Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Palo Alto Networks PAN-OS REST Objects API
21 actions
21 updates
phrasing
extends
openapi/palo-alto-networks-objects-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 21 · first 16 shown; the file carries all of them
$.info
$.paths['/Objects/Addresses'].get
$.paths['/Objects/Addresses'].put
$.paths['/Objects/Addresses'].post
$.paths['/Objects/Addresses'].delete
$.paths['/Objects/AddressGroups'].get
$.paths['/Objects/AddressGroups'].put
$.paths['/Objects/AddressGroups'].post
$.paths['/Objects/AddressGroups'].delete
$.paths['/Objects/Services'].get
$.paths['/Objects/Services'].put
$.paths['/Objects/Services'].post
$.paths['/Objects/Services'].delete
$.paths['/Objects/ServiceGroups'].get
$.paths['/Objects/ServiceGroups'].put
$.paths['/Objects/ServiceGroups'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Palo Alto Networks PAN-OS REST Objects API
version: 1.0.0
extends: openapi/palo-alto-networks-objects-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 20
- target: $.paths['/Objects/Addresses'].get
update:
x-apievangelist-phrasing:
intent: List firewall address objects
effect: read
questions:
- Which IP addresses, subnets and FQDNs are defined as address objects on my firewall?
- Can I see only the address objects shared across device groups rather than one vsys?
- What address objects exist in vsys1 on the PAN-OS firewall?
instructions:
- text: List all address objects on the firewall.
- text: Show address objects in virtual system {vsys}.
slots:
vsys: query.vsys
- text: Look up the address object named {name} at location {location}.
slots:
name: query.name
location: query.location
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/Addresses'].put
update:
x-apievangelist-phrasing:
intent: Replace an address object's definition
effect: write
questions:
- How do I change the IP subnet an existing address object points to?
- Does editing an address object replace its whole definition or just the fields I send?
- Can I switch an existing address object from an IP range to an FQDN?
instructions:
- text: Replace address object {name} with the definition {entry}.
slots:
name: query.name
entry: requestBody.entry
- text: Update address object {name} in vsys {vsys} so it resolves to {entry}.
slots:
name: query.name
vsys: query.vsys
entry: requestBody.entry
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/Addresses'].post
update:
x-apievangelist-phrasing:
intent: Create a firewall address object
effect: write
questions:
- How do I define a new IP netmask, IP range or FQDN as a named address object?
- Does a new address object name have to be unique within its location?
- Can I add a wildcard address object to use in security rules?
instructions:
- text: Create address object {name} with {entry}.
slots:
name: query.name
entry: requestBody.entry
- text: Add a new address object {name} at {location} defined as {entry}.
slots:
name: query.name
location: query.location
entry: requestBody.entry
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/Addresses'].delete
update:
x-apievangelist-phrasing:
intent: Delete a firewall address object
effect: destructive
questions:
- Why can't I remove an address object that a security rule still references?
- What happens if I delete an address object that belongs to an address group?
instructions:
- text: Delete address object {name}.
slots:
name: query.name
- text: Remove the address object {name} from vsys {vsys}.
slots:
name: query.name
vsys: query.vsys
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/AddressGroups'].get
update:
x-apievangelist-phrasing:
intent: List firewall address groups
effect: read
questions:
- Which address groups are configured on my firewall, static and dynamic?
- Can I see which address groups exist in a particular vsys or device group?
instructions:
- text: List every address group on the firewall.
- text: Show the address group named {name}.
slots:
name: query.name
- text: List address groups at location {location}.
slots:
location: query.location
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/AddressGroups'].put
update:
x-apievangelist-phrasing:
intent: Replace an address group definition
effect: write
questions:
- How do I change the members of an existing static address group?
- Can I rewrite the tag filter on a dynamic address group I already have?
instructions:
- text: Replace address group {name} with the definition {entry}.
slots:
name: query.name
entry: requestBody.entry
- text: Update the members of address group {name} to {entry}.
slots:
name: query.name
entry: requestBody.entry
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/AddressGroups'].post
update:
x-apievangelist-phrasing:
intent: Create a static or dynamic address group
effect: write
questions:
- Can I build an address group that picks up addresses automatically by tag?
- What is needed to group several address objects into one new static group?
instructions:
- text: Create address group {name} with members {entry}.
slots:
name: query.name
entry: requestBody.entry
- text: Create a dynamic address group {name} in vsys {vsys} using the tag filter {entry}.
slots:
name: query.name
vsys: query.vsys
entry: requestBody.entry
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/AddressGroups'].delete
update:
x-apievangelist-phrasing:
intent: Delete a firewall address group
effect: destructive
questions:
- Is it possible to remove an address group without deleting the address objects inside it?
- Which call removes an address group by name from the firewall?
instructions:
- text: Delete address group {name}.
slots:
name: query.name
- text: Remove address group {name} from location {location}.
slots:
name: query.name
location: query.location
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/Services'].get
update:
x-apievangelist-phrasing:
intent: List TCP/UDP service objects
effect: read
questions:
- Which TCP and UDP port definitions exist as service objects on my firewall?
- Can I check whether a service object for a given port already exists by name?
instructions:
- text: List all service objects on the firewall.
- text: Show the service object named {name}.
slots:
name: query.name
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/Services'].put
update:
x-apievangelist-phrasing:
intent: Update a service object's ports
effect: write
questions:
- How do I change the destination port on an existing service object?
- Can I switch a service object from TCP to UDP after creating it?
instructions:
- text: Update service object {name} to {entry}.
slots:
name: query.name
entry: requestBody.entry
- text: Change the port definition of service {name} in vsys {vsys} to {entry}.
slots:
name: query.name
vsys: query.vsys
entry: requestBody.entry
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/Services'].post
update:
x-apievangelist-phrasing:
intent: Create a TCP or UDP service object
effect: write
questions:
- How do I define a custom port or port range as a service for firewall rules?
- Can a new service object cover a range of destination ports?
instructions:
- text: Create service object {name} for {entry}.
slots:
name: query.name
entry: requestBody.entry
- text: Add a new service {name} at location {location} with protocol and port {entry}.
slots:
name: query.name
location: query.location
entry: requestBody.entry
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/Services'].delete
update:
x-apievangelist-phrasing:
intent: Delete a service object
effect: destructive
questions:
- What removes a custom port service object I no longer use?
- Can I delete a service object from one specific vsys only?
instructions:
- text: Delete service object {name}.
slots:
name: query.name
- text: Remove service {name} from vsys {vsys}.
slots:
name: query.name
vsys: query.vsys
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/ServiceGroups'].get
update:
x-apievangelist-phrasing:
intent: List service groups
effect: read
questions:
- Which service groups bundle my port definitions together on the firewall?
- Can I look up one service group by name to see what it contains?
instructions:
- text: List all service groups.
- text: Show the service group {name}.
slots:
name: query.name
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/ServiceGroups'].put
update:
x-apievangelist-phrasing:
intent: Update a service group's members
effect: write
questions:
- How do I add or remove services in an existing service group?
- Can I edit a service group's membership in place by name?
instructions:
- text: Update service group {name} to contain {entry}.
slots:
name: query.name
entry: requestBody.entry
- text: Replace the members of service group {name} in vsys {vsys} with {entry}.
slots:
name: query.name
vsys: query.vsys
entry: requestBody.entry
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/ServiceGroups'].post
update:
x-apievangelist-phrasing:
intent: Create a service group
effect: write
questions:
- Can I bundle several service objects into one group for use in a policy rule?
- What does it take to create a new service group on the firewall?
instructions:
- text: Create service group {name} with services {entry}.
slots:
name: query.name
entry: requestBody.entry
- text: Create a new service group {name} at {location} containing {entry}.
slots:
name: query.name
location: query.location
entry: requestBody.entry
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/ServiceGroups'].delete
update:
x-apievangelist-phrasing:
intent: Delete a service group
effect: destructive
questions:
- Which call removes a service group by name?
- Can I delete a service group but keep the individual service objects?
instructions:
- text: Delete service group {name}.
slots:
name: query.name
- text: Remove service group {name} from location {location}.
slots:
name: query.name
location: query.location
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/Tags'].get
update:
x-apievangelist-phrasing:
intent: List configuration tags
effect: read
questions:
- Which tags are defined on my firewall for grouping addresses and rules?
- Can I list the tags available in a particular vsys?
instructions:
- text: List all tags on the firewall.
- text: Show the tag named {name}.
slots:
name: query.name
- text: List tags defined in vsys {vsys}.
slots:
vsys: query.vsys
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/Tags'].put
update:
x-apievangelist-phrasing:
intent: Update a tag's color or comment
effect: write
questions:
- How do I change the color or comment on an existing firewall tag?
- Can I edit a tag that is already used by dynamic address groups?
instructions:
- text: Update tag {name} with {entry}.
slots:
name: query.name
entry: requestBody.entry
- text: Change the color and comment of tag {name} in vsys {vsys} to {entry}.
slots:
name: query.name
vsys: query.vsys
entry: requestBody.entry
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/Tags'].post
update:
x-apievangelist-phrasing:
intent: Create a tag for grouping objects
effect: write
questions:
- How do I create a tag with a color so I can drive dynamic address groups from it?
- Can I add a comment to a new tag when I create it?
instructions:
- text: Create tag {name} with {entry}.
slots:
name: query.name
entry: requestBody.entry
- text: Add a new tag {name} at location {location} with color and comment {entry}.
slots:
name: query.name
location: query.location
entry: requestBody.entry
method: generated
generated: '2026-09-26'
- target: $.paths['/Objects/Tags'].delete
update:
x-apievangelist-phrasing:
intent: Delete a tag
effect: destructive
questions:
- Which call deletes a tag I no longer use on the firewall?
- Can I remove a tag from one vsys by name?
instructions:
- text: Delete tag {name}.
slots:
name: query.name
- text: Remove tag {name} from vsys {vsys}.
slots:
name: query.name
vsys: query.vsys
method: generated
generated: '2026-09-26'