# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Kibana Security Attack discovery API version: 1.0.0 extends: openapi/elk-stack-security-attack-discovery-api-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 16 - target: $.paths['/api/attack_discovery/_bulk'].post update: x-apievangelist-phrasing: intent: Bulk update Attack discoveries effect: write questions: - Can I change the workflow status of many Attack discoveries at once? - How do I mark a batch of attack findings as acknowledged or shared in one request? instructions: - text: Apply the bulk Attack discovery update {update}. slots: update: requestBody.update - text: Change the workflow status and visibility of discoveries using {update}. slots: update: requestBody.update method: generated generated: '2026-09-26' - target: $.paths['/api/attack_discovery/_find'].get update: x-apievangelist-phrasing: intent: Search Attack discoveries effect: read questions: - Which Attack discoveries were found in the last day? - Can I filter discoveries by status, connector or the alerts they reference? instructions: - text: Find Attack discoveries matching {search}. slots: search: query.search - text: List discoveries with status {status} between {start} and {end}. slots: status: query.status start: query.start end: query.end - text: Show discoveries that include alert {alert_ids}. slots: alert_ids: query.alert_ids method: generated generated: '2026-09-26' - target: $.paths['/api/attack_discovery/_generate'].post update: x-apievangelist-phrasing: intent: Generate attack discoveries from alerts with AI effect: write questions: - How do I have an AI connector analyse my security alerts for attack chains? - Can I limit how many alerts Attack Discovery analyses in one run? instructions: - text: Generate attack discoveries from alerts in {alertsIndexPattern}, analysing up to {size} alerts with connector config {apiConfig}. slots: alertsIndexPattern: requestBody.alertsIndexPattern size: requestBody.size apiConfig: requestBody.apiConfig - text: Run Attack Discovery on {alertsIndexPattern} from {start} to {end} using connector {connectorName}. slots: alertsIndexPattern: requestBody.alertsIndexPattern start: requestBody.start end: requestBody.end connectorName: requestBody.connectorName method: generated generated: '2026-09-26' - target: $.paths['/api/attack_discovery/generations'].get update: x-apievangelist-phrasing: intent: List my recent Attack Discovery generations effect: read questions: - What is the status of my recent Attack Discovery runs? - Can I see only the scheduled generations and their statistics? instructions: - text: List my latest Attack Discovery generations. - text: Show the last {size} generations between {start} and {end}. slots: size: query.size start: query.start end: query.end method: generated generated: '2026-09-26' - target: $.paths['/api/attack_discovery/generations/{execution_uuid}'].get update: x-apievangelist-phrasing: intent: Get one Attack Discovery generation effect: read questions: - Which attack discoveries did a particular generation run produce? - Can I retrieve a generation's results with anonymized values replaced? instructions: - text: Get Attack Discovery generation {execution_uuid}. slots: execution_uuid: path.execution_uuid - text: Show the discoveries from run {execution_uuid} with replacements set to {with_replacements}. slots: execution_uuid: path.execution_uuid with_replacements: query.with_replacements method: generated generated: '2026-09-26' - target: $.paths['/api/attack_discovery/generations/{execution_uuid}/_dismiss'].post update: x-apievangelist-phrasing: intent: Dismiss an Attack Discovery generation effect: write questions: - How do I stop a finished generation from showing in the UI? - What does dismissing an Attack Discovery generation change? instructions: - text: Dismiss Attack Discovery generation {execution_uuid}. slots: execution_uuid: path.execution_uuid - text: Hide the generation {execution_uuid} from my status view. slots: execution_uuid: path.execution_uuid method: generated generated: '2026-09-26' - target: $.paths['/api/attack_discovery/schedules'].post update: x-apievangelist-phrasing: intent: Create an Attack Discovery schedule effect: write questions: - Can Attack Discovery run automatically on an interval? - How do I set up recurring AI analysis of alerts with actions when findings appear? instructions: - text: Create an Attack Discovery schedule {name} running every {schedule} with params {params}. slots: name: requestBody.name schedule: requestBody.schedule params: requestBody.params - text: Schedule {name} on interval {schedule} with params {params} and notify via {actions}. slots: name: requestBody.name schedule: requestBody.schedule params: requestBody.params actions: requestBody.actions method: generated generated: '2026-09-26' - target: $.paths['/api/attack_discovery/schedules/_bulk_delete'].post update: x-apievangelist-phrasing: intent: Delete several Attack Discovery schedules effect: destructive questions: - Can I delete multiple Attack Discovery schedules at once? - What removes a list of discovery schedules by ID? instructions: - text: Bulk delete Attack Discovery schedules {ids}. slots: ids: requestBody.ids - text: 'Remove all of these discovery schedules: {ids}.' slots: ids: requestBody.ids method: generated generated: '2026-09-26' - target: $.paths['/api/attack_discovery/schedules/_bulk_disable'].post update: x-apievangelist-phrasing: intent: Disable several Attack Discovery schedules effect: write questions: - Can I pause a set of Attack Discovery schedules together? - Which call disables multiple discovery schedules by ID? instructions: - text: Bulk disable Attack Discovery schedules {ids}. slots: ids: requestBody.ids - text: 'Pause all of these discovery schedules: {ids}.' slots: ids: requestBody.ids method: generated generated: '2026-09-26' - target: $.paths['/api/attack_discovery/schedules/_bulk_enable'].post update: x-apievangelist-phrasing: intent: Enable several Attack Discovery schedules effect: write questions: - Can I resume a group of paused Attack Discovery schedules together? - Which call enables multiple discovery schedules by ID? instructions: - text: Bulk enable Attack Discovery schedules {ids}. slots: ids: requestBody.ids - text: 'Resume all of these discovery schedules: {ids}.' slots: ids: requestBody.ids method: generated generated: '2026-09-26' - target: $.paths['/api/attack_discovery/schedules/_find'].get update: x-apievangelist-phrasing: intent: List Attack Discovery schedules effect: read questions: - What Attack Discovery schedules are configured? - Can I sort discovery schedules by a field and page through them? instructions: - text: List my Attack Discovery schedules. - text: Show discovery schedules sorted by {sort_field} {sort_direction}, page {page}. slots: sort_field: query.sort_field sort_direction: query.sort_direction page: query.page method: generated generated: '2026-09-26' - target: $.paths['/api/attack_discovery/schedules/{id}'].get update: x-apievangelist-phrasing: intent: Get an Attack Discovery schedule effect: read questions: - What interval, parameters and actions does one discovery schedule have? - Can I see a schedule's execution history? instructions: - text: Get Attack Discovery schedule {id}. slots: id: path.id - text: Show the configuration and run history of discovery schedule {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/attack_discovery/schedules/{id}'].put update: x-apievangelist-phrasing: intent: Replace an Attack Discovery schedule's settings effect: write questions: - How do I change the interval or connector of an existing discovery schedule? - Does updating a discovery schedule replace its whole configuration? instructions: - text: 'Update discovery schedule {id}: name {name}, interval {schedule}, params {params}, actions {actions}.' slots: id: path.id name: requestBody.name schedule: requestBody.schedule params: requestBody.params actions: requestBody.actions - text: Reconfigure schedule {id} to run every {schedule} as {name} with params {params} and actions {actions}. slots: id: path.id schedule: requestBody.schedule name: requestBody.name params: requestBody.params actions: requestBody.actions method: generated generated: '2026-09-26' - target: $.paths['/api/attack_discovery/schedules/{id}'].delete update: x-apievangelist-phrasing: intent: Delete an Attack Discovery schedule effect: destructive questions: - How do I permanently remove one Attack Discovery schedule? - Is deleting a discovery schedule reversible? instructions: - text: Delete Attack Discovery schedule {id}. slots: id: path.id - text: Permanently remove discovery schedule {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/attack_discovery/schedules/{id}/_disable'].post update: x-apievangelist-phrasing: intent: Disable an Attack Discovery schedule effect: write questions: - How do I pause one discovery schedule but keep its settings? - Will a running execution finish if I disable its schedule? instructions: - text: Disable Attack Discovery schedule {id}. slots: id: path.id - text: Stop discovery schedule {id} from starting new runs. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/attack_discovery/schedules/{id}/_enable'].post update: x-apievangelist-phrasing: intent: Enable an Attack Discovery schedule effect: write questions: - How do I turn a disabled discovery schedule back on? - When does a re-enabled discovery schedule run next? instructions: - text: Enable Attack Discovery schedule {id}. slots: id: path.id - text: Resume discovery schedule {id} on its interval. slots: id: path.id method: generated generated: '2026-09-26'