Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Prisma Cloud REST API Doc AWS Logging Accounts API
18 actions
18 updates
phrasing
extends
openapi/palo-alto-networks-aws-logging-accounts-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 18 · first 16 shown; the file carries all of them
$.info
$.paths['/v1/cloudAccounts/awsLoggingAccounts'].get
$.paths['/v1/cloudAccounts/awsLoggingAccounts'].post
$.paths['/v1/cloudAccounts/awsLoggingAccounts/cft'].post
$.paths['/v1/cloudAccounts/awsLoggingAccounts/permissionsStatus'].post
$.paths['/v1/cloudAccounts/awsLoggingAccounts/{accountId}'].get
$.paths['/v1/cloudAccounts/awsLoggingAccounts/{accountId}/buckets/{bucketName}'].delete
$.paths['/v1/cloudAccounts/awsLoggingAccounts/{accountId}/cft'].get
$.paths['/v1/cloudAccounts/awsLoggingAccounts/{accountId}/cft'].post
$.paths['/v1/cloudAccounts/awsLoggingAccounts/{accountId}/role/{roleName}/externalId'].get
$.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}'].put
$.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}'].delete
$.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}/buckets'].get
$.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}/buckets'].post
$.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}/buckets/{bucketName}'].get
$.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}/buckets/{bucketName}'].put
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Prisma Cloud REST API Doc AWS Logging Accounts API
version: 1.0.0
extends: openapi/palo-alto-networks-aws-logging-accounts-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 17
- target: $.paths['/v1/cloudAccounts/awsLoggingAccounts'].get
update:
x-apievangelist-phrasing:
intent: List all AWS logging accounts
effect: read
questions:
- Which AWS logging accounts are onboarded to Prisma Cloud?
- Can I list logging accounts only for one AWS partition such as GovCloud?
instructions:
- text: List all AWS logging accounts in partition {awsPartition}.
slots:
awsPartition: query.awsPartition
- text: Show every onboarded AWS logging account and its details.
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/cloudAccounts/awsLoggingAccounts'].post
update:
x-apievangelist-phrasing:
intent: Add a new AWS logging account
effect: write
questions:
- How do I onboard a new AWS logging account with its role and S3 buckets?
- What role ARN and external ID are needed to register a logging account?
instructions:
- text: Add AWS logging account {loggingAccountId} named {loggingAccountName} using role ARN {loggingAccountRoleArn}.
slots:
loggingAccountId: requestBody.loggingAccountId
loggingAccountName: requestBody.loggingAccountName
loggingAccountRoleArn: requestBody.loggingAccountRoleArn
- text: Register logging account {loggingAccountId} with role {loggingAccountRoleName}, external ID {externalId} and buckets {loggingAccountBuckets}.
slots:
loggingAccountId: requestBody.loggingAccountId
loggingAccountRoleName: requestBody.loggingAccountRoleName
externalId: requestBody.externalId
loggingAccountBuckets: requestBody.loggingAccountBuckets
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/cft'].post
update:
x-apievangelist-phrasing:
intent: Generate a CloudFormation template for a new logging account
effect: write
questions:
- Can Prisma Cloud generate the CloudFormation template I need before onboarding a logging account?
- How do I get a CFT that creates the role for a logging account I haven't added yet?
instructions:
- text: Generate a CFT for new AWS logging account {loggingAccountId} with role name {loggingAccountRoleName}.
slots:
loggingAccountId: requestBody.loggingAccountId
loggingAccountRoleName: requestBody.loggingAccountRoleName
- text: Create a CloudFormation template for a logging account in partition {awsPartition} covering buckets {loggingAccountBuckets}.
slots:
awsPartition: requestBody.awsPartition
loggingAccountBuckets: requestBody.loggingAccountBuckets
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/permissionsStatus'].post
update:
x-apievangelist-phrasing:
intent: Check permissions status for logging account details
effect: read
questions:
- Before saving, can I check whether a logging account's role and buckets have the right permissions?
- What permission status would an AWS logging account get with a given role ARN and bucket list?
instructions:
- text: Check permission status for unsaved logging account {loggingAccountId} using role ARN {loggingAccountRoleArn}.
slots:
loggingAccountId: requestBody.loggingAccountId
loggingAccountRoleArn: requestBody.loggingAccountRoleArn
- text: Validate the permissions of logging account details {loggingAccountName} with buckets {loggingAccountBuckets} before onboarding.
slots:
loggingAccountName: requestBody.loggingAccountName
loggingAccountBuckets: requestBody.loggingAccountBuckets
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{accountId}'].get
update:
x-apievangelist-phrasing:
intent: Get one AWS logging account
effect: read
questions:
- How do I see the details of a single AWS logging account?
- What role and buckets are configured on a specific logging account?
instructions:
- text: Get the details of AWS logging account {accountId}.
slots:
accountId: path.accountId
- text: Show me the configuration of logging account {accountId}.
slots:
accountId: path.accountId
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{accountId}/buckets/{bucketName}'].delete
update:
x-apievangelist-phrasing:
intent: Remove an S3 bucket from a logging account
effect: destructive
questions:
- Can I detach one S3 bucket from a logging account without deleting the account?
- How do I stop Prisma Cloud from reading logs out of a particular bucket?
instructions:
- text: Delete S3 bucket {bucketName} from logging account {accountId}.
slots:
bucketName: path.bucketName
accountId: path.accountId
- text: Remove bucket {bucketName} from AWS logging account {accountId}.
slots:
bucketName: path.bucketName
accountId: path.accountId
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{accountId}/cft'].get
update:
x-apievangelist-phrasing:
intent: Regenerate the CFT for an existing logging account
effect: read
questions:
- Can I download a fresh CloudFormation template for a logging account that's already onboarded?
- Where do I get the current CFT for an existing logging account?
instructions:
- text: Regenerate the CloudFormation template for existing logging account {accountId}.
slots:
accountId: path.accountId
- text: Get the current CFT for AWS logging account {accountId}.
slots:
accountId: path.accountId
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{accountId}/cft'].post
update:
x-apievangelist-phrasing:
intent: Regenerate a logging account CFT after a role name change
effect: write
questions:
- I renamed the IAM role on my logging account; how do I get an updated CFT?
- Can I regenerate a CloudFormation template for an existing account with a new role name?
instructions:
- text: Regenerate the CFT for logging account {accountId} with new role name {loggingAccountRoleName}.
slots:
accountId: path.accountId
loggingAccountRoleName: requestBody.loggingAccountRoleName
- text: Build a new CloudFormation template for account {accountId} because its role changed to {loggingAccountRoleName}.
slots:
accountId: path.accountId
loggingAccountRoleName: requestBody.loggingAccountRoleName
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{accountId}/role/{roleName}/externalId'].get
update:
x-apievangelist-phrasing:
intent: Get the external ID for a logging account role
effect: read
questions:
- What external ID should the trust policy use for my logging account role?
- How do I look up the external ID for a given account and role name?
instructions:
- text: Get the external ID for logging account {accountId} and role {roleName}.
slots:
accountId: path.accountId
roleName: path.roleName
- text: Show the external ID tied to role {roleName} on AWS account {accountId}.
slots:
roleName: path.roleName
accountId: path.accountId
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}'].put
update:
x-apievangelist-phrasing:
intent: Update an AWS logging account
effect: write
questions:
- Can I rename a logging account or change its role ARN?
- How do I update the bucket list on an onboarded logging account?
instructions:
- text: Rename logging account {loggingAccountId} to {loggingAccountName}.
slots:
loggingAccountId: path.loggingAccountId
loggingAccountName: requestBody.loggingAccountName
- text: Update logging account {loggingAccountId} to use role ARN {loggingAccountRoleArn}.
slots:
loggingAccountId: path.loggingAccountId
loggingAccountRoleArn: requestBody.loggingAccountRoleArn
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}'].delete
update:
x-apievangelist-phrasing:
intent: Delete an AWS logging account
effect: destructive
questions:
- How do I offboard an AWS logging account entirely?
- What gets removed when a logging account is deleted from Prisma Cloud?
instructions:
- text: Delete AWS logging account {loggingAccountId}.
slots:
loggingAccountId: path.loggingAccountId
- text: Offboard logging account {loggingAccountId} from Prisma Cloud.
slots:
loggingAccountId: path.loggingAccountId
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}/buckets'].get
update:
x-apievangelist-phrasing:
intent: List S3 bucket names on a logging account
effect: read
questions:
- Which S3 buckets are attached to my logging account?
- Can I get just the bucket names for a logging account?
instructions:
- text: List the S3 bucket names on logging account {loggingAccountId}.
slots:
loggingAccountId: path.loggingAccountId
- text: Show which buckets logging account {loggingAccountId} reads from.
slots:
loggingAccountId: path.loggingAccountId
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}/buckets'].post
update:
x-apievangelist-phrasing:
intent: Add an S3 bucket to a logging account
effect: write
questions:
- How do I attach another S3 bucket to an existing logging account?
- Can I set path prefixes and a KMS key when adding a bucket?
instructions:
- text: Add S3 bucket {bucketName} in region {bucketRegion} to logging account {loggingAccountId}.
slots:
bucketName: requestBody.bucketName
bucketRegion: requestBody.bucketRegion
loggingAccountId: path.loggingAccountId
- text: Attach bucket {bucketName} with KMS key {keyArn} to logging account {loggingAccountId}.
slots:
bucketName: requestBody.bucketName
keyArn: requestBody.keyArn
loggingAccountId: path.loggingAccountId
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}/buckets/{bucketName}'].get
update:
x-apievangelist-phrasing:
intent: Get S3 bucket details on a logging account
effect: read
questions:
- What region, prefixes and key are configured for a specific bucket on my logging account?
- Can I inspect one bucket's settings within a logging account?
instructions:
- text: Get details of bucket {bucketName} on logging account {loggingAccountId}.
slots:
bucketName: path.bucketName
loggingAccountId: path.loggingAccountId
- text: Show the region and path prefixes for bucket {bucketName} in account {loggingAccountId}.
slots:
bucketName: path.bucketName
loggingAccountId: path.loggingAccountId
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}/buckets/{bucketName}'].put
update:
x-apievangelist-phrasing:
intent: Update an S3 bucket on a logging account
effect: write
questions:
- How do I change the path prefixes on a bucket already attached to a logging account?
- Can I swap the KMS key used for a logging bucket?
instructions:
- text: Set path prefixes {bucketPathPrefixes} on bucket {bucketName} in logging account {loggingAccountId}.
slots:
bucketPathPrefixes: requestBody.bucketPathPrefixes
bucketName: path.bucketName
loggingAccountId: path.loggingAccountId
- text: Change the KMS key of bucket {bucketName} on account {loggingAccountId} to {keyArn}.
slots:
bucketName: path.bucketName
loggingAccountId: path.loggingAccountId
keyArn: requestBody.keyArn
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}/permissionsStatus'].get
update:
x-apievangelist-phrasing:
intent: Get the permissions status of a saved logging account
effect: read
questions:
- Is my onboarded logging account healthy, or is it missing permissions?
- What is the current status of a saved logging account by its ID?
instructions:
- text: Get the permissions status of logging account {loggingAccountId}.
slots:
loggingAccountId: path.loggingAccountId
- text: Check whether saved logging account {loggingAccountId} is healthy.
slots:
loggingAccountId: path.loggingAccountId
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}/permissionsStatus'].post
update:
x-apievangelist-phrasing:
intent: Check a saved logging account's status with new details
effect: read
questions:
- Can I test an existing logging account's permissions against a different role or bucket?
- What detailed status would my saved logging account have with a changed role ARN?
instructions:
- text: Check detailed status of existing logging account {loggingAccountId} against role ARN {loggingAccountRoleArn}.
slots:
loggingAccountId: path.loggingAccountId
loggingAccountRoleArn: requestBody.loggingAccountRoleArn
- text: Test saved account {loggingAccountId} permissions using buckets {loggingAccountBuckets}.
slots:
loggingAccountId: path.loggingAccountId
loggingAccountBuckets: requestBody.loggingAccountBuckets
method: generated
generated: '2026-09-26'