# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Prisma Cloud REST API Doc AWS Logging Accounts API version: 1.0.0 extends: openapi/palo-alto-networks-aws-logging-accounts-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 17 - target: $.paths['/v1/cloudAccounts/awsLoggingAccounts'].get update: x-apievangelist-phrasing: intent: List all AWS logging accounts effect: read questions: - Which AWS logging accounts are onboarded to Prisma Cloud? - Can I list logging accounts only for one AWS partition such as GovCloud? instructions: - text: List all AWS logging accounts in partition {awsPartition}. slots: awsPartition: query.awsPartition - text: Show every onboarded AWS logging account and its details. method: generated generated: '2026-09-26' - target: $.paths['/v1/cloudAccounts/awsLoggingAccounts'].post update: x-apievangelist-phrasing: intent: Add a new AWS logging account effect: write questions: - How do I onboard a new AWS logging account with its role and S3 buckets? - What role ARN and external ID are needed to register a logging account? instructions: - text: Add AWS logging account {loggingAccountId} named {loggingAccountName} using role ARN {loggingAccountRoleArn}. slots: loggingAccountId: requestBody.loggingAccountId loggingAccountName: requestBody.loggingAccountName loggingAccountRoleArn: requestBody.loggingAccountRoleArn - text: Register logging account {loggingAccountId} with role {loggingAccountRoleName}, external ID {externalId} and buckets {loggingAccountBuckets}. slots: loggingAccountId: requestBody.loggingAccountId loggingAccountRoleName: requestBody.loggingAccountRoleName externalId: requestBody.externalId loggingAccountBuckets: requestBody.loggingAccountBuckets method: generated generated: '2026-09-26' - target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/cft'].post update: x-apievangelist-phrasing: intent: Generate a CloudFormation template for a new logging account effect: write questions: - Can Prisma Cloud generate the CloudFormation template I need before onboarding a logging account? - How do I get a CFT that creates the role for a logging account I haven't added yet? instructions: - text: Generate a CFT for new AWS logging account {loggingAccountId} with role name {loggingAccountRoleName}. slots: loggingAccountId: requestBody.loggingAccountId loggingAccountRoleName: requestBody.loggingAccountRoleName - text: Create a CloudFormation template for a logging account in partition {awsPartition} covering buckets {loggingAccountBuckets}. slots: awsPartition: requestBody.awsPartition loggingAccountBuckets: requestBody.loggingAccountBuckets method: generated generated: '2026-09-26' - target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/permissionsStatus'].post update: x-apievangelist-phrasing: intent: Check permissions status for logging account details effect: read questions: - Before saving, can I check whether a logging account's role and buckets have the right permissions? - What permission status would an AWS logging account get with a given role ARN and bucket list? instructions: - text: Check permission status for unsaved logging account {loggingAccountId} using role ARN {loggingAccountRoleArn}. slots: loggingAccountId: requestBody.loggingAccountId loggingAccountRoleArn: requestBody.loggingAccountRoleArn - text: Validate the permissions of logging account details {loggingAccountName} with buckets {loggingAccountBuckets} before onboarding. slots: loggingAccountName: requestBody.loggingAccountName loggingAccountBuckets: requestBody.loggingAccountBuckets method: generated generated: '2026-09-26' - target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{accountId}'].get update: x-apievangelist-phrasing: intent: Get one AWS logging account effect: read questions: - How do I see the details of a single AWS logging account? - What role and buckets are configured on a specific logging account? instructions: - text: Get the details of AWS logging account {accountId}. slots: accountId: path.accountId - text: Show me the configuration of logging account {accountId}. slots: accountId: path.accountId method: generated generated: '2026-09-26' - target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{accountId}/buckets/{bucketName}'].delete update: x-apievangelist-phrasing: intent: Remove an S3 bucket from a logging account effect: destructive questions: - Can I detach one S3 bucket from a logging account without deleting the account? - How do I stop Prisma Cloud from reading logs out of a particular bucket? instructions: - text: Delete S3 bucket {bucketName} from logging account {accountId}. slots: bucketName: path.bucketName accountId: path.accountId - text: Remove bucket {bucketName} from AWS logging account {accountId}. slots: bucketName: path.bucketName accountId: path.accountId method: generated generated: '2026-09-26' - target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{accountId}/cft'].get update: x-apievangelist-phrasing: intent: Regenerate the CFT for an existing logging account effect: read questions: - Can I download a fresh CloudFormation template for a logging account that's already onboarded? - Where do I get the current CFT for an existing logging account? instructions: - text: Regenerate the CloudFormation template for existing logging account {accountId}. slots: accountId: path.accountId - text: Get the current CFT for AWS logging account {accountId}. slots: accountId: path.accountId method: generated generated: '2026-09-26' - target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{accountId}/cft'].post update: x-apievangelist-phrasing: intent: Regenerate a logging account CFT after a role name change effect: write questions: - I renamed the IAM role on my logging account; how do I get an updated CFT? - Can I regenerate a CloudFormation template for an existing account with a new role name? instructions: - text: Regenerate the CFT for logging account {accountId} with new role name {loggingAccountRoleName}. slots: accountId: path.accountId loggingAccountRoleName: requestBody.loggingAccountRoleName - text: Build a new CloudFormation template for account {accountId} because its role changed to {loggingAccountRoleName}. slots: accountId: path.accountId loggingAccountRoleName: requestBody.loggingAccountRoleName method: generated generated: '2026-09-26' - target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{accountId}/role/{roleName}/externalId'].get update: x-apievangelist-phrasing: intent: Get the external ID for a logging account role effect: read questions: - What external ID should the trust policy use for my logging account role? - How do I look up the external ID for a given account and role name? instructions: - text: Get the external ID for logging account {accountId} and role {roleName}. slots: accountId: path.accountId roleName: path.roleName - text: Show the external ID tied to role {roleName} on AWS account {accountId}. slots: roleName: path.roleName accountId: path.accountId method: generated generated: '2026-09-26' - target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}'].put update: x-apievangelist-phrasing: intent: Update an AWS logging account effect: write questions: - Can I rename a logging account or change its role ARN? - How do I update the bucket list on an onboarded logging account? instructions: - text: Rename logging account {loggingAccountId} to {loggingAccountName}. slots: loggingAccountId: path.loggingAccountId loggingAccountName: requestBody.loggingAccountName - text: Update logging account {loggingAccountId} to use role ARN {loggingAccountRoleArn}. slots: loggingAccountId: path.loggingAccountId loggingAccountRoleArn: requestBody.loggingAccountRoleArn method: generated generated: '2026-09-26' - target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}'].delete update: x-apievangelist-phrasing: intent: Delete an AWS logging account effect: destructive questions: - How do I offboard an AWS logging account entirely? - What gets removed when a logging account is deleted from Prisma Cloud? instructions: - text: Delete AWS logging account {loggingAccountId}. slots: loggingAccountId: path.loggingAccountId - text: Offboard logging account {loggingAccountId} from Prisma Cloud. slots: loggingAccountId: path.loggingAccountId method: generated generated: '2026-09-26' - target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}/buckets'].get update: x-apievangelist-phrasing: intent: List S3 bucket names on a logging account effect: read questions: - Which S3 buckets are attached to my logging account? - Can I get just the bucket names for a logging account? instructions: - text: List the S3 bucket names on logging account {loggingAccountId}. slots: loggingAccountId: path.loggingAccountId - text: Show which buckets logging account {loggingAccountId} reads from. slots: loggingAccountId: path.loggingAccountId method: generated generated: '2026-09-26' - target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}/buckets'].post update: x-apievangelist-phrasing: intent: Add an S3 bucket to a logging account effect: write questions: - How do I attach another S3 bucket to an existing logging account? - Can I set path prefixes and a KMS key when adding a bucket? instructions: - text: Add S3 bucket {bucketName} in region {bucketRegion} to logging account {loggingAccountId}. slots: bucketName: requestBody.bucketName bucketRegion: requestBody.bucketRegion loggingAccountId: path.loggingAccountId - text: Attach bucket {bucketName} with KMS key {keyArn} to logging account {loggingAccountId}. slots: bucketName: requestBody.bucketName keyArn: requestBody.keyArn loggingAccountId: path.loggingAccountId method: generated generated: '2026-09-26' - target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}/buckets/{bucketName}'].get update: x-apievangelist-phrasing: intent: Get S3 bucket details on a logging account effect: read questions: - What region, prefixes and key are configured for a specific bucket on my logging account? - Can I inspect one bucket's settings within a logging account? instructions: - text: Get details of bucket {bucketName} on logging account {loggingAccountId}. slots: bucketName: path.bucketName loggingAccountId: path.loggingAccountId - text: Show the region and path prefixes for bucket {bucketName} in account {loggingAccountId}. slots: bucketName: path.bucketName loggingAccountId: path.loggingAccountId method: generated generated: '2026-09-26' - target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}/buckets/{bucketName}'].put update: x-apievangelist-phrasing: intent: Update an S3 bucket on a logging account effect: write questions: - How do I change the path prefixes on a bucket already attached to a logging account? - Can I swap the KMS key used for a logging bucket? instructions: - text: Set path prefixes {bucketPathPrefixes} on bucket {bucketName} in logging account {loggingAccountId}. slots: bucketPathPrefixes: requestBody.bucketPathPrefixes bucketName: path.bucketName loggingAccountId: path.loggingAccountId - text: Change the KMS key of bucket {bucketName} on account {loggingAccountId} to {keyArn}. slots: bucketName: path.bucketName loggingAccountId: path.loggingAccountId keyArn: requestBody.keyArn method: generated generated: '2026-09-26' - target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}/permissionsStatus'].get update: x-apievangelist-phrasing: intent: Get the permissions status of a saved logging account effect: read questions: - Is my onboarded logging account healthy, or is it missing permissions? - What is the current status of a saved logging account by its ID? instructions: - text: Get the permissions status of logging account {loggingAccountId}. slots: loggingAccountId: path.loggingAccountId - text: Check whether saved logging account {loggingAccountId} is healthy. slots: loggingAccountId: path.loggingAccountId method: generated generated: '2026-09-26' - target: $.paths['/v1/cloudAccounts/awsLoggingAccounts/{loggingAccountId}/permissionsStatus'].post update: x-apievangelist-phrasing: intent: Check a saved logging account's status with new details effect: read questions: - Can I test an existing logging account's permissions against a different role or bucket? - What detailed status would my saved logging account have with a changed role ARN? instructions: - text: Check detailed status of existing logging account {loggingAccountId} against role ARN {loggingAccountRoleArn}. slots: loggingAccountId: path.loggingAccountId loggingAccountRoleArn: requestBody.loggingAccountRoleArn - text: Test saved account {loggingAccountId} permissions using buckets {loggingAccountBuckets}. slots: loggingAccountId: path.loggingAccountId loggingAccountBuckets: requestBody.loggingAccountBuckets method: generated generated: '2026-09-26'