# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks Incidents API version: 1.0.0 extends: openapi/palo-alto-networks-incidents-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 20 - target: $.paths['/incidents/get_incidents'].post update: x-apievangelist-phrasing: intent: List Cortex XDR incidents effect: read questions: - Which Cortex XDR incidents are open right now at high severity? - Can I filter XDR incidents by creation time to see what came in overnight? - What incidents has XDR grouped from related alerts this week? instructions: - text: Pull the Cortex XDR incidents matching filter {request_data}. slots: request_data: requestBody.request_data - text: List my newest Cortex XDR incidents that are still new or under investigation. method: generated generated: '2026-09-26' - target: $.paths['/incidents/get_incident_extra_data'].post update: x-apievangelist-phrasing: intent: Get a Cortex XDR incident with its alerts effect: read questions: - How do I see every alert and artifact attached to one Cortex XDR incident? - Which endpoints and file hashes are tied to a specific XDR incident? instructions: - text: Get the full Cortex XDR incident details, alerts and network artifacts for {request_data}. slots: request_data: requestBody.request_data - text: Show the file artifacts and endpoints for the XDR incident described in {request_data}. slots: request_data: requestBody.request_data method: generated generated: '2026-09-26' - target: $.paths['/incidents/update_incident'].post update: x-apievangelist-phrasing: intent: Update a Cortex XDR incident effect: write questions: - How do I reassign a Cortex XDR incident to another analyst? - Can I change the severity of an XDR incident without touching its other fields? instructions: - text: Update the Cortex XDR incident with the changes in {request_data}. slots: request_data: requestBody.request_data - text: Set the status and assignee on an XDR incident using {request_data}. slots: request_data: requestBody.request_data method: generated generated: '2026-09-26' - target: $.paths['/incident_management/get_incidents'].post update: x-apievangelist-phrasing: intent: List Xpanse attack surface incidents effect: read questions: - Which attack surface exposures has Xpanse flagged that still need remediation? - Can I list Xpanse incidents about misconfigured certificates or shadow IT? - What unintended internet-facing services are open as attack surface incidents? instructions: - text: List Xpanse attack surface incidents matching {request_data}. slots: request_data: requestBody.request_data - text: Show the unresolved attack surface incidents assigned to my team. method: generated generated: '2026-09-26' - target: $.paths['/incident_management/update_incident'].post update: x-apievangelist-phrasing: intent: Update an Xpanse attack surface incident effect: write questions: - How do I close an attack surface incident once the exposure is fixed? - Can I record resolution details on an Xpanse incident to track remediation? instructions: - text: Update the Xpanse attack surface incident using {request_data}. slots: request_data: requestBody.request_data - text: Mark the attack surface exposure in {request_data} as resolved. slots: request_data: requestBody.request_data method: generated generated: '2026-09-26' - target: $.paths['/incident'].post update: x-apievangelist-phrasing: intent: Create a Cortex XSOAR incident effect: write questions: - How do I open a new incident in Cortex XSOAR from an external alert? - Can XSOAR start an investigation automatically when I create an incident? - Which custom fields can I set when raising an XSOAR incident of a given type? instructions: - text: Create an XSOAR incident named {name} of type {type} with severity {severity}. slots: name: requestBody.name type: requestBody.type severity: requestBody.severity - text: Open an XSOAR incident called {name} owned by {owner} and start its investigation. slots: name: requestBody.name owner: requestBody.owner - text: Raise incident {name} in XSOAR with details {details}. slots: name: requestBody.name details: requestBody.details method: generated generated: '2026-09-26' - target: $.paths['/incidents/search'].get update: x-apievangelist-phrasing: intent: Search XSOAR incidents with a query string effect: read questions: - Can I search XSOAR incidents with a Lucene query like status:Active AND severity:High? - What XSOAR incidents were created between two dates? instructions: - text: Search XSOAR incidents with query {query} and return {size} results. slots: query: query.query size: query.size - text: Find XSOAR incidents created from {fromdate} to {todate} via the URL query search. slots: fromdate: query.fromdate todate: query.todate method: generated generated: '2026-09-26' - target: $.paths['/incidents/search'].post update: x-apievangelist-phrasing: intent: Search XSOAR incidents with a structured filter effect: read questions: - How do I run a complex XSOAR incident search with field selection and sorting? - Can I page through XSOAR search results using a structured filter body? instructions: - text: Search XSOAR incidents using structured filter {filter}. slots: filter: requestBody.filter - text: Run a structured XSOAR incident search for {filter} between {fromDate} and {toDate}. slots: filter: requestBody.filter fromDate: requestBody.fromDate toDate: requestBody.toDate method: generated generated: '2026-09-26' - target: $.paths['/incident/{id}'].get update: x-apievangelist-phrasing: intent: Get an XSOAR incident by ID effect: read questions: - How do I fetch every field of one XSOAR incident? - Where do I get an XSOAR incident's current version before updating it? instructions: - text: Get XSOAR incident {id}. slots: id: path.id - text: Show all fields and metadata for XSOAR incident {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/incident/update'].post update: x-apievangelist-phrasing: intent: Update or close an XSOAR incident effect: write questions: - How do I close an XSOAR incident with a close reason and notes? - Does updating an XSOAR incident need its version for optimistic locking? instructions: - text: Set XSOAR incident {id} to status {status} and owner {owner}. slots: id: requestBody.id status: requestBody.status owner: requestBody.owner - text: Close XSOAR incident {id} with reason {closeReason} and notes {closeNotes}. slots: id: requestBody.id closeReason: requestBody.closeReason closeNotes: requestBody.closeNotes method: generated generated: '2026-09-26' - target: $.paths['/incidents'].get update: x-apievangelist-phrasing: intent: List DLP incidents effect: read questions: - Which DLP incidents found sensitive data across my monitored channels this month? - Can I filter data loss prevention incidents by severity and status? instructions: - text: List DLP incidents with severity {severity} and status {status}. slots: severity: query.severity status: query.status - text: Show DLP incidents detected between {start_time} and {end_time}. slots: start_time: query.start_time end_time: query.end_time method: generated generated: '2026-09-26' - target: $.paths['/incidents/{incident_id}'].get update: x-apievangelist-phrasing: intent: Get a DLP incident effect: read questions: - Who was the user behind a particular DLP incident and what file was involved? - How do I see the remediation history of one DLP incident? instructions: - text: Get DLP incident {incident_id}. slots: incident_id: path.incident_id - text: Show the data pattern match context for DLP incident {incident_id}. slots: incident_id: path.incident_id method: generated generated: '2026-09-26' - target: $.paths['/incidents/{incident_id}'].put update: x-apievangelist-phrasing: intent: Update a DLP incident's status effect: write questions: - How do I move a DLP incident forward in the review workflow? - Can I add reviewer comments to a DLP incident? instructions: - text: Set DLP incident {incident_id} to status {status}. slots: incident_id: path.incident_id status: requestBody.status - text: Add reviewer comments {reviewer_comments} to DLP incident {incident_id}. slots: incident_id: path.incident_id reviewer_comments: requestBody.reviewer_comments method: generated generated: '2026-09-26' - target: $.paths['/incidents/{incident_id}/snippets'].get update: x-apievangelist-phrasing: intent: Get DLP match snippets for an incident effect: read questions: - Can I see the text around the sensitive data that triggered a DLP policy? - Are matched values masked in DLP incident snippets? instructions: - text: Get the content snippets for DLP incident {incident_id}. slots: incident_id: path.incident_id - text: Show what surrounded the matched sensitive data in incident {incident_id}. slots: incident_id: path.incident_id method: generated generated: '2026-09-26' - target: $.paths['/email-incidents'].get update: x-apievangelist-phrasing: intent: List email DLP incidents effect: read questions: - Which emails or attachments leaked sensitive data this week? - Can I page through email DLP incidents filtered by status? instructions: - text: List email DLP incidents with status {status}. slots: status: query.status - text: Show email DLP incidents between {start_time} and {end_time}. slots: start_time: query.start_time end_time: query.end_time method: generated generated: '2026-09-26' - target: $.paths['/email-incidents/{id}'].get update: x-apievangelist-phrasing: intent: Get an email DLP incident effect: read questions: - Who sent the email that triggered a DLP incident and who received it? - What verdict was applied to a specific email DLP incident? instructions: - text: Get email DLP incident {id}. slots: id: path.id - text: Show the sender, recipients and subject of email incident {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/email-incidents/{id}/verdict'].put update: x-apievangelist-phrasing: intent: Allow or block a flagged email effect: write questions: - How do I release a quarantined email that DLP blocked by mistake? - Can I override the automated verdict on an email incident and record why? instructions: - text: Set the verdict of email incident {id} to {verdict}. slots: id: path.id verdict: requestBody.verdict - text: Allow the blocked email in incident {id} with comment {comment}. slots: id: path.id comment: requestBody.comment method: generated generated: '2026-09-26' - target: $.paths['/api/incidents'].get update: x-apievangelist-phrasing: intent: List SaaS Security incidents effect: read questions: - Which SaaS apps have open incidents like external sharing of sensitive files? - Can I filter SaaS Security incidents by application and date range? instructions: - text: List SaaS Security incidents for app {app_id}. slots: app_id: query.app_id - text: Show SaaS Security incidents with severity {severity} created since {start_date}. slots: severity: query.severity start_date: query.start_date method: generated generated: '2026-09-26' - target: $.paths['/api/incidents/{id}'].get update: x-apievangelist-phrasing: intent: Get a SaaS Security incident effect: read questions: - Which users and assets were affected by a particular SaaS Security incident? - What is the event timeline for one SaaS app incident? instructions: - text: Get SaaS Security incident {id}. slots: id: path.id - text: Show the policy violations and remediation status of SaaS incident {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/api/incidents/{id}'].put update: x-apievangelist-phrasing: intent: Update a SaaS Security incident effect: write questions: - How do I assign a SaaS Security incident to someone from my SOAR playbook? - Can I add a note to a SaaS incident's timeline? instructions: - text: Assign SaaS Security incident {id} to user {assignee_id}. slots: id: path.id assignee_id: requestBody.assignee_id - text: Add note {note} to SaaS incident {id} and set status {status}. slots: id: path.id note: requestBody.note status: requestBody.status method: generated generated: '2026-09-26'