# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Kibana Alerting API version: 1.0.0 extends: openapi/elk-stack-alerting-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 23 - target: $.paths['/api/alerting/_health'].get update: x-apievangelist-phrasing: intent: Check alerting framework health effect: read questions: - Is the Kibana alerting framework healthy and able to run rules? - Can I check whether alerting has the prerequisites it needs, like encryption keys? instructions: - text: Check the health of the alerting framework. - text: Report whether rule execution is healthy right now. method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rule_types'].get update: x-apievangelist-phrasing: intent: List available rule types effect: read questions: - Which kinds of alerting rules can I create with my privileges? - What rule types are registered and which action groups do they support? instructions: - text: List the rule types I can use. - text: Show every registered rule type with its action groups. method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rule/{id}'].get update: x-apievangelist-phrasing: intent: Get a rule's details effect: read questions: - What schedule, params and actions does a particular rule have? - Can I retrieve a single rule by its identifier? instructions: - text: Get the details of rule {id}. slots: id: path.id - text: Show me how rule {id} is configured. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rule/{id}'].put update: x-apievangelist-phrasing: intent: Update an existing rule effect: write questions: - How do I change the name, schedule or actions on an existing rule? - Can I adjust a rule's alert delay or flapping settings after it was created? instructions: - text: Update rule {id} with name {name} and schedule {schedule}. slots: id: path.id name: requestBody.name schedule: requestBody.schedule - text: 'Edit rule {id}: keep name {name}, run every {schedule}, and tag it {tags}.' slots: id: path.id name: requestBody.name schedule: requestBody.schedule tags: requestBody.tags method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rule/{id}'].post update: x-apievangelist-phrasing: intent: Create a rule effect: write questions: - How do I create a new alerting rule under an ID I pick? - Can I create a rule and let Kibana generate its identifier? instructions: - text: Create a new rule with ID {id}. slots: id: path.id - text: Set up a brand new alerting rule stored as {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rule/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a rule effect: destructive questions: - How do I permanently delete an alerting rule? - Can I remove a rule I no longer need? instructions: - text: Delete rule {id}. slots: id: path.id - text: Permanently remove alerting rule {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rule/{id}/_disable'].post update: x-apievangelist-phrasing: intent: Disable a rule effect: write questions: - How do I turn off a rule without deleting it? - When I disable a rule, can its active alerts be untracked too? instructions: - text: Disable rule {id}. slots: id: path.id - text: Disable rule {id} and set untrack to {untrack} for its alerts. slots: id: path.id untrack: requestBody.untrack method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rule/{id}/_enable'].post update: x-apievangelist-phrasing: intent: Enable a rule effect: write questions: - How do I turn a disabled rule back on? - Can I re-enable a rule so its checks start running again? instructions: - text: Enable rule {id}. slots: id: path.id - text: Turn rule {id} back on. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rule/{id}/_mute_all'].post update: x-apievangelist-phrasing: intent: Mute all alerts for a rule effect: write questions: - Can I silence every alert a rule produces while it keeps running? - What mutes all of a rule's alerts at once? instructions: - text: Mute all alerts for rule {id}. slots: id: path.id - text: Stop every alert from rule {id} from triggering actions. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rule/{id}/_unmute_all'].post update: x-apievangelist-phrasing: intent: Unmute all alerts for a rule effect: write questions: - How do I undo muting all of a rule's alerts? - Can a rule whose alerts are all muted start notifying again? instructions: - text: Unmute all alerts for rule {id}. slots: id: path.id - text: Let every alert from rule {id} trigger actions again. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rule/{id}/_update_api_key'].post update: x-apievangelist-phrasing: intent: Refresh the API key a rule runs with effect: write questions: - How do I regenerate the API key an alerting rule uses? - Can a rule's credentials be switched to mine after the original owner left? instructions: - text: Update the API key for rule {id}. slots: id: path.id - text: Regenerate the credentials rule {id} runs with. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rule/{id}/query_inspector'].get update: x-apievangelist-phrasing: intent: Inspect the Elasticsearch query a rule runs effect: read questions: - What Elasticsearch query does my rule actually execute? - Can I run a rule's query and see the response for a specific alert's time range? instructions: - text: Show the Elasticsearch query behind rule {id}. slots: id: path.id - text: Execute rule {id}'s query in mode {mode} using the time range of alert {alert_id}. slots: id: path.id mode: query.mode alert_id: query.alert_id method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rule/{id}/snooze_schedule'].post update: x-apievangelist-phrasing: intent: Schedule a snooze for a rule effect: write questions: - Can I schedule a recurring snooze so a rule stays quiet during maintenance? - If a rule is snoozed, does it still run its checks? instructions: - text: Schedule a snooze for rule {id} using {schedule}. slots: id: path.id schedule: requestBody.schedule - text: Add a recurring quiet period {schedule} to rule {id}. slots: schedule: requestBody.schedule id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rule/{rule_id}/alert/{alert_id}/_mute'].post update: x-apievangelist-phrasing: intent: Mute one alert of a rule effect: write questions: - Can I mute a single alert instance without muting the whole rule? - How do I silence one noisy host's alert on a rule? instructions: - text: Mute alert {alert_id} on rule {rule_id}. slots: alert_id: path.alert_id rule_id: path.rule_id - text: Mute alert {alert_id} of rule {rule_id}, checking it exists first ({validate_alerts_existence}). slots: alert_id: path.alert_id rule_id: path.rule_id validate_alerts_existence: query.validate_alerts_existence method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rule/{rule_id}/alert/{alert_id}/_snooze'].post update: x-apievangelist-phrasing: intent: Snooze one alert of a rule effect: write questions: - Can I snooze a single alert until a time or until a condition is met? - Is snoozing one alert different from muting it? instructions: - text: Snooze alert {alert_id} on rule {rule_id} until {expires_at}. slots: alert_id: path.alert_id rule_id: path.rule_id expires_at: requestBody.expires_at - text: Snooze alert {alert_id} of rule {rule_id} until conditions {conditions} are met. slots: alert_id: path.alert_id rule_id: path.rule_id conditions: requestBody.conditions method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rule/{rule_id}/alert/{alert_id}/_unmute'].post update: x-apievangelist-phrasing: intent: Unmute one alert of a rule effect: write questions: - How do I unmute a single alert I muted earlier? - Can one muted alert instance trigger actions again? instructions: - text: Unmute alert {alert_id} on rule {rule_id}. slots: alert_id: path.alert_id rule_id: path.rule_id - text: Let alert {alert_id} from rule {rule_id} notify again after muting. slots: alert_id: path.alert_id rule_id: path.rule_id method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rule/{rule_id}/alert/{alert_id}/_unsnooze'].post update: x-apievangelist-phrasing: intent: Unsnooze one alert of a rule effect: write questions: - How do I end the snooze on one alert before it expires? - Can I cancel a single alert's snooze condition? instructions: - text: Unsnooze alert {alert_id} on rule {rule_id}. slots: alert_id: path.alert_id rule_id: path.rule_id - text: Cancel the snooze on alert {alert_id} of rule {rule_id} early. slots: alert_id: path.alert_id rule_id: path.rule_id method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rule/{ruleId}/snooze_schedule/{scheduleId}'].delete update: x-apievangelist-phrasing: intent: Delete a rule's snooze schedule effect: destructive questions: - How do I remove a scheduled snooze from a rule? - Can I cancel one recurring snooze window on a rule? instructions: - text: Delete snooze schedule {scheduleId} from rule {ruleId}. slots: scheduleId: path.scheduleId ruleId: path.ruleId - text: Remove the scheduled quiet period {scheduleId} on rule {ruleId}. slots: scheduleId: path.scheduleId ruleId: path.ruleId method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rules/_find'].get update: x-apievangelist-phrasing: intent: Search and list rules effect: read questions: - Which rules match a search term or KQL filter? - Can I page through rules and return only certain fields? instructions: - text: Find rules matching {search}. slots: search: query.search - text: List rules filtered by {filter}, sorted by {sort_field} {sort_order}. slots: filter: query.filter sort_field: query.sort_field sort_order: query.sort_order - text: Show page {page} of rules, {per_page} per page. slots: page: query.page per_page: query.per_page method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rules/backfill/_find'].post update: x-apievangelist-phrasing: intent: Find rule backfills effect: read questions: - Which backfill runs are scheduled or running for my rules? - Can I filter backfills by rule and by time window? instructions: - text: Find backfills for rules {rule_ids}. slots: rule_ids: query.rule_ids - text: List backfills that cover {start} to {end}, sorted by {sort_field}. slots: start: query.start end: query.end sort_field: query.sort_field method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rules/backfill/_schedule'].post update: x-apievangelist-phrasing: intent: Schedule a rule backfill effect: write questions: - Can I rerun a rule over a past time range to catch missed alerts? - What call schedules a backfill for one or more rules? instructions: - text: Schedule a backfill for my rules, sending kbn-xsrf header {kbn_xsrf}. slots: kbn_xsrf: header.kbn-xsrf - text: Queue a historical backfill run for the rules I choose. method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rules/backfill/{id}'].get update: x-apievangelist-phrasing: intent: Get a backfill effect: read questions: - What is the status of a specific backfill I scheduled? - Can I look up one backfill by its ID? instructions: - text: Get backfill {id}. slots: id: path.id - text: Show the progress of backfill {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/alerting/rules/backfill/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a backfill effect: destructive questions: - How do I cancel a backfill I no longer want? - Can I delete one scheduled backfill by its ID? instructions: - text: Delete backfill {id}. slots: id: path.id - text: Cancel and remove the backfill {id}. slots: id: path.id method: generated generated: '2026-09-26'