# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks Settings API version: 1.0.0 extends: openapi/palo-alto-networks-settings-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 84 - target: $.paths['/api/v34.03/settings/certificates'].post update: x-apievangelist-phrasing: intent: Set custom CA client cert settings (v34.03) effect: write questions: - Can I upload a custom CA certificate through the v34.03 settings API? - What certificate period can I set for custom-CA clients on v34.03? instructions: - text: Using API v34.03, set the custom CA certificate to {accessCaCert}. slots: accessCaCert: requestBody.accessCaCert - text: On v34.03, set the custom-CA certificate period to {certificatePeriodDays} days. slots: certificatePeriodDays: requestBody.certificatePeriodDays method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/certs'].get update: x-apievangelist-phrasing: intent: Get Compute certificate settings (v34.03) effect: read questions: - What does the v34.03 API report for Compute certificate settings? - Where is the CA expiration shown in the older 34.03 certs endpoint? instructions: - text: Show Compute certificate settings from API v34.03. - text: Get console SAN and CA expiration using the v34.03 endpoint. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/certs'].post update: x-apievangelist-phrasing: intent: Set Compute certificate settings (v34.03) effect: write questions: - Can I change the console SAN list via the v34.03 API? - Where do I set CA expiration on the older 34.03 API? instructions: - text: On v34.03, set the console SAN list to {consoleSAN}. slots: consoleSAN: requestBody.consoleSAN - text: Using API v34.03, set the CA expiration to {caExpiration}. slots: caExpiration: requestBody.caExpiration method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/console-certificate'].post update: x-apievangelist-phrasing: intent: Set console access cert settings (v34.03) effect: write questions: - Can I set a custom console certificate through the v34.03 API? - Does v34.03 let me require revocation checks for console clients? instructions: - text: Using API v34.03, set the console CA certificate to {consoleCaCert}. slots: consoleCaCert: requestBody.consoleCaCert - text: On v34.03, set console certificate revocation checking to {checkRevocation}. slots: checkRevocation: requestBody.checkRevocation method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/custom-labels'].get update: x-apievangelist-phrasing: intent: Get custom alert labels (v34.03) effect: read questions: - Which alert labels does the v34.03 API return? - Where do I read custom alert labels on the older 34.03 API? instructions: - text: Show custom alert labels from API v34.03. - text: List alert labels using the v34.03 endpoint. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/custom-labels'].post update: x-apievangelist-phrasing: intent: Set custom alert labels (v34.03) effect: write questions: - Can I add alert labels through the v34.03 settings API? - Where do I define alert labels on API version 34.03? instructions: - text: Using API v34.03, set alert labels to {labels}. slots: labels: requestBody.labels - text: On v34.03, add alert labels {labels}. slots: labels: requestBody.labels method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/defender'].get update: x-apievangelist-phrasing: intent: Get advanced Defender settings (v34.03) effect: read questions: - What does the v34.03 API return for advanced Defender settings? - Where are Defender settings on the older 34.03 API? instructions: - text: Show advanced Defender settings from API v34.03. - text: Get the Defender configuration using the v34.03 endpoint. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/intelligence'].get update: x-apievangelist-phrasing: intent: Get Intelligence Stream settings (v34.03) effect: read questions: - What Intelligence Stream settings does the v34.03 API report? - Is the custom Intelligence endpoint shown on the older 34.03 API? instructions: - text: Show Intelligence Stream settings from API v34.03. - text: Check the Windows feed setting using the v34.03 endpoint. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/intelligence'].post update: x-apievangelist-phrasing: intent: Configure Intelligence Stream (v34.03) effect: write questions: - Can I enable the Intelligence Stream through the v34.03 API? - Does v34.03 support a custom Intelligence endpoint? instructions: - text: On v34.03, enable Intelligence Stream at {address} with token {token}. slots: address: requestBody.address token: requestBody.token - text: Using API v34.03, set custom endpoint {customEndpoint} with credential {customEndpointCredentialID}. slots: customEndpoint: requestBody.customEndpoint customEndpointCredentialID: requestBody.customEndpointCredentialID method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/ldap'].get update: x-apievangelist-phrasing: intent: Get LDAP integration settings (v34.03) effect: read questions: - What LDAP settings does the v34.03 API return? - Where do I read the LDAP search base on the older 34.03 API? instructions: - text: Show LDAP settings from API v34.03. - text: Get the LDAP server type using the v34.03 endpoint. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/ldap'].post update: x-apievangelist-phrasing: intent: Configure LDAP integration (v34.03) effect: write questions: - Can I set up LDAP through the v34.03 settings API? - Does v34.03 let me set user and group search bases for LDAP? instructions: - text: Using API v34.03, enable LDAP at {url} of type {type} with search base {searchBase}. slots: url: requestBody.url type: requestBody.type searchBase: requestBody.searchBase - text: On v34.03, set LDAP bind account {accountUpn} and group search base {groupSearchBase}. slots: accountUpn: requestBody.accountUpn groupSearchBase: requestBody.groupSearchBase method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/license'].get update: x-apievangelist-phrasing: intent: Get the Compute license (v34.03) effect: read questions: - What license does the v34.03 API report for Compute? - Where do I read license details on the older 34.03 API? instructions: - text: Show the Compute license from API v34.03. - text: Get license details using the v34.03 endpoint. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/license'].post update: x-apievangelist-phrasing: intent: Install a Compute license key (v34.03) effect: write questions: - Can I apply a license key through the v34.03 API? - Where do I enter a license key on API version 34.03? instructions: - text: Using API v34.03, install license key {key}. slots: key: requestBody.key - text: On v34.03, replace the license with key {key}. slots: key: requestBody.key method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/logging'].get update: x-apievangelist-phrasing: intent: Get logging settings (v34.03) effect: read questions: - What logging settings does the v34.03 API return? - Is syslog shown in the older 34.03 logging endpoint? instructions: - text: Show logging settings from API v34.03. - text: Get syslog configuration using the v34.03 endpoint. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/logging'].post update: x-apievangelist-phrasing: intent: Configure logging settings (v34.03) effect: write questions: - Can I set syslog forwarding through the v34.03 API? - Does v34.03 let me include forensic links in logs? instructions: - text: On v34.03, set syslog logging to {syslog}. slots: syslog: requestBody.syslog - text: Using API v34.03, set console address {consoleAddress} and metrics collection {enableMetricsCollection}. slots: consoleAddress: requestBody.consoleAddress enableMetricsCollection: requestBody.enableMetricsCollection method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/logon'].get update: x-apievangelist-phrasing: intent: Get logon settings (v34.03) effect: read questions: - What logon settings does the v34.03 API report? - Where do I read the session timeout on the older 34.03 API? instructions: - text: Show logon settings from API v34.03. - text: Check basic auth status using the v34.03 endpoint. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/logon'].post update: x-apievangelist-phrasing: intent: Configure logon settings (v34.03) effect: write questions: - Can I change the session timeout through the v34.03 API? - Does v34.03 support enforcing strong passwords? instructions: - text: Using API v34.03, set session timeout to {sessionTimeoutSec} seconds. slots: sessionTimeoutSec: requestBody.sessionTimeoutSec - text: On v34.03, set strong passwords {strongPassword} and basic auth disabled {basicAuthDisabled}. slots: strongPassword: requestBody.strongPassword basicAuthDisabled: requestBody.basicAuthDisabled method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/oauth'].get update: x-apievangelist-phrasing: intent: Get OAuth sign-in settings (v34.03) effect: read questions: - What OAuth settings does the v34.03 API return? - Where do I read the OAuth client ID on the older 34.03 API? instructions: - text: Show OAuth settings from API v34.03. - text: Get the OAuth provider using the v34.03 endpoint. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/oauth'].post update: x-apievangelist-phrasing: intent: Configure OAuth sign-in (v34.03) effect: write questions: - Can I set up OAuth login through the v34.03 API? - Does v34.03 let me set the OAuth group claim? instructions: - text: On v34.03, enable OAuth with client {clientID}, auth URL {authURL} and token URL {tokenURL}. slots: clientID: requestBody.clientID authURL: requestBody.authURL tokenURL: requestBody.tokenURL - text: Using API v34.03, set OAuth provider {providerName} with group claim {groupClaim}. slots: providerName: requestBody.providerName groupClaim: requestBody.groupClaim method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/oidc'].get update: x-apievangelist-phrasing: intent: Get OpenID Connect settings (v34.03) effect: read questions: - What OIDC settings does the v34.03 API return? - Where is the OIDC issuer URL on the older 34.03 API? instructions: - text: Show OpenID Connect settings from API v34.03. - text: Get the OIDC issuer using the v34.03 endpoint. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/oidc'].post update: x-apievangelist-phrasing: intent: Configure OpenID Connect sign-in (v34.03) effect: write questions: - Can I set up OIDC single sign-on through the v34.03 API? - Does v34.03 let me set the OIDC user claim? instructions: - text: Using API v34.03, enable OIDC with issuer {openIDIssuesURL} and client {clientID}. slots: openIDIssuesURL: requestBody.openIDIssuesURL clientID: requestBody.clientID - text: On v34.03, set OIDC user claim {userClaim} and group scope {groupScope}. slots: userClaim: requestBody.userClaim groupScope: requestBody.groupScope method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/proxy'].get update: x-apievangelist-phrasing: intent: Get Compute proxy settings (v34.03) effect: read questions: - What proxy settings does the v34.03 API report? - Where is the no-proxy list on the older 34.03 API? instructions: - text: Show proxy settings from API v34.03. - text: Get the proxy address using the v34.03 endpoint. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/proxy'].post update: x-apievangelist-phrasing: intent: Configure the Compute proxy (v34.03) effect: write questions: - Can I set an HTTP proxy through the v34.03 API? - Does v34.03 let Defenders trust a proxy CA? instructions: - text: On v34.03, route traffic through proxy {httpProxy} excluding {noProxy}. slots: httpProxy: requestBody.httpProxy noProxy: requestBody.noProxy - text: Using API v34.03, set proxy user {user} and proxy CA {ca}. slots: user: requestBody.user ca: requestBody.ca method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/registry'].get update: x-apievangelist-phrasing: intent: Get registry scanning settings (v34.03) effect: read questions: - What registry scan settings does the v34.03 API return? - Where do I list scanned registries on the older 34.03 API? instructions: - text: Show registry scan settings from API v34.03. - text: List configured registries using the v34.03 endpoint. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/registry'].put update: x-apievangelist-phrasing: intent: Replace registry scan specs (v34.03) effect: write questions: - Can I replace all registry specifications through the v34.03 API? - Does v34.03 let me save registry settings without starting a scan? instructions: - text: Using API v34.03, replace registry specifications with {specifications}. slots: specifications: requestBody.specifications - text: On v34.03, overwrite registry specs with {specifications} and scan later {scanLater}. slots: specifications: requestBody.specifications scanLater: query.scanLater method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/registry'].post update: x-apievangelist-phrasing: intent: Add a registry to scan (v34.03) effect: write questions: - Can I add a container registry for scanning via the v34.03 API? - Does v34.03 support capping images scanned per repository? instructions: - text: On v34.03, add registry {registry} of type {version} with repositories {repository}. slots: registry: requestBody.registry version: requestBody.version repository: requestBody.repository - text: Using API v34.03, add registry {registry} with credential {credentialID} and cap {cap}. slots: registry: requestBody.registry credentialID: requestBody.credentialID cap: requestBody.cap method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/saml'].get update: x-apievangelist-phrasing: intent: Get SAML sign-in settings (v34.03) effect: read questions: - What SAML settings does the v34.03 API return? - Where is the SAML issuer on the older 34.03 API? instructions: - text: Show SAML settings from API v34.03. - text: Get SAML audience using the v34.03 endpoint. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/saml'].post update: x-apievangelist-phrasing: intent: Configure SAML sign-in (v34.03) effect: write questions: - Can I set up SAML SSO through the v34.03 API? - Does v34.03 let me set the SAML group attribute? instructions: - text: Using API v34.03, enable SAML with SSO URL {url}, issuer {issuer} and audience {audience}. slots: url: requestBody.url issuer: requestBody.issuer audience: requestBody.audience - text: On v34.03, set SAML group attribute {groupAttribute} and console URL {consoleURL}. slots: groupAttribute: requestBody.groupAttribute consoleURL: requestBody.consoleURL method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/scan'].get update: x-apievangelist-phrasing: intent: Get global scan settings (v34.03) effect: read questions: - What scan intervals does the v34.03 API report? - Where are global scan settings on the older 34.03 API? instructions: - text: Show global scan settings from API v34.03. - text: Get image and registry scan periods using the v34.03 endpoint. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/scan'].post update: x-apievangelist-phrasing: intent: Configure global scan settings (v34.03) effect: write questions: - Can I change the image scan interval through the v34.03 API? - Does v34.03 support a retention period for deleted registry images? instructions: - text: On v34.03, set image scan period to {imagesScanPeriodMs} ms. slots: imagesScanPeriodMs: requestBody.imagesScanPeriodMs - text: Using API v34.03, set registry retention {registryScanRetentionDays} days and negligible vulns shown {showNegligibleVulnerabilities}. slots: registryScanRetentionDays: requestBody.registryScanRetentionDays showNegligibleVulnerabilities: requestBody.showNegligibleVulnerabilities method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/tas'].get update: x-apievangelist-phrasing: intent: Get TAS settings (v34.03) effect: read questions: - What TAS settings does the v34.03 API return? - Where are Tanzu settings on the older 34.03 API? instructions: - text: Show TAS settings from API v34.03. - text: Get Tanzu Application Service config using the v34.03 endpoint. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/tas'].post update: x-apievangelist-phrasing: intent: Save TAS settings (v34.03) effect: write questions: - Can I save TAS settings through the v34.03 API? - Where do I update Tanzu settings on API version 34.03? instructions: - text: Save TAS settings using API v34.03. - text: On v34.03, update the Tanzu Application Service settings. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/telemetry'].get update: x-apievangelist-phrasing: intent: Get telemetry settings (v34.03) effect: read questions: - What telemetry setting does the v34.03 API report? - Where do I check telemetry on the older 34.03 API? instructions: - text: Show telemetry settings from API v34.03. - text: Check telemetry status using the v34.03 endpoint. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/telemetry'].post update: x-apievangelist-phrasing: intent: Turn telemetry on or off (v34.03) effect: write questions: - Can I toggle telemetry through the v34.03 API? - Does v34.03 let me opt out of telemetry? instructions: - text: Using API v34.03, set telemetry enabled to {enabled}. slots: enabled: requestBody.enabled - text: On v34.03, switch telemetry to {enabled}. slots: enabled: requestBody.enabled method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/trusted-certificate'].post update: x-apievangelist-phrasing: intent: Add one trusted certificate (v34.03) effect: write questions: - Can I append a single trusted certificate through the v34.03 API? - Where do I add one PEM certificate on API version 34.03? instructions: - text: Using API v34.03, add certificate {certificate} to the trusted list. slots: certificate: requestBody.certificate - text: On v34.03, trust PEM certificate {certificate}. slots: certificate: requestBody.certificate method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/trusted-certificates'].post update: x-apievangelist-phrasing: intent: Configure trusted certificates (v34.03) effect: write questions: - Can I set the full trusted certificate list via the v34.03 API? - Does v34.03 support revocation checks for trusted certificates? instructions: - text: On v34.03, enable trusted certificates with list {certs}. slots: certs: requestBody.certs - text: Using API v34.03, set trusted certs enabled {enabled} and revocation checking {checkRevocation}. slots: enabled: requestBody.enabled checkRevocation: requestBody.checkRevocation method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/vm'].get update: x-apievangelist-phrasing: intent: Get VM image scan settings (v34.03) effect: read questions: - What VM image scan settings does the v34.03 API return? - Where are VM scan rules on the older 34.03 API? instructions: - text: Show VM image scan settings from API v34.03. - text: List VM scan rules using the v34.03 endpoint. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/vm'].put update: x-apievangelist-phrasing: intent: Update VM image scan settings (v34.03) effect: write questions: - Can I update VM image scan settings through the v34.03 API? - Where do I change VM scanning on API version 34.03? instructions: - text: Update VM image scan settings using API v34.03. - text: On v34.03, replace the VM image scan configuration. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.03/settings/wildfire'].get update: x-apievangelist-phrasing: intent: Get WildFire settings (v34.03) effect: read questions: - What WildFire settings does the v34.03 API return? - Where do I check WildFire on the older 34.03 API? instructions: - text: Show WildFire settings from API v34.03. - text: Get WildFire configuration using the v34.03 endpoint. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/certificates'].post update: x-apievangelist-phrasing: intent: Set custom CA certificate settings for clients effect: write questions: - Can I upload a custom CA certificate for clients that access through a custom CA? - What certificate validity period in days can I set for custom-CA client access? instructions: - text: Set the custom CA certificate for client access to {accessCaCert}. slots: accessCaCert: requestBody.accessCaCert - text: Set the custom-CA client certificate period to {certificatePeriodDays} days. slots: certificatePeriodDays: requestBody.certificatePeriodDays method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/certs'].get update: x-apievangelist-phrasing: intent: Get Compute certificate settings effect: read questions: - When does the Prisma Cloud Compute CA certificate expire? - Which SAN entries are set on the Compute console server certificate? instructions: - text: Show the Compute certificate settings. - text: Get the console SAN list and CA expiration from certificate settings. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/certs'].post update: x-apievangelist-phrasing: intent: Set Compute certificate settings effect: write questions: - Can I change the SAN list used for the Compute console server certificate? - Where do I set the CA certificate expiration for Compute? instructions: - text: Set the console server certificate SAN list to {consoleSAN}. slots: consoleSAN: requestBody.consoleSAN - text: Set the Compute CA expiration to {caExpiration}. slots: caExpiration: requestBody.caExpiration method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/console-certificate'].post update: x-apievangelist-phrasing: intent: Set console access certificate settings effect: write questions: - Can I use my own custom certificate for clients accessing the Compute console? - Is it possible to require certificate revocation checks for console clients? instructions: - text: Set the console CA certificate to {consoleCaCert}. slots: consoleCaCert: requestBody.consoleCaCert - text: Turn console client certificate revocation checking to {checkRevocation}. slots: checkRevocation: requestBody.checkRevocation method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/custom-labels'].get update: x-apievangelist-phrasing: intent: Get custom alert labels effect: read questions: - Which custom alert labels are configured in Compute? - What labels get attached to alerts right now? instructions: - text: Show my custom alert labels. - text: List the alert labels currently configured. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/custom-labels'].post update: x-apievangelist-phrasing: intent: Set custom alert labels effect: write questions: - Can I add custom labels that show up on alerts? - Where do I define which labels are included with alerts? instructions: - text: Set the custom alert labels to {labels}. slots: labels: requestBody.labels - text: Add alert labels {labels} to Compute. slots: labels: requestBody.labels method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/defender'].get update: x-apievangelist-phrasing: intent: Get advanced Defender settings effect: read questions: - What are the advanced Defender settings in Prisma Cloud Compute? - Where can I review how Defenders are configured globally? instructions: - text: Show the advanced Defender settings. - text: Get the global Defender configuration. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/intelligence'].get update: x-apievangelist-phrasing: intent: Get Intelligence Stream settings effect: read questions: - Is the Intelligence Stream enabled, and what address does it use? - Am I using a custom endpoint for the Intelligence Stream feed? instructions: - text: Show the Intelligence Stream settings. - text: Check whether the Windows feed is enabled in Intelligence Stream. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/intelligence'].post update: x-apievangelist-phrasing: intent: Configure the Intelligence Stream effect: write questions: - Can I point the Intelligence Stream at a custom endpoint with its own CA? - Is there a way to disable log uploading for the Intelligence Stream? instructions: - text: Enable the Intelligence Stream at {address} with token {token}. slots: address: requestBody.address token: requestBody.token - text: Use custom Intelligence Stream endpoint {customEndpoint} with credential {customEndpointCredentialID}. slots: customEndpoint: requestBody.customEndpoint customEndpointCredentialID: requestBody.customEndpointCredentialID method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/ldap'].get update: x-apievangelist-phrasing: intent: Get LDAP integration settings effect: read questions: - Is LDAP integration enabled, and which server URL does it use? - What LDAP search bases are configured for users and groups? instructions: - text: Show the LDAP integration settings. - text: Get the LDAP server type and search base. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/ldap'].post update: x-apievangelist-phrasing: intent: Configure LDAP integration effect: write questions: - Can I connect Compute to Active Directory or OpenLDAP for sign-in? - Where do I set the user and group search base for LDAP? instructions: - text: Enable LDAP against {url} of type {type} with search base {searchBase}. slots: url: requestBody.url type: requestBody.type searchBase: requestBody.searchBase - text: Set the LDAP bind account to {accountUpn} and group search base to {groupSearchBase}. slots: accountUpn: requestBody.accountUpn groupSearchBase: requestBody.groupSearchBase method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/license'].get update: x-apievangelist-phrasing: intent: Get the Compute license effect: read questions: - What Prisma Cloud Compute license is installed? - Where can I check my current Compute license details? instructions: - text: Show the installed Compute license. - text: Get my Prisma Cloud Compute license details. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/license'].post update: x-apievangelist-phrasing: intent: Install a Compute license key effect: write questions: - Can I apply a new license key to Prisma Cloud Compute through the API? - Where do I enter a renewed Compute license key? instructions: - text: Install Compute license key {key}. slots: key: requestBody.key - text: Replace the Compute license with key {key}. slots: key: requestBody.key method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/logging'].get update: x-apievangelist-phrasing: intent: Get logging settings effect: read questions: - Is syslog forwarding turned on for Compute? - Which console address is used in logging and alert links? instructions: - text: Show the logging settings. - text: Get the syslog and stdout logging configuration. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/logging'].post update: x-apievangelist-phrasing: intent: Configure logging settings effect: write questions: - Can I send Compute events to a syslog server? - Is it possible to include forensic event links in logs? instructions: - text: Set syslog logging to {syslog}. slots: syslog: requestBody.syslog - text: Set the console address used in logs to {consoleAddress} and metrics collection to {enableMetricsCollection}. slots: consoleAddress: requestBody.consoleAddress enableMetricsCollection: requestBody.enableMetricsCollection method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/logon'].get update: x-apievangelist-phrasing: intent: Get logon settings effect: read questions: - What is the session timeout for console logons? - Is strong password enforcement on for console users? instructions: - text: Show the logon settings. - text: Check whether basic auth is disabled for logons. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/logon'].post update: x-apievangelist-phrasing: intent: Configure logon settings effect: write questions: - Can I shorten the console session timeout? - Is there a way to require strong passwords and disable basic auth? instructions: - text: Set the console session timeout to {sessionTimeoutSec} seconds. slots: sessionTimeoutSec: requestBody.sessionTimeoutSec - text: Set strong password enforcement to {strongPassword} and basic auth disabled to {basicAuthDisabled}. slots: strongPassword: requestBody.strongPassword basicAuthDisabled: requestBody.basicAuthDisabled method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/oauth'].get update: x-apievangelist-phrasing: intent: Get OAuth sign-in settings effect: read questions: - Which OAuth identity provider is configured for console sign-in? - What auth and token URLs does the OAuth login use? instructions: - text: Show the OAuth settings. - text: Get the OAuth provider name and client ID. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/oauth'].post update: x-apievangelist-phrasing: intent: Configure OAuth sign-in effect: write questions: - Can users sign in to Compute with an OAuth 2.0 identity provider? - Where do I set the OAuth client ID, secret and group claim? instructions: - text: Enable OAuth sign-in with client {clientID} at auth URL {authURL} and token URL {tokenURL}. slots: clientID: requestBody.clientID authURL: requestBody.authURL tokenURL: requestBody.tokenURL - text: Set the OAuth provider to {providerName} with group claim {groupClaim}. slots: providerName: requestBody.providerName groupClaim: requestBody.groupClaim method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/oidc'].get update: x-apievangelist-phrasing: intent: Get OpenID Connect settings effect: read questions: - Is OpenID Connect login enabled on the console? - What OIDC issuer URL is configured? instructions: - text: Show the OpenID Connect settings. - text: Get the OIDC client ID and issuer URL. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/oidc'].post update: x-apievangelist-phrasing: intent: Configure OpenID Connect sign-in effect: write questions: - Can I set up single sign-on to Compute with an OpenID Connect provider? - Which user claim does OIDC login map usernames from? instructions: - text: Enable OIDC sign-in with issuer {openIDIssuesURL} and client {clientID}. slots: openIDIssuesURL: requestBody.openIDIssuesURL clientID: requestBody.clientID - text: Set the OIDC user claim to {userClaim} and group scope to {groupScope}. slots: userClaim: requestBody.userClaim groupScope: requestBody.groupScope method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/proxy'].get update: x-apievangelist-phrasing: intent: Get Compute proxy settings effect: read questions: - Is Compute sending traffic through an HTTP proxy? - Which addresses bypass the proxy? instructions: - text: Show the proxy settings. - text: Get the proxy address and no-proxy list. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/proxy'].post update: x-apievangelist-phrasing: intent: Configure the Compute proxy effect: write questions: - Can Defenders trust a TLS-intercepting proxy's CA? - Where do I set proxy credentials and exclusions? instructions: - text: Route traffic through proxy {httpProxy} excluding {noProxy}. slots: httpProxy: requestBody.httpProxy noProxy: requestBody.noProxy - text: Set proxy user {user} and trust proxy CA {ca}. slots: user: requestBody.user ca: requestBody.ca method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/registry'].get update: x-apievangelist-phrasing: intent: Get registry scanning settings effect: read questions: - Which container registries are configured for scanning? - What Harbor scanner and webhook paths are set for registry scanning? instructions: - text: Show the registry scan settings. - text: List the registries configured for image scanning. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/registry'].put update: x-apievangelist-phrasing: intent: Replace all registry scanning specifications effect: write questions: - Can I replace the whole list of registry scan specifications at once? - Is it possible to save registry settings without kicking off a scan? instructions: - text: Replace all registry scan specifications with {specifications}. slots: specifications: requestBody.specifications - text: Overwrite the registry specifications with {specifications} and scan later {scanLater}. slots: specifications: requestBody.specifications scanLater: query.scanLater method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/registry'].post update: x-apievangelist-phrasing: intent: Add a registry to scan effect: write questions: - Can I add one more container registry to image scanning? - Is there a cap on how many images per repo get scanned when I add a registry? instructions: - text: Add registry {registry} of type {version} for scanning, repositories {repository}. slots: registry: requestBody.registry version: requestBody.version repository: requestBody.repository - text: Add registry {registry} using credential {credentialID} and scan the newest {cap} images per repo. slots: registry: requestBody.registry credentialID: requestBody.credentialID cap: requestBody.cap method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/saml'].get update: x-apievangelist-phrasing: intent: Get SAML sign-in settings effect: read questions: - Is SAML single sign-on enabled on Compute? - Which SAML issuer and SSO URL are configured? instructions: - text: Show the SAML settings. - text: Get the SAML issuer and audience. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/saml'].post update: x-apievangelist-phrasing: intent: Configure SAML sign-in effect: write questions: - Can I set up SAML single sign-on for the Compute console? - Where do I set the SAML group attribute used for roles? instructions: - text: Enable SAML with IdP SSO URL {url}, issuer {issuer} and audience {audience}. slots: url: requestBody.url issuer: requestBody.issuer audience: requestBody.audience - text: Set the SAML group attribute to {groupAttribute} and console URL to {consoleURL}. slots: groupAttribute: requestBody.groupAttribute consoleURL: requestBody.consoleURL method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/scan'].get update: x-apievangelist-phrasing: intent: Get global scan settings effect: read questions: - How often are images, hosts and containers scanned? - Are negligible vulnerabilities shown in scan results? instructions: - text: Show the global scan settings. - text: Get the scan periods for images and registries. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/scan'].post update: x-apievangelist-phrasing: intent: Configure global scan settings effect: write questions: - Can I change how often container images get scanned? - Is it possible to keep deleted registry images for a set number of days? instructions: - text: Set the image scan period to {imagesScanPeriodMs} ms. slots: imagesScanPeriodMs: requestBody.imagesScanPeriodMs - text: Set registry scan retention to {registryScanRetentionDays} days and show negligible vulnerabilities {showNegligibleVulnerabilities}. slots: registryScanRetentionDays: requestBody.registryScanRetentionDays showNegligibleVulnerabilities: requestBody.showNegligibleVulnerabilities method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/tas'].get update: x-apievangelist-phrasing: intent: Get TAS settings effect: read questions: - What are the Tanzu Application Service settings in Compute? - Where can I review TAS integration settings? instructions: - text: Show the TAS settings. - text: Get the Tanzu Application Service configuration. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/tas'].post update: x-apievangelist-phrasing: intent: Save TAS settings effect: write questions: - Can I save Tanzu Application Service settings through the API? - Where do I update the TAS integration? instructions: - text: Save the TAS settings. - text: Update the Tanzu Application Service settings. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/telemetry'].get update: x-apievangelist-phrasing: intent: Get telemetry settings effect: read questions: - Is telemetry currently enabled in Compute? - Does my console share telemetry? instructions: - text: Show the telemetry settings. - text: Check whether telemetry is on. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/telemetry'].post update: x-apievangelist-phrasing: intent: Turn telemetry on or off effect: write questions: - Can I opt out of telemetry? - Is there a setting to enable telemetry again? instructions: - text: Set telemetry enabled to {enabled}. slots: enabled: requestBody.enabled - text: Disable telemetry by setting enabled to {enabled}. slots: enabled: requestBody.enabled method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/trusted-certificate'].post update: x-apievangelist-phrasing: intent: Add one certificate to the trusted list effect: write questions: - Can I append a single PEM certificate to the trusted certificate list? - Where do I add one more trusted certificate without replacing the others? instructions: - text: Add certificate {certificate} to the trusted certificate list. slots: certificate: requestBody.certificate - text: 'Trust this PEM certificate: {certificate}.' slots: certificate: requestBody.certificate method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/trusted-certificates'].post update: x-apievangelist-phrasing: intent: Configure trusted certificate settings effect: write questions: - Can I turn on the trusted certificates feature and set the full list? - Is revocation checking available for trusted certificates? instructions: - text: Enable trusted certificates with list {certs}. slots: certs: requestBody.certs - text: Set trusted certificate feature enabled {enabled} with revocation checking {checkRevocation}. slots: enabled: requestBody.enabled checkRevocation: requestBody.checkRevocation method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/vm'].get update: x-apievangelist-phrasing: intent: Get VM image scan settings effect: read questions: - Which VM images are configured for scanning? - Where can I see VM image scan settings? instructions: - text: Show the VM image scan settings. - text: List the VM image scan rules. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/vm'].put update: x-apievangelist-phrasing: intent: Update VM image scan settings effect: write questions: - Can I change which VM images get scanned? - Is updating VM image scan settings a full replacement? instructions: - text: Update the VM image scan settings. - text: Replace the VM image scan configuration. method: generated generated: '2026-09-26' - target: $.paths['/api/v34.04/settings/wildfire'].get update: x-apievangelist-phrasing: intent: Get WildFire settings effect: read questions: - Is WildFire malware analysis enabled in Compute? - Where do I see the WildFire settings? instructions: - text: Show the WildFire settings. - text: Get the current WildFire configuration. method: generated generated: '2026-09-26' - target: $.paths['/settings/enterprise'].get update: x-apievangelist-phrasing: intent: Get enterprise settings for the tenant effect: read questions: - What enterprise-wide settings are configured for my Prisma Cloud tenant? - Are audit logs and alarms enabled at the tenant level? instructions: - text: Show my tenant's enterprise settings. - text: Get the enterprise session timeout and access key maximum validity. method: generated generated: '2026-09-26' - target: $.paths['/settings/enterprise'].post update: x-apievangelist-phrasing: intent: Configure enterprise settings for the tenant effect: write questions: - Can I require a note whenever someone dismisses an alert? - How do I limit how long access keys stay valid across the tenant? instructions: - text: Set the browser session timeout to {sessionTimeout} and access key max validity to {accessKeyMaxValidity} days. slots: sessionTimeout: requestBody.sessionTimeout accessKeyMaxValidity: requestBody.accessKeyMaxValidity - text: 'Require an alert dismissal note: {requireAlertDismissalNote}.' slots: requireAlertDismissalNote: requestBody.requireAlertDismissalNote - text: Enable default policies {defaultPoliciesEnabled} for the tenant. slots: defaultPoliciesEnabled: requestBody.defaultPoliciesEnabled method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v1/satellite'].get update: x-apievangelist-phrasing: intent: List Satellite cluster details effect: read questions: - Which Satellite clusters are registered for my Prisma tenant? - Where can I see the details of my onboarded Satellite clusters? instructions: - text: List Satellite clusters for tenant {tenant}. slots: tenant: header.x-prisma-tenant-id - text: Show all Satellite cluster details for Prisma tenant {tenant}. slots: tenant: header.x-prisma-tenant-id method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v1/satellite'].post update: x-apievangelist-phrasing: intent: Add Satellite cluster details effect: write questions: - How do I register a new Satellite cluster with its asset ID? - Can I include configuration when adding Satellite details? instructions: - text: Add Satellite details for cluster asset {clusterAssetId} in tenant {tenant}. slots: clusterAssetId: requestBody.clusterAssetId tenant: header.x-prisma-tenant-id - text: Register cluster {clusterAssetId} as a Satellite for tenant {tenant} with config {config}. slots: clusterAssetId: requestBody.clusterAssetId tenant: header.x-prisma-tenant-id config: requestBody.config method: generated generated: '2026-09-26' - target: $.paths['/appid/api/v1/satellite/{id}'].delete update: x-apievangelist-phrasing: intent: Delete Satellite details effect: destructive questions: - How do I remove a Satellite cluster registration? - Is deleting Satellite details done by the Satellite record's ID? instructions: - text: Delete Satellite {id} for tenant {tenant}. slots: id: path.id tenant: header.x-prisma-tenant-id - text: Remove the Satellite cluster record {id} from tenant {tenant}. slots: id: path.id tenant: header.x-prisma-tenant-id method: generated generated: '2026-09-26' - target: $.paths['/api/settings/log-forwarding'].get update: x-apievangelist-phrasing: intent: Get SaaS Security log forwarding settings effect: read questions: - Where are my SaaS Security logs being forwarded to? - Which syslog servers, SIEM integrations or storage buckets receive SaaS Security logs? instructions: - text: Show the SaaS Security log forwarding configuration. - text: List the enabled log forwarding destinations for my SaaS Security tenant. method: generated generated: '2026-09-26'