Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Palo Alto Networks Incidents API
21 actions
21 updates
phrasing
extends
openapi/palo-alto-networks-incidents-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 21 · first 16 shown; the file carries all of them
$.info
$.paths['/incidents/get_incidents'].post
$.paths['/incidents/get_incident_extra_data'].post
$.paths['/incidents/update_incident'].post
$.paths['/incident_management/get_incidents'].post
$.paths['/incident_management/update_incident'].post
$.paths['/incident'].post
$.paths['/incidents/search'].get
$.paths['/incidents/search'].post
$.paths['/incident/{id}'].get
$.paths['/incident/update'].post
$.paths['/incidents'].get
$.paths['/incidents/{incident_id}'].get
$.paths['/incidents/{incident_id}'].put
$.paths['/incidents/{incident_id}/snippets'].get
$.paths['/email-incidents'].get
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Palo Alto Networks Incidents API
version: 1.0.0
extends: openapi/palo-alto-networks-incidents-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 20
- target: $.paths['/incidents/get_incidents'].post
update:
x-apievangelist-phrasing:
intent: List Cortex XDR incidents
effect: read
questions:
- Which Cortex XDR incidents are open right now at high severity?
- Can I filter XDR incidents by creation time to see what came in overnight?
- What incidents has XDR grouped from related alerts this week?
instructions:
- text: Pull the Cortex XDR incidents matching filter {request_data}.
slots:
request_data: requestBody.request_data
- text: List my newest Cortex XDR incidents that are still new or under investigation.
method: generated
generated: '2026-09-26'
- target: $.paths['/incidents/get_incident_extra_data'].post
update:
x-apievangelist-phrasing:
intent: Get a Cortex XDR incident with its alerts
effect: read
questions:
- How do I see every alert and artifact attached to one Cortex XDR incident?
- Which endpoints and file hashes are tied to a specific XDR incident?
instructions:
- text: Get the full Cortex XDR incident details, alerts and network artifacts for {request_data}.
slots:
request_data: requestBody.request_data
- text: Show the file artifacts and endpoints for the XDR incident described in {request_data}.
slots:
request_data: requestBody.request_data
method: generated
generated: '2026-09-26'
- target: $.paths['/incidents/update_incident'].post
update:
x-apievangelist-phrasing:
intent: Update a Cortex XDR incident
effect: write
questions:
- How do I reassign a Cortex XDR incident to another analyst?
- Can I change the severity of an XDR incident without touching its other fields?
instructions:
- text: Update the Cortex XDR incident with the changes in {request_data}.
slots:
request_data: requestBody.request_data
- text: Set the status and assignee on an XDR incident using {request_data}.
slots:
request_data: requestBody.request_data
method: generated
generated: '2026-09-26'
- target: $.paths['/incident_management/get_incidents'].post
update:
x-apievangelist-phrasing:
intent: List Xpanse attack surface incidents
effect: read
questions:
- Which attack surface exposures has Xpanse flagged that still need remediation?
- Can I list Xpanse incidents about misconfigured certificates or shadow IT?
- What unintended internet-facing services are open as attack surface incidents?
instructions:
- text: List Xpanse attack surface incidents matching {request_data}.
slots:
request_data: requestBody.request_data
- text: Show the unresolved attack surface incidents assigned to my team.
method: generated
generated: '2026-09-26'
- target: $.paths['/incident_management/update_incident'].post
update:
x-apievangelist-phrasing:
intent: Update an Xpanse attack surface incident
effect: write
questions:
- How do I close an attack surface incident once the exposure is fixed?
- Can I record resolution details on an Xpanse incident to track remediation?
instructions:
- text: Update the Xpanse attack surface incident using {request_data}.
slots:
request_data: requestBody.request_data
- text: Mark the attack surface exposure in {request_data} as resolved.
slots:
request_data: requestBody.request_data
method: generated
generated: '2026-09-26'
- target: $.paths['/incident'].post
update:
x-apievangelist-phrasing:
intent: Create a Cortex XSOAR incident
effect: write
questions:
- How do I open a new incident in Cortex XSOAR from an external alert?
- Can XSOAR start an investigation automatically when I create an incident?
- Which custom fields can I set when raising an XSOAR incident of a given type?
instructions:
- text: Create an XSOAR incident named {name} of type {type} with severity {severity}.
slots:
name: requestBody.name
type: requestBody.type
severity: requestBody.severity
- text: Open an XSOAR incident called {name} owned by {owner} and start its investigation.
slots:
name: requestBody.name
owner: requestBody.owner
- text: Raise incident {name} in XSOAR with details {details}.
slots:
name: requestBody.name
details: requestBody.details
method: generated
generated: '2026-09-26'
- target: $.paths['/incidents/search'].get
update:
x-apievangelist-phrasing:
intent: Search XSOAR incidents with a query string
effect: read
questions:
- Can I search XSOAR incidents with a Lucene query like status:Active AND severity:High?
- What XSOAR incidents were created between two dates?
instructions:
- text: Search XSOAR incidents with query {query} and return {size} results.
slots:
query: query.query
size: query.size
- text: Find XSOAR incidents created from {fromdate} to {todate} via the URL query search.
slots:
fromdate: query.fromdate
todate: query.todate
method: generated
generated: '2026-09-26'
- target: $.paths['/incidents/search'].post
update:
x-apievangelist-phrasing:
intent: Search XSOAR incidents with a structured filter
effect: read
questions:
- How do I run a complex XSOAR incident search with field selection and sorting?
- Can I page through XSOAR search results using a structured filter body?
instructions:
- text: Search XSOAR incidents using structured filter {filter}.
slots:
filter: requestBody.filter
- text: Run a structured XSOAR incident search for {filter} between {fromDate} and {toDate}.
slots:
filter: requestBody.filter
fromDate: requestBody.fromDate
toDate: requestBody.toDate
method: generated
generated: '2026-09-26'
- target: $.paths['/incident/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get an XSOAR incident by ID
effect: read
questions:
- How do I fetch every field of one XSOAR incident?
- Where do I get an XSOAR incident's current version before updating it?
instructions:
- text: Get XSOAR incident {id}.
slots:
id: path.id
- text: Show all fields and metadata for XSOAR incident {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/incident/update'].post
update:
x-apievangelist-phrasing:
intent: Update or close an XSOAR incident
effect: write
questions:
- How do I close an XSOAR incident with a close reason and notes?
- Does updating an XSOAR incident need its version for optimistic locking?
instructions:
- text: Set XSOAR incident {id} to status {status} and owner {owner}.
slots:
id: requestBody.id
status: requestBody.status
owner: requestBody.owner
- text: Close XSOAR incident {id} with reason {closeReason} and notes {closeNotes}.
slots:
id: requestBody.id
closeReason: requestBody.closeReason
closeNotes: requestBody.closeNotes
method: generated
generated: '2026-09-26'
- target: $.paths['/incidents'].get
update:
x-apievangelist-phrasing:
intent: List DLP incidents
effect: read
questions:
- Which DLP incidents found sensitive data across my monitored channels this month?
- Can I filter data loss prevention incidents by severity and status?
instructions:
- text: List DLP incidents with severity {severity} and status {status}.
slots:
severity: query.severity
status: query.status
- text: Show DLP incidents detected between {start_time} and {end_time}.
slots:
start_time: query.start_time
end_time: query.end_time
method: generated
generated: '2026-09-26'
- target: $.paths['/incidents/{incident_id}'].get
update:
x-apievangelist-phrasing:
intent: Get a DLP incident
effect: read
questions:
- Who was the user behind a particular DLP incident and what file was involved?
- How do I see the remediation history of one DLP incident?
instructions:
- text: Get DLP incident {incident_id}.
slots:
incident_id: path.incident_id
- text: Show the data pattern match context for DLP incident {incident_id}.
slots:
incident_id: path.incident_id
method: generated
generated: '2026-09-26'
- target: $.paths['/incidents/{incident_id}'].put
update:
x-apievangelist-phrasing:
intent: Update a DLP incident's status
effect: write
questions:
- How do I move a DLP incident forward in the review workflow?
- Can I add reviewer comments to a DLP incident?
instructions:
- text: Set DLP incident {incident_id} to status {status}.
slots:
incident_id: path.incident_id
status: requestBody.status
- text: Add reviewer comments {reviewer_comments} to DLP incident {incident_id}.
slots:
incident_id: path.incident_id
reviewer_comments: requestBody.reviewer_comments
method: generated
generated: '2026-09-26'
- target: $.paths['/incidents/{incident_id}/snippets'].get
update:
x-apievangelist-phrasing:
intent: Get DLP match snippets for an incident
effect: read
questions:
- Can I see the text around the sensitive data that triggered a DLP policy?
- Are matched values masked in DLP incident snippets?
instructions:
- text: Get the content snippets for DLP incident {incident_id}.
slots:
incident_id: path.incident_id
- text: Show what surrounded the matched sensitive data in incident {incident_id}.
slots:
incident_id: path.incident_id
method: generated
generated: '2026-09-26'
- target: $.paths['/email-incidents'].get
update:
x-apievangelist-phrasing:
intent: List email DLP incidents
effect: read
questions:
- Which emails or attachments leaked sensitive data this week?
- Can I page through email DLP incidents filtered by status?
instructions:
- text: List email DLP incidents with status {status}.
slots:
status: query.status
- text: Show email DLP incidents between {start_time} and {end_time}.
slots:
start_time: query.start_time
end_time: query.end_time
method: generated
generated: '2026-09-26'
- target: $.paths['/email-incidents/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get an email DLP incident
effect: read
questions:
- Who sent the email that triggered a DLP incident and who received it?
- What verdict was applied to a specific email DLP incident?
instructions:
- text: Get email DLP incident {id}.
slots:
id: path.id
- text: Show the sender, recipients and subject of email incident {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/email-incidents/{id}/verdict'].put
update:
x-apievangelist-phrasing:
intent: Allow or block a flagged email
effect: write
questions:
- How do I release a quarantined email that DLP blocked by mistake?
- Can I override the automated verdict on an email incident and record why?
instructions:
- text: Set the verdict of email incident {id} to {verdict}.
slots:
id: path.id
verdict: requestBody.verdict
- text: Allow the blocked email in incident {id} with comment {comment}.
slots:
id: path.id
comment: requestBody.comment
method: generated
generated: '2026-09-26'
- target: $.paths['/api/incidents'].get
update:
x-apievangelist-phrasing:
intent: List SaaS Security incidents
effect: read
questions:
- Which SaaS apps have open incidents like external sharing of sensitive files?
- Can I filter SaaS Security incidents by application and date range?
instructions:
- text: List SaaS Security incidents for app {app_id}.
slots:
app_id: query.app_id
- text: Show SaaS Security incidents with severity {severity} created since {start_date}.
slots:
severity: query.severity
start_date: query.start_date
method: generated
generated: '2026-09-26'
- target: $.paths['/api/incidents/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get a SaaS Security incident
effect: read
questions:
- Which users and assets were affected by a particular SaaS Security incident?
- What is the event timeline for one SaaS app incident?
instructions:
- text: Get SaaS Security incident {id}.
slots:
id: path.id
- text: Show the policy violations and remediation status of SaaS incident {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/incidents/{id}'].put
update:
x-apievangelist-phrasing:
intent: Update a SaaS Security incident
effect: write
questions:
- How do I assign a SaaS Security incident to someone from my SOAR playbook?
- Can I add a note to a SaaS incident's timeline?
instructions:
- text: Assign SaaS Security incident {id} to user {assignee_id}.
slots:
id: path.id
assignee_id: requestBody.assignee_id
- text: Add note {note} to SaaS incident {id} and set status {status}.
slots:
id: path.id
note: requestBody.note
status: requestBody.status
method: generated
generated: '2026-09-26'