# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks Cortex XSOAR REST Investigations API version: 1.0.0 extends: openapi/palo-alto-networks-investigations-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 2 - target: $.paths['/investigations/{id}'].get update: x-apievangelist-phrasing: intent: Get an investigation's details effect: read questions: - What's in the war room and playbook status of a specific investigation? - Which incidents are linked to an investigation? instructions: - text: Get investigation {id} with its war room entries. slots: id: path.id - text: Show the playbook status for investigation {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/investigation/add'].post update: x-apievangelist-phrasing: intent: Start an investigation on an incident effect: write questions: - How do I open a new investigation on an existing incident? - Can one incident have more than one investigation? instructions: - text: Create an investigation for incident {incidentId}. slots: incidentId: requestBody.incidentId - text: Start investigation {name} on incident {incidentId}. slots: name: requestBody.name incidentId: requestBody.incidentId method: generated generated: '2026-09-26'