# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Kibana Security entity store API version: 1.0.0 extends: openapi/elk-stack-security-entity-store-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 17 - target: $.paths['/api/security/entity_store'].put update: x-apievangelist-phrasing: intent: Change Entity Store log extraction settings effect: write questions: - Can I adjust how the Entity Store extracts entities from logs after it is installed? - Where is the shared log extraction configuration for entity engines updated? instructions: - text: Update the Entity Store log extraction configuration to {logExtraction}. slots: logExtraction: requestBody.logExtraction - text: Apply log extraction settings {logExtraction} to the installed Entity Store. slots: logExtraction: requestBody.logExtraction method: generated generated: '2026-09-26' - target: $.paths['/api/security/entity_store/entities'].get update: x-apievangelist-phrasing: intent: List entities in the Entity Store effect: read questions: - Which hosts, users and services has the Entity Store recorded? - Can I page through entity records with a cursor instead of page numbers? - Is it possible to filter entities to only certain entity types and sort them? instructions: - text: List Entity Store entities of types {entity_types}, {per_page} per page. slots: entity_types: query.entity_types per_page: query.per_page - text: Find entities matching filter {filterQuery} sorted by {sort_field}. slots: filterQuery: query.filterQuery sort_field: query.sort_field method: generated generated: '2026-09-26' - target: $.paths['/api/security/entity_store/entities/'].delete update: x-apievangelist-phrasing: intent: Delete an entity record effect: destructive questions: - How can I remove a single host or user entity from the Entity Store? - Is a deleted entity removed from the latest index right away? instructions: - text: Delete entity {entityId} from the Entity Store. slots: entityId: requestBody.entityId - text: Remove the entity record with ID {entityId}. slots: entityId: requestBody.entityId method: generated generated: '2026-09-26' - target: $.paths['/api/security/entity_store/entities/{entityType}'].put update: x-apievangelist-phrasing: intent: Update one entity record effect: write questions: - Can I edit fields on an existing host or user entity? - How do I overwrite protected fields on an entity record? instructions: - text: Update an existing {entityType} entity record with these fields. slots: entityType: path.entityType - text: Force-update protected fields on a {entityType} entity, force {force}. slots: entityType: path.entityType force: query.force method: generated generated: '2026-09-26' - target: $.paths['/api/security/entity_store/entities/{entityType}'].post update: x-apievangelist-phrasing: intent: Create an entity record effect: write questions: - How do I add a new user or host entity to the Entity Store by hand? - Which entity types can I create records for? instructions: - text: Create a new {entityType} entity in the Entity Store. slots: entityType: path.entityType - text: Add a {entityType} entity record with the details I provide. slots: entityType: path.entityType method: generated generated: '2026-09-26' - target: $.paths['/api/security/entity_store/entities/bulk'].put update: x-apievangelist-phrasing: intent: Update many entity records at once effect: write questions: - Can I update a batch of entity records in a single request? - Does bulk entity update support forcing changes to protected fields? instructions: - text: 'Bulk update these entity records: {entities}.' slots: entities: requestBody.entities - text: Apply updates {entities} to multiple entities with force {force}. slots: entities: requestBody.entities force: query.force method: generated generated: '2026-09-26' - target: $.paths['/api/security/entity_store/install'].post update: x-apievangelist-phrasing: intent: Install the Entity Store effect: write questions: - How do I turn on the Entity Store for hosts and users in Elastic Security? - Can I enable history snapshots when installing entity engines? instructions: - text: Install the Entity Store with engines for {entityTypes}. slots: entityTypes: requestBody.entityTypes - text: Set up Entity Store engines for {entityTypes} with history snapshot {historySnapshot}. slots: entityTypes: requestBody.entityTypes historySnapshot: requestBody.historySnapshot method: generated generated: '2026-09-26' - target: $.paths['/api/security/entity_store/resolution/group'].get update: x-apievangelist-phrasing: intent: Show an entity's resolution group effect: read questions: - Which other entities have been linked to this one as the same identity? - Can I see every account resolved together with a given entity? instructions: - text: Show the resolution group for entity {entity_id}. slots: entity_id: query.entity_id - text: List all entities linked to {entity_id}. slots: entity_id: query.entity_id method: generated generated: '2026-09-26' - target: $.paths['/api/security/entity_store/resolution/link'].post update: x-apievangelist-phrasing: intent: Link entities as the same identity effect: write questions: - How do I tell Elastic Security that several user accounts belong to the same person? - When do newly linked entities show up in reads? instructions: - text: Link entities {entity_ids} to target entity {target_id}. slots: entity_ids: requestBody.entity_ids target_id: requestBody.target_id - text: Merge {entity_ids} into the resolution group of {target_id}. slots: entity_ids: requestBody.entity_ids target_id: requestBody.target_id method: generated generated: '2026-09-26' - target: $.paths['/api/security/entity_store/resolution/rules'].get update: x-apievangelist-phrasing: intent: List entity resolution rules effect: read questions: - What managed entity resolution rules exist in this space, and which are enabled? - Can I see the effective state of every resolution rule? instructions: - text: List the entity resolution rules in this space. - text: Show which resolution rules are currently enabled. method: generated generated: '2026-09-26' - target: $.paths['/api/security/entity_store/resolution/rules/{id}/disable'].put update: x-apievangelist-phrasing: intent: Disable an entity resolution rule effect: write questions: - Can I switch off a managed resolution rule that is merging entities wrongly? - Does disabling a resolution rule apply only to the current space? instructions: - text: Disable resolution rule {id}. slots: id: path.id - text: Turn off entity resolution rule {id} in this space. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/security/entity_store/resolution/rules/{id}/enable'].put update: x-apievangelist-phrasing: intent: Enable an entity resolution rule effect: write questions: - How do I turn a managed resolution rule back on? - Can I activate a resolution rule for just this space? instructions: - text: Enable resolution rule {id}. slots: id: path.id - text: Switch on entity resolution rule {id} for this space. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/security/entity_store/resolution/unlink'].post update: x-apievangelist-phrasing: intent: Unlink entities from their resolution group effect: write questions: - How can I separate accounts that were wrongly linked as one identity? - Can I pull several entities out of their resolution groups at once? instructions: - text: Unlink entities {entity_ids} from their resolution group. slots: entity_ids: requestBody.entity_ids - text: Detach {entity_ids} so they are no longer resolved together. slots: entity_ids: requestBody.entity_ids method: generated generated: '2026-09-26' - target: $.paths['/api/security/entity_store/start'].put update: x-apievangelist-phrasing: intent: Start stopped entity engines effect: write questions: - How do I resume entity engines I paused earlier? - Can I restart processing for only some entity types? instructions: - text: Start the entity engines for {entityTypes}. slots: entityTypes: requestBody.entityTypes - text: Resume all stopped Entity Store engines. method: generated generated: '2026-09-26' - target: $.paths['/api/security/entity_store/status'].get update: x-apievangelist-phrasing: intent: Check Entity Store status effect: read questions: - Is the Entity Store installed and are its engines running? - Can I get component-level health details for each entity engine? instructions: - text: Show the Entity Store status. - text: Get engine statuses with component health, include_components {include_components}. slots: include_components: query.include_components method: generated generated: '2026-09-26' - target: $.paths['/api/security/entity_store/stop'].put update: x-apievangelist-phrasing: intent: Stop running entity engines effect: write questions: - Can I pause entity engines without uninstalling the Entity Store? - How do I stop data processing for one entity type? instructions: - text: Stop the entity engines for {entityTypes}. slots: entityTypes: requestBody.entityTypes - text: Pause every running Entity Store engine. method: generated generated: '2026-09-26' - target: $.paths['/api/security/entity_store/uninstall'].post update: x-apievangelist-phrasing: intent: Uninstall the Entity Store effect: destructive questions: - How do I remove the Entity Store and its engines completely? - Can I uninstall engines for only certain entity types? instructions: - text: Uninstall the Entity Store engines for {entityTypes}. slots: entityTypes: requestBody.entityTypes - text: Remove the Entity Store and all its resources. method: generated generated: '2026-09-26'