# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Kibana Security Osquery API version: 1.0.0 extends: openapi/elk-stack-security-osquery-api-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 21 - target: $.paths['/api/osquery/history'].get update: x-apievangelist-phrasing: intent: View combined osquery execution history effect: read questions: - Can I see live, rule-triggered and scheduled osquery runs in one timeline? - Which osquery executions ran between two dates? - Is it possible to filter osquery history to queries a specific user ran? instructions: - text: Show my unified osquery history from {startDate} to {endDate}. slots: startDate: query.startDate endDate: query.endDate - text: List osquery executions run by users {userIds}. slots: userIds: query.userIds - text: Get the next page of osquery history using cursor {nextPage}. slots: nextPage: query.nextPage method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/live_queries'].get update: x-apievangelist-phrasing: intent: List live osquery queries effect: read questions: - Which live queries have been run against my hosts? - Can I filter the list of live queries with KQL? instructions: - text: List all live osquery queries. - text: Find live queries matching {kuery}, sorted by {sort}. slots: kuery: query.kuery sort: query.sort method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/live_queries'].post update: x-apievangelist-phrasing: intent: Run a live osquery query on hosts effect: write questions: - How do I run an osquery SQL query on my endpoints right now? - Can I target a live query at a specific agent policy or platform? - Is it possible to run a saved query or a whole pack as a live query? instructions: - text: Run live query {query} on agents {agent_ids}. slots: query: requestBody.query agent_ids: requestBody.agent_ids - text: Run live query {query} on every agent in policies {agent_policy_ids}. slots: query: requestBody.query agent_policy_ids: requestBody.agent_policy_ids - text: Launch saved query {saved_query_id} live on all {agent_platforms} hosts. slots: saved_query_id: requestBody.saved_query_id agent_platforms: requestBody.agent_platforms method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/live_queries/{id}'].get update: x-apievangelist-phrasing: intent: Get a live query's details effect: read questions: - What queries and agents were part of a specific live query run? - Can I check the status of a live query I launched? instructions: - text: Get the details of live query {id}. slots: id: path.id - text: Show which agents live query {id} targeted. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/live_queries/{id}/results/{actionId}'].get update: x-apievangelist-phrasing: intent: Get the result rows of a live query effect: read questions: - Where do I see the rows my live osquery query returned? - Can I page through live query results and filter them? instructions: - text: Show results of action {actionId} in live query {id}. slots: actionId: path.actionId id: path.id - text: Page {page} of live query {id} action {actionId} results filtered by {kuery}. slots: page: query.page id: path.id actionId: path.actionId kuery: query.kuery method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/live_queries/{id}/results/{actionId}/_export'].post update: x-apievangelist-phrasing: intent: Download live query results as a file effect: read questions: - Can I download a live query's results as a file? - Which file formats can live osquery results be exported in? instructions: - text: Export live query {id} action {actionId} results as {format}. slots: id: path.id actionId: path.actionId format: query.format - text: Download {format} results of live query {id} action {actionId} for agents {agentIds}. slots: format: query.format id: path.id actionId: path.actionId agentIds: requestBody.agentIds method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/packs'].get update: x-apievangelist-phrasing: intent: List osquery packs effect: read questions: - What osquery query packs do I have? - Can I sort my query packs by name? instructions: - text: List all osquery packs. - text: Show page {page} of query packs sorted by {sort}. slots: page: query.page sort: query.sort method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/packs'].post update: x-apievangelist-phrasing: intent: Create an osquery pack effect: write questions: - How do I bundle several scheduled osquery queries into a pack? - Can I assign a new pack to specific agent policies? instructions: - text: Create pack {name} with queries {queries}. slots: name: requestBody.name queries: requestBody.queries - text: Create an enabled pack {name} assigned to policies {policy_ids}. slots: name: requestBody.name policy_ids: requestBody.policy_ids method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/packs/{id}'].get update: x-apievangelist-phrasing: intent: Get an osquery pack effect: read questions: - Which queries are inside a given osquery pack? - What schedule and policies does a pack use? instructions: - text: Get the details of pack {id}. slots: id: path.id - text: Show the queries in osquery pack {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/packs/{id}'].put update: x-apievangelist-phrasing: intent: Update an osquery pack effect: write questions: - Can I change the queries or schedule of an existing pack? - Why can't I edit a prebuilt osquery pack? instructions: - text: Update pack {id} with queries {queries}. slots: id: path.id queries: requestBody.queries - text: Disable pack {id} by setting enabled to {enabled}. slots: id: path.id enabled: requestBody.enabled method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/packs/{id}'].delete update: x-apievangelist-phrasing: intent: Delete an osquery pack effect: destructive questions: - How do I remove a query pack I no longer use? - Does deleting a pack stop its scheduled queries? instructions: - text: Delete osquery pack {id}. slots: id: path.id - text: Remove pack {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/packs/{id}/copy'].post update: x-apievangelist-phrasing: intent: Duplicate an osquery pack effect: write questions: - Can I clone a query pack so I can edit the copy? - What name does a copied pack get, and is it enabled? instructions: - text: Copy pack {id}. slots: id: path.id - text: Make a disabled duplicate of osquery pack {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/saved_queries'].get update: x-apievangelist-phrasing: intent: List saved osquery queries effect: read questions: - What saved osquery queries are available to reuse? - Can I page through saved queries sorted by a field? instructions: - text: List all saved osquery queries. - text: Show page {page} of saved queries, {pageSize} per page. slots: page: query.page pageSize: query.pageSize method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/saved_queries'].post update: x-apievangelist-phrasing: intent: Save an osquery query for reuse effect: write questions: - How do I save an osquery SQL statement so I can run it later? - Can a saved query be limited to one platform? instructions: - text: Save query {query} with id {id}. slots: query: requestBody.query id: requestBody.id - text: Save osquery {query} for platform {platform} as {id}. slots: query: requestBody.query platform: requestBody.platform id: requestBody.id method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/saved_queries/{id}'].get update: x-apievangelist-phrasing: intent: Get a saved osquery query effect: read questions: - What SQL and ECS mapping does a particular saved query use? - Can I look up one saved query by id? instructions: - text: Get saved query {id}. slots: id: path.id - text: Show the SQL of saved query {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/saved_queries/{id}'].put update: x-apievangelist-phrasing: intent: Update a saved osquery query effect: write questions: - Can I edit the SQL of a query I saved earlier? - Are prebuilt saved queries editable? instructions: - text: Change saved query {id} to run {query}. slots: id: path.id query: requestBody.query - text: Update the interval of saved query {id} to {interval}. slots: id: path.id interval: requestBody.interval method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/saved_queries/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a saved osquery query effect: destructive questions: - How do I delete a saved osquery query? - Is removing a saved query permanent? instructions: - text: Delete saved query {id}. slots: id: path.id - text: Remove the saved osquery query {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/saved_queries/{id}/copy'].post update: x-apievangelist-phrasing: intent: Duplicate a saved osquery query effect: write questions: - Can I clone a saved query as a starting point for a new one? - What suffix is added to a copied saved query's name? instructions: - text: Copy saved query {id}. slots: id: path.id - text: Make a duplicate of saved osquery query {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/scheduled_results/{scheduleId}/{executionCount}'].get update: x-apievangelist-phrasing: intent: Get per-agent status of a scheduled query run effect: read questions: - Which agents succeeded or failed on a particular scheduled osquery execution? - Can I see success and failure counts for one scheduled query run? instructions: - text: Show per-agent results for schedule {scheduleId} execution {executionCount}. slots: scheduleId: path.scheduleId executionCount: path.executionCount - text: List failing agents in scheduled run {executionCount} of {scheduleId}. slots: executionCount: path.executionCount scheduleId: path.scheduleId method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/scheduled_results/{scheduleId}/{executionCount}/_export'].post update: x-apievangelist-phrasing: intent: Download scheduled query results as a file effect: read questions: - Can I export every row from a scheduled osquery execution to a file? - Which formats can scheduled query results be downloaded in? instructions: - text: Export schedule {scheduleId} run {executionCount} results as {format}. slots: scheduleId: path.scheduleId executionCount: path.executionCount format: query.format - text: Download {format} rows of scheduled run {executionCount} of {scheduleId} filtered by {kuery}. slots: format: query.format executionCount: path.executionCount scheduleId: path.scheduleId kuery: requestBody.kuery method: generated generated: '2026-09-26' - target: $.paths['/api/osquery/scheduled_results/{scheduleId}/{executionCount}/results'].get update: x-apievangelist-phrasing: intent: Get the data rows of a scheduled query run effect: read questions: - What actual osquery output did a scheduled query return on one run? - Can I page through scheduled query result rows from a start date? instructions: - text: Show the result rows of schedule {scheduleId} execution {executionCount}. slots: scheduleId: path.scheduleId executionCount: path.executionCount - text: Get page {page} of output rows for scheduled run {executionCount} of {scheduleId}. slots: page: query.page executionCount: path.executionCount scheduleId: path.scheduleId method: generated generated: '2026-09-26'