# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks PAN-OS REST Objects API version: 1.0.0 extends: openapi/palo-alto-networks-objects-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 20 - target: $.paths['/Objects/Addresses'].get update: x-apievangelist-phrasing: intent: List firewall address objects effect: read questions: - Which IP addresses, subnets and FQDNs are defined as address objects on my firewall? - Can I see only the address objects shared across device groups rather than one vsys? - What address objects exist in vsys1 on the PAN-OS firewall? instructions: - text: List all address objects on the firewall. - text: Show address objects in virtual system {vsys}. slots: vsys: query.vsys - text: Look up the address object named {name} at location {location}. slots: name: query.name location: query.location method: generated generated: '2026-09-26' - target: $.paths['/Objects/Addresses'].put update: x-apievangelist-phrasing: intent: Replace an address object's definition effect: write questions: - How do I change the IP subnet an existing address object points to? - Does editing an address object replace its whole definition or just the fields I send? - Can I switch an existing address object from an IP range to an FQDN? instructions: - text: Replace address object {name} with the definition {entry}. slots: name: query.name entry: requestBody.entry - text: Update address object {name} in vsys {vsys} so it resolves to {entry}. slots: name: query.name vsys: query.vsys entry: requestBody.entry method: generated generated: '2026-09-26' - target: $.paths['/Objects/Addresses'].post update: x-apievangelist-phrasing: intent: Create a firewall address object effect: write questions: - How do I define a new IP netmask, IP range or FQDN as a named address object? - Does a new address object name have to be unique within its location? - Can I add a wildcard address object to use in security rules? instructions: - text: Create address object {name} with {entry}. slots: name: query.name entry: requestBody.entry - text: Add a new address object {name} at {location} defined as {entry}. slots: name: query.name location: query.location entry: requestBody.entry method: generated generated: '2026-09-26' - target: $.paths['/Objects/Addresses'].delete update: x-apievangelist-phrasing: intent: Delete a firewall address object effect: destructive questions: - Why can't I remove an address object that a security rule still references? - What happens if I delete an address object that belongs to an address group? instructions: - text: Delete address object {name}. slots: name: query.name - text: Remove the address object {name} from vsys {vsys}. slots: name: query.name vsys: query.vsys method: generated generated: '2026-09-26' - target: $.paths['/Objects/AddressGroups'].get update: x-apievangelist-phrasing: intent: List firewall address groups effect: read questions: - Which address groups are configured on my firewall, static and dynamic? - Can I see which address groups exist in a particular vsys or device group? instructions: - text: List every address group on the firewall. - text: Show the address group named {name}. slots: name: query.name - text: List address groups at location {location}. slots: location: query.location method: generated generated: '2026-09-26' - target: $.paths['/Objects/AddressGroups'].put update: x-apievangelist-phrasing: intent: Replace an address group definition effect: write questions: - How do I change the members of an existing static address group? - Can I rewrite the tag filter on a dynamic address group I already have? instructions: - text: Replace address group {name} with the definition {entry}. slots: name: query.name entry: requestBody.entry - text: Update the members of address group {name} to {entry}. slots: name: query.name entry: requestBody.entry method: generated generated: '2026-09-26' - target: $.paths['/Objects/AddressGroups'].post update: x-apievangelist-phrasing: intent: Create a static or dynamic address group effect: write questions: - Can I build an address group that picks up addresses automatically by tag? - What is needed to group several address objects into one new static group? instructions: - text: Create address group {name} with members {entry}. slots: name: query.name entry: requestBody.entry - text: Create a dynamic address group {name} in vsys {vsys} using the tag filter {entry}. slots: name: query.name vsys: query.vsys entry: requestBody.entry method: generated generated: '2026-09-26' - target: $.paths['/Objects/AddressGroups'].delete update: x-apievangelist-phrasing: intent: Delete a firewall address group effect: destructive questions: - Is it possible to remove an address group without deleting the address objects inside it? - Which call removes an address group by name from the firewall? instructions: - text: Delete address group {name}. slots: name: query.name - text: Remove address group {name} from location {location}. slots: name: query.name location: query.location method: generated generated: '2026-09-26' - target: $.paths['/Objects/Services'].get update: x-apievangelist-phrasing: intent: List TCP/UDP service objects effect: read questions: - Which TCP and UDP port definitions exist as service objects on my firewall? - Can I check whether a service object for a given port already exists by name? instructions: - text: List all service objects on the firewall. - text: Show the service object named {name}. slots: name: query.name method: generated generated: '2026-09-26' - target: $.paths['/Objects/Services'].put update: x-apievangelist-phrasing: intent: Update a service object's ports effect: write questions: - How do I change the destination port on an existing service object? - Can I switch a service object from TCP to UDP after creating it? instructions: - text: Update service object {name} to {entry}. slots: name: query.name entry: requestBody.entry - text: Change the port definition of service {name} in vsys {vsys} to {entry}. slots: name: query.name vsys: query.vsys entry: requestBody.entry method: generated generated: '2026-09-26' - target: $.paths['/Objects/Services'].post update: x-apievangelist-phrasing: intent: Create a TCP or UDP service object effect: write questions: - How do I define a custom port or port range as a service for firewall rules? - Can a new service object cover a range of destination ports? instructions: - text: Create service object {name} for {entry}. slots: name: query.name entry: requestBody.entry - text: Add a new service {name} at location {location} with protocol and port {entry}. slots: name: query.name location: query.location entry: requestBody.entry method: generated generated: '2026-09-26' - target: $.paths['/Objects/Services'].delete update: x-apievangelist-phrasing: intent: Delete a service object effect: destructive questions: - What removes a custom port service object I no longer use? - Can I delete a service object from one specific vsys only? instructions: - text: Delete service object {name}. slots: name: query.name - text: Remove service {name} from vsys {vsys}. slots: name: query.name vsys: query.vsys method: generated generated: '2026-09-26' - target: $.paths['/Objects/ServiceGroups'].get update: x-apievangelist-phrasing: intent: List service groups effect: read questions: - Which service groups bundle my port definitions together on the firewall? - Can I look up one service group by name to see what it contains? instructions: - text: List all service groups. - text: Show the service group {name}. slots: name: query.name method: generated generated: '2026-09-26' - target: $.paths['/Objects/ServiceGroups'].put update: x-apievangelist-phrasing: intent: Update a service group's members effect: write questions: - How do I add or remove services in an existing service group? - Can I edit a service group's membership in place by name? instructions: - text: Update service group {name} to contain {entry}. slots: name: query.name entry: requestBody.entry - text: Replace the members of service group {name} in vsys {vsys} with {entry}. slots: name: query.name vsys: query.vsys entry: requestBody.entry method: generated generated: '2026-09-26' - target: $.paths['/Objects/ServiceGroups'].post update: x-apievangelist-phrasing: intent: Create a service group effect: write questions: - Can I bundle several service objects into one group for use in a policy rule? - What does it take to create a new service group on the firewall? instructions: - text: Create service group {name} with services {entry}. slots: name: query.name entry: requestBody.entry - text: Create a new service group {name} at {location} containing {entry}. slots: name: query.name location: query.location entry: requestBody.entry method: generated generated: '2026-09-26' - target: $.paths['/Objects/ServiceGroups'].delete update: x-apievangelist-phrasing: intent: Delete a service group effect: destructive questions: - Which call removes a service group by name? - Can I delete a service group but keep the individual service objects? instructions: - text: Delete service group {name}. slots: name: query.name - text: Remove service group {name} from location {location}. slots: name: query.name location: query.location method: generated generated: '2026-09-26' - target: $.paths['/Objects/Tags'].get update: x-apievangelist-phrasing: intent: List configuration tags effect: read questions: - Which tags are defined on my firewall for grouping addresses and rules? - Can I list the tags available in a particular vsys? instructions: - text: List all tags on the firewall. - text: Show the tag named {name}. slots: name: query.name - text: List tags defined in vsys {vsys}. slots: vsys: query.vsys method: generated generated: '2026-09-26' - target: $.paths['/Objects/Tags'].put update: x-apievangelist-phrasing: intent: Update a tag's color or comment effect: write questions: - How do I change the color or comment on an existing firewall tag? - Can I edit a tag that is already used by dynamic address groups? instructions: - text: Update tag {name} with {entry}. slots: name: query.name entry: requestBody.entry - text: Change the color and comment of tag {name} in vsys {vsys} to {entry}. slots: name: query.name vsys: query.vsys entry: requestBody.entry method: generated generated: '2026-09-26' - target: $.paths['/Objects/Tags'].post update: x-apievangelist-phrasing: intent: Create a tag for grouping objects effect: write questions: - How do I create a tag with a color so I can drive dynamic address groups from it? - Can I add a comment to a new tag when I create it? instructions: - text: Create tag {name} with {entry}. slots: name: query.name entry: requestBody.entry - text: Add a new tag {name} at location {location} with color and comment {entry}. slots: name: query.name location: query.location entry: requestBody.entry method: generated generated: '2026-09-26' - target: $.paths['/Objects/Tags'].delete update: x-apievangelist-phrasing: intent: Delete a tag effect: destructive questions: - Which call deletes a tag I no longer use on the firewall? - Can I remove a tag from one vsys by name? instructions: - text: Delete tag {name}. slots: name: query.name - text: Remove tag {name} from vsys {vsys}. slots: name: query.name vsys: query.vsys method: generated generated: '2026-09-26'