Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for OpenAPI definition Discovery and Exposure Management API
27 actions
27 updates
phrasing
extends
openapi/palo-alto-networks-discovery-and-exposure-management-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 27 · first 16 shown; the file carries all of them
$.info
$.paths['/asm/api/v1/convert-cloud-account'].post
$.paths['/asm/api/v1/asset'].post
$.paths['/asm/api/v1/asset/{asset_id}/finding'].post
$.paths['/asm/api/v1/asset/{asset_id}/finding/filters'].post
$.paths['/asm/api/v1/asset/snooze'].post
$.paths['/asm/api/v1/asset/reopen'].post
$.paths['/asm/api/v1/asset/email'].post
$.paths['/asm/api/v1/asset/download'].post
$.paths['/asm/api/v1/asset/aggregation-by-resource-type'].post
$.paths['/asm/api/v1/asset/aggregation-by-cloud-type'].post
$.paths['/asm/api/v1/service'].get
$.paths['/asm/api/v1/service/{serviceId}'].get
$.paths['/asm/api/v1/industry-benchmarks'].get
$.paths['/asm/api/v1/dashboard/convertible-accounts'].get
$.paths['/asm/api/v1/dashboard/asset'].get
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for OpenAPI definition Discovery and Exposure Management API
version: 1.0.0
extends: openapi/palo-alto-networks-discovery-and-exposure-management-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 26
- target: $.paths['/asm/api/v1/convert-cloud-account'].post
update:
x-apievangelist-phrasing:
intent: Onboard unmanaged cloud accounts to CSPM
effect: write
questions:
- How do I bring cloud accounts found by exposure discovery under CSPM protection?
- Can I convert several unmanaged cloud accounts to managed ones in one request?
instructions:
- text: Onboard cloud accounts {cloudAccounts} to CSPM so their unmanaged assets get secured.
slots:
cloudAccounts: requestBody.cloudAccounts
- text: Convert the unmanaged cloud accounts from the exposure dashboard into CSPM-managed accounts.
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/asset'].post
update:
x-apievangelist-phrasing:
intent: List discovered assets with filters
effect: read
questions:
- Which internet-exposed assets were discovered in my AWS and Azure clouds?
- Can I filter the discovered asset inventory by managed versus unmanaged and service type?
- What assets match a search text in the exposure management inventory?
instructions:
- text: List discovered assets of cloud type {cloudTypes} and asset type {assetTypes}.
slots:
cloudTypes: requestBody.cloudTypes
assetTypes: requestBody.assetTypes
- text: Search the asset inventory for {searchText} as of snapshot {snapshotDate}.
slots:
searchText: requestBody.searchText
snapshotDate: requestBody.snapshotDate
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/asset/{asset_id}/finding'].post
update:
x-apievangelist-phrasing:
intent: Get security findings for an asset
effect: read
questions:
- What security findings and vulnerabilities were discovered on a specific asset?
- Can I narrow an asset's findings to only critical and high severities?
instructions:
- text: Show the security findings for asset {asset_id}.
slots:
asset_id: path.asset_id
- text: List findings on asset {asset_id} with severity {severities}.
slots:
asset_id: path.asset_id
severities: requestBody.severities
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/asset/{asset_id}/finding/filters'].post
update:
x-apievangelist-phrasing:
intent: Get the filter values for an asset's findings
effect: read
questions:
- Which finding types and severities can I filter on for a particular asset?
- What filter values are available before I pull an asset's findings?
instructions:
- text: Get the available finding filters and their values for asset {asset_id}.
slots:
asset_id: path.asset_id
- text: Show which finding filter options exist for asset {asset_id} on snapshot {snapshotDate}.
slots:
asset_id: path.asset_id
snapshotDate: requestBody.snapshotDate
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/asset/snooze'].post
update:
x-apievangelist-phrasing:
intent: Snooze notifications for unmanaged assets
effect: write
questions:
- How do I silence alerts from unmanaged internet-exposed assets for a while?
- Can I snooze every asset matching a regex pattern permanently?
instructions:
- text: Snooze notifications for unmanaged assets {assets} because {reason}.
slots:
assets: requestBody.assets
reason: requestBody.reason
- text: Snooze all unmanaged assets matching regex {regex} for time range {snoozeTimeRange}.
slots:
regex: requestBody.regex
snoozeTimeRange: requestBody.snoozeTimeRange
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/asset/reopen'].post
update:
x-apievangelist-phrasing:
intent: Unsnooze snoozed unmanaged assets
effect: write
questions:
- How do I turn notifications back on for assets I previously snoozed?
- Can I reopen snoozed assets that match a regex pattern?
instructions:
- text: Unsnooze the snoozed assets {assets}.
slots:
assets: requestBody.assets
- text: Reopen every snoozed asset matching regex {regex}.
slots:
regex: requestBody.regex
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/asset/email'].post
update:
x-apievangelist-phrasing:
intent: Email asset details to colleagues
effect: write
questions:
- Can I email the details of an exposed asset to my team?
- How do I share an unmanaged asset's details by email with a comment?
instructions:
- text: Email the details of asset {asmAssetId} to {userEmailIds}.
slots:
asmAssetId: requestBody.asmAssetId
userEmailIds: requestBody.userEmailIds
- text: Send asset {name} details to {userEmailIds} with the note {comment}.
slots:
name: requestBody.name
userEmailIds: requestBody.userEmailIds
comment: requestBody.comment
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/asset/download'].post
update:
x-apievangelist-phrasing:
intent: Download a filtered list of unmanaged assets
effect: read
questions:
- Can I export the list of unmanaged assets to a file?
- How do I download only the unmanaged assets from one cloud provider?
instructions:
- text: Download the unmanaged asset list for cloud type {cloudTypes}.
slots:
cloudTypes: requestBody.cloudTypes
- text: Export unmanaged assets of service type {serviceTypes} as of {snapshotDate}.
slots:
serviceTypes: requestBody.serviceTypes
snapshotDate: requestBody.snapshotDate
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/asset/aggregation-by-resource-type'].post
update:
x-apievangelist-phrasing:
intent: Count assets grouped by asset type
effect: read
questions:
- How many discovered assets do I have of each asset type?
- What is the breakdown of asset counts per resource type for one cloud?
instructions:
- text: Count assets by asset type for cloud type {cloudTypes}.
slots:
cloudTypes: requestBody.cloudTypes
- text: Give me the per-asset-type asset totals for manage type {manageType}.
slots:
manageType: requestBody.manageType
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/asset/aggregation-by-cloud-type'].post
update:
x-apievangelist-phrasing:
intent: Count assets grouped by cloud provider
effect: read
questions:
- How many discovered assets sit in each cloud service provider?
- Which cloud provider holds the most unmanaged assets?
instructions:
- text: Count assets per cloud provider for snapshot {snapshotDate}.
slots:
snapshotDate: requestBody.snapshotDate
- text: Break down asset totals by cloud provider for manage type {manageType}.
slots:
manageType: requestBody.manageType
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/service'].get
update:
x-apievangelist-phrasing:
intent: List discovered exposed services
effect: read
questions:
- What exposed services has attack surface discovery found across my environment?
- Can I list discovered services as of a past snapshot date?
instructions:
- text: List all discovered services.
- text: List discovered services for snapshot date {snapshot_date}.
slots:
snapshot_date: query.snapshot_date
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/service/{serviceId}'].get
update:
x-apievangelist-phrasing:
intent: Get details of a discovered service
effect: read
questions:
- What are the details of one specific discovered service?
- Can I get the full detail record for a service by its id?
instructions:
- text: Show details for service {serviceId}.
slots:
serviceId: path.serviceId
- text: Get service {serviceId} as it looked on {snapshot_date}.
slots:
serviceId: path.serviceId
snapshot_date: query.snapshot_date
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/industry-benchmarks'].get
update:
x-apievangelist-phrasing:
intent: Get industry benchmark data
effect: read
questions:
- How does my exposure compare against industry benchmark data?
- What industry benchmarks does Palo Alto Networks use to judge vulnerability risk?
instructions:
- text: Fetch the industry benchmark data for exposure risk.
- text: Show me the industry benchmarks used to score security risks.
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/dashboard/convertible-accounts'].get
update:
x-apievangelist-phrasing:
intent: List cloud accounts that can be onboarded to CSPM
effect: read
questions:
- Which cloud accounts are not yet managed by CSPM but could be onboarded?
- Can I filter convertible cloud accounts by country?
instructions:
- text: List cloud accounts eligible for CSPM onboarding.
- text: Show convertible cloud accounts in country {country_code} with alert category {alert_categories}.
slots:
country_code: query.country_code
alert_categories: query.alert_categories
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/dashboard/asset'].get
update:
x-apievangelist-phrasing:
intent: List unmanaged assets that can be onboarded
effect: read
questions:
- Which unmanaged assets could I bring under CSPM management?
- What convertible assets belong to one particular cloud account?
instructions:
- text: List convertible unmanaged assets in cloud account {cloud_account_id}.
slots:
cloud_account_id: query.cloud_account_id
- text: Show onboardable assets located in country {country_code}.
slots:
country_code: query.country_code
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/dashboard/asset/trend'].get
update:
x-apievangelist-phrasing:
intent: Get the 90-day managed versus unmanaged asset trend
effect: read
questions:
- How have my managed, unmanaged and remediated asset counts trended over 90 days?
- Is the number of unmanaged assets going down over the last quarter?
instructions:
- text: Show the 90-day asset trend ending at {timestamp}.
slots:
timestamp: query.timestamp
- text: Chart managed versus remediated assets over the last 90 days from {timestamp}.
slots:
timestamp: query.timestamp
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/dashboard/asset/top-risk'].get
update:
x-apievangelist-phrasing:
intent: Get the top risks across assets
effect: read
questions:
- What are the biggest risks across my discovered assets right now?
- Which asset risks rank highest on the exposure dashboard?
instructions:
- text: List the top asset risks.
- text: Show me the highest-ranked risks from the asset dashboard.
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/dashboard/asset/internet-exposure-risk'].get
update:
x-apievangelist-phrasing:
intent: Get internet exposure risk by asset type
effect: read
questions:
- How is internet exposure risk distributed across asset types in the last day?
- Which asset types carried the most internet exposure risk over the past 24 hours?
instructions:
- text: Show the internet exposure risk distribution per asset type for the last 24 hours.
- text: Get today's internet exposure risk statistics for every asset type.
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/dashboard/asset/geolocation'].get
update:
x-apievangelist-phrasing:
intent: Count assets by geographic location
effect: read
questions:
- Where in the world are my discovered assets located?
- How many assets do I have in each geographic location?
instructions:
- text: Count my assets by geolocation.
- text: Show the asset distribution across locations on a map.
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/dashboard/asset/count'].get
update:
x-apievangelist-phrasing:
intent: Count assets that can be onboarded
effect: read
questions:
- How many unmanaged assets are convertible to CSPM in total?
- What is the total number of onboardable assets?
instructions:
- text: Get the total count of convertible assets.
- text: Tell me how many assets are ready to onboard to CSPM.
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/asset/{asset_id}/vulnerability'].get
update:
x-apievangelist-phrasing:
intent: List vulnerabilities in an asset
effect: read
questions:
- What vulnerabilities exist in one asset on a given snapshot date?
- Can I see the CVEs behind the top risks widget for an unmanaged asset?
instructions:
- text: List vulnerabilities in asset {asset_id} on {snapshot_date}.
slots:
asset_id: path.asset_id
snapshot_date: query.snapshot_date
- text: Show vulnerabilities for {manage_type} asset {asset_id} as of {snapshot_date}.
slots:
manage_type: query.manage_type
asset_id: path.asset_id
snapshot_date: query.snapshot_date
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/asset/{assetId}/flowlog-relationships'].get
update:
x-apievangelist-phrasing:
intent: Get traffic flows between unmanaged and managed assets
effect: read
questions:
- Is an internet-exposed unmanaged asset talking to any of my secured assets?
- Can I see flow log traffic between an unmanaged asset and managed ones?
instructions:
- text: Show flow log relationships for unmanaged asset {assetId}.
slots:
assetId: path.assetId
- text: Get traffic flows for asset {assetId} on {snapshot_date}.
slots:
assetId: path.assetId
snapshot_date: query.snapshot_date
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/asset/{asmAssetId}/service'].get
update:
x-apievangelist-phrasing:
intent: List services running on an asset
effect: read
questions:
- Which services are linked to a specific discovered asset?
- What exposed services does one asset run on a given snapshot?
instructions:
- text: List services for asset {asmAssetId} on {snapshot_date}.
slots:
asmAssetId: path.asmAssetId
snapshot_date: query.snapshot_date
- text: Show what services asset {asmAssetId} exposed as of {snapshot_date}.
slots:
asmAssetId: path.asmAssetId
snapshot_date: query.snapshot_date
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/asset/vulnerability'].get
update:
x-apievangelist-phrasing:
intent: Find distros and packages affected by a CVE
effect: read
questions:
- Which Linux distributions and packages are impacted by a given CVE?
- Can I look up affected distros for a vulnerability by its CVE ID?
instructions:
- text: List distros and packages impacted by {cve_id}.
slots:
cve_id: query.cve_id
- text: Look up which distributions are affected by vulnerability {cve_id}.
slots:
cve_id: query.cve_id
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/asset/snoozed-regex'].get
update:
x-apievangelist-phrasing:
intent: List regex patterns used to snooze assets
effect: read
questions:
- What regex patterns are currently being used to snooze assets?
- Which snooze patterns did we set up for unmanaged assets?
instructions:
- text: List the regex patterns used for snoozing assets.
- text: Show all asset snooze regex patterns.
method: generated
generated: '2026-09-26'
- target: $.paths['/asm/api/v1/asset/filters'].get
update:
x-apievangelist-phrasing:
intent: List supported asset filters and values
effect: read
questions:
- Which filters and values can I use when querying the asset inventory?
- What cloud types and asset types are valid asset filter values?
instructions:
- text: List the supported asset filters and their values.
- text: Show the filter options I can pass to the asset list endpoints.
method: generated
generated: '2026-09-26'