# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks Alerts API version: 1.0.0 extends: openapi/palo-alto-networks-alerts-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 37 - target: $.paths['/alerts/get_alerts'].post update: x-apievangelist-phrasing: intent: Search detections across endpoint, network and cloud effect: read questions: - Can I pull endpoint, network and cloud detections filtered by severity and category in one request? - Which detections came in from my endpoints in the last day, filtered by alert ID or timestamp? instructions: - text: Get the endpoint, network and cloud detections that match filter {request_data}. slots: request_data: requestBody.request_data - text: Pull every high-severity detection from endpoint, network and cloud sources raised since yesterday. method: generated generated: '2026-09-26' - target: $.paths['/alert/v1/policy'].post update: x-apievangelist-phrasing: intent: Page through policies with their alert counts effect: read questions: - Which policies have the most open alerts right now, using the newer paginated policy endpoint? - Can I get each policy with its alert count and a next-page token for the following batch? instructions: - text: List policies with their alert counts for time range {time_range}, {size} per page. slots: time_range: requestBody.timeRange size: requestBody.size - text: Fetch the next page of policies with alert counts using token {next_page_token}. slots: next_page_token: requestBody.nextPageToken method: generated generated: '2026-09-26' - target: $.paths['/alert/v1/aggregate'].post update: x-apievangelist-phrasing: intent: Group alert counts by a policy field effect: read questions: - Can I bucket my alert counts by a policy field such as severity or policy type? - What does my alert volume look like when grouped by a policy attribute of my choosing? instructions: - text: Aggregate alert counts grouped by policy field {group_by}. slots: group_by: requestBody.groupBy - text: Group alerts by {group_by} for time range {time_range} and show the count in each group. slots: group_by: requestBody.groupBy time_range: requestBody.timeRange method: generated generated: '2026-09-26' - target: $.paths['/alert/v1/{id}/graph'].get update: x-apievangelist-phrasing: intent: Get an alert's evidence graph effect: read questions: - Can I get the evidence behind an alert as graph data I can draw? - Is there a way to visualise how the resources in an alert connect, in JSON Graph Format? instructions: - text: Get the evidence graph for alert {id}. slots: id: path.id - text: Return the JSON Graph Format evidence data for alert {id} so I can render it. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/alerts/api/v1/notification/ondemand'].post update: x-apievangelist-phrasing: intent: Send an on-demand notification for an alert effect: write questions: - Can I push a single alert to Jira, email or Slack right now instead of waiting for a rule? - Which channels can I send an on-demand alert notification to? instructions: - text: Send an on-demand notification for alert {alert_id} using config {config}. slots: alert_id: requestBody.alertId config: requestBody.onDemandNotificationConfig - text: Open a Jira ticket for alert {alert_id} with notification settings {config}. slots: alert_id: requestBody.alertId config: requestBody.onDemandNotificationConfig method: generated generated: '2026-09-26' - target: $.paths['/filter/alert/suggest'].get update: x-apievangelist-phrasing: intent: List the available alert filters effect: read questions: - What filters can I use when querying cloud alerts? - Which alert filter keys exist and what are their default options? instructions: - text: Show me every alert filter key and its default or recently used options. - text: List the alert filters I can apply to an alert search. method: generated generated: '2026-09-26' - target: $.paths['/filter/alert/suggest'].post update: x-apievangelist-phrasing: intent: Autocomplete values for an alert filter effect: read questions: - What values can I pick for a specific alert filter like cloud.region? - Can I type part of a value and get matching suggestions for an alert filter? instructions: - text: Suggest values for alert filter {filter_name}. slots: filter_name: requestBody.filterName - text: Autocomplete alert filter {filter_name} with values containing {query}. slots: filter_name: requestBody.filterName query: requestBody.query method: generated generated: '2026-09-26' - target: $.paths['/alert'].get update: x-apievangelist-phrasing: intent: List cloud alerts via query string (v1, 10k cap) effect: read questions: - Can I list Prisma Cloud alerts with query-string filters using the original v1 endpoint? - Is the original GET alert list capped at 10,000 results? instructions: - text: Using the v1 GET alert list, show alerts from the last {time_amount} {time_unit} with time type {time_type}, detailed {detailed}. slots: time_amount: query.timeAmount time_unit: query.timeUnit time_type: query.timeType detailed: query.detailed - text: 'v1 GET list: {alert_status} alerts, severity {severity}, last {time_amount} {time_unit} ({time_type}, detailed {detailed}).' slots: alert_status: query.alert.status severity: query.policy.severity time_amount: query.timeAmount time_unit: query.timeUnit time_type: query.timeType detailed: query.detailed method: generated generated: '2026-09-26' - target: $.paths['/alert'].post update: x-apievangelist-phrasing: intent: List cloud alerts via request body (v1, 10k cap) effect: read questions: - Can I post a filter body to list cloud alerts with the v1 endpoint and pick only certain fields? - What happens when the v1 POST alert list passes 10,000 results? instructions: - text: Post filters {filters} to the v1 alert list and return alerts for time range {time_range}. slots: filters: requestBody.filters time_range: requestBody.timeRange - text: Using the v1 POST alert list, return only fields {fields} for alerts matching {filters}. slots: fields: requestBody.fields filters: requestBody.filters method: generated generated: '2026-09-26' - target: $.paths['/v2/alert'].get update: x-apievangelist-phrasing: intent: Page through cloud alerts via query string (v2) effect: read questions: - Can I page past 10,000 alerts using query parameters and a page token? - Does the v2 GET alert list include alert rules in its response? instructions: - text: Page through v2 alerts from the last {time_amount} {time_unit} ({time_type}, detailed {detailed}), starting at token {page_token}. slots: time_amount: query.timeAmount time_unit: query.timeUnit time_type: query.timeType detailed: query.detailed page_token: query.pageToken - text: Via the v2 GET list, show alerts on cloud account {account} from the last {time_amount} {time_unit} ({time_type}, detailed {detailed}). slots: account: query.cloud.account time_amount: query.timeAmount time_unit: query.timeUnit time_type: query.timeType detailed: query.detailed method: generated generated: '2026-09-26' - target: $.paths['/v2/alert'].post update: x-apievangelist-phrasing: intent: Page through cloud alerts via request body (v2) effect: read questions: - Can I send a JSON filter body and page through more than 10,000 alerts with a page token? - Which v2 POST alert list option lets me choose the fields returned for each alert? instructions: - text: Post filters {filters} to the v2 alert list and continue from page token {page_token}. slots: filters: requestBody.filters page_token: requestBody.pageToken - text: Using the v2 POST alert list, return {limit} alerts matching {filters} sorted by {sort_by}. slots: limit: requestBody.limit filters: requestBody.filters sort_by: requestBody.sortBy method: generated generated: '2026-09-26' - target: $.paths['/alert/policy'].get update: x-apievangelist-phrasing: intent: Count alerts per policy via query string effect: read questions: - How many alerts does each policy have, filtered with query parameters? - Can I see alert counts per policy just for one cloud type using a GET request? instructions: - text: Count alerts per policy for cloud type {cloud_type} using the GET grouping. slots: cloud_type: query.cloud.type - text: Show per-policy alert counts for compliance standard {standard} via query parameters. slots: standard: query.policy.complianceStandard method: generated generated: '2026-09-26' - target: $.paths['/alert/policy'].post update: x-apievangelist-phrasing: intent: Count alerts per policy via request body effect: read questions: - Can I post a filter body and get back alert counts grouped by policy? - Which policies are generating alerts in a given time range, counted with a POST filter? instructions: - text: Post filters {filters} and return alert counts grouped by policy. slots: filters: requestBody.filters - text: Give me per-policy alert counts for time range {time_range} using a POST body. slots: time_range: requestBody.timeRange method: generated generated: '2026-09-26' - target: $.paths['/alert/{id}'].get update: x-apievangelist-phrasing: intent: Get a cloud alert by ID effect: read questions: - What are the full details of one Prisma Cloud alert when I have its ID? - What rate limit applies when fetching a single alert's info? instructions: - text: Get the details of alert {id}. slots: id: path.id - text: Show detailed information for alert {id} with detailed set to {detailed}. slots: id: path.id detailed: query.detailed method: generated generated: '2026-09-26' - target: $.paths['/alert/dismiss'].post update: x-apievangelist-phrasing: intent: Dismiss or snooze cloud alerts effect: write questions: - Can I snooze alerts for a period instead of dismissing them outright? - What do I need to send to dismiss a batch of alerts with a note? instructions: - text: Dismiss alerts {alerts} matching filter {filter} with note {note}. slots: alerts: requestBody.alerts filter: requestBody.filter note: requestBody.dismissalNote - text: Snooze all alerts for policies {policies} matching {filter} for {snooze_range}. slots: policies: requestBody.policies filter: requestBody.filter snooze_range: requestBody.dismissalTimeRange method: generated generated: '2026-09-26' - target: $.paths['/alert/dismiss/require_dismissal_note'].get update: x-apievangelist-phrasing: intent: Check whether dismissing requires a note effect: read questions: - Do users have to give a reason when they dismiss an alert in my tenant? - Is a dismissal note currently mandatory for alerts? instructions: - text: Tell me whether a dismissal note is required when dismissing alerts. - text: Check the current dismissal-note requirement setting. method: generated generated: '2026-09-26' - target: $.paths['/alert/dismiss/require_dismissal_note'].put update: x-apievangelist-phrasing: intent: Require or stop requiring a dismissal note effect: write questions: - Can I force everyone to enter a reason before dismissing an alert? - How do I turn off the mandatory dismissal note for alerts? instructions: - text: Set the dismissal note requirement to {required}. slots: required: requestBody.requireDismissalNote - text: Make a dismissal note mandatory for every alert dismissal. method: generated generated: '2026-09-26' - target: $.paths['/alert/reopen'].post update: x-apievangelist-phrasing: intent: Reopen dismissed or snoozed alerts effect: write questions: - Can I set alerts I dismissed or snoozed back to open? - What's needed to reopen every snoozed alert for a policy? instructions: - text: Reopen alerts {alerts} matching filter {filter}. slots: alerts: requestBody.alerts filter: requestBody.filter - text: Set every dismissed alert for policies {policies} matching {filter} back to open. slots: policies: requestBody.policies filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/alert/count/{status}'].get update: x-apievangelist-phrasing: intent: Count alerts in a given status effect: read questions: - How many open alerts do I have in total? - Can I get just the number of dismissed or snoozed alerts without listing them? instructions: - text: Count my alerts with status {status}. slots: status: path.status - text: Give me the total number of {status} alerts. slots: status: path.status method: generated generated: '2026-09-26' - target: $.paths['/alert/jobs'].post update: x-apievangelist-phrasing: intent: Start a job to export alerts as JSON effect: write questions: - Can I export a large alert list as a downloadable JSON file in the background? - Do sortBy, limit and pageToken apply when I submit an alert JSON export job? instructions: - text: Submit a JSON export job for alerts matching {filters} in time range {time_range}. slots: filters: requestBody.filters time_range: requestBody.timeRange - text: Kick off a background job that builds a JSON alert list with fields {fields}. slots: fields: requestBody.fields method: generated generated: '2026-09-26' - target: $.paths['/alert/jobs/{id}/status'].get update: x-apievangelist-phrasing: intent: Check an alert JSON export job's status effect: read questions: - Is my alert JSON export job finished yet? - What status is the alert list job I submitted earlier in? instructions: - text: Check the status of alert JSON export job {id}. slots: id: path.id - text: Tell me whether alert list job {id} is ready to download. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/alert/jobs/{id}/download'].get update: x-apievangelist-phrasing: intent: Download an exported alert list as JSON effect: read questions: - Where do I fetch the JSON alert list once the export job completes? - Can I download the results of an alert list job as JSON? instructions: - text: Download the JSON alert list produced by job {id}. slots: id: path.id - text: Fetch the finished alert export from job {id} in JSON. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/alert/csv'].post update: x-apievangelist-phrasing: intent: Start a job to export alerts as CSV effect: write questions: - Can I get my alerts as a CSV file for a spreadsheet? - How do I generate an alert CSV for a filtered set of alerts? instructions: - text: Submit a CSV generation job for alerts matching {filters}. slots: filters: requestBody.filters - text: Start a CSV export of alerts for time range {time_range}. slots: time_range: requestBody.timeRange method: generated generated: '2026-09-26' - target: $.paths['/alert/csv/{id}/status'].get update: x-apievangelist-phrasing: intent: Check an alert CSV export job's status effect: read questions: - Has my alert CSV finished generating? - What state is the alert CSV job I kicked off in? instructions: - text: Check the status of alert CSV job {id}. slots: id: path.id - text: Tell me if the alert CSV for job {id} is ready. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/alert/csv/{id}/download'].get update: x-apievangelist-phrasing: intent: Download an exported alert CSV effect: read questions: - Where can I download the alert CSV once it's generated? - Can I grab the finished alert CSV file for a job? instructions: - text: Download the alert CSV produced by job {id}. slots: id: path.id - text: Save the CSV alert list from job {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/alert/policy/jobs'].post update: x-apievangelist-phrasing: intent: Start a job listing alerts grouped by policy effect: write questions: - Can I run a background job that lists alerts grouped by the policy they violated? - Is there an async export of alerts organised per policy? instructions: - text: Submit a job that lists alerts grouped by violated policy for filters {filters}. slots: filters: requestBody.filters - text: Start an async per-policy alert listing for time range {time_range}. slots: time_range: requestBody.timeRange method: generated generated: '2026-09-26' - target: $.paths['/alert/policy/jobs/{id}/status'].get update: x-apievangelist-phrasing: intent: Check a per-policy alert job's status effect: read questions: - Is my alerts-by-policy job done? - What's the status of the job I submitted to group alerts by policy? instructions: - text: Check the status of alerts-by-policy job {id}. slots: id: path.id - text: Tell me whether policy alert job {id} has completed. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/alert/policy/jobs/{id}/download'].get update: x-apievangelist-phrasing: intent: Download per-policy alert results as JSON effect: read questions: - Where do I download the alerts-grouped-by-policy results? - Can I fetch the JSON output of a per-policy alert job? instructions: - text: Download the per-policy alert JSON from job {id}. slots: id: path.id - text: Fetch the alerts-by-policy results for job {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/alert/remediation'].post update: x-apievangelist-phrasing: intent: Generate remediation commands for alerts effect: read questions: - What CLI commands would fix the misconfigurations behind these alerts? - Can I get fully constructed remediation commands for alerts on a remediable policy? instructions: - text: Generate remediation commands for alerts {alerts} matching filter {filter}. slots: alerts: requestBody.alerts filter: requestBody.filter - text: Show the remediation commands for policies {policies} within filter {filter}. slots: policies: requestBody.policies filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/alert/remediation/{id}'].patch update: x-apievangelist-phrasing: intent: Remediate an alert automatically effect: write questions: - Can Prisma Cloud fix the issue behind an alert for me? - Which alerts can be auto-remediated, and how do I trigger it? instructions: - text: Remediate alert {id}. slots: id: path.id - text: Run the remediation for alert {id} on its remediable policy. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/policy/api/v1/fetch/remediation/{policyId}'].get update: x-apievangelist-phrasing: intent: Get AI-assisted remediation for a policy effect: read questions: - Is there AI-assisted guidance on how to fix a policy violation on a specific asset? - What recommendation steps are available to mitigate a policy's finding? instructions: - text: Get AI-assisted remediation for policy {policy_id} on asset {asset_id} for alert {alert_id}. slots: policy_id: path.policyId asset_id: query.unifiedAssetId alert_id: query.alertId - text: Show the recommended fix steps for policy {policy_id}, asset {asset_id}, alert {alert_id}. slots: policy_id: path.policyId asset_id: query.unifiedAssetId alert_id: query.alertId method: generated generated: '2026-09-26' - target: $.paths['/v1/alerts/id/{id}/status/{status}'].patch update: x-apievangelist-phrasing: intent: Update a data detection (DDR) alert's status effect: write questions: - Can I change the status of a data detection and response alert? - What's the call to mark a DDR alert as resolved? instructions: - text: Set DDR alert {id} to status {status}. slots: id: path.id status: path.status - text: Mark data detection alert {id} as {status} using API key {api_key}. slots: id: path.id status: path.status api_key: header.dig-api-key method: generated generated: '2026-09-26' - target: $.paths['/v1/alerts'].get update: x-apievangelist-phrasing: intent: List data detection (DDR) alerts effect: read questions: - Which data detection and response alerts fired on my cloud assets this week? - Can I filter DDR alerts by asset name, policy severity or cloud provider? instructions: - text: List DDR alerts with policy severity {severity}. slots: severity: query.policySeverity.equals - text: Show DDR alerts on assets whose name contains {asset}, page {page}. slots: asset: query.assetName.contains page: query.page method: generated generated: '2026-09-26' - target: $.paths['/alert/list'].get update: x-apievangelist-phrasing: intent: List IoT Security alerts effect: read questions: - What alerts has IoT Security raised about anomalous device behaviour? - Can I list only unresolved IoT device alerts within a time window? instructions: - text: List IoT Security alerts for customer {customer_id}. slots: customer_id: query.customerid - text: Show IoT alerts for customer {customer_id} between {start} and {end} with resolved {resolved}. slots: customer_id: query.customerid start: query.stime end: query.etime resolved: query.resolved method: generated generated: '2026-09-26' - target: $.paths['/alert/detail'].get update: x-apievangelist-phrasing: intent: Get details of an IoT Security alert effect: read questions: - Which device was affected by an IoT alert, and what response is recommended? - Can I see the timeline for a single IoT Security alert? instructions: - text: Get IoT alert {id} for customer {customer_id}. slots: id: query.id customer_id: query.customerid - text: Show the affected device and recommended actions for IoT alert {id} under customer {customer_id}. slots: id: query.id customer_id: query.customerid method: generated generated: '2026-09-26' - target: $.paths['/alert/update'].put update: x-apievangelist-phrasing: intent: Resolve or unresolve an IoT Security alert effect: write questions: - Can I mark an IoT device alert as resolved and record why? - Are resolved IoT alerts kept for later analysis? instructions: - text: Mark IoT alert {id} for customer {customer_id} as resolved {resolved} with reason {reason}. slots: id: query.id customer_id: query.customerid resolved: query.resolved reason: query.reason - text: Set IoT alert {id} for customer {customer_id} to resolved {resolved}. slots: id: query.id customer_id: query.customerid resolved: query.resolved method: generated generated: '2026-09-26' - target: $.paths['/dspm/api/v1/alerts'].get update: x-apievangelist-phrasing: intent: List data security (DSPM) alerts effect: read questions: - Which alerts flag sensitive data exposure, such as a data store that became public? - Can I filter data security alerts by severity and cloud provider? instructions: - text: List data security alerts with severity {severity} and status {status}. slots: severity: query.severity status: query.status - text: Show sensitive-data exposure alerts on {cloud_provider} since {start_time}. slots: cloud_provider: query.cloudProvider start_time: query.start_time method: generated generated: '2026-09-26'