Palo Alto Networks · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Palo Alto Networks Incidents API

21 actions 21 updates phrasing extends openapi/palo-alto-networks-incidents-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 21 · first 16 shown; the file carries all of them

$.info
$.paths['/incidents/get_incidents'].post
$.paths['/incidents/get_incident_extra_data'].post
$.paths['/incidents/update_incident'].post
$.paths['/incident_management/get_incidents'].post
$.paths['/incident_management/update_incident'].post
$.paths['/incident'].post
$.paths['/incidents/search'].get
$.paths['/incidents/search'].post
$.paths['/incident/{id}'].get
$.paths['/incident/update'].post
$.paths['/incidents'].get
$.paths['/incidents/{incident_id}'].get
$.paths['/incidents/{incident_id}'].put
$.paths['/incidents/{incident_id}/snippets'].get
$.paths['/email-incidents'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Palo Alto Networks Incidents API
  version: 1.0.0
extends: openapi/palo-alto-networks-incidents-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 20
- target: $.paths['/incidents/get_incidents'].post
  update:
    x-apievangelist-phrasing:
      intent: List Cortex XDR incidents
      effect: read
      questions:
      - Which Cortex XDR incidents are open right now at high severity?
      - Can I filter XDR incidents by creation time to see what came in overnight?
      - What incidents has XDR grouped from related alerts this week?
      instructions:
      - text: Pull the Cortex XDR incidents matching filter {request_data}.
        slots:
          request_data: requestBody.request_data
      - text: List my newest Cortex XDR incidents that are still new or under investigation.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/incidents/get_incident_extra_data'].post
  update:
    x-apievangelist-phrasing:
      intent: Get a Cortex XDR incident with its alerts
      effect: read
      questions:
      - How do I see every alert and artifact attached to one Cortex XDR incident?
      - Which endpoints and file hashes are tied to a specific XDR incident?
      instructions:
      - text: Get the full Cortex XDR incident details, alerts and network artifacts for {request_data}.
        slots:
          request_data: requestBody.request_data
      - text: Show the file artifacts and endpoints for the XDR incident described in {request_data}.
        slots:
          request_data: requestBody.request_data
      method: generated
      generated: '2026-09-26'
- target: $.paths['/incidents/update_incident'].post
  update:
    x-apievangelist-phrasing:
      intent: Update a Cortex XDR incident
      effect: write
      questions:
      - How do I reassign a Cortex XDR incident to another analyst?
      - Can I change the severity of an XDR incident without touching its other fields?
      instructions:
      - text: Update the Cortex XDR incident with the changes in {request_data}.
        slots:
          request_data: requestBody.request_data
      - text: Set the status and assignee on an XDR incident using {request_data}.
        slots:
          request_data: requestBody.request_data
      method: generated
      generated: '2026-09-26'
- target: $.paths['/incident_management/get_incidents'].post
  update:
    x-apievangelist-phrasing:
      intent: List Xpanse attack surface incidents
      effect: read
      questions:
      - Which attack surface exposures has Xpanse flagged that still need remediation?
      - Can I list Xpanse incidents about misconfigured certificates or shadow IT?
      - What unintended internet-facing services are open as attack surface incidents?
      instructions:
      - text: List Xpanse attack surface incidents matching {request_data}.
        slots:
          request_data: requestBody.request_data
      - text: Show the unresolved attack surface incidents assigned to my team.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/incident_management/update_incident'].post
  update:
    x-apievangelist-phrasing:
      intent: Update an Xpanse attack surface incident
      effect: write
      questions:
      - How do I close an attack surface incident once the exposure is fixed?
      - Can I record resolution details on an Xpanse incident to track remediation?
      instructions:
      - text: Update the Xpanse attack surface incident using {request_data}.
        slots:
          request_data: requestBody.request_data
      - text: Mark the attack surface exposure in {request_data} as resolved.
        slots:
          request_data: requestBody.request_data
      method: generated
      generated: '2026-09-26'
- target: $.paths['/incident'].post
  update:
    x-apievangelist-phrasing:
      intent: Create a Cortex XSOAR incident
      effect: write
      questions:
      - How do I open a new incident in Cortex XSOAR from an external alert?
      - Can XSOAR start an investigation automatically when I create an incident?
      - Which custom fields can I set when raising an XSOAR incident of a given type?
      instructions:
      - text: Create an XSOAR incident named {name} of type {type} with severity {severity}.
        slots:
          name: requestBody.name
          type: requestBody.type
          severity: requestBody.severity
      - text: Open an XSOAR incident called {name} owned by {owner} and start its investigation.
        slots:
          name: requestBody.name
          owner: requestBody.owner
      - text: Raise incident {name} in XSOAR with details {details}.
        slots:
          name: requestBody.name
          details: requestBody.details
      method: generated
      generated: '2026-09-26'
- target: $.paths['/incidents/search'].get
  update:
    x-apievangelist-phrasing:
      intent: Search XSOAR incidents with a query string
      effect: read
      questions:
      - Can I search XSOAR incidents with a Lucene query like status:Active AND severity:High?
      - What XSOAR incidents were created between two dates?
      instructions:
      - text: Search XSOAR incidents with query {query} and return {size} results.
        slots:
          query: query.query
          size: query.size
      - text: Find XSOAR incidents created from {fromdate} to {todate} via the URL query search.
        slots:
          fromdate: query.fromdate
          todate: query.todate
      method: generated
      generated: '2026-09-26'
- target: $.paths['/incidents/search'].post
  update:
    x-apievangelist-phrasing:
      intent: Search XSOAR incidents with a structured filter
      effect: read
      questions:
      - How do I run a complex XSOAR incident search with field selection and sorting?
      - Can I page through XSOAR search results using a structured filter body?
      instructions:
      - text: Search XSOAR incidents using structured filter {filter}.
        slots:
          filter: requestBody.filter
      - text: Run a structured XSOAR incident search for {filter} between {fromDate} and {toDate}.
        slots:
          filter: requestBody.filter
          fromDate: requestBody.fromDate
          toDate: requestBody.toDate
      method: generated
      generated: '2026-09-26'
- target: $.paths['/incident/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an XSOAR incident by ID
      effect: read
      questions:
      - How do I fetch every field of one XSOAR incident?
      - Where do I get an XSOAR incident's current version before updating it?
      instructions:
      - text: Get XSOAR incident {id}.
        slots:
          id: path.id
      - text: Show all fields and metadata for XSOAR incident {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/incident/update'].post
  update:
    x-apievangelist-phrasing:
      intent: Update or close an XSOAR incident
      effect: write
      questions:
      - How do I close an XSOAR incident with a close reason and notes?
      - Does updating an XSOAR incident need its version for optimistic locking?
      instructions:
      - text: Set XSOAR incident {id} to status {status} and owner {owner}.
        slots:
          id: requestBody.id
          status: requestBody.status
          owner: requestBody.owner
      - text: Close XSOAR incident {id} with reason {closeReason} and notes {closeNotes}.
        slots:
          id: requestBody.id
          closeReason: requestBody.closeReason
          closeNotes: requestBody.closeNotes
      method: generated
      generated: '2026-09-26'
- target: $.paths['/incidents'].get
  update:
    x-apievangelist-phrasing:
      intent: List DLP incidents
      effect: read
      questions:
      - Which DLP incidents found sensitive data across my monitored channels this month?
      - Can I filter data loss prevention incidents by severity and status?
      instructions:
      - text: List DLP incidents with severity {severity} and status {status}.
        slots:
          severity: query.severity
          status: query.status
      - text: Show DLP incidents detected between {start_time} and {end_time}.
        slots:
          start_time: query.start_time
          end_time: query.end_time
      method: generated
      generated: '2026-09-26'
- target: $.paths['/incidents/{incident_id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a DLP incident
      effect: read
      questions:
      - Who was the user behind a particular DLP incident and what file was involved?
      - How do I see the remediation history of one DLP incident?
      instructions:
      - text: Get DLP incident {incident_id}.
        slots:
          incident_id: path.incident_id
      - text: Show the data pattern match context for DLP incident {incident_id}.
        slots:
          incident_id: path.incident_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/incidents/{incident_id}'].put
  update:
    x-apievangelist-phrasing:
      intent: Update a DLP incident's status
      effect: write
      questions:
      - How do I move a DLP incident forward in the review workflow?
      - Can I add reviewer comments to a DLP incident?
      instructions:
      - text: Set DLP incident {incident_id} to status {status}.
        slots:
          incident_id: path.incident_id
          status: requestBody.status
      - text: Add reviewer comments {reviewer_comments} to DLP incident {incident_id}.
        slots:
          incident_id: path.incident_id
          reviewer_comments: requestBody.reviewer_comments
      method: generated
      generated: '2026-09-26'
- target: $.paths['/incidents/{incident_id}/snippets'].get
  update:
    x-apievangelist-phrasing:
      intent: Get DLP match snippets for an incident
      effect: read
      questions:
      - Can I see the text around the sensitive data that triggered a DLP policy?
      - Are matched values masked in DLP incident snippets?
      instructions:
      - text: Get the content snippets for DLP incident {incident_id}.
        slots:
          incident_id: path.incident_id
      - text: Show what surrounded the matched sensitive data in incident {incident_id}.
        slots:
          incident_id: path.incident_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/email-incidents'].get
  update:
    x-apievangelist-phrasing:
      intent: List email DLP incidents
      effect: read
      questions:
      - Which emails or attachments leaked sensitive data this week?
      - Can I page through email DLP incidents filtered by status?
      instructions:
      - text: List email DLP incidents with status {status}.
        slots:
          status: query.status
      - text: Show email DLP incidents between {start_time} and {end_time}.
        slots:
          start_time: query.start_time
          end_time: query.end_time
      method: generated
      generated: '2026-09-26'
- target: $.paths['/email-incidents/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get an email DLP incident
      effect: read
      questions:
      - Who sent the email that triggered a DLP incident and who received it?
      - What verdict was applied to a specific email DLP incident?
      instructions:
      - text: Get email DLP incident {id}.
        slots:
          id: path.id
      - text: Show the sender, recipients and subject of email incident {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/email-incidents/{id}/verdict'].put
  update:
    x-apievangelist-phrasing:
      intent: Allow or block a flagged email
      effect: write
      questions:
      - How do I release a quarantined email that DLP blocked by mistake?
      - Can I override the automated verdict on an email incident and record why?
      instructions:
      - text: Set the verdict of email incident {id} to {verdict}.
        slots:
          id: path.id
          verdict: requestBody.verdict
      - text: Allow the blocked email in incident {id} with comment {comment}.
        slots:
          id: path.id
          comment: requestBody.comment
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/incidents'].get
  update:
    x-apievangelist-phrasing:
      intent: List SaaS Security incidents
      effect: read
      questions:
      - Which SaaS apps have open incidents like external sharing of sensitive files?
      - Can I filter SaaS Security incidents by application and date range?
      instructions:
      - text: List SaaS Security incidents for app {app_id}.
        slots:
          app_id: query.app_id
      - text: Show SaaS Security incidents with severity {severity} created since {start_date}.
        slots:
          severity: query.severity
          start_date: query.start_date
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/incidents/{id}'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a SaaS Security incident
      effect: read
      questions:
      - Which users and assets were affected by a particular SaaS Security incident?
      - What is the event timeline for one SaaS app incident?
      instructions:
      - text: Get SaaS Security incident {id}.
        slots:
          id: path.id
      - text: Show the policy violations and remediation status of SaaS incident {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/incidents/{id}'].put
  update:
    x-apievangelist-phrasing:
      intent: Update a SaaS Security incident
      effect: write
      questions:
      - How do I assign a SaaS Security incident to someone from my SOAR playbook?
      - Can I add a note to a SaaS incident's timeline?
      instructions:
      - text: Assign SaaS Security incident {id} to user {assignee_id}.
        slots:
          id: path.id
          assignee_id: requestBody.assignee_id
      - text: Add note {note} to SaaS incident {id} and set status {status}.
        slots:
          id: path.id
          note: requestBody.note
          status: requestBody.status
      method: generated
      generated: '2026-09-26'