# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Kibana Security Endpoint Exceptions API version: 1.0.0 extends: openapi/elk-stack-security-endpoint-exceptions-api-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 6 - target: $.paths['/api/endpoint_list'].post update: x-apievangelist-phrasing: intent: Create the Elastic Endpoint exception list effect: write questions: - How do I set up the exception list that Elastic Endpoint rules use? - What happens if the Endpoint exception list already exists when I create it? instructions: - text: Create the Elastic Endpoint exception list. - text: Initialize the endpoint_list container for Endpoint rule exceptions. method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint_list/items'].get update: x-apievangelist-phrasing: intent: Get an Endpoint exception item effect: read questions: - What conditions does a specific Endpoint exception item contain? - Can I look up an Endpoint exception by its human item_id instead of the ID? instructions: - text: Show Endpoint exception item {item_id}. slots: item_id: query.item_id - text: Get the Endpoint exception with ID {id}. slots: id: query.id method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint_list/items'].put update: x-apievangelist-phrasing: intent: Update an Endpoint exception item effect: write questions: - How do I edit the entries of an existing Endpoint exception? - Can I change which operating systems an Endpoint exception applies to? instructions: - text: 'Update Endpoint exception {item_id}: name {name}, description {description}, type {type}, entries {entries}.' slots: item_id: requestBody.item_id name: requestBody.name description: requestBody.description type: requestBody.type entries: requestBody.entries - text: Change OS types to {os_types} on exception {id} ({name}, {description}, {type}, {entries}). slots: os_types: requestBody.os_types id: requestBody.id name: requestBody.name description: requestBody.description type: requestBody.type entries: requestBody.entries method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint_list/items'].post update: x-apievangelist-phrasing: intent: Add an Endpoint exception item effect: write questions: - How do I stop Elastic Endpoint from alerting on a trusted process? - Can a new Endpoint exception target only Windows or macOS? instructions: - text: Add Endpoint exception {name} ({description}) of type {type} with entries {entries}. slots: name: requestBody.name description: requestBody.description type: requestBody.type entries: requestBody.entries - text: 'Create a {type} Endpoint exception {name} for OS {os_types}: {description}, entries {entries}.' slots: name: requestBody.name description: requestBody.description type: requestBody.type entries: requestBody.entries os_types: requestBody.os_types method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint_list/items'].delete update: x-apievangelist-phrasing: intent: Delete an Endpoint exception item effect: destructive questions: - How can I remove an Endpoint exception so those events alert again? - Can I delete an Endpoint exception using its item_id? instructions: - text: Delete Endpoint exception item {item_id}. slots: item_id: query.item_id - text: Remove the Endpoint exception with ID {id}. slots: id: query.id method: generated generated: '2026-09-26' - target: $.paths['/api/endpoint_list/items/_find'].get update: x-apievangelist-phrasing: intent: List Endpoint exception items effect: read questions: - Which exceptions are currently on the Elastic Endpoint list? - Can I filter and sort the Endpoint exception items? instructions: - text: List all Endpoint exception items. - text: Find Endpoint exceptions matching {filter} sorted by {sort_field}. slots: filter: query.filter sort_field: query.sort_field method: generated generated: '2026-09-26'