# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Elasticsearch Request & Response Specification ml anomaly API version: 1.0.0 extends: openapi/elk-stack-ml-anomaly-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 70 - target: $.paths['/_ml/anomaly_detectors/{job_id}/_close'].post update: x-apievangelist-phrasing: intent: Close an anomaly detection job effect: write questions: - Can I still look at results after I close an anomaly detection job? - What happens to a machine learning job once it is closed and stops receiving data? - Is there a way to force-close a job that won't close cleanly? instructions: - text: Close anomaly detection job {job_id}. slots: job_id: path.job_id - text: Force-close ML job {job_id} and give it {timeout} to finish. slots: job_id: path.job_id timeout: query.timeout method: generated generated: '2026-09-26' - target: $.paths['/_ml/calendars/{calendar_id}'].get update: x-apievangelist-phrasing: intent: Get one ML calendar's configuration effect: read questions: - What jobs are attached to a specific machine learning calendar? - Can I look up a single ML calendar by its ID? instructions: - text: Show me the configuration of ML calendar {calendar_id}. slots: calendar_id: path.calendar_id - text: Fetch calendar {calendar_id} with a GET request. slots: calendar_id: path.calendar_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/calendars/{calendar_id}'].put update: x-apievangelist-phrasing: intent: Create an ML calendar effect: write questions: - How do I create a calendar for planned downtime in Elastic machine learning? - Can a new calendar be linked to several anomaly jobs when I create it? instructions: - text: Create ML calendar {calendar_id} for jobs {job_ids}. slots: calendar_id: path.calendar_id job_ids: requestBody.job_ids - text: Create a new calendar {calendar_id} described as {description}. slots: calendar_id: path.calendar_id description: requestBody.description method: generated generated: '2026-09-26' - target: $.paths['/_ml/calendars/{calendar_id}'].post update: x-apievangelist-phrasing: intent: Get one ML calendar via POST body paging effect: read questions: - Can I fetch a specific ML calendar using a POST request with paging in the body? - Which endpoint lets me page a named calendar's details through a request body? instructions: - text: Using a POST body, get calendar {calendar_id} with page settings {page}. slots: calendar_id: path.calendar_id page: requestBody.page - text: POST to read calendar {calendar_id}'s configuration. slots: calendar_id: path.calendar_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/calendars/{calendar_id}'].delete update: x-apievangelist-phrasing: intent: Delete an ML calendar effect: destructive questions: - Does deleting a machine learning calendar also remove its scheduled events? - How can I get rid of a calendar I no longer need for anomaly jobs? instructions: - text: Delete ML calendar {calendar_id}. slots: calendar_id: path.calendar_id - text: Remove calendar {calendar_id} and all its scheduled events. slots: calendar_id: path.calendar_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/calendars/{calendar_id}/events/{event_id}'].delete update: x-apievangelist-phrasing: intent: Delete a scheduled event from a calendar effect: destructive questions: - Can I remove one scheduled event from an ML calendar without deleting the calendar? - What do I need to drop a single maintenance window event from a calendar? instructions: - text: Delete event {event_id} from calendar {calendar_id}. slots: event_id: path.event_id calendar_id: path.calendar_id - text: Remove scheduled event {event_id} on ML calendar {calendar_id}. slots: event_id: path.event_id calendar_id: path.calendar_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/calendars/{calendar_id}/jobs/{job_id}'].put update: x-apievangelist-phrasing: intent: Add an anomaly job to a calendar effect: write questions: - How do I make an existing anomaly job respect a calendar's scheduled events? - Can I attach one more job to a calendar that already exists? instructions: - text: Add anomaly job {job_id} to calendar {calendar_id}. slots: job_id: path.job_id calendar_id: path.calendar_id - text: Attach job {job_id} to ML calendar {calendar_id} so it skips those events. slots: job_id: path.job_id calendar_id: path.calendar_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/calendars/{calendar_id}/jobs/{job_id}'].delete update: x-apievangelist-phrasing: intent: Remove an anomaly job from a calendar effect: destructive questions: - Can I detach a job from a calendar without deleting the calendar itself? - What's the way to stop a specific job following a calendar's events? instructions: - text: Remove job {job_id} from calendar {calendar_id}. slots: job_id: path.job_id calendar_id: path.calendar_id - text: Detach anomaly job {job_id} from ML calendar {calendar_id}. slots: job_id: path.job_id calendar_id: path.calendar_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/datafeeds/{datafeed_id}'].get update: x-apievangelist-phrasing: intent: Get configuration for specific datafeeds effect: read questions: - Can I look up several datafeeds at once with a comma-separated list or wildcard? - What indices and query is a particular datafeed configured with? instructions: - text: Show the configuration of datafeed {datafeed_id}. slots: datafeed_id: path.datafeed_id - text: Get datafeeds matching {datafeed_id} without generated fields ({exclude_generated}). slots: datafeed_id: path.datafeed_id exclude_generated: query.exclude_generated method: generated generated: '2026-09-26' - target: $.paths['/_ml/datafeeds/{datafeed_id}'].put update: x-apievangelist-phrasing: intent: Create a datafeed for an anomaly job effect: write questions: - How do I feed data from Elasticsearch indices into an anomaly detection job? - Can one anomaly job have more than one datafeed? - Can a new datafeed use a custom query and aggregations? instructions: - text: Create datafeed {datafeed_id} for job {job_id} reading from indices {indices}. slots: datafeed_id: path.datafeed_id job_id: requestBody.job_id indices: requestBody.indices - text: Set up datafeed {datafeed_id} that filters source data with query {query}. slots: datafeed_id: path.datafeed_id query: requestBody.query method: generated generated: '2026-09-26' - target: $.paths['/_ml/datafeeds/{datafeed_id}'].delete update: x-apievangelist-phrasing: intent: Delete a datafeed effect: destructive questions: - Can I delete a datafeed that is still running? - What removes a datafeed I no longer use for anomaly detection? instructions: - text: Delete datafeed {datafeed_id}. slots: datafeed_id: path.datafeed_id - text: Force-delete running datafeed {datafeed_id}. slots: datafeed_id: path.datafeed_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/_delete_expired_data/{job_id}'].delete update: x-apievangelist-phrasing: intent: Purge expired ML data for one job effect: destructive questions: - Can I clean up expired results and snapshots for just one anomaly job? - Which call deletes retention-expired forecast data for a specific job? instructions: - text: Delete expired results and snapshots for job {job_id}. slots: job_id: path.job_id - text: Purge expired ML data for job {job_id}, throttled to {requests_per_second} requests per second. slots: job_id: path.job_id requests_per_second: query.requests_per_second method: generated generated: '2026-09-26' - target: $.paths['/_ml/_delete_expired_data'].delete update: x-apievangelist-phrasing: intent: Purge expired ML data across all jobs effect: destructive questions: - How can I clear out expired results, snapshots and forecasts for every ML job? - Is there a cluster-wide cleanup for machine learning data past its retention period? instructions: - text: Delete expired machine learning data for all jobs. - text: Run the cluster-wide expired ML data cleanup with a {timeout} timeout. slots: timeout: query.timeout method: generated generated: '2026-09-26' - target: $.paths['/_ml/filters/{filter_id}'].get update: x-apievangelist-phrasing: intent: Get one ML filter effect: read questions: - What strings are in a specific machine learning filter? - Can I look up a single filter used by my detection rules? instructions: - text: Show the items in ML filter {filter_id}. slots: filter_id: path.filter_id - text: Get filter {filter_id}. slots: filter_id: path.filter_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/filters/{filter_id}'].put update: x-apievangelist-phrasing: intent: Create an ML filter list effect: write questions: - How do I create a list of values that custom rules in anomaly jobs can reference? - Can a filter be shared by several anomaly detection jobs? instructions: - text: Create filter {filter_id} containing {items}. slots: filter_id: path.filter_id items: requestBody.items - text: Create ML filter {filter_id} described as {description}. slots: filter_id: path.filter_id description: requestBody.description method: generated generated: '2026-09-26' - target: $.paths['/_ml/filters/{filter_id}'].delete update: x-apievangelist-phrasing: intent: Delete an ML filter effect: destructive questions: - Why can't I delete a filter that a job still references? - What removes an ML filter list I no longer need? instructions: - text: Delete ML filter {filter_id}. slots: filter_id: path.filter_id - text: Remove the unused filter {filter_id}. slots: filter_id: path.filter_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/_forecast'].post update: x-apievangelist-phrasing: intent: Forecast future values for an anomaly job effect: write questions: - Can I predict how a time series will behave over the next few days? - Why do forecasts fail on population analysis jobs? - How long are forecast results kept by default? instructions: - text: Forecast job {job_id} for the next {duration}. slots: job_id: path.job_id duration: query.duration - text: Run a forecast on {job_id} that expires in {expires_in}. slots: job_id: path.job_id expires_in: query.expires_in method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/_forecast'].delete update: x-apievangelist-phrasing: intent: Delete all forecasts from a job effect: destructive questions: - Can I wipe every forecast a job has before its retention ends? - What clears all forecast results from an anomaly job at once? instructions: - text: Delete all forecasts for job {job_id}. slots: job_id: path.job_id - text: Clear every forecast on {job_id}, succeeding even if there are none. slots: job_id: path.job_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/_forecast/{forecast_id}'].delete update: x-apievangelist-phrasing: intent: Delete specific forecasts from a job effect: destructive questions: - Can I delete only one forecast by its ID and keep the others? - What removes particular forecast runs from an anomaly job? instructions: - text: Delete forecast {forecast_id} from job {job_id}. slots: forecast_id: path.forecast_id job_id: path.job_id - text: Remove forecasts {forecast_id} on anomaly job {job_id}. slots: forecast_id: path.forecast_id job_id: path.job_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}'].get update: x-apievangelist-phrasing: intent: Get configuration of specific anomaly jobs effect: read questions: - Can I get the detectors and settings of a job by name, group or wildcard? - What configuration does a particular anomaly detection job have? instructions: - text: Show the configuration of anomaly job {job_id}. slots: job_id: path.job_id - text: Get config for all jobs in group {job_id}. slots: job_id: path.job_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}'].put update: x-apievangelist-phrasing: intent: Create an anomaly detection job effect: write questions: - How do I set up a new anomaly detection job in Elastic? - Can I include a datafeed config when I create the job? - What analysis and data description settings must a new job define? instructions: - text: Create anomaly job {job_id} with analysis config {analysis_config} and data description {data_description}. slots: job_id: path.job_id analysis_config: requestBody.analysis_config data_description: requestBody.data_description - text: Create job {job_id} in groups {groups} with the given detectors {analysis_config} and time field {data_description}. slots: job_id: path.job_id groups: requestBody.groups analysis_config: requestBody.analysis_config data_description: requestBody.data_description method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}'].delete update: x-apievangelist-phrasing: intent: Delete an anomaly detection job effect: destructive questions: - Does deleting an anomaly job remove its model state and results too? - Can I delete several jobs at once with a wildcard? instructions: - text: Delete anomaly detection job {job_id}. slots: job_id: path.job_id - text: Force-delete job {job_id} and its user annotations. slots: job_id: path.job_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/model_snapshots/{snapshot_id}'].get update: x-apievangelist-phrasing: intent: Get a specific model snapshot effect: read questions: - What does a particular model snapshot of my anomaly job contain? - Can I look up one snapshot by its ID? instructions: - text: Show snapshot {snapshot_id} for job {job_id}. slots: snapshot_id: path.snapshot_id job_id: path.job_id - text: Get model snapshot {snapshot_id} of anomaly job {job_id} with a GET request. slots: snapshot_id: path.snapshot_id job_id: path.job_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/model_snapshots/{snapshot_id}'].post update: x-apievangelist-phrasing: intent: Get a specific model snapshot via POST body effect: read questions: - Can I fetch one model snapshot using a POST request body for sort and range? - Which call reads a named snapshot with filters passed in the body? instructions: - text: Using a POST body, get snapshot {snapshot_id} of job {job_id}. slots: snapshot_id: path.snapshot_id job_id: path.job_id - text: POST to read snapshot {snapshot_id} on job {job_id} sorted by {sort}. slots: snapshot_id: path.snapshot_id job_id: path.job_id sort: requestBody.sort method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/model_snapshots/{snapshot_id}'].delete update: x-apievangelist-phrasing: intent: Delete a model snapshot effect: destructive questions: - Why can't I delete the active model snapshot of a job? - What removes an old model snapshot I no longer need? instructions: - text: Delete model snapshot {snapshot_id} from job {job_id}. slots: snapshot_id: path.snapshot_id job_id: path.job_id - text: Remove the unused snapshot {snapshot_id} on anomaly job {job_id}. slots: snapshot_id: path.snapshot_id job_id: path.job_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/_estimate_model_memory'].post update: x-apievangelist-phrasing: intent: Estimate an anomaly job's model memory effect: read questions: - How much memory will an anomaly detection job model need before I create it? - Can field cardinality estimates improve the memory prediction? instructions: - text: Estimate model memory for analysis config {analysis_config}. slots: analysis_config: requestBody.analysis_config - text: Estimate job memory with analysis config {analysis_config} and overall cardinality {overall_cardinality}. slots: analysis_config: requestBody.analysis_config overall_cardinality: requestBody.overall_cardinality method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/_flush'].post update: x-apievangelist-phrasing: intent: Flush buffered data in an anomaly job effect: write questions: - Can I force an anomaly job to process data it has buffered? - Is it possible to calculate interim results when flushing a job? instructions: - text: Flush buffered data for job {job_id}. slots: job_id: path.job_id - text: Flush job {job_id} and advance time to {advance_time}. slots: job_id: path.job_id advance_time: query.advance_time method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/results/buckets/{timestamp}'].get update: x-apievangelist-phrasing: intent: Get the result bucket at a timestamp effect: read questions: - What did an anomaly job find in the bucket at a specific time? - Can I read a single result bucket by its timestamp? instructions: - text: Get the bucket at {timestamp} for job {job_id}. slots: timestamp: path.timestamp job_id: path.job_id - text: Show the result bucket for job {job_id} at {timestamp} with records expanded. slots: job_id: path.job_id timestamp: path.timestamp method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/results/buckets/{timestamp}'].post update: x-apievangelist-phrasing: intent: Get a timestamped bucket via POST body effect: read questions: - Can I fetch one timestamped result bucket with its options sent in a POST body? - Which endpoint reads a specific bucket using a request body? instructions: - text: Using a POST body, get bucket {timestamp} of job {job_id}. slots: timestamp: path.timestamp job_id: path.job_id - text: POST for job {job_id}'s bucket at {timestamp} with anomaly score at least {anomaly_score}. slots: job_id: path.job_id timestamp: path.timestamp anomaly_score: requestBody.anomaly_score method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/results/buckets'].get update: x-apievangelist-phrasing: intent: List result buckets for an anomaly job effect: read questions: - How do I see a chronological view of an anomaly job's results? - Can I list only buckets above a certain anomaly score? instructions: - text: List result buckets for job {job_id}. slots: job_id: path.job_id - text: List buckets for {job_id} between {start} and {end} with score over {anomaly_score}. slots: job_id: path.job_id start: query.start end: query.end anomaly_score: query.anomaly_score method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/results/buckets'].post update: x-apievangelist-phrasing: intent: List result buckets via POST body effect: read questions: - Can I page through all of a job's buckets using filters in a POST body? - Which call lists bucket results when I'd rather send the time range in the body? instructions: - text: Using a POST body, list buckets for job {job_id} from {start} to {end}. slots: job_id: path.job_id start: requestBody.start end: requestBody.end - text: POST to list all buckets for {job_id} with paging {page}. slots: job_id: path.job_id page: requestBody.page method: generated generated: '2026-09-26' - target: $.paths['/_ml/calendars/{calendar_id}/events'].get update: x-apievangelist-phrasing: intent: List scheduled events in a calendar effect: read questions: - What maintenance events are scheduled in a machine learning calendar? - Can I see only events that affect a particular job? instructions: - text: List scheduled events in calendar {calendar_id}. slots: calendar_id: path.calendar_id - text: Show events in {calendar_id} between {start} and {end}. slots: calendar_id: path.calendar_id start: query.start end: query.end method: generated generated: '2026-09-26' - target: $.paths['/_ml/calendars/{calendar_id}/events'].post update: x-apievangelist-phrasing: intent: Add scheduled events to a calendar effect: write questions: - How do I schedule a holiday or outage so anomaly jobs ignore it? - Can I add several events to a calendar in one request? instructions: - text: Add events {events} to calendar {calendar_id}. slots: events: requestBody.events calendar_id: path.calendar_id - text: Schedule these downtime events {events} on ML calendar {calendar_id}. slots: events: requestBody.events calendar_id: path.calendar_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/calendars'].get update: x-apievangelist-phrasing: intent: List all ML calendars effect: read questions: - Which machine learning calendars exist in my cluster? - Can I page through every calendar I've set up? instructions: - text: List all ML calendars. - text: List calendars starting at {from}, {size} per page. slots: from: query.from size: query.size method: generated generated: '2026-09-26' - target: $.paths['/_ml/calendars'].post update: x-apievangelist-phrasing: intent: List all ML calendars via POST body effect: read questions: - Can I list every calendar with paging options sent in a POST body? - Which call returns all calendars when a GET isn't convenient? instructions: - text: Using a POST body, list all calendars with paging {page}. slots: page: requestBody.page - text: POST to list every machine learning calendar. method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/results/categories/{category_id}'].get update: x-apievangelist-phrasing: intent: Get one category result for a job effect: read questions: - What log messages fall into a particular category of my anomaly job? - Can I look up one categorization result by its ID? instructions: - text: Get category {category_id} for job {job_id}. slots: category_id: path.category_id job_id: path.job_id - text: Show category {category_id} of anomaly job {job_id} with a GET request. slots: category_id: path.category_id job_id: path.job_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/results/categories/{category_id}'].post update: x-apievangelist-phrasing: intent: Get one category result via POST body effect: read questions: - Can I fetch a single category result using a POST request? - Which endpoint reads a specific category with paging in the body? instructions: - text: Using a POST body, get category {category_id} of job {job_id}. slots: category_id: path.category_id job_id: path.job_id - text: POST to read category {category_id} on job {job_id} for partition {partition_field_value}. slots: category_id: path.category_id job_id: path.job_id partition_field_value: query.partition_field_value method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/results/categories'].get update: x-apievangelist-phrasing: intent: List category results for a job effect: read questions: - What message categories has my categorization job discovered? - Can I list categories only for one partition value? instructions: - text: List all categories for job {job_id}. slots: job_id: path.job_id - text: List categories of {job_id} for partition {partition_field_value}, {size} at a time. slots: job_id: path.job_id partition_field_value: query.partition_field_value size: query.size method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/results/categories'].post update: x-apievangelist-phrasing: intent: List category results via POST body effect: read questions: - Can I list every category of a job with paging sent in a POST body? - Which call pages through all categories using a request body? instructions: - text: Using a POST body, list categories for job {job_id} with paging {page}. slots: job_id: path.job_id page: requestBody.page - text: POST to list all categorization results of {job_id}. slots: job_id: path.job_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/datafeeds/{datafeed_id}/_stats'].get update: x-apievangelist-phrasing: intent: Get stats for specific datafeeds effect: read questions: - Is a particular datafeed started or stopped right now? - Can I check stats for several named datafeeds in one call? instructions: - text: Show stats for datafeed {datafeed_id}. slots: datafeed_id: path.datafeed_id - text: Get running state and timing stats for datafeeds {datafeed_id}. slots: datafeed_id: path.datafeed_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/datafeeds/_stats'].get update: x-apievangelist-phrasing: intent: Get stats for all datafeeds effect: read questions: - Which of my datafeeds are currently running? - What's the overall state of every datafeed in the cluster? instructions: - text: Show stats for all datafeeds. - text: Get every datafeed's stats, erroring if none match ({allow_no_match}). slots: allow_no_match: query.allow_no_match method: generated generated: '2026-09-26' - target: $.paths['/_ml/datafeeds'].get update: x-apievangelist-phrasing: intent: List all datafeed configurations effect: read questions: - What datafeeds are configured in my cluster? - Can I export all datafeed configs without generated fields? instructions: - text: List all datafeed configurations. - text: List every datafeed config with exclude_generated set to {exclude_generated}. slots: exclude_generated: query.exclude_generated method: generated generated: '2026-09-26' - target: $.paths['/_ml/filters'].get update: x-apievangelist-phrasing: intent: List all ML filters effect: read questions: - Which filter lists exist for my anomaly detection rules? - Can I page through all ML filters? instructions: - text: List all ML filters. - text: List filters from {from}, {size} per page. slots: from: query.from size: query.size method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/results/influencers'].get update: x-apievangelist-phrasing: intent: List influencers behind a job's anomalies effect: read questions: - Which entities contributed most to the anomalies my job found? - Can I list only influencers above a certain influencer score? instructions: - text: List influencers for job {job_id}. slots: job_id: path.job_id - text: Show influencers of {job_id} with score above {influencer_score} since {start}. slots: job_id: path.job_id influencer_score: query.influencer_score start: query.start method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/results/influencers'].post update: x-apievangelist-phrasing: intent: List influencers via POST body effect: read questions: - Can I page through a job's influencer results with a POST request body? - Which call lists influencers when paging is sent in the body? instructions: - text: Using a POST body, list influencers for job {job_id} with paging {page}. slots: job_id: path.job_id page: requestBody.page - text: POST to get the entities to blame for anomalies in {job_id}. slots: job_id: path.job_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/_stats'].get update: x-apievangelist-phrasing: intent: Get stats for all anomaly jobs effect: read questions: - What state are all my anomaly detection jobs in? - How much data have my ML jobs processed overall? instructions: - text: Show stats for every anomaly detection job. - text: Get all job stats, allowing an empty match ({allow_no_match}). slots: allow_no_match: query.allow_no_match method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/_stats'].get update: x-apievangelist-phrasing: intent: Get stats for a specific anomaly job effect: read questions: - Is a particular anomaly job opened or closed, and how many records has it processed? - Can I check model memory usage for one job? instructions: - text: Show stats for anomaly job {job_id}. slots: job_id: path.job_id - text: Get data counts and state for jobs {job_id}. slots: job_id: path.job_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors'].get update: x-apievangelist-phrasing: intent: List all anomaly detection jobs effect: read questions: - What anomaly detection jobs have been set up in my cluster? - Can I export every job's configuration without generated fields? instructions: - text: List all anomaly detection jobs. - text: List every job config with exclude_generated {exclude_generated}. slots: exclude_generated: query.exclude_generated method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/model_snapshots/{snapshot_id}/_upgrade/_stats'].get update: x-apievangelist-phrasing: intent: Check model snapshot upgrade progress effect: read questions: - Is my model snapshot upgrade still running? - Where can I see the status of a snapshot being upgraded to a new version? instructions: - text: Show upgrade stats for snapshot {snapshot_id} of job {job_id}. slots: snapshot_id: path.snapshot_id job_id: path.job_id - text: Check whether the upgrade of snapshot {snapshot_id} on {job_id} has finished. slots: snapshot_id: path.snapshot_id job_id: path.job_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/model_snapshots'].get update: x-apievangelist-phrasing: intent: List model snapshots for a job effect: read questions: - Which model snapshots does my anomaly job have to revert to? - Can I list snapshots taken within a time range? instructions: - text: List model snapshots for job {job_id}. slots: job_id: path.job_id - text: List snapshots of {job_id} from {start} to {end}, newest first. slots: job_id: path.job_id start: query.start end: query.end method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/model_snapshots'].post update: x-apievangelist-phrasing: intent: List model snapshots via POST body effect: read questions: - Can I list all of a job's snapshots with filters sent in a POST body? - Which call pages every snapshot of a job through a request body? instructions: - text: Using a POST body, list snapshots of job {job_id} with paging {page}. slots: job_id: path.job_id page: requestBody.page - text: POST to list all model snapshots for {job_id} sorted by {sort}. slots: job_id: path.job_id sort: requestBody.sort method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/results/overall_buckets'].get update: x-apievangelist-phrasing: intent: Get overall buckets across several jobs effect: read questions: - How can I see a combined anomaly score across multiple jobs over time? - Can I only return overall buckets above a certain score? instructions: - text: Get overall buckets for jobs {job_id}. slots: job_id: path.job_id - text: Get overall buckets for {job_id} using the top {top_n} jobs and a {bucket_span} span. slots: job_id: path.job_id top_n: query.top_n bucket_span: query.bucket_span method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/results/overall_buckets'].post update: x-apievangelist-phrasing: intent: Get overall buckets via POST body effect: read questions: - Can I request overall bucket summaries with settings in a POST body? - Which call combines scores across jobs when I send the options in the body? instructions: - text: Using a POST body, get overall buckets for {job_id} with score at least {overall_score}. slots: job_id: path.job_id overall_score: requestBody.overall_score - text: POST for the summarized overall buckets of jobs {job_id}. slots: job_id: path.job_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/results/records'].get update: x-apievangelist-phrasing: intent: List anomaly records for a job effect: read questions: - What exact anomalous events did my detection job flag? - Can I list only records with a high record score? instructions: - text: List anomaly records for job {job_id}. slots: job_id: path.job_id - text: Show records of {job_id} scoring over {record_score} since {start}. slots: job_id: path.job_id record_score: query.record_score start: query.start method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/results/records'].post update: x-apievangelist-phrasing: intent: List anomaly records via POST body effect: read questions: - Can I fetch detailed anomaly records using a POST request body? - Which call pages anomaly records with the sort passed in the body? instructions: - text: Using a POST body, list anomaly records for {job_id} sorted by {sort}. slots: job_id: path.job_id sort: requestBody.sort - text: POST to get records for job {job_id} with paging {page}. slots: job_id: path.job_id page: requestBody.page method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/_open'].post update: x-apievangelist-phrasing: intent: Open an anomaly detection job effect: write questions: - What do I need to do before a job can receive and analyze data? - Does reopening a job restore its model state? instructions: - text: Open anomaly job {job_id}. slots: job_id: path.job_id - text: Open job {job_id} and wait up to {timeout}. slots: job_id: path.job_id timeout: query.timeout method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/_data'].post update: x-apievangelist-phrasing: intent: Send data to an anomaly job effect: write questions: - Can I push data straight into an anomaly job without a datafeed? - Is it possible to post data to multiple jobs at once? instructions: - text: Send this data to job {job_id} for analysis. slots: job_id: path.job_id - text: Post data to {job_id} and reset buckets from {reset_start} to {reset_end}. slots: job_id: path.job_id reset_start: query.reset_start reset_end: query.reset_end method: generated generated: '2026-09-26' - target: $.paths['/_ml/datafeeds/{datafeed_id}/_preview'].get update: x-apievangelist-phrasing: intent: Preview an existing datafeed's data effect: read questions: - What data will a datafeed I already created actually return? - Can I preview a datafeed's output for a specific time window? instructions: - text: Preview datafeed {datafeed_id}. slots: datafeed_id: path.datafeed_id - text: Preview the first page of {datafeed_id} starting at {start}. slots: datafeed_id: path.datafeed_id start: query.start method: generated generated: '2026-09-26' - target: $.paths['/_ml/datafeeds/{datafeed_id}/_preview'].post update: x-apievangelist-phrasing: intent: Preview an existing datafeed via POST effect: read questions: - Can I preview a named datafeed using a POST request? - Which call previews an existing datafeed with overrides in the body? instructions: - text: Using POST, preview datafeed {datafeed_id} from {start} to {end}. slots: datafeed_id: path.datafeed_id start: query.start end: query.end - text: POST a preview request for datafeed {datafeed_id}. slots: datafeed_id: path.datafeed_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/datafeeds/_preview'].get update: x-apievangelist-phrasing: intent: Preview an unsaved datafeed config effect: read questions: - Can I test a datafeed configuration before creating it? - What would a draft datafeed return for a draft job config? instructions: - text: Preview datafeed config {datafeed_config} with job config {job_config}. slots: datafeed_config: requestBody.datafeed_config job_config: requestBody.job_config - text: Show a preview of the unsaved datafeed {datafeed_config}. slots: datafeed_config: requestBody.datafeed_config method: generated generated: '2026-09-26' - target: $.paths['/_ml/datafeeds/_preview'].post update: x-apievangelist-phrasing: intent: Preview an unsaved datafeed config via POST effect: read questions: - Can I POST a draft datafeed and job config to see sample results? - Which POST call previews a datafeed that hasn't been created? instructions: - text: Using POST, preview draft datafeed {datafeed_config} for job {job_config}. slots: datafeed_config: requestBody.datafeed_config job_config: requestBody.job_config - text: POST a preview for datafeed config {datafeed_config} starting at {start}. slots: datafeed_config: requestBody.datafeed_config start: query.start method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/_reset'].post update: x-apievangelist-phrasing: intent: Reset an anomaly job to start over effect: destructive questions: - Can I wipe a job's model state and results but keep its configuration? - What makes an anomaly job behave as if it had just been created? instructions: - text: Reset anomaly job {job_id}. slots: job_id: path.job_id - text: Reset job {job_id} and also delete user annotations. slots: job_id: path.job_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/model_snapshots/{snapshot_id}/_revert'].post update: x-apievangelist-phrasing: intent: Revert an anomaly job to a snapshot effect: destructive questions: - How do I roll a job's model back to before an unusual event skewed it? - Can I delete results produced after the snapshot I revert to? instructions: - text: Revert job {job_id} to snapshot {snapshot_id}. slots: job_id: path.job_id snapshot_id: path.snapshot_id - text: Roll {job_id} back to snapshot {snapshot_id} and delete intervening results. slots: job_id: path.job_id snapshot_id: path.snapshot_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/datafeeds/{datafeed_id}/_start'].post update: x-apievangelist-phrasing: intent: Start a datafeed effect: write questions: - What needs to be open before I start a datafeed? - Can I start a datafeed from a specific time and have it stop at an end time? instructions: - text: Start datafeed {datafeed_id}. slots: datafeed_id: path.datafeed_id - text: Start {datafeed_id} from {start} and stop at {end}. slots: datafeed_id: path.datafeed_id start: query.start end: query.end method: generated generated: '2026-09-26' - target: $.paths['/_ml/datafeeds/{datafeed_id}/_stop'].post update: x-apievangelist-phrasing: intent: Stop a datafeed effect: write questions: - Can I stop a datafeed from pulling data and close its job at the same time? - Is there a way to force-stop a stuck datafeed? instructions: - text: Stop datafeed {datafeed_id}. slots: datafeed_id: path.datafeed_id - text: Force-stop {datafeed_id} within {timeout}. slots: datafeed_id: path.datafeed_id timeout: query.timeout method: generated generated: '2026-09-26' - target: $.paths['/_ml/datafeeds/{datafeed_id}/_update'].post update: x-apievangelist-phrasing: intent: Update a datafeed's settings effect: write questions: - Do I have to restart a datafeed for my config changes to apply? - Can I change the query or indices of a datafeed I already created? instructions: - text: Update datafeed {datafeed_id} to use query {query}. slots: datafeed_id: path.datafeed_id query: requestBody.query - text: Change the indices of existing datafeed {datafeed_id} to {indices}. slots: datafeed_id: path.datafeed_id indices: requestBody.indices method: generated generated: '2026-09-26' - target: $.paths['/_ml/filters/{filter_id}/_update'].post update: x-apievangelist-phrasing: intent: Add or remove items in an ML filter effect: write questions: - Can I add new values to a filter list without recreating it? - How are items removed from an existing ML filter? instructions: - text: Add {add_items} to filter {filter_id}. slots: add_items: requestBody.add_items filter_id: path.filter_id - text: Remove {remove_items} from ML filter {filter_id}. slots: remove_items: requestBody.remove_items filter_id: path.filter_id method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/_update'].post update: x-apievangelist-phrasing: intent: Update an anomaly job's properties effect: write questions: - Which settings of an existing anomaly job can I change? - Can I change the results retention days of a job after it's created? instructions: - text: Update job {job_id} description to {description}. slots: job_id: path.job_id description: requestBody.description - text: Set results retention on existing job {job_id} to {results_retention_days} days. slots: job_id: path.job_id results_retention_days: requestBody.results_retention_days method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/model_snapshots/{snapshot_id}/_update'].post update: x-apievangelist-phrasing: intent: Update a model snapshot's properties effect: write questions: - Can I keep a model snapshot from being deleted by retention? - Is it possible to relabel a snapshot's description? instructions: - text: 'Mark snapshot {snapshot_id} of job {job_id} as retained: {retain}.' slots: snapshot_id: path.snapshot_id job_id: path.job_id retain: requestBody.retain - text: Set the description of snapshot {snapshot_id} on {job_id} to {description}. slots: snapshot_id: path.snapshot_id job_id: path.job_id description: requestBody.description method: generated generated: '2026-09-26' - target: $.paths['/_ml/anomaly_detectors/{job_id}/model_snapshots/{snapshot_id}/_upgrade'].post update: x-apievangelist-phrasing: intent: Upgrade a model snapshot to the latest version effect: write questions: - What happens to old snapshot formats when I upgrade Elasticsearch major versions? - Can I wait for the snapshot upgrade to complete before the call returns? instructions: - text: Upgrade snapshot {snapshot_id} of job {job_id} to the latest format. slots: snapshot_id: path.snapshot_id job_id: path.job_id - text: Upgrade snapshot {snapshot_id} on {job_id} and wait for completion. slots: snapshot_id: path.snapshot_id job_id: path.job_id method: generated generated: '2026-09-26'