# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks Audits API version: 1.0.0 extends: openapi/palo-alto-networks-audits-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 96 - target: $.paths['/api/v34.03/audits/access'].get update: x-apievangelist-phrasing: intent: List Docker access audit events (v34.03) effect: read questions: - Which Docker commands were allowed or blocked on my hosts, according to the v34.03 audits API? - Can I filter v34.03 Docker access audits by user and hostname? instructions: - text: List v34.03 Docker access audit events on host {hostname} for user {user}. slots: hostname: query.hostname user: query.user - text: Show v34.03 Docker access audits triggered by rule {ruleName} between {from} and {to}. slots: ruleName: query.ruleName from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/access/download'].get update: x-apievangelist-phrasing: intent: Download Docker access audit events (v34.03) effect: read questions: - Can I export Docker access audit events to a file using the v34.03 API? - Is there a way to download v34.03 Docker access audits for one cluster? instructions: - text: Download the v34.03 Docker access audit file for cluster {cluster}. slots: cluster: query.cluster - text: Export v34.03 Docker access audits from {from} to {to} as a download. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/admission'].get update: x-apievangelist-phrasing: intent: List Kubernetes admission audit events (v34.03) effect: read questions: - Which admission control decisions were audited in a namespace under v34.03? - Can I find v34.03 admission audits tied to a MITRE attack technique? instructions: - text: List v34.03 admission audit events in namespace {namespace}. slots: namespace: query.namespace - text: Show v34.03 admission audits for operation {operation} on cluster {cluster}. slots: operation: query.operation cluster: query.cluster method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/admission/download'].get update: x-apievangelist-phrasing: intent: Download admission audit events (v34.03) effect: read questions: - Can I download admission controller audits as a file from the v34.03 API? - Is it possible to export v34.03 admission audits for a single namespace? instructions: - text: Download v34.03 admission audit events for namespace {namespace}. slots: namespace: query.namespace - text: Export the v34.03 admission audit file between {from} and {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/app/agentless'].get update: x-apievangelist-phrasing: intent: List WAAS agentless audit events (v34.03) effect: read questions: - What web attacks did WAAS agentless protection record under the v34.03 API? - Can I narrow v34.03 WAAS agentless audits to OWASP Top 10 findings or one country? instructions: - text: List v34.03 WAAS agentless audit events on host {hostname}. slots: hostname: query.hostname - text: Show v34.03 WAAS agentless audits from country {country} for URL path {urlPath}. slots: country: query.country urlPath: query.urlPath method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/app/agentless/download'].get update: x-apievangelist-phrasing: intent: Download WAAS agentless audit events (v34.03) effect: read questions: - Can I export WAAS agentless firewall audits to a file in v34.03? - Is there a download of v34.03 WAAS agentless events for one rule? instructions: - text: Download v34.03 WAAS agentless audits for rule {ruleName}. slots: ruleName: query.ruleName - text: Export the v34.03 WAAS agentless audit file for {from} to {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/app/agentless/timeslice'].get update: x-apievangelist-phrasing: intent: Chart WAAS agentless audits over time (v34.03) effect: read questions: - How are WAAS agentless audit events spread across a timeframe in v34.03? - Can I bucket v34.03 WAAS agentless events into a set number of time slices? instructions: - text: Split v34.03 WAAS agentless audits from {from} to {to} into {buckets} time buckets. slots: from: query.from to: query.to buckets: query.buckets - text: Get the v34.03 WAAS agentless audit timeline for host {hostname}. slots: hostname: query.hostname method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/app/app-embedded'].get update: x-apievangelist-phrasing: intent: List WAAS app-embedded audit events (v34.03) effect: read questions: - What attacks did app-embedded WAAS defenders block, per the v34.03 audits API? - Can I filter v34.03 app-embedded WAAS audits by app ID or effect? instructions: - text: List v34.03 WAAS app-embedded audit events for app {appID}. slots: appID: query.appID - text: Show v34.03 app-embedded WAAS audits with effect {effect} since {from}. slots: effect: query.effect from: query.from method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/app/app-embedded/download'].get update: x-apievangelist-phrasing: intent: Download WAAS app-embedded audit events (v34.03) effect: read questions: - Can I download app-embedded WAAS audits as a file in v34.03? - Is there an export of v34.03 app-embedded WAAS events for one app? instructions: - text: Download v34.03 WAAS app-embedded audits for app {appID}. slots: appID: query.appID - text: Export the v34.03 app-embedded WAAS audit file from {from} to {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/app/app-embedded/timeslice'].get update: x-apievangelist-phrasing: intent: Chart WAAS app-embedded audits over time (v34.03) effect: read questions: - How did app-embedded WAAS audit volume change over a timeframe in v34.03? - Can I get v34.03 app-embedded WAAS event counts per time bucket? instructions: - text: Bucket v34.03 WAAS app-embedded audits from {from} to {to} into {buckets} slices. slots: from: query.from to: query.to buckets: query.buckets - text: Get the v34.03 app-embedded WAAS audit timeline for app {appID}. slots: appID: query.appID method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/app/container'].get update: x-apievangelist-phrasing: intent: List WAAS container audit events (v34.03) effect: read questions: - Which web attacks against my containers did WAAS log in v34.03? - Can I filter v34.03 WAAS container audits by image or container name? instructions: - text: List v34.03 WAAS container audit events for image {imageName}. slots: imageName: query.imageName - text: Show v34.03 WAAS container audits for container {containerName} on cluster {cluster}. slots: containerName: query.containerName cluster: query.cluster method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/app/container/download'].get update: x-apievangelist-phrasing: intent: Download WAAS container audit events (v34.03) effect: read questions: - Can I pull a v34.03 file export of the web application firewall events for my containers? - Is there a v34.03 download of WAAS container audits for one image? instructions: - text: Download v34.03 WAAS container audits for image {imageName}. slots: imageName: query.imageName - text: Export the v34.03 WAAS container audit file between {from} and {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/app/container/timeslice'].get update: x-apievangelist-phrasing: intent: Chart WAAS container audits over time (v34.03) effect: read questions: - How are WAAS container audit events distributed over time in v34.03? - Can I split v34.03 WAAS container events into time buckets for a chart? instructions: - text: Bucket v34.03 WAAS container audits from {from} to {to} into {buckets} slices. slots: from: query.from to: query.to buckets: query.buckets - text: Get the v34.03 WAAS container audit timeslice for image {imageName}. slots: imageName: query.imageName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/app/host'].get update: x-apievangelist-phrasing: intent: List WAAS host audit events (v34.03) effect: read questions: - What web attacks on host-based apps did WAAS record in v34.03? - Can I filter v34.03 WAAS host audits by the connecting IP or user agent? instructions: - text: List v34.03 WAAS audits for web apps running directly on host {hostname}. slots: hostname: query.hostname - text: Show v34.03 WAAS host audits from connecting IPs {connectingIPs}. slots: connectingIPs: query.connectingIPs method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/app/host/download'].get update: x-apievangelist-phrasing: intent: Download WAAS host audit events (v34.03) effect: read questions: - Can I download WAAS host firewall audits as a file with v34.03? - Is there an export of v34.03 WAAS host audits for one hostname? instructions: - text: Download v34.03 WAAS host audits for host {hostname}. slots: hostname: query.hostname - text: Export the v34.03 WAAS host audit file from {from} to {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/app/host/timeslice'].get update: x-apievangelist-phrasing: intent: Chart WAAS host audits over time (v34.03) effect: read questions: - How did WAAS host audit activity trend across a period in v34.03? - Can I get v34.03 WAAS host audit counts grouped into time buckets? instructions: - text: Bucket v34.03 WAAS host audits from {from} to {to} into {buckets} slices. slots: from: query.from to: query.to buckets: query.buckets - text: Get the v34.03 WAAS host audit timeslice for host {hostname}. slots: hostname: query.hostname method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/app/serverless'].get update: x-apievangelist-phrasing: intent: List WAAS serverless audit events (v34.03) effect: read questions: - Which attacks on my serverless functions did WAAS log in v34.03? - Can I filter v34.03 WAAS serverless audits by function or runtime? instructions: - text: List v34.03 WAAS serverless audit events for function {function}. slots: function: query.function - text: Show v34.03 WAAS serverless audits on runtime {runtime}. slots: runtime: query.runtime method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/app/serverless/download'].get update: x-apievangelist-phrasing: intent: Download WAAS serverless audit events (v34.03) effect: read questions: - Can I get a v34.03 downloadable file of firewall events for my serverless functions? - Is there a v34.03 download of WAAS serverless events for one function? instructions: - text: Download v34.03 WAAS serverless audits for function {function}. slots: function: query.function - text: Export the v34.03 WAAS serverless audit file from {from} to {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/app/serverless/timeslice'].get update: x-apievangelist-phrasing: intent: Chart WAAS serverless audits over time (v34.03) effect: read questions: - How are WAAS serverless audit events spread over a timeframe in v34.03? - Can I bucket v34.03 WAAS serverless events by time for a trend view? instructions: - text: Bucket v34.03 WAAS serverless audits from {from} to {to} into {buckets} slices. slots: from: query.from to: query.to buckets: query.buckets - text: Get the v34.03 WAAS serverless audit timeline for function {function}. slots: function: query.function method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/network/container'].get update: x-apievangelist-phrasing: intent: List CNNS container network audits (v34.03) effect: read questions: - Which container-to-container connections did cloud native network security flag in v34.03? - Can I see only blocked v34.03 CNNS container connections between two images? instructions: - text: List v34.03 CNNS container audits from image {srcImageName} to image {dstImageName}. slots: srcImageName: query.srcImageName dstImageName: query.dstImageName - text: Show v34.03 CNNS container network audits with block filter {block}. slots: block: query.block method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/network/container/download'].get update: x-apievangelist-phrasing: intent: Download CNNS container network audits (v34.03) effect: read questions: - Can I export CNNS container network audits as a file in v34.03? - Is there a v34.03 download of container network audits for one source image? instructions: - text: Download v34.03 CNNS container audits for source image {srcImageName}. slots: srcImageName: query.srcImageName - text: Export the v34.03 CNNS container audit file from {from} to {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/network/host'].get update: x-apievangelist-phrasing: intent: List CNNS host network audits (v34.03) effect: read questions: - Which host-to-host connections did CNNS audit in v34.03? - Can I filter v34.03 CNNS host audits by source and destination hostnames? instructions: - text: List v34.03 CNNS host audits from {srcHostnames} to {dstHostnames}. slots: srcHostnames: query.srcHostnames dstHostnames: query.dstHostnames - text: Show v34.03 CNNS host network audits since {from}. slots: from: query.from method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/firewall/network/host/download'].get update: x-apievangelist-phrasing: intent: Download CNNS host network audits (v34.03) effect: read questions: - Can I download CNNS host network audits as a file in v34.03? - Is there a v34.03 export of host network audits for specific source hosts? instructions: - text: Download v34.03 CNNS host audits for source hosts {srcHostnames}. slots: srcHostnames: query.srcHostnames - text: Export the v34.03 CNNS host audit file between {from} and {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/incidents'].get update: x-apievangelist-phrasing: intent: List incident audit events (v34.03) effect: read questions: - What security incidents has Prisma Cloud Compute recorded, per the v34.03 API? - Can I list only unacknowledged v34.03 incidents in one category? instructions: - text: List v34.03 incidents in category {category} on host {hostname}. slots: category: query.category hostname: query.hostname - text: Show v34.03 incident audits with acknowledged set to {acknowledged}. slots: acknowledged: query.acknowledged method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/incidents/acknowledge/{id}'].patch update: x-apievangelist-phrasing: intent: Archive an incident (v34.03) effect: write questions: - How do I acknowledge and archive an incident through the v34.03 API? - Can I mark a v34.03 incident as acknowledged so it leaves the active list? instructions: - text: Archive incident {id} using the v34.03 API. slots: id: path.id - text: Set acknowledged to {acknowledged} on v34.03 incident {id}. slots: acknowledged: requestBody.acknowledged id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/incidents/download'].get update: x-apievangelist-phrasing: intent: Download incident audit events (v34.03) effect: read questions: - Can I export incident audits to a file with the v34.03 API? - Is there a v34.03 download of incidents for one cluster? instructions: - text: Download v34.03 incident audits for cluster {cluster}. slots: cluster: query.cluster - text: Export the v34.03 incident file from {from} to {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/kubernetes'].get update: x-apievangelist-phrasing: intent: List Kubernetes audit events (v34.03) effect: read questions: - Which Kubernetes API activity was flagged in the v34.03 audits? - Can I filter v34.03 Kubernetes audits by user or cluster? instructions: - text: List v34.03 Kubernetes audit events for user {user}. slots: user: query.user - text: Show v34.03 Kubernetes audits on cluster {cluster} since {from}. slots: cluster: query.cluster from: query.from method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/kubernetes/download'].get update: x-apievangelist-phrasing: intent: Download Kubernetes audit events (v34.03) effect: read questions: - Can I download Kubernetes audit events as a file in v34.03? - Is there a v34.03 export of Kubernetes audits for one cluster? instructions: - text: Download v34.03 Kubernetes audits for cluster {cluster}. slots: cluster: query.cluster - text: Export the v34.03 Kubernetes audit file from {from} to {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/mgmt'].get update: x-apievangelist-phrasing: intent: List management audit events (v34.03) effect: read questions: - Who changed settings in the Console, according to the v34.03 management audits? - Can I see v34.03 management audit events for one admin username? instructions: - text: List v34.03 management audit events by user {username}. slots: username: query.username - text: Show v34.03 management audits of type {type} between {from} and {to}. slots: type: query.type from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/mgmt/download'].get update: x-apievangelist-phrasing: intent: Download management audit events (v34.03) effect: read questions: - Can I export Console management audits to a file in v34.03? - Is there a v34.03 download of admin activity for one username? instructions: - text: Download v34.03 management audits for user {username}. slots: username: query.username - text: Export the v34.03 management audit file from {from} to {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/mgmt/filters'].get update: x-apievangelist-phrasing: intent: Get management audit filter values (v34.03) effect: read questions: - What filter values can I use when searching management audits in v34.03? - Which usernames and audit types appear as v34.03 management audit filters? instructions: - text: Get the v34.03 management audit filter options. - text: Show the v34.03 management audit filters available for type {type}. slots: type: query.type method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/runtime/app-embedded'].get update: x-apievangelist-phrasing: intent: List runtime app-embedded audit events (v34.03) effect: read questions: - What runtime alerts did app-embedded defenders raise in v34.03? - Can I filter v34.03 app-embedded runtime audits by attack type or process path? instructions: - text: List v34.03 runtime app-embedded audits for app {appID}. slots: appID: query.appID - text: Show v34.03 app-embedded runtime audits with attack type {attackType}. slots: attackType: query.attackType method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/runtime/app-embedded/download'].get update: x-apievangelist-phrasing: intent: Download runtime app-embedded audits (v34.03) effect: read questions: - Can I grab a v34.03 file of runtime (not WAAS) alerts from app-embedded defenders? - Is there a v34.03 export of runtime app-embedded events for one app? instructions: - text: Download v34.03 runtime app-embedded audits for app {appID}. slots: appID: query.appID - text: Export the v34.03 runtime app-embedded audit file from {from} to {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/runtime/container'].get update: x-apievangelist-phrasing: intent: List runtime container audit events (v34.03) effect: read questions: - What suspicious process, network or file activity did runtime defense see in containers in v34.03? - Can I filter v34.03 container runtime audits by image and namespace? instructions: - text: List v34.03 runtime container audits for image {imageName} in namespace {namespace}. slots: imageName: query.imageName namespace: query.namespace - text: Show v34.03 container runtime audits for container {container}. slots: container: query.container method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/runtime/container/download'].get update: x-apievangelist-phrasing: intent: Download runtime container audits (v34.03) effect: read questions: - Can I export container runtime audits to a file in v34.03? - Is there a v34.03 download of runtime container events for one image? instructions: - text: Download v34.03 runtime container audits for image {imageName}. slots: imageName: query.imageName - text: Export the v34.03 runtime container audit file between {from} and {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/runtime/container/timeslice'].get update: x-apievangelist-phrasing: intent: Chart runtime container audits over time (v34.03) effect: read questions: - How did container runtime audit volume trend across a timeframe in v34.03? - Can I bucket v34.03 runtime container events into time slices? instructions: - text: Bucket v34.03 runtime container audits from {from} to {to} into {buckets} slices. slots: from: query.from to: query.to buckets: query.buckets - text: Get the v34.03 runtime container audit timeline for image {imageName}. slots: imageName: query.imageName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/runtime/file-integrity'].get update: x-apievangelist-phrasing: intent: List file integrity audit events (v34.03) effect: read questions: - Which monitored files were changed on my hosts, per v34.03 file integrity audits? - Can I filter v34.03 file integrity events by path or event type? instructions: - text: List v34.03 file integrity audits on host {hostname} for path {path}. slots: hostname: query.hostname path: query.path - text: Show v34.03 file integrity events of type {eventType}. slots: eventType: query.eventType method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/runtime/file-integrity/download'].get update: x-apievangelist-phrasing: intent: Download file integrity audit events (v34.03) effect: read questions: - Can I download file integrity monitoring audits as a file in v34.03? - Is there a v34.03 export of file integrity events for one host? instructions: - text: Download v34.03 file integrity audits for host {hostname}. slots: hostname: query.hostname - text: Export the v34.03 file integrity audit file from {from} to {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/runtime/host'].get update: x-apievangelist-phrasing: intent: List runtime host audit events (v34.03) effect: read questions: - What runtime alerts did host defenders raise in the v34.03 audits? - Can I filter v34.03 host runtime audits by user or process path? instructions: - text: List v34.03 runtime host audits on host {hostname}. slots: hostname: query.hostname - text: Show v34.03 host runtime audits for process path {processPath} run by {user}. slots: processPath: query.processPath user: query.user method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/runtime/host/download'].get update: x-apievangelist-phrasing: intent: Download runtime host audits (v34.03) effect: read questions: - Can I export host runtime audits to a file in v34.03? - Is there a v34.03 download of runtime host events for one hostname? instructions: - text: Download v34.03 runtime host audits for host {hostname}. slots: hostname: query.hostname - text: Export the v34.03 runtime host audit file from {from} to {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/runtime/host/timeslice'].get update: x-apievangelist-phrasing: intent: Chart runtime host audits over time (v34.03) effect: read questions: - How are host runtime audit events distributed over time in v34.03? - Can I get v34.03 runtime host audit counts per time bucket? instructions: - text: Bucket v34.03 runtime host audits from {from} to {to} into {buckets} slices. slots: from: query.from to: query.to buckets: query.buckets - text: Get the v34.03 runtime host audit timeline for host {hostname}. slots: hostname: query.hostname method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/runtime/log-inspection'].get update: x-apievangelist-phrasing: intent: List log inspection audit events (v34.03) effect: read questions: - Which log inspection rules matched lines in my host logs, per v34.03? - Can I filter v34.03 log inspection audits by log file? instructions: - text: List v34.03 log inspection audits for log file {logfile}. slots: logfile: query.logfile - text: Show v34.03 log inspection events on host {hostname}. slots: hostname: query.hostname method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/runtime/log-inspection/download'].get update: x-apievangelist-phrasing: intent: Download log inspection audit events (v34.03) effect: read questions: - Can I download log inspection audits as a file in v34.03? - Is there a v34.03 export of log inspection events for one host? instructions: - text: Download v34.03 log inspection audits for host {hostname}. slots: hostname: query.hostname - text: Export the v34.03 log inspection audit file from {from} to {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/runtime/serverless'].get update: x-apievangelist-phrasing: intent: List runtime serverless audit events (v34.03) effect: read questions: - What runtime alerts fired for my serverless functions in v34.03? - Can I filter v34.03 serverless runtime audits by function and effect? instructions: - text: List v34.03 runtime serverless audits for function {function}. slots: function: query.function - text: Show v34.03 serverless runtime audits with effect {effect} on runtime {runtime}. slots: effect: query.effect runtime: query.runtime method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/runtime/serverless/download'].get update: x-apievangelist-phrasing: intent: Download runtime serverless audits (v34.03) effect: read questions: - Can I export serverless runtime audits to a file in v34.03? - Is there a v34.03 file export of runtime defense alerts for one serverless function? instructions: - text: Download v34.03 runtime serverless audits for function {function}. slots: function: query.function - text: Export the v34.03 runtime serverless audit file from {from} to {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/runtime/serverless/timeslice'].get update: x-apievangelist-phrasing: intent: Chart runtime serverless audits over time (v34.03) effect: read questions: - How did serverless runtime audit activity trend over a timeframe in v34.03? - Can I split v34.03 runtime serverless events into time buckets? instructions: - text: Bucket v34.03 runtime serverless audits from {from} to {to} into {buckets} slices. slots: from: query.from to: query.to buckets: query.buckets - text: Get the v34.03 runtime serverless audit timeline for function {function}. slots: function: query.function method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/trust'].get update: x-apievangelist-phrasing: intent: List trusted image audit events (v34.03) effect: read questions: - Which untrusted images were alerted on or blocked, per the v34.03 trust audits? - Can I filter v34.03 trust audits by rule and effect? instructions: - text: List v34.03 trusted image audits for rule {ruleName}. slots: ruleName: query.ruleName - text: Show v34.03 trust audits with effect {effect}. slots: effect: query.effect method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/audits/trust/download'].get update: x-apievangelist-phrasing: intent: Download trusted image audit events (v34.03) effect: read questions: - Can I download trusted image audits as a file in v34.03? - Is there a v34.03 export of trust audits for one rule? instructions: - text: Download v34.03 trust audits for rule {ruleName}. slots: ruleName: query.ruleName - text: Export the v34.03 trusted image audit file from {from} to {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/access'].get update: x-apievangelist-phrasing: intent: List Docker access audit events (v34.04) effect: read questions: - On the newer v34.04 audits API, which Docker commands did Defender allow or deny? - Does v34.04 let me show only allowed Docker access requests? instructions: - text: Get Docker access audits from v34.04 for cluster {cluster}. slots: cluster: query.cluster - text: Using v34.04, show Docker access audits where allow is {allow} for user {user}. slots: allow: query.allow user: query.user method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/access/download'].get update: x-apievangelist-phrasing: intent: Download Docker access audit events (v34.04) effect: read questions: - Is there a v34.04 endpoint to save Docker access audits as a file? - With v34.04, can I export Docker access audits for a single host? instructions: - text: Save a v34.04 Docker access audit export for host {hostname}. slots: hostname: query.hostname - text: Using v34.04, download Docker access audits for rule {ruleName}. slots: ruleName: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/admission'].get update: x-apievangelist-phrasing: intent: List Kubernetes admission audit events (v34.04) effect: read questions: - On v34.04, which requests did the admission controller audit in my clusters? - Does the v34.04 admission audit list filter by attack technique? instructions: - text: Get v34.04 admission audits tagged with attack techniques {attackTechniques}. slots: attackTechniques: query.attackTechniques - text: Using v34.04, show admission audit events on cluster {cluster}. slots: cluster: query.cluster method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/admission/download'].get update: x-apievangelist-phrasing: intent: Download admission audit events (v34.04) effect: read questions: - Is there a v34.04 way to save admission audits to a file? - With v34.04, can I export admission audits for one cluster? instructions: - text: Save a v34.04 admission audit export for cluster {cluster}. slots: cluster: query.cluster - text: Using v34.04, download admission audits for operation {operation}. slots: operation: query.operation method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/app/agentless'].get update: x-apievangelist-phrasing: intent: List WAAS agentless audit events (v34.04) effect: read questions: - On v34.04, what attacks did agentless WAAS protection detect? - Does v34.04 let me filter WAAS agentless audits by OWASP API Top 10 category? instructions: - text: Get v34.04 WAAS agentless audits for request host {requestHost}. slots: requestHost: query.requestHost - text: Using v34.04, show WAAS agentless audits matching OWASP Top 10 {owaspTop10}. slots: owaspTop10: query.owaspTop10 method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/app/agentless/download'].get update: x-apievangelist-phrasing: intent: Download WAAS agentless audit events (v34.04) effect: read questions: - Is there a v34.04 endpoint to save WAAS agentless audits as a file? - With v34.04, can I export agentless WAAS events for one host? instructions: - text: Save a v34.04 WAAS agentless audit export for host {hostname}. slots: hostname: query.hostname - text: Using v34.04, download WAAS agentless audits from country {country}. slots: country: query.country method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/app/agentless/timeslice'].get update: x-apievangelist-phrasing: intent: Chart WAAS agentless audits over time (v34.04) effect: read questions: - On v34.04, how do agentless WAAS events break down across a time window? - Does v34.04 return WAAS agentless audit counts per time bucket? instructions: - text: Using v34.04, split WAAS agentless audits from {from} to {to} into {buckets} buckets. slots: from: query.from to: query.to buckets: query.buckets - text: Get a v34.04 WAAS agentless timeslice for rule {ruleName}. slots: ruleName: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/app/app-embedded'].get update: x-apievangelist-phrasing: intent: List WAAS app-embedded audit events (v34.04) effect: read questions: - On v34.04, which attacks did app-embedded WAAS defenders catch? - Does v34.04 let me filter app-embedded WAAS audits by URL or HTTP method? instructions: - text: Get v34.04 WAAS app-embedded audits for URL {url}. slots: url: query.url - text: Using v34.04, show app-embedded WAAS audits for HTTP method {method}. slots: method: query.method method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/app/app-embedded/download'].get update: x-apievangelist-phrasing: intent: Download WAAS app-embedded audit events (v34.04) effect: read questions: - Is there a v34.04 way to save app-embedded WAAS audits to a file? - With v34.04, can I export app-embedded WAAS events for one rule? instructions: - text: Save a v34.04 WAAS app-embedded audit export for rule {ruleName}. slots: ruleName: query.ruleName - text: Using v34.04, download app-embedded WAAS audits on cluster {cluster}. slots: cluster: query.cluster method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/app/app-embedded/timeslice'].get update: x-apievangelist-phrasing: intent: Chart WAAS app-embedded audits over time (v34.04) effect: read questions: - On v34.04, how do app-embedded WAAS events spread across a time window? - Does v34.04 give app-embedded WAAS audit counts per time bucket? instructions: - text: Using v34.04, split WAAS app-embedded audits from {from} to {to} into {buckets} buckets. slots: from: query.from to: query.to buckets: query.buckets - text: Get a v34.04 app-embedded WAAS timeslice for rule {ruleName}. slots: ruleName: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/app/container'].get update: x-apievangelist-phrasing: intent: List WAAS container audit events (v34.04) effect: read questions: - On v34.04, which web attacks did WAAS record against my containers? - Does v34.04 let me filter WAAS container audits by attack technique or protection type? instructions: - text: Get v34.04 WAAS container audits in namespace {ns}. slots: ns: query.ns - text: Using v34.04, show WAAS container audits for protection {protection}. slots: protection: query.protection method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/app/container/download'].get update: x-apievangelist-phrasing: intent: Download WAAS container audit events (v34.04) effect: read questions: - Is there a v34.04 endpoint that saves container web firewall events as a file? - With v34.04, can I export WAAS container events for one container? instructions: - text: Save a v34.04 WAAS container audit export for container {containerName}. slots: containerName: query.containerName - text: Using v34.04, download WAAS container audits for rule {ruleName}. slots: ruleName: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/app/container/timeslice'].get update: x-apievangelist-phrasing: intent: Chart WAAS container audits over time (v34.04) effect: read questions: - On v34.04, how do WAAS container events break down over a time window? - Does v34.04 return WAAS container audit counts in time buckets? instructions: - text: Using v34.04, split WAAS container audits from {from} to {to} into {buckets} buckets. slots: from: query.from to: query.to buckets: query.buckets - text: Get a v34.04 WAAS container timeslice for container {containerName}. slots: containerName: query.containerName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/app/host'].get update: x-apievangelist-phrasing: intent: List WAAS host audit events (v34.04) effect: read questions: - On v34.04, what web attacks did WAAS log for host-based apps? - Does v34.04 let me filter WAAS host audits by country or subnet? instructions: - text: Get v34.04 WAAS host audits from subnet {subnet}. slots: subnet: query.subnet - text: Using v34.04, show WAAS host audits for user agent {userAgentHeader}. slots: userAgentHeader: query.userAgentHeader method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/app/host/download'].get update: x-apievangelist-phrasing: intent: Download WAAS host audit events (v34.04) effect: read questions: - Is there a v34.04 way to save WAAS host audits to a file? - With v34.04, can I export WAAS host events for one rule? instructions: - text: Save a v34.04 WAAS host audit export for rule {ruleName}. slots: ruleName: query.ruleName - text: Using v34.04, download WAAS host audits for host {hostname}. slots: hostname: query.hostname method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/app/host/timeslice'].get update: x-apievangelist-phrasing: intent: Chart WAAS host audits over time (v34.04) effect: read questions: - On v34.04, how do WAAS host events spread across a time window? - Does v34.04 give WAAS host audit counts per time bucket? instructions: - text: Using v34.04, split WAAS host audits from {from} to {to} into {buckets} buckets. slots: from: query.from to: query.to buckets: query.buckets - text: Get a v34.04 WAAS host timeslice for rule {ruleName}. slots: ruleName: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/app/serverless'].get update: x-apievangelist-phrasing: intent: List WAAS serverless audit events (v34.04) effect: read questions: - On v34.04, which attacks against serverless functions did WAAS record? - Does v34.04 let me filter WAAS serverless audits by URL path or effect? instructions: - text: Get v34.04 WAAS serverless audits for URL path {urlPath}. slots: urlPath: query.urlPath - text: Using v34.04, show WAAS serverless audits with effect {effect}. slots: effect: query.effect method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/app/serverless/download'].get update: x-apievangelist-phrasing: intent: Download WAAS serverless audit events (v34.04) effect: read questions: - Can v34.04 give me a saved file of web firewall hits on serverless functions? - With v34.04, can I export WAAS serverless events for one runtime? instructions: - text: Save a v34.04 WAAS serverless audit export for runtime {runtime}. slots: runtime: query.runtime - text: Using v34.04, download WAAS serverless audits for function {function}. slots: function: query.function method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/app/serverless/timeslice'].get update: x-apievangelist-phrasing: intent: Chart WAAS serverless audits over time (v34.04) effect: read questions: - On v34.04, what does the over-time pattern of WAAS attacks on my serverless functions look like? - Does v34.04 return WAAS serverless audit counts per time bucket? instructions: - text: Using v34.04, split WAAS serverless audits from {from} to {to} into {buckets} buckets. slots: from: query.from to: query.to buckets: query.buckets - text: Get a v34.04 WAAS serverless timeslice for runtime {runtime}. slots: runtime: query.runtime method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/network/container'].get update: x-apievangelist-phrasing: intent: List CNNS container network audits (v34.04) effect: read questions: - On v34.04, which container network connections did CNNS audit or block? - Does v34.04 let me see container network audits for one destination image? instructions: - text: Get v34.04 CNNS container audits for destination image {dstImageName}. slots: dstImageName: query.dstImageName - text: Using v34.04, show CNNS container network audits between {from} and {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/network/container/download'].get update: x-apievangelist-phrasing: intent: Download CNNS container network audits (v34.04) effect: read questions: - Is there a v34.04 way to save CNNS container network audits to a file? - With v34.04, can I export only blocked container network connections? instructions: - text: Save a v34.04 CNNS container audit export with block filter {block}. slots: block: query.block - text: Using v34.04, download CNNS container audits for destination image {dstImageName}. slots: dstImageName: query.dstImageName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/network/host'].get update: x-apievangelist-phrasing: intent: List CNNS host network audits (v34.04) effect: read questions: - On v34.04, which host network connections did CNNS record? - Does v34.04 let me list host network audits for one destination host? instructions: - text: Get v34.04 CNNS host audits for destination hosts {dstHostnames}. slots: dstHostnames: query.dstHostnames - text: Using v34.04, show CNNS host network audits between {from} and {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/firewall/network/host/download'].get update: x-apievangelist-phrasing: intent: Download CNNS host network audits (v34.04) effect: read questions: - Is there a v34.04 endpoint to save CNNS host network audits as a file? - With v34.04, can I export host network audits for specific destination hosts? instructions: - text: Save a v34.04 CNNS host audit export for destination hosts {dstHostnames}. slots: dstHostnames: query.dstHostnames - text: Using v34.04, download CNNS host audits since {from}. slots: from: query.from method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/incidents'].get update: x-apievangelist-phrasing: intent: List incident audit events (v34.04) effect: read questions: - On v34.04, which incidents were raised for a given container or function? - Does v34.04 let me filter incidents by type or custom rule name? instructions: - text: Get v34.04 incidents for container {containerID}. slots: containerID: query.containerID - text: Using v34.04, show incidents of type {type} from custom rule {customRuleName}. slots: type: query.type customRuleName: query.customRuleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/incidents/acknowledge/{id}'].patch update: x-apievangelist-phrasing: intent: Archive an incident (v34.04) effect: write questions: - On v34.04, can I archive an incident once it has been investigated? - Which v34.04 call flags an incident as acknowledged by its ID? instructions: - text: Using v34.04, archive incident {id}. slots: id: path.id - text: Acknowledge v34.04 incident {id} with acknowledged {acknowledged}. slots: id: path.id acknowledged: requestBody.acknowledged method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/incidents/download'].get update: x-apievangelist-phrasing: intent: Download incident audit events (v34.04) effect: read questions: - Is there a v34.04 way to save incidents to a file? - With v34.04, can I export incidents in one category? instructions: - text: Save a v34.04 incident export for category {category}. slots: category: query.category - text: Using v34.04, download incidents for host {hostname}. slots: hostname: query.hostname method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/kubernetes'].get update: x-apievangelist-phrasing: intent: List Kubernetes audit events (v34.04) effect: read questions: - On v34.04, which Kubernetes audit events matched my rules? - Does v34.04 let me filter Kubernetes audits by attack technique? instructions: - text: Get v34.04 Kubernetes audits with attack techniques {attackTechniques}. slots: attackTechniques: query.attackTechniques - text: Using v34.04, show Kubernetes audit events for user {user}. slots: user: query.user method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/kubernetes/download'].get update: x-apievangelist-phrasing: intent: Download Kubernetes audit events (v34.04) effect: read questions: - Is there a v34.04 endpoint to save Kubernetes audits as a file? - With v34.04, can I export Kubernetes audits for one user? instructions: - text: Save a v34.04 Kubernetes audit export for user {user}. slots: user: query.user - text: Using v34.04, download Kubernetes audits on cluster {cluster}. slots: cluster: query.cluster method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/mgmt'].get update: x-apievangelist-phrasing: intent: List management audit events (v34.04) effect: read questions: - On v34.04, what administrative changes were made in the Console? - Does v34.04 let me filter management audits by audit type? instructions: - text: Get v34.04 management audits of type {type}. slots: type: query.type - text: Using v34.04, show admin activity by {username} since {from}. slots: username: query.username from: query.from method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/mgmt/download'].get update: x-apievangelist-phrasing: intent: Download management audit events (v34.04) effect: read questions: - Is there a v34.04 way to save management audits to a file? - With v34.04, can I export management audits of one type? instructions: - text: Save a v34.04 management audit export for type {type}. slots: type: query.type - text: Using v34.04, download management audits for user {username}. slots: username: query.username method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/mgmt/filters'].get update: x-apievangelist-phrasing: intent: Get management audit filter values (v34.04) effect: read questions: - On v34.04, which values can I filter management audits on? - Does v34.04 list the usernames available for filtering management audits? instructions: - text: Using v34.04, list the management audit filter values. - text: Get v34.04 management audit filter options for user {username}. slots: username: query.username method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/runtime/app-embedded'].get update: x-apievangelist-phrasing: intent: List runtime app-embedded audit events (v34.04) effect: read questions: - On v34.04, which runtime events did app-embedded defenders report? - Does v34.04 let me filter app-embedded runtime audits by effect? instructions: - text: Get v34.04 runtime app-embedded audits with effect {effect}. slots: effect: query.effect - text: Using v34.04, show app-embedded runtime audits for request {requestID}. slots: requestID: query.requestID method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/runtime/app-embedded/download'].get update: x-apievangelist-phrasing: intent: Download runtime app-embedded audits (v34.04) effect: read questions: - Is there a v34.04 endpoint to save app-embedded runtime audits as a file? - With v34.04, can I export runtime app-embedded events by attack type? instructions: - text: Save a v34.04 runtime app-embedded audit export for attack type {attackType}. slots: attackType: query.attackType - text: Using v34.04, download runtime app-embedded audits for app {appID}. slots: appID: query.appID method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/runtime/container'].get update: x-apievangelist-phrasing: intent: List runtime container audit events (v34.04) effect: read questions: - On v34.04, what runtime anomalies were detected in my containers? - Does v34.04 let me filter container runtime audits by attack type or rule? instructions: - text: Get v34.04 runtime container audits with attack type {attackType}. slots: attackType: query.attackType - text: Using v34.04, show container runtime audits for rule {ruleName} on cluster {cluster}. slots: ruleName: query.ruleName cluster: query.cluster method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/runtime/container/download'].get update: x-apievangelist-phrasing: intent: Download runtime container audits (v34.04) effect: read questions: - Is there a v34.04 way to save container runtime audits to a file? - With v34.04, can I export runtime container events for one namespace? instructions: - text: Save a v34.04 runtime container audit export for namespace {namespace}. slots: namespace: query.namespace - text: Using v34.04, download runtime container audits for image {imageName}. slots: imageName: query.imageName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/runtime/container/timeslice'].get update: x-apievangelist-phrasing: intent: Chart runtime container audits over time (v34.04) effect: read questions: - On v34.04, how do container runtime events spread across a time window? - Does v34.04 return runtime container audit counts per time bucket? instructions: - text: Using v34.04, split runtime container audits from {from} to {to} into {buckets} buckets. slots: from: query.from to: query.to buckets: query.buckets - text: Get a v34.04 runtime container timeslice for namespace {namespace}. slots: namespace: query.namespace method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/runtime/file-integrity'].get update: x-apievangelist-phrasing: intent: List file integrity audit events (v34.04) effect: read questions: - On v34.04, which file changes did file integrity monitoring catch? - Does v34.04 let me filter file integrity audits by cluster? instructions: - text: Get v34.04 file integrity audits for path {path}. slots: path: query.path - text: Using v34.04, show file integrity events on cluster {cluster}. slots: cluster: query.cluster method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/runtime/file-integrity/download'].get update: x-apievangelist-phrasing: intent: Download file integrity audit events (v34.04) effect: read questions: - Is there a v34.04 endpoint to save file integrity audits as a file? - With v34.04, can I export file integrity events for one path? instructions: - text: Save a v34.04 file integrity audit export for path {path}. slots: path: query.path - text: Using v34.04, download file integrity audits of event type {eventType}. slots: eventType: query.eventType method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/runtime/host'].get update: x-apievangelist-phrasing: intent: List runtime host audit events (v34.04) effect: read questions: - On v34.04, what runtime anomalies did host defenders detect? - Does v34.04 let me filter host runtime audits by attack type or effect? instructions: - text: Get v34.04 runtime host audits with attack type {attackType}. slots: attackType: query.attackType - text: Using v34.04, show host runtime audits with effect {effect} for rule {ruleName}. slots: effect: query.effect ruleName: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/runtime/host/download'].get update: x-apievangelist-phrasing: intent: Download runtime host audits (v34.04) effect: read questions: - Is there a v34.04 way to save host runtime audits to a file? - With v34.04, can I export runtime host events for one rule? instructions: - text: Save a v34.04 runtime host audit export for rule {ruleName}. slots: ruleName: query.ruleName - text: Using v34.04, download runtime host audits for host {hostname}. slots: hostname: query.hostname method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/runtime/host/timeslice'].get update: x-apievangelist-phrasing: intent: Chart runtime host audits over time (v34.04) effect: read questions: - On v34.04, how do host runtime events break down across a time window? - Does v34.04 give runtime host audit counts in time buckets? instructions: - text: Using v34.04, split runtime host audits from {from} to {to} into {buckets} buckets. slots: from: query.from to: query.to buckets: query.buckets - text: Get a v34.04 runtime host timeslice for rule {ruleName}. slots: ruleName: query.ruleName method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/runtime/log-inspection'].get update: x-apievangelist-phrasing: intent: List log inspection audit events (v34.04) effect: read questions: - On v34.04, which log lines triggered log inspection audits? - Does v34.04 let me filter log inspection audits by cluster? instructions: - text: Get v34.04 log inspection audits for log file {logfile}. slots: logfile: query.logfile - text: Using v34.04, show log inspection events on cluster {cluster}. slots: cluster: query.cluster method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/runtime/log-inspection/download'].get update: x-apievangelist-phrasing: intent: Download log inspection audit events (v34.04) effect: read questions: - Is there a v34.04 endpoint to save log inspection audits as a file? - With v34.04, can I export log inspection events for one log file? instructions: - text: Save a v34.04 log inspection audit export for log file {logfile}. slots: logfile: query.logfile - text: Using v34.04, download log inspection audits for host {hostname}. slots: hostname: query.hostname method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/runtime/serverless'].get update: x-apievangelist-phrasing: intent: List runtime serverless audit events (v34.04) effect: read questions: - On v34.04, what runtime events were raised for serverless functions? - Does v34.04 let me filter serverless runtime audits by attack type or request ID? instructions: - text: Get v34.04 runtime serverless audits with attack type {attackType}. slots: attackType: query.attackType - text: Using v34.04, show serverless runtime audits for request {requestID}. slots: requestID: query.requestID method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/runtime/serverless/download'].get update: x-apievangelist-phrasing: intent: Download runtime serverless audits (v34.04) effect: read questions: - Is there a v34.04 way to save serverless runtime audits to a file? - With v34.04, can I export runtime defense alerts (not WAAS) for one serverless runtime? instructions: - text: Save a v34.04 export of runtime defense alerts for serverless runtime {runtime}. slots: runtime: query.runtime - text: Using v34.04, download runtime serverless audits for function {function}. slots: function: query.function method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/runtime/serverless/timeslice'].get update: x-apievangelist-phrasing: intent: Chart runtime serverless audits over time (v34.04) effect: read questions: - On v34.04, how do runtime defense alerts on serverless functions trend over a time window? - Does v34.04 return runtime serverless audit counts per time bucket? instructions: - text: Using v34.04, split runtime serverless audits from {from} to {to} into {buckets} buckets. slots: from: query.from to: query.to buckets: query.buckets - text: Chart v34.04 runtime defense alerts for function {function} across time buckets. slots: function: query.function method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/trust'].get update: x-apievangelist-phrasing: intent: List trusted image audit events (v34.04) effect: read questions: - On v34.04, which images violated my trusted image rules? - Does v34.04 let me list trust audits within a time range? instructions: - text: Get v34.04 trusted image audits with effect {effect}. slots: effect: query.effect - text: Using v34.04, show trust audits between {from} and {to}. slots: from: query.from to: query.to method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/audits/trust/download'].get update: x-apievangelist-phrasing: intent: Download trusted image audit events (v34.04) effect: read questions: - Is there a v34.04 endpoint to save trusted image audits as a file? - With v34.04, can I export only blocked trust audits? instructions: - text: Save a v34.04 trust audit export with effect {effect}. slots: effect: query.effect - text: Using v34.04, download trusted image audits for rule {ruleName}. slots: ruleName: query.ruleName method: generated generated: '2026-09-26'