# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Kibana Significant Events API version: 1.0.0 extends: openapi/elk-stack-significant-events-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 5 - target: $.paths['/api/streams/{name}/queries'].get update: x-apievangelist-phrasing: intent: List significant-event queries on a stream effect: read questions: - Which significant-event queries are attached to a stream? - How do I see the detection queries defined for one stream? instructions: - text: List the queries linked to stream {name}. slots: name: path.name - text: Show every significant-event query on stream {name}. slots: name: path.name method: generated generated: '2026-09-26' - target: $.paths['/api/streams/{name}/queries/_bulk'].post update: x-apievangelist-phrasing: intent: Bulk add and remove stream queries effect: write questions: - How do I add and delete several significant-event queries on a stream in one call? - Can I replace a stream's queries in bulk? instructions: - text: Apply query operations {operations} to stream {name}. slots: operations: requestBody.operations name: path.name - text: Bulk update the significant-event queries on stream {name} with {operations}. slots: name: path.name operations: requestBody.operations method: generated generated: '2026-09-26' - target: $.paths['/api/streams/{name}/queries/{queryId}'].put update: x-apievangelist-phrasing: intent: Add a significant-event query to a stream effect: write questions: - How do I add an ES|QL query that flags significant events on a stream? - Can I give a significant-event query a severity score and an expiry date? instructions: - text: Add query {queryId} titled {title} with ES|QL {esql} to stream {name}. slots: queryId: path.queryId title: requestBody.title esql: requestBody.esql name: path.name - text: Upsert query {queryId} on stream {name} titled {title} using {esql} with severity {severity_score}. slots: queryId: path.queryId name: path.name title: requestBody.title esql: requestBody.esql severity_score: requestBody.severity_score method: generated generated: '2026-09-26' - target: $.paths['/api/streams/{name}/queries/{queryId}'].delete update: x-apievangelist-phrasing: intent: Remove a significant-event query from a stream effect: destructive questions: - How do I remove a detection query from a stream? - Is removing a query that isn't on the stream an error? instructions: - text: Remove query {queryId} from stream {name}. slots: queryId: path.queryId name: path.name - text: Delete significant-event query {queryId} on stream {name}. slots: queryId: path.queryId name: path.name method: generated generated: '2026-09-26' - target: $.paths['/api/streams/{name}/significant_events'].get update: x-apievangelist-phrasing: intent: Read a stream's significant events over time effect: read questions: - What significant events happened on a stream during a time range? - Can I search significant events using semantic or hybrid search? - How do I bucket significant events by hour? instructions: - text: Show significant events on stream {name} from {from} to {to} in {bucketSize} buckets. slots: name: path.name from: query.from to: query.to bucketSize: query.bucketSize - text: Find significant events on stream {name} matching {query} between {from} and {to}, bucketed by {bucketSize}. slots: name: path.name query: query.query from: query.from to: query.to bucketSize: query.bucketSize method: generated generated: '2026-09-26'