# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks Search API version: 1.0.0 extends: openapi/palo-alto-networks-search-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 20 - target: $.paths['/search/config'].post update: x-apievangelist-phrasing: intent: Run an RQL config search effect: read questions: - How do I run an RQL config query to find misconfigured cloud resources in Prisma Cloud? - Can I save a config search with a name and description when I run it? - Which cloud resources violate policy right now according to a config query? instructions: - text: Run the config query {query} and save it as {searchName}. slots: query: requestBody.query searchName: requestBody.searchName - text: Run config query {query} and include the full resource JSON in the results. slots: query: requestBody.query method: generated generated: '2026-09-26' - target: $.paths['/search'].post update: x-apievangelist-phrasing: intent: Search network flow logs with RQL effect: read questions: - How can I query cloud flow logs to see which network traffic reached a resource? - Can a network flow-log search be returned as a CSV instead of JSON? - What network traffic matched my RQL query over the last day? instructions: - text: Search flow logs with network query {query} over time range {timeRange}. slots: query: requestBody.query timeRange: requestBody.timeRange - text: Run network query {query} for {timeRange} grouped by {groupBy}. slots: query: requestBody.query timeRange: requestBody.timeRange groupBy: requestBody.groupBy method: generated generated: '2026-09-26' - target: $.paths['/search/event'].post update: x-apievangelist-phrasing: intent: Search audit events with RQL effect: read questions: - How do I find console and API access events in the audit log using RQL? - Which privileged activities happened in my cloud accounts this week? - Is there a way to detect signs of account compromise from audit event data? instructions: - text: Run audit event query {query} over {timeRange}. slots: query: requestBody.query timeRange: requestBody.timeRange - text: Search audit events with {query} and return at most {limit} results. slots: query: requestBody.query limit: requestBody.limit method: generated generated: '2026-09-26' - target: $.paths['/search/event/aggregate'].post update: x-apievangelist-phrasing: intent: Run an aggregated audit event search effect: read questions: - Can I get audit event results broken down by location and service? - Where geographically and in which services did my audit events come from? instructions: - text: Run aggregated event query {query} to show location and service breakdowns. slots: query: requestBody.query - text: Aggregate audit events matching {query} over {timeRange} by location and service. slots: query: requestBody.query timeRange: requestBody.timeRange method: generated generated: '2026-09-26' - target: $.paths['/search/event/filtered'].post update: x-apievangelist-phrasing: intent: Filter audit event search results effect: read questions: - How do I narrow down the results of an aggregated audit event search with extra filters? - Can I refine event log results after the first search without rerunning everything? instructions: - text: Refine event results for {query} using filters {filters}. slots: query: requestBody.query filters: requestBody.filters - text: Filter the event log search {query} down with {filters} and sort by {sort}. slots: query: requestBody.query filters: requestBody.filters sort: requestBody.sort method: generated generated: '2026-09-26' - target: $.paths['/search/event/page'].post update: x-apievangelist-phrasing: intent: Get the next page of audit event results effect: read questions: - My audit event search returned over 100 results — how do I fetch the next page? - What token do I pass to page through event search results? instructions: - text: Fetch the next page of event search results using page token {pageToken}. slots: pageToken: requestBody.pageToken - text: Get {limit} more audit events with page token {pageToken}. slots: limit: requestBody.limit pageToken: requestBody.pageToken method: generated generated: '2026-09-26' - target: $.paths['/search/event/raw/{id}'].get update: x-apievangelist-phrasing: intent: Get raw metadata for an audit event effect: read questions: - How do I see the raw metadata behind a single audit event? - Can I pull the unprocessed JSON for one specific event ID? instructions: - text: Show the raw event data for audit event {id}. slots: id: path.id - text: Get raw metadata for event {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/search/suggest'].post update: x-apievangelist-phrasing: intent: Autocomplete a partial RQL query effect: read questions: - What can I type next to finish a partial RQL query? - Which expressions, values and operators are valid after the RQL I've started writing? instructions: - text: Suggest completions for the partial RQL query {query}. slots: query: requestBody.query - text: Autocomplete {query} for time range {timeRange}. slots: query: requestBody.query timeRange: requestBody.timeRange method: generated generated: '2026-09-26' - target: $.paths['/search/alert'].get update: x-apievangelist-phrasing: intent: Get investigation data for an alert effect: read questions: - How do I pull the search data needed to investigate an anomaly or network alert? - Does alert investigation data work for every alert type or only anomaly and network alerts? instructions: - text: Get investigation search data for alert {alertId}. slots: alertId: query.alertId - text: Investigate network alert {alertId}. slots: alertId: query.alertId method: generated generated: '2026-09-26' - target: $.paths['/search/config/page'].post update: x-apievangelist-phrasing: intent: Get the next page of config search results effect: read questions: - My config search found over 100 resources — how do I load the next page? - Can I include resource JSON when paging through config search results? instructions: - text: Load the next page of config search results with token {pageToken}. slots: pageToken: requestBody.pageToken - text: Fetch {limit} more config results using page token {pageToken}. slots: limit: requestBody.limit pageToken: requestBody.pageToken method: generated generated: '2026-09-26' - target: $.paths['/search/event/filtered/download'].post update: x-apievangelist-phrasing: intent: Download audit event search results as CSV effect: read questions: - Can I export an audit event log search to a CSV file? - How do I download filtered event search results for a spreadsheet? instructions: - text: Download audit events matching {query} as a CSV. slots: query: requestBody.query - text: Export the event log search {query} for {timeRange} to CSV. slots: query: requestBody.query timeRange: requestBody.timeRange method: generated generated: '2026-09-26' - target: $.paths['/search/config/jobs'].post update: x-apievangelist-phrasing: intent: Start a config search CSV export job effect: write questions: - How do I kick off a background job that builds a CSV of config query results? - Can I generate a config CSV from a saved search ID rather than a new query? - What job ID and status do I get back when submitting a config CSV job? instructions: - text: Submit a CSV generation job for config query {query} named {searchName}. slots: query: requestBody.query searchName: requestBody.searchName - text: Start a config CSV job from saved search {id}. slots: id: requestBody.id method: generated generated: '2026-09-26' - target: $.paths['/search/config/jobs/{id}/download'].get update: x-apievangelist-phrasing: intent: Download a finished config CSV job effect: read questions: - My config CSV job is done — how do I download the file? - Where do I get the CSV produced by a submitted config search job? instructions: - text: Download the CSV output of config search job {id}. slots: id: path.id - text: Fetch the finished config CSV for job {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/search/api/v1/config'].post update: x-apievangelist-phrasing: intent: Run a config search by RQL query (v1 API) effect: read questions: - How do I run an RQL config query through the v1 search API and get a page token back? - Can I skip saving the search to history when I run a v1 config query? instructions: - text: Run v1 config query {query} without creating a saved search. slots: query: requestBody.query - text: Use the v1 config search API to run {query} with next page token {nextPageToken}. slots: query: requestBody.query nextPageToken: requestBody.nextPageToken method: generated generated: '2026-09-26' - target: $.paths['/search/api/v1/config/async'].post update: x-apievangelist-phrasing: intent: Get config search results as CSV asynchronously effect: read questions: - Can the reporting service send config query results as CSV asynchronously? - How do I get an async CSV of a saved config search from the reporting service? instructions: - text: Request async CSV results from the reporting service for config query {query}. slots: query: requestBody.query - text: Get async CSV results for saved search {savedSearchId} with query {query}. slots: savedSearchId: requestBody.savedSearchId query: requestBody.query method: generated generated: '2026-09-26' - target: $.paths['/search/api/v1/config/download'].post update: x-apievangelist-phrasing: intent: Download config search results as CSV directly effect: read questions: - How do I download config query results straight to a CSV in one call? - Is there a synchronous endpoint that returns a config search as CSV? instructions: - text: Download config query {query} results as a CSV file right now. slots: query: requestBody.query - text: Export saved config search {savedSearchId} using query {query} to CSV immediately. slots: savedSearchId: requestBody.savedSearchId query: requestBody.query method: generated generated: '2026-09-26' - target: $.paths['/search/api/v2/config'].post update: x-apievangelist-phrasing: intent: Run a config search with a start time (v2) effect: read questions: - How do I run a v2 config query that starts at a given time and ends now? - Does the v2 config search return the newer descriptive resource type names like EC2 Instance? instructions: - text: Run v2 config query {query} starting from {startTime}. slots: query: requestBody.query startTime: requestBody.startTime - text: Use config search v2 to run {query} returning {limit} results. slots: query: requestBody.query limit: requestBody.limit method: generated generated: '2026-09-26' - target: $.paths['/search/api/v2/config/{id}'].post update: x-apievangelist-phrasing: intent: Rerun a saved config search by ID (v2) effect: read questions: - Can I rerun an existing config search by its ID using the v2 start-time format? - How do I page through a v2 config search that I already created? instructions: - text: Rerun config search {id} with the v2 API from {startTime}. slots: id: path.id startTime: requestBody.startTime - text: Get the next v2 results for search {id} using token {nextPageToken}. slots: id: path.id nextPageToken: requestBody.nextPageToken method: generated generated: '2026-09-26' - target: $.paths['/search/api/v1/config/{id}'].post update: x-apievangelist-phrasing: intent: Rerun a saved config search by ID (v1) effect: read questions: - How do I get results for an existing config search ID with a time range in v1? - Can I rerun a previous config search by ID instead of retyping the RQL? instructions: - text: Rerun v1 config search {id} over time range {timeRange}. slots: id: path.id timeRange: requestBody.timeRange - text: Get {limit} results from existing config search {id}. slots: limit: requestBody.limit id: path.id method: generated generated: '2026-09-26' - target: $.paths['/search/asset'].post update: x-apievangelist-phrasing: intent: Search cloud assets with RQL effect: read questions: - Which cloud assets match an RQL asset query across my resource configurations? - Can one asset search cover config, network and event query types? instructions: - text: Search assets with RQL {query} over {timeRange}. slots: query: requestBody.query timeRange: requestBody.timeRange - text: Find up to {limit} assets matching {query} in {timeRange}. slots: limit: requestBody.limit query: requestBody.query timeRange: requestBody.timeRange method: generated generated: '2026-09-26'