# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Aggreagate Monitoring Data Resource API version: 1.0.0 extends: openapi/palo-alto-networks-data-resource-api-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 28 - target: $.paths['/mt/monitor/v1/agg/alerts'].post update: x-apievangelist-phrasing: intent: Count alerts across tenants effect: read questions: - How many alerts are open across all my Prisma Access tenants right now? - Can I get a single aggregated alert count for a parent tenant and its child tenants? instructions: - text: Give me the total alert count across all tenants in the {region} data lake region. slots: region: header.X-PANW-Region - text: Count alerts across tenants matching filter {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/alerts/list'].post update: x-apievangelist-phrasing: intent: List alert counts by source across tenants effect: read questions: - Which sources are generating the most alerts across my tenants? - Where are my multi-tenant alerts coming from, broken down by source? instructions: - text: Break down alert counts by source across tenants in region {region}. slots: region: header.X-PANW-Region - text: List per-source alert counts for tenants matching {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/applicationUsage'].post update: x-apievangelist-phrasing: intent: List application usage by application type effect: read questions: - What kinds of applications are my users consuming the most, grouped by application type? - Can I see application usage split by type across my Prisma Access tenants? instructions: - text: Show application usage grouped by application type for region {region}. slots: region: header.X-PANW-Region - text: Report usage per application type using filter {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/applications'].post update: x-apievangelist-phrasing: intent: Count applications across tenants effect: read questions: - How many distinct applications are seen across all my tenants? - Is there a way to get one aggregated application count for every child tenant? instructions: - text: Give me the total number of applications seen across tenants in {region}. slots: region: header.X-PANW-Region - text: Count applications across tenants with filter {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/applications/list'].post update: x-apievangelist-phrasing: intent: List applications seen across tenants effect: read questions: - Which applications are actually in use across my tenants, listed out? - Can I pull the full aggregated list of applications for my parent and child tenants? instructions: - text: List every application observed across tenants in region {region}. slots: region: header.X-PANW-Region - text: Pull the aggregated application list for tenants matching {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/applications/source'].post update: x-apievangelist-phrasing: intent: Count applications by source effect: read questions: - How many applications come from remote networks versus mobile users versus proxy nodes? - Which traffic source accounts for the most applications across my tenants? instructions: - text: Count applications by source (remote networks, mobile users, proxy nodes) in {region}. slots: region: header.X-PANW-Region - text: Split the application count by traffic source using filter {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/applications/summary'].post update: x-apievangelist-phrasing: intent: Summarize risky applications across tenants effect: read questions: - How many risky applications are showing up across my tenants? - Can I get a summary count of high-risk apps for all child tenants at once? instructions: - text: Summarize the count of risky applications across tenants in {region}. slots: region: header.X-PANW-Region - text: Give me the risky-app summary for tenants matching {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/incidents/count'].post update: x-apievangelist-phrasing: intent: Count incidents by severity effect: read questions: - How many critical versus warning incidents do my tenants have? - What does my incident count look like broken down by severity? instructions: - text: Count incidents by severity across tenants in {region}. slots: region: header.X-PANW-Region - text: Give me incident totals per severity level for filter {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/incidents/impactedList'].post update: x-apievangelist-phrasing: intent: List objects impacted by incidents effect: read questions: - Which sites, users or objects are impacted by current incidents? - What is affected by the incidents open across my tenants? instructions: - text: List the objects impacted by incidents in region {region}. slots: region: header.X-PANW-Region - text: Show impacted objects for incidents matching {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/incidents/list'].post update: x-apievangelist-phrasing: intent: List incidents across tenants effect: read questions: - What incidents are currently recorded across my tenants? - Can I pull the individual incident list for my parent tenant and its children? instructions: - text: List all incidents across tenants in {region}. slots: region: header.X-PANW-Region - text: Fetch the incident list filtered by {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/incidents/tenants'].post update: x-apievangelist-phrasing: intent: Rank tenants by incident count effect: read questions: - Which of my tenants have the most open critical and warning incidents? - Who are my top tenants by incident count? instructions: - text: Rank the top tenants by open critical plus warning incidents in {region}. slots: region: header.X-PANW-Region - text: Show which tenants lead in incidents for filter {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/incidents/trends'].post update: x-apievangelist-phrasing: intent: Chart incident trends over time effect: read questions: - How have open critical, open warning and closed incidents trended over time? - Can I get an incident histogram to see whether things are getting better or worse? instructions: - text: Build an incident trend histogram for region {region}. slots: region: header.X-PANW-Region - text: Show the open critical, open warning and closed incident trend for filter {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/location/list'].get update: x-apievangelist-phrasing: intent: List compute locations with coordinates effect: read questions: - Which compute locations are available, with their latitude and longitude? - Where are the compute locations I could plot on a map? instructions: - text: List compute locations with latitude and longitude for region {region}. slots: region: header.X-PANW-Region - text: Give me the map coordinates of every compute location. method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/locationsTenants'].post update: x-apievangelist-phrasing: intent: Count tenants at a compute location effect: read questions: - How many tenants have assets at a particular compute location? - Which compute locations host the most tenants? instructions: - text: Count tenants with assets at the compute location in filter {filter}. slots: filter: requestBody.filter - text: Show the number of tenants per compute location in {region}. slots: region: header.X-PANW-Region method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/locationsUsers'].post update: x-apievangelist-phrasing: intent: Count users at compute locations effect: read questions: - How many users are connected at or across my compute locations? - Which compute location is serving the largest number of users? instructions: - text: Count users at the compute locations in filter {filter}. slots: filter: requestBody.filter - text: Give me user counts per compute location for {region}. slots: region: header.X-PANW-Region method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/resource'].post update: x-apievangelist-phrasing: intent: Count network inventory across tenants effect: read questions: - How much network inventory do I have across all tenants? - Can I see aggregated counts of my network resources for every child tenant? instructions: - text: Count network inventory across tenants in {region}. slots: region: header.X-PANW-Region - text: Aggregate network inventory for tenants matching {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/serviceConnectivity'].post update: x-apievangelist-phrasing: intent: Count remote network and service connection status effect: read questions: - How many of my remote network and service connection sites are up versus down? - What is the status breakdown of RN and SC sites across tenants? instructions: - text: Count remote network and service connection sites by status in {region}. slots: region: header.X-PANW-Region - text: Show RN and SC site status counts for filter {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/serviceConnectivity/cdlStatus'].post update: x-apievangelist-phrasing: intent: Check Cortex Data Lake connectivity status effect: read questions: - Are my tenants successfully connected to Cortex Data Lake? - Which tenants have CDL connectivity problems? instructions: - text: Show Cortex Data Lake connectivity status across tenants in {region}. slots: region: header.X-PANW-Region - text: List CDL connection status for tenants matching {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/serviceConnectivity/gatewayStatus'].post update: x-apievangelist-phrasing: intent: Check mobile gateway connection status effect: read questions: - Are my mobile user gateways connected across tenants? - What is the aggregated connection status of mobile gateways? instructions: - text: Show mobile gateway connection status across tenants in {region}. slots: region: header.X-PANW-Region - text: List mobile gateway status returning properties {properties}. slots: properties: requestBody.properties method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/serviceConnectivity/licenseAllocated'].get update: x-apievangelist-phrasing: intent: Get GlobalProtect licenses allocated effect: read questions: - How many GlobalProtect licenses are allocated for mobile users, explicit proxy and remote networks? - What is my total GP license allocation across tenants? instructions: - text: Show total GlobalProtect licenses allocated across tenants in {region}. slots: region: header.X-PANW-Region - text: Report GP license allocation for mobile users, explicit proxy, okyo and remote networks. method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/serviceConnectivity/topOutliers'].post update: x-apievangelist-phrasing: intent: List sites exceeding allocated bandwidth effect: read questions: - Which sites are consuming more bandwidth than they were allocated? - Who are the top bandwidth outliers across my tenants? instructions: - text: List the top outlier sites over their bandwidth allocation in {region}. slots: region: header.X-PANW-Region - text: Find sites exceeding allocated bandwidth for filter {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/serviceConnectivity/uniqueUsers'].post update: x-apievangelist-phrasing: intent: Count unique GlobalProtect users in 90 days effect: read questions: - How many unique GlobalProtect users connected in the last 90 days? - Can I see distinct GP user counts across all my tenants? instructions: - text: Count unique GlobalProtect users from the last 90 days in {region}. slots: region: header.X-PANW-Region - text: List unique GP users with properties {properties}. slots: properties: requestBody.properties method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/threats'].post update: x-apievangelist-phrasing: intent: Count threats across tenants effect: read questions: - How many threats have been detected across all my tenants? - Can I get one aggregated threat total for the parent tenant and its children? instructions: - text: Give me the total threat count across tenants in {region}. slots: region: header.X-PANW-Region - text: Count threats for tenants matching {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/threats/list'].post update: x-apievangelist-phrasing: intent: List threats across tenants effect: read questions: - Which specific threats were seen across my tenants? - What threats should I review, listed one by one? instructions: - text: List every threat observed across tenants in {region}. slots: region: header.X-PANW-Region - text: Pull the aggregated threat list for filter {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/threats/source'].post update: x-apievangelist-phrasing: intent: Count critical threats by source effect: read questions: - Are critical threats coming from remote networks, mobile users or proxy nodes? - Which source is responsible for the most critical threats? instructions: - text: Break down critical threats by source in {region}. slots: region: header.X-PANW-Region - text: Count critical threats per source for filter {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/threats/summary'].post update: x-apievangelist-phrasing: intent: Summarize threats across tenants effect: read questions: - What does the overall threat picture look like across my tenants? - Can I get a high-level threat summary instead of the full list? instructions: - text: Summarize threats across tenants in region {region}. slots: region: header.X-PANW-Region - text: Give me the threat summary for tenants matching {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/url/summary'].post update: x-apievangelist-phrasing: intent: Summarize URL counts across tenants effect: read questions: - How many URLs are my users visiting across all tenants? - Is there a single summary count of URLs for every child tenant? instructions: - text: Summarize URL counts across tenants in {region}. slots: region: header.X-PANW-Region - text: Give me the URL count summary for filter {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26' - target: $.paths['/mt/monitor/v1/agg/urlLogs'].post update: x-apievangelist-phrasing: intent: Rank tenants by risky URL activity effect: read questions: - Which tenants have the most risky URL visits? - Who are my top tenants when it comes to risky web browsing? instructions: - text: Rank the top tenants with risky URLs in {region}. slots: region: header.X-PANW-Region - text: Show tenants with the most risky URL hits for filter {filter}. slots: filter: requestBody.filter method: generated generated: '2026-09-26'