# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks SASE Aggregate Monitoring Aggregation… version: 1.0.0 extends: openapi/palo-alto-networks-aggregation-queries-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 5 - target: $.paths['/agg/query/threat'].post update: x-apievangelist-phrasing: intent: Aggregate threat events across tenants effect: read questions: - How many threat events did my managed tenants see, broken down by severity? - Can I chart threats over time as a histogram across a TSG hierarchy? instructions: - text: Aggregate threat events for TSG {tsg_id} over {time_range}. slots: tsg_id: requestBody.tsg_id time_range: requestBody.time_range - text: Count threats in TSG {tsg_id} grouped by {group_by}, filtered by {filter}. slots: tsg_id: requestBody.tsg_id group_by: requestBody.group_by filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/agg/query/url'].post update: x-apievangelist-phrasing: intent: Aggregate URL categorization and web activity effect: read questions: - Which URL categories are my tenants' users visiting most? - Can I find web policy violations across managed tenants by URL action? instructions: - text: Report URL category activity for TSG {tsg_id} over {time_range}. slots: tsg_id: requestBody.tsg_id time_range: requestBody.time_range - text: Summarize web browsing in TSG {tsg_id} by URL category, filtered by {filter}. slots: tsg_id: requestBody.tsg_id filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/agg/query/application'].post update: x-apievangelist-phrasing: intent: Aggregate application usage across tenants effect: read questions: - Which applications use the most sessions and bytes across my tenants? - Can I filter application usage by risk level or category? instructions: - text: Show application usage for TSG {tsg_id} over {time_range}. slots: tsg_id: requestBody.tsg_id time_range: requestBody.time_range - text: Rank the top {count} applications by session count in TSG {tsg_id}. slots: count: requestBody.count tsg_id: requestBody.tsg_id method: generated generated: '2026-09-26' - target: $.paths['/agg/query/bandwidth'].post update: x-apievangelist-phrasing: intent: Aggregate bandwidth utilization by location effect: read questions: - How much bandwidth are my SASE locations using for capacity planning? - Can I break bandwidth utilization down by traffic direction? instructions: - text: Report bandwidth utilization for TSG {tsg_id} over {time_range}. slots: tsg_id: requestBody.tsg_id time_range: requestBody.time_range - text: Plot bandwidth for TSG {tsg_id} as a time histogram {histogram} grouped by {group_by}. slots: tsg_id: requestBody.tsg_id histogram: requestBody.histogram group_by: requestBody.group_by method: generated generated: '2026-09-26' - target: $.paths['/agg/query/license'].post update: x-apievangelist-phrasing: intent: Aggregate license utilization across tenants effect: read questions: - How much of our SASE license capacity is each tenant consuming? - Can I pull license utilization per product for chargeback reports? instructions: - text: Show license utilization for TSG {tsg_id}. slots: tsg_id: requestBody.tsg_id - text: Break down license use in TSG {tsg_id} by {group_by} for chargeback. slots: tsg_id: requestBody.tsg_id group_by: requestBody.group_by method: generated generated: '2026-09-26'