intent: List runtime host audit events (v34.03)
effect: read
questions:
- What runtime alerts did host defenders raise in the v34.03 audits?
- Can I filter v34.03 host runtime audits by user or process path?
instructions:
- text: List v34.03 runtime host audits on host {hostname}.
slots:
hostname: query.hostname
- text: Show v34.03 host runtime audits for process path {processPath} run by {user}.
slots:
processPath: query.processPath
user: query.user
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/host/download'].get
update:
x-apievangelist-phrasing:
intent: Download runtime host audits (v34.03)
effect: read
questions:
- Can I export host runtime audits to a file in v34.03?
- Is there a v34.03 download of runtime host events for one hostname?
instructions:
- text: Download v34.03 runtime host audits for host {hostname}.
slots:
hostname: query.hostname
- text: Export the v34.03 runtime host audit file from {from} to {to}.
slots:
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/host/timeslice'].get
update:
x-apievangelist-phrasing:
intent: Chart runtime host audits over time (v34.03)
effect: read
questions:
- How are host runtime audit events distributed over time in v34.03?
- Can I get v34.03 runtime host audit counts per time bucket?
instructions:
- text: Bucket v34.03 runtime host audits from {from} to {to} into {buckets} slices.
slots:
from: query.from
to: query.to
buckets: query.buckets
- text: Get the v34.03 runtime host audit timeline for host {hostname}.
slots:
hostname: query.hostname
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/log-inspection'].get
update:
x-apievangelist-phrasing:
intent: List log inspection audit events (v34.03)
effect: read
questions:
- Which log inspection rules matched lines in my host logs, per v34.03?
- Can I filter v34.03 log inspection audits by log file?
instructions:
- text: List v34.03 log inspection audits for log file {logfile}.
slots:
logfile: query.logfile
- text: Show v34.03 log inspection events on host {hostname}.
slots:
hostname: query.hostname
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/log-inspection/download'].get
update:
x-apievangelist-phrasing:
intent: Download log inspection audit events (v34.03)
effect: read
questions:
- Can I download log inspection audits as a file in v34.03?
- Is there a v34.03 export of log inspection events for one host?
instructions:
- text: Download v34.03 log inspection audits for host {hostname}.
slots:
hostname: query.hostname
- text: Export the v34.03 log inspection audit file from {from} to {to}.
slots:
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/serverless'].get
update:
x-apievangelist-phrasing:
intent: List runtime serverless audit events (v34.03)
effect: read
questions:
- What runtime alerts fired for my serverless functions in v34.03?
- Can I filter v34.03 serverless runtime audits by function and effect?
instructions:
- text: List v34.03 runtime serverless audits for function {function}.
slots:
function: query.function
- text: Show v34.03 serverless runtime audits with effect {effect} on runtime {runtime}.
slots:
effect: query.effect
runtime: query.runtime
method: generated
generated: '2026-09-26'
- target: $.paths['/api/v34.03/audits/runtime/serverless/download'].get
update:
x-apievangelist-phrasing:
intent: Download runtime serverless audits (v34.03)
effect: read
questions:
- Can I export serverless runtime audits to a file in v34.03?
- Is there a v34.03 file export of runtime defense alerts for one serverless function?
instructions:
- text: Download v34.03 runtime serverless audits for function {function}.
slots:
function: query.function
- text: Export the v34.03 runtime serverless audit file from {from} to {to}.
slots:
from: query.from
to: query.to
method: generated
generated: '2026-09-26'
# --- truncated at 32 KB (66 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/overlays/palo-alto-networks-audits-api-phrasing-overlay.yaml