Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for public dlp DLP API
11 actions
11 updates
phrasing
extends
openapi/palo-alto-networks-dlp-api-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 11
$.info
$.paths['/v1/public/report/{reportId}'].get
$.paths['/v1/api/incidents/{incidentID}/assignee'].put
$.paths['/v1/api/incidents/{incidentID}/notes'].put
$.paths['/v1/api/incidents/{incidentID}/notes'].delete
$.paths['/v1/api/incidents/{incidentID}/resolution-status'].put
$.paths['/v1/api/incidents/assignee'].get
$.paths['/v1/api/incidents/assignee'].put
$.paths['/v1/api/incidents/assignee/{assigneeId}'].get
$.paths['/v2/api/incidents/{incidentID}'].get
$.paths['/v2/api/incidents'].get
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for public dlp DLP API
version: 1.0.0
extends: openapi/palo-alto-networks-dlp-api-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 10
- target: $.paths['/v1/public/report/{reportId}'].get
update:
x-apievangelist-phrasing:
intent: Get a DLP scan report
effect: read
questions:
- Can I retrieve an Enterprise DLP report by its ID?
- Can I include the matched-data snippets when fetching a DLP report?
instructions:
- text: Get DLP report {reportId}.
slots:
reportId: path.reportId
- text: Get DLP report {reportId} with snippets set to {fetchSnippets}.
slots:
reportId: path.reportId
fetchSnippets: query.fetchSnippets
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/api/incidents/{incidentID}/assignee'].put
update:
x-apievangelist-phrasing:
intent: Assign an Enterprise DLP incident
effect: write
questions:
- How do I assign a DLP incident to an analyst?
- Does assigning an incident need its region if it is outside the US?
instructions:
- text: Assign DLP incident {incidentID}.
slots:
incidentID: path.incidentID
- text: Set the assignee on incident {incidentID} in region {region}.
slots:
incidentID: path.incidentID
region: query.region
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/api/incidents/{incidentID}/notes'].put
update:
x-apievangelist-phrasing:
intent: Update notes on a DLP incident
effect: write
questions:
- Can I write investigation notes on an Enterprise DLP incident?
- Can I edit the note attached to a DLP incident?
instructions:
- text: Update the notes on DLP incident {incidentID}.
slots:
incidentID: path.incidentID
- text: Save a note to incident {incidentID} in region {region}.
slots:
incidentID: path.incidentID
region: query.region
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/api/incidents/{incidentID}/notes'].delete
update:
x-apievangelist-phrasing:
intent: Remove notes from a DLP incident
effect: destructive
questions:
- Is there a way to clear the notes on a DLP incident?
- Can I remove incident notes for an incident outside the default US region?
instructions:
- text: Remove the notes from DLP incident {incidentID}.
slots:
incidentID: path.incidentID
- text: Delete incident {incidentID} notes in region {region}.
slots:
incidentID: path.incidentID
region: query.region
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/api/incidents/{incidentID}/resolution-status'].put
update:
x-apievangelist-phrasing:
intent: Set a DLP incident's resolution
effect: write
questions:
- How do I mark an Enterprise DLP incident as resolved?
- Can I change the resolution status of an incident in another region?
instructions:
- text: Update the resolution status of DLP incident {incidentID}.
slots:
incidentID: path.incidentID
- text: Resolve incident {incidentID} in region {region}.
slots:
incidentID: path.incidentID
region: query.region
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/api/incidents/assignee'].get
update:
x-apievangelist-phrasing:
intent: List DLP incident assignees
effect: read
questions:
- Who can DLP incidents be assigned to?
- Which assignees are set up for Enterprise DLP?
instructions:
- text: List all DLP incident assignees.
- text: Show everyone available to take DLP incidents.
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/api/incidents/assignee'].put
update:
x-apievangelist-phrasing:
intent: Add or update a DLP incident assignee
effect: write
questions:
- How do I add a new person who can be assigned DLP incidents?
- Can I deactivate an existing DLP assignee?
instructions:
- text: Add assignee {firstName} {lastName} with email {emailAddress} and status {status}.
slots:
firstName: requestBody.firstName
lastName: requestBody.lastName
emailAddress: requestBody.emailAddress
status: requestBody.status
- text: Set assignee {id} ({emailAddress}, {firstName} {lastName}) to status {status}.
slots:
id: requestBody.id
emailAddress: requestBody.emailAddress
firstName: requestBody.firstName
lastName: requestBody.lastName
status: requestBody.status
method: generated
generated: '2026-09-26'
- target: $.paths['/v1/api/incidents/assignee/{assigneeId}'].get
update:
x-apievangelist-phrasing:
intent: Get a DLP incident assignee
effect: read
questions:
- Where can I look up one DLP assignee's details?
- Is a specific DLP assignee still active?
instructions:
- text: Get DLP assignee {assigneeId}.
slots:
assigneeId: path.assigneeId
- text: Show whether assignee {assigneeId} is active.
slots:
assigneeId: path.assigneeId
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/api/incidents/{incidentID}'].get
update:
x-apievangelist-phrasing:
intent: Get an Enterprise DLP incident
effect: read
questions:
- What are the full details of one Enterprise DLP incident?
- How do I read a DLP incident stored in a non-US region?
instructions:
- text: Get Enterprise DLP incident {incidentID}.
slots:
incidentID: path.incidentID
- text: Show DLP incident {incidentID} from region {region}.
slots:
incidentID: path.incidentID
region: query.region
method: generated
generated: '2026-09-26'
- target: $.paths['/v2/api/incidents'].get
update:
x-apievangelist-phrasing:
intent: List Enterprise DLP incidents
effect: read
questions:
- Which DLP incidents came from the firewall channel versus Prisma Access?
- Can I find every DLP incident triggered by a particular file hash?
- What DLP incidents involved a given user in the last week?
instructions:
- text: List Enterprise DLP incidents from channel {channel} since {start_time}.
slots:
channel: query.channel
start_time: query.start_time
- text: Find DLP incidents triggered by file hashes {file_shas}.
slots:
file_shas: query.file_shas
- text: List DLP incidents for users {user_ids} in region {region}.
slots:
user_ids: query.user_ids
region: query.region
method: generated
generated: '2026-09-26'