Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Palo Alto Networks Search API
21 actions
21 updates
phrasing
extends
openapi/palo-alto-networks-search-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 21 · first 16 shown; the file carries all of them
$.info
$.paths['/search/config'].post
$.paths['/search'].post
$.paths['/search/event'].post
$.paths['/search/event/aggregate'].post
$.paths['/search/event/filtered'].post
$.paths['/search/event/page'].post
$.paths['/search/event/raw/{id}'].get
$.paths['/search/suggest'].post
$.paths['/search/alert'].get
$.paths['/search/config/page'].post
$.paths['/search/event/filtered/download'].post
$.paths['/search/config/jobs'].post
$.paths['/search/config/jobs/{id}/download'].get
$.paths['/search/api/v1/config'].post
$.paths['/search/api/v1/config/async'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Palo Alto Networks Search API
version: 1.0.0
extends: openapi/palo-alto-networks-search-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 20
- target: $.paths['/search/config'].post
update:
x-apievangelist-phrasing:
intent: Run an RQL config search
effect: read
questions:
- How do I run an RQL config query to find misconfigured cloud resources in Prisma Cloud?
- Can I save a config search with a name and description when I run it?
- Which cloud resources violate policy right now according to a config query?
instructions:
- text: Run the config query {query} and save it as {searchName}.
slots:
query: requestBody.query
searchName: requestBody.searchName
- text: Run config query {query} and include the full resource JSON in the results.
slots:
query: requestBody.query
method: generated
generated: '2026-09-26'
- target: $.paths['/search'].post
update:
x-apievangelist-phrasing:
intent: Search network flow logs with RQL
effect: read
questions:
- How can I query cloud flow logs to see which network traffic reached a resource?
- Can a network flow-log search be returned as a CSV instead of JSON?
- What network traffic matched my RQL query over the last day?
instructions:
- text: Search flow logs with network query {query} over time range {timeRange}.
slots:
query: requestBody.query
timeRange: requestBody.timeRange
- text: Run network query {query} for {timeRange} grouped by {groupBy}.
slots:
query: requestBody.query
timeRange: requestBody.timeRange
groupBy: requestBody.groupBy
method: generated
generated: '2026-09-26'
- target: $.paths['/search/event'].post
update:
x-apievangelist-phrasing:
intent: Search audit events with RQL
effect: read
questions:
- How do I find console and API access events in the audit log using RQL?
- Which privileged activities happened in my cloud accounts this week?
- Is there a way to detect signs of account compromise from audit event data?
instructions:
- text: Run audit event query {query} over {timeRange}.
slots:
query: requestBody.query
timeRange: requestBody.timeRange
- text: Search audit events with {query} and return at most {limit} results.
slots:
query: requestBody.query
limit: requestBody.limit
method: generated
generated: '2026-09-26'
- target: $.paths['/search/event/aggregate'].post
update:
x-apievangelist-phrasing:
intent: Run an aggregated audit event search
effect: read
questions:
- Can I get audit event results broken down by location and service?
- Where geographically and in which services did my audit events come from?
instructions:
- text: Run aggregated event query {query} to show location and service breakdowns.
slots:
query: requestBody.query
- text: Aggregate audit events matching {query} over {timeRange} by location and service.
slots:
query: requestBody.query
timeRange: requestBody.timeRange
method: generated
generated: '2026-09-26'
- target: $.paths['/search/event/filtered'].post
update:
x-apievangelist-phrasing:
intent: Filter audit event search results
effect: read
questions:
- How do I narrow down the results of an aggregated audit event search with extra filters?
- Can I refine event log results after the first search without rerunning everything?
instructions:
- text: Refine event results for {query} using filters {filters}.
slots:
query: requestBody.query
filters: requestBody.filters
- text: Filter the event log search {query} down with {filters} and sort by {sort}.
slots:
query: requestBody.query
filters: requestBody.filters
sort: requestBody.sort
method: generated
generated: '2026-09-26'
- target: $.paths['/search/event/page'].post
update:
x-apievangelist-phrasing:
intent: Get the next page of audit event results
effect: read
questions:
- My audit event search returned over 100 results — how do I fetch the next page?
- What token do I pass to page through event search results?
instructions:
- text: Fetch the next page of event search results using page token {pageToken}.
slots:
pageToken: requestBody.pageToken
- text: Get {limit} more audit events with page token {pageToken}.
slots:
limit: requestBody.limit
pageToken: requestBody.pageToken
method: generated
generated: '2026-09-26'
- target: $.paths['/search/event/raw/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get raw metadata for an audit event
effect: read
questions:
- How do I see the raw metadata behind a single audit event?
- Can I pull the unprocessed JSON for one specific event ID?
instructions:
- text: Show the raw event data for audit event {id}.
slots:
id: path.id
- text: Get raw metadata for event {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/search/suggest'].post
update:
x-apievangelist-phrasing:
intent: Autocomplete a partial RQL query
effect: read
questions:
- What can I type next to finish a partial RQL query?
- Which expressions, values and operators are valid after the RQL I've started writing?
instructions:
- text: Suggest completions for the partial RQL query {query}.
slots:
query: requestBody.query
- text: Autocomplete {query} for time range {timeRange}.
slots:
query: requestBody.query
timeRange: requestBody.timeRange
method: generated
generated: '2026-09-26'
- target: $.paths['/search/alert'].get
update:
x-apievangelist-phrasing:
intent: Get investigation data for an alert
effect: read
questions:
- How do I pull the search data needed to investigate an anomaly or network alert?
- Does alert investigation data work for every alert type or only anomaly and network alerts?
instructions:
- text: Get investigation search data for alert {alertId}.
slots:
alertId: query.alertId
- text: Investigate network alert {alertId}.
slots:
alertId: query.alertId
method: generated
generated: '2026-09-26'
- target: $.paths['/search/config/page'].post
update:
x-apievangelist-phrasing:
intent: Get the next page of config search results
effect: read
questions:
- My config search found over 100 resources — how do I load the next page?
- Can I include resource JSON when paging through config search results?
instructions:
- text: Load the next page of config search results with token {pageToken}.
slots:
pageToken: requestBody.pageToken
- text: Fetch {limit} more config results using page token {pageToken}.
slots:
limit: requestBody.limit
pageToken: requestBody.pageToken
method: generated
generated: '2026-09-26'
- target: $.paths['/search/event/filtered/download'].post
update:
x-apievangelist-phrasing:
intent: Download audit event search results as CSV
effect: read
questions:
- Can I export an audit event log search to a CSV file?
- How do I download filtered event search results for a spreadsheet?
instructions:
- text: Download audit events matching {query} as a CSV.
slots:
query: requestBody.query
- text: Export the event log search {query} for {timeRange} to CSV.
slots:
query: requestBody.query
timeRange: requestBody.timeRange
method: generated
generated: '2026-09-26'
- target: $.paths['/search/config/jobs'].post
update:
x-apievangelist-phrasing:
intent: Start a config search CSV export job
effect: write
questions:
- How do I kick off a background job that builds a CSV of config query results?
- Can I generate a config CSV from a saved search ID rather than a new query?
- What job ID and status do I get back when submitting a config CSV job?
instructions:
- text: Submit a CSV generation job for config query {query} named {searchName}.
slots:
query: requestBody.query
searchName: requestBody.searchName
- text: Start a config CSV job from saved search {id}.
slots:
id: requestBody.id
method: generated
generated: '2026-09-26'
- target: $.paths['/search/config/jobs/{id}/download'].get
update:
x-apievangelist-phrasing:
intent: Download a finished config CSV job
effect: read
questions:
- My config CSV job is done — how do I download the file?
- Where do I get the CSV produced by a submitted config search job?
instructions:
- text: Download the CSV output of config search job {id}.
slots:
id: path.id
- text: Fetch the finished config CSV for job {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/search/api/v1/config'].post
update:
x-apievangelist-phrasing:
intent: Run a config search by RQL query (v1 API)
effect: read
questions:
- How do I run an RQL config query through the v1 search API and get a page token back?
- Can I skip saving the search to history when I run a v1 config query?
instructions:
- text: Run v1 config query {query} without creating a saved search.
slots:
query: requestBody.query
- text: Use the v1 config search API to run {query} with next page token {nextPageToken}.
slots:
query: requestBody.query
nextPageToken: requestBody.nextPageToken
method: generated
generated: '2026-09-26'
- target: $.paths['/search/api/v1/config/async'].post
update:
x-apievangelist-phrasing:
intent: Get config search results as CSV asynchronously
effect: read
questions:
- Can the reporting service send config query results as CSV asynchronously?
- How do I get an async CSV of a saved config search from the reporting service?
instructions:
- text: Request async CSV results from the reporting service for config query {query}.
slots:
query: requestBody.query
- text: Get async CSV results for saved search {savedSearchId} with query {query}.
slots:
savedSearchId: requestBody.savedSearchId
query: requestBody.query
method: generated
generated: '2026-09-26'
- target: $.paths['/search/api/v1/config/download'].post
update:
x-apievangelist-phrasing:
intent: Download config search results as CSV directly
effect: read
questions:
- How do I download config query results straight to a CSV in one call?
- Is there a synchronous endpoint that returns a config search as CSV?
instructions:
- text: Download config query {query} results as a CSV file right now.
slots:
query: requestBody.query
- text: Export saved config search {savedSearchId} using query {query} to CSV immediately.
slots:
savedSearchId: requestBody.savedSearchId
query: requestBody.query
method: generated
generated: '2026-09-26'
- target: $.paths['/search/api/v2/config'].post
update:
x-apievangelist-phrasing:
intent: Run a config search with a start time (v2)
effect: read
questions:
- How do I run a v2 config query that starts at a given time and ends now?
- Does the v2 config search return the newer descriptive resource type names like EC2 Instance?
instructions:
- text: Run v2 config query {query} starting from {startTime}.
slots:
query: requestBody.query
startTime: requestBody.startTime
- text: Use config search v2 to run {query} returning {limit} results.
slots:
query: requestBody.query
limit: requestBody.limit
method: generated
generated: '2026-09-26'
- target: $.paths['/search/api/v2/config/{id}'].post
update:
x-apievangelist-phrasing:
intent: Rerun a saved config search by ID (v2)
effect: read
questions:
- Can I rerun an existing config search by its ID using the v2 start-time format?
- How do I page through a v2 config search that I already created?
instructions:
- text: Rerun config search {id} with the v2 API from {startTime}.
slots:
id: path.id
startTime: requestBody.startTime
- text: Get the next v2 results for search {id} using token {nextPageToken}.
slots:
id: path.id
nextPageToken: requestBody.nextPageToken
method: generated
generated: '2026-09-26'
- target: $.paths['/search/api/v1/config/{id}'].post
update:
x-apievangelist-phrasing:
intent: Rerun a saved config search by ID (v1)
effect: read
questions:
- How do I get results for an existing config search ID with a time range in v1?
- Can I rerun a previous config search by ID instead of retyping the RQL?
instructions:
- text: Rerun v1 config search {id} over time range {timeRange}.
slots:
id: path.id
timeRange: requestBody.timeRange
- text: Get {limit} results from existing config search {id}.
slots:
limit: requestBody.limit
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/search/asset'].post
update:
x-apievangelist-phrasing:
intent: Search cloud assets with RQL
effect: read
questions:
- Which cloud assets match an RQL asset query across my resource configurations?
- Can one asset search cover config, network and event query types?
instructions:
- text: Search assets with RQL {query} over {timeRange}.
slots:
query: requestBody.query
timeRange: requestBody.timeRange
- text: Find up to {limit} assets matching {query} in {timeRange}.
slots:
limit: requestBody.limit
query: requestBody.query
timeRange: requestBody.timeRange
method: generated
generated: '2026-09-26'