# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Kibana Cases API version: 1.0.0 extends: openapi/elk-stack-cases-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 29 - target: $.paths['/api/cases'].post update: x-apievangelist-phrasing: intent: Open a new case effect: write questions: - How do I open a new security or observability case in Kibana from a script? - Can I set severity, assignees and tags when I first create a case? instructions: - text: Open a case titled {title} described as {description}, owned by {owner}, tagged {tags}. slots: title: requestBody.title description: requestBody.description owner: requestBody.owner tags: requestBody.tags - text: Create a {severity} severity case {title} and assign it to {assignees}. slots: severity: requestBody.severity title: requestBody.title assignees: requestBody.assignees method: generated generated: '2026-09-26' - target: $.paths['/api/cases'].delete update: x-apievangelist-phrasing: intent: Delete one or more cases effect: destructive questions: - How do I permanently delete several Kibana cases at once? - Does deleting a case also remove its comments and attachments? instructions: - text: Delete cases {ids}. slots: ids: query.ids - text: Permanently remove the case with ID {ids}. slots: ids: query.ids method: generated generated: '2026-09-26' - target: $.paths['/api/cases'].patch update: x-apievangelist-phrasing: intent: Update fields on existing cases effect: write questions: - How do I close a case or change its status programmatically? - Can I bulk-update severity or title on several existing cases in one call? instructions: - text: Apply these case updates {cases}. slots: cases: requestBody.cases - text: Mark the existing cases in {cases} as closed. slots: cases: requestBody.cases method: generated generated: '2026-09-26' - target: $.paths['/api/cases/_find'].get update: x-apievangelist-phrasing: intent: Search and filter cases effect: read questions: - Which open cases are assigned to me? - Can I find critical-severity cases created in the last week? - What cases carry a particular tag? instructions: - text: Find cases with status {status} and severity {severity}. slots: status: query.status severity: query.severity - text: Search cases for {search} tagged {tags}. slots: search: query.search tags: query.tags - text: List cases assigned to {assignees} opened between {from} and {to}. slots: assignees: query.assignees from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/cases/{caseId}'].get update: x-apievangelist-phrasing: intent: Get a case's details effect: read questions: - What's the current status and description of a specific case? - Who opened a given case and when? instructions: - text: Show me the details of case {caseId}. slots: caseId: path.caseId - text: Fetch case {caseId} with its title, status and severity. slots: caseId: path.caseId method: generated generated: '2026-09-26' - target: $.paths['/api/cases/{caseId}/alerts'].get update: x-apievangelist-phrasing: intent: List alerts attached to a case effect: read questions: - Which detection alerts have been attached to this case? - How can I see every alert linked to one case? instructions: - text: List all alerts attached to case {caseId}. slots: caseId: path.caseId - text: Get the alert IDs linked to case {caseId}. slots: caseId: path.caseId method: generated generated: '2026-09-26' - target: $.paths['/api/cases/{caseId}/comments'].post update: x-apievangelist-phrasing: intent: Add a comment or alert to a case effect: write questions: - How do I post a note on a case? - Can I attach an alert to a case as a new case attachment? instructions: - text: Add a new comment to case {caseId}. slots: caseId: path.caseId - text: Attach an alert to case {caseId}. slots: caseId: path.caseId method: generated generated: '2026-09-26' - target: $.paths['/api/cases/{caseId}/comments'].delete update: x-apievangelist-phrasing: intent: Delete every comment and alert on a case effect: destructive questions: - How do I wipe all comments and attached alerts from a case in one go? - Can I clear a case's entire comment history? instructions: - text: Delete all comments and alerts from case {caseId}. slots: caseId: path.caseId - text: Clear the whole comment history on case {caseId}. slots: caseId: path.caseId method: generated generated: '2026-09-26' - target: $.paths['/api/cases/{caseId}/comments'].patch update: x-apievangelist-phrasing: intent: Edit an existing case comment or alert effect: write questions: - How do I fix a typo in a comment I already posted on a case? - Can I change an existing alert attachment on a case? instructions: - text: Edit an existing comment on case {caseId}. slots: caseId: path.caseId - text: Update the text of a comment I already posted to case {caseId}. slots: caseId: path.caseId method: generated generated: '2026-09-26' - target: $.paths['/api/cases/{caseId}/comments/_find'].get update: x-apievangelist-phrasing: intent: Page through a case's comments effect: read questions: - What comments have been left on this case, newest first? - Can I paginate through a long comment thread on a case? instructions: - text: Find comments on case {caseId}, sorted {sortOrder}. slots: caseId: path.caseId sortOrder: query.sortOrder - text: Show page {page} of comments on case {caseId}, {perPage} per page. slots: page: query.page caseId: path.caseId perPage: query.perPage method: generated generated: '2026-09-26' - target: $.paths['/api/cases/{caseId}/comments/{commentId}'].get update: x-apievangelist-phrasing: intent: Get one case comment or alert effect: read questions: - How do I read a single comment on a case by its ID? - What does a specific alert attachment on a case contain? instructions: - text: Get comment {commentId} on case {caseId}. slots: commentId: path.commentId caseId: path.caseId - text: Show the attachment {commentId} from case {caseId}. slots: commentId: path.commentId caseId: path.caseId method: generated generated: '2026-09-26' - target: $.paths['/api/cases/{caseId}/comments/{commentId}'].delete update: x-apievangelist-phrasing: intent: Delete a single case comment or alert effect: destructive questions: - How do I remove just one comment from a case? - Can I detach a single alert from a case without touching the other comments? instructions: - text: Delete comment {commentId} from case {caseId}. slots: commentId: path.commentId caseId: path.caseId - text: Remove only attachment {commentId} on case {caseId}. slots: commentId: path.commentId caseId: path.caseId method: generated generated: '2026-09-26' - target: $.paths['/api/cases/{caseId}/connector/{connectorId}/_push'].post update: x-apievangelist-phrasing: intent: Push a case to an external ticketing system effect: write questions: - How do I send a case to an external incident system like Jira or ServiceNow through its connector? - Can I sync the latest case updates to the external service it's linked to? instructions: - text: Push case {caseId} through connector {connectorId}. slots: caseId: path.caseId connectorId: path.connectorId - text: Sync case {caseId} to the external service behind connector {connectorId}. slots: caseId: path.caseId connectorId: path.connectorId method: generated generated: '2026-09-26' - target: $.paths['/api/cases/{caseId}/fields'].get update: x-apievangelist-phrasing: intent: Get fields applicable to an existing case effect: read questions: - Which custom fields apply to a case that's already open? - What fields can I fill in on this particular case? instructions: - text: Get the applicable fields for existing case {caseId}. slots: caseId: path.caseId - text: List the custom fields that apply to case {caseId}. slots: caseId: path.caseId method: generated generated: '2026-09-26' - target: $.paths['/api/cases/{caseId}/files'].post update: x-apievangelist-phrasing: intent: Attach a file to a case effect: write questions: - How do I upload a screenshot or log file to a case? - Can I set a custom filename when attaching a file to a case? instructions: - text: Attach file {file} to case {caseId}. slots: file: requestBody.file caseId: path.caseId - text: Upload {file} to case {caseId} named {filename}. slots: file: requestBody.file caseId: path.caseId filename: requestBody.filename method: generated generated: '2026-09-26' - target: $.paths['/api/cases/{caseId}/user_actions/_find'].get update: x-apievangelist-phrasing: intent: Review a case's activity history effect: read questions: - Who changed what on this case and when? - Can I filter a case's activity log to only status changes or comments? instructions: - text: Show the activity history for case {caseId}. slots: caseId: path.caseId - text: Find user actions of types {types} on case {caseId}. slots: types: query.types caseId: path.caseId method: generated generated: '2026-09-26' - target: $.paths['/api/cases/alerts/{alertId}'].get update: x-apievangelist-phrasing: intent: Find cases that contain an alert effect: read questions: - Which cases is this alert already attached to? - Has a given alert been added to any security case yet? instructions: - text: Find the cases that include alert {alertId}. slots: alertId: path.alertId - text: List {owner} cases containing alert {alertId}. slots: owner: query.owner alertId: path.alertId method: generated generated: '2026-09-26' - target: $.paths['/api/cases/configure'].get update: x-apievangelist-phrasing: intent: Get case settings effect: read questions: - How are cases configured to close and which connector do they use by default? - What custom fields and templates are set up in case settings? instructions: - text: Show the case settings for {owner}. slots: owner: query.owner - text: Get the current case configuration, including default connector and closure type. method: generated generated: '2026-09-26' - target: $.paths['/api/cases/configure'].post update: x-apievangelist-phrasing: intent: Create case settings effect: write questions: - How do I set up the default connector and closure behaviour for cases the first time? - Can I make cases close automatically when they're pushed to an external system? instructions: - text: Create case settings for {owner} with closure type {closure_type} and connector {connector}. slots: owner: requestBody.owner closure_type: requestBody.closure_type connector: requestBody.connector - text: Add initial case settings for {owner} with custom fields {customFields}. slots: owner: requestBody.owner customFields: requestBody.customFields method: generated generated: '2026-09-26' - target: $.paths['/api/cases/configure/{configurationId}'].patch update: x-apievangelist-phrasing: intent: Change existing case settings effect: write questions: - How do I switch the default connector on case settings I already created? - Why do I need to pass a version when editing case settings? instructions: - text: Update case settings {configurationId} at version {version} to closure type {closure_type}. slots: configurationId: path.configurationId version: requestBody.version closure_type: requestBody.closure_type - text: Change the connector on configuration {configurationId} (version {version}) to {connector}. slots: configurationId: path.configurationId version: requestBody.version connector: requestBody.connector method: generated generated: '2026-09-26' - target: $.paths['/api/cases/configure/connectors/_find'].get update: x-apievangelist-phrasing: intent: List connectors usable by cases effect: read questions: - Which external connectors can cases be pushed to? - What case connectors are available in this space? instructions: - text: List the connectors available for cases. - text: Show which ticketing connectors I can attach to cases. method: generated generated: '2026-09-26' - target: $.paths['/api/cases/fields'].get update: x-apievangelist-phrasing: intent: Get fields available to new cases effect: read questions: - What fields would a new case have for a given solution before I open it? - Which fields does a case template add? instructions: - text: Get the fields applicable to {owner} cases. slots: owner: query.owner - text: Show fields a new {owner} case would get from template {templateId}. slots: owner: query.owner templateId: query.templateId method: generated generated: '2026-09-26' - target: $.paths['/api/cases/reporters'].get update: x-apievangelist-phrasing: intent: List users who opened cases effect: read questions: - Who has been opening cases? - Can I see the list of case creators for just security cases? instructions: - text: List the users who opened cases. - text: Show case reporters for {owner}. slots: owner: query.owner method: generated generated: '2026-09-26' - target: $.paths['/api/cases/tags'].get update: x-apievangelist-phrasing: intent: List tags used on cases effect: read questions: - What tags are in use across all my cases? - Which case tags exist for observability cases? instructions: - text: List every tag used on cases. - text: Get the case tags for {owner}. slots: owner: query.owner method: generated generated: '2026-09-26' - target: $.paths['/api/cases/templates'].get update: x-apievangelist-phrasing: intent: List case templates effect: read questions: - What case templates have been defined? - Can I list only enabled case templates by a certain author? instructions: - text: List all case templates. - text: Search case templates for {search} where enabled is {isEnabled}. slots: search: query.search isEnabled: query.isEnabled method: generated generated: '2026-09-26' - target: $.paths['/api/cases/templates'].post update: x-apievangelist-phrasing: intent: Create a case template effect: write questions: - How do I create a reusable template for new cases? - Can I validate a case template with a dry run before saving it? instructions: - text: Create a case template {name} for {owner} with definition {definition}. slots: name: requestBody.name owner: requestBody.owner definition: requestBody.definition - text: Dry-run a new case template for {owner} using definition {definition}. slots: owner: requestBody.owner definition: requestBody.definition method: generated generated: '2026-09-26' - target: $.paths['/api/cases/templates/{template_id}'].get update: x-apievangelist-phrasing: intent: Get a case template effect: read questions: - What does a specific case template define? - Can I fetch an older version of a case template? instructions: - text: Get case template {template_id}. slots: template_id: path.template_id - text: Show version {version} of case template {template_id}. slots: version: query.version template_id: path.template_id method: generated generated: '2026-09-26' - target: $.paths['/api/cases/templates/{template_id}'].put update: x-apievangelist-phrasing: intent: Update a case template effect: write questions: - How do I change the definition of an existing case template? - Can I disable a case template without deleting it? instructions: - text: Replace case template {template_id} for {owner} with definition {definition}. slots: template_id: path.template_id owner: requestBody.owner definition: requestBody.definition - text: Set isEnabled to {isEnabled} on case template {template_id}. slots: isEnabled: requestBody.isEnabled template_id: path.template_id method: generated generated: '2026-09-26' - target: $.paths['/api/cases/templates/{template_id}'].delete update: x-apievangelist-phrasing: intent: Delete a case template effect: destructive questions: - How do I delete a case template I no longer use? - Can I remove a case template by its ID? instructions: - text: Delete case template {template_id}. slots: template_id: path.template_id - text: Remove the case template with ID {template_id}. slots: template_id: path.template_id method: generated generated: '2026-09-26'