get_recent_flow_activity
Retrieve a snapshot of the last 10-20 minutes of network flow activity to identify current security threats or immediate network issues. Returns up to 50 recent flows for quick analysis.
Instructions
Get recent network flow activity snapshot (last 10-20 minutes). Returns up to 50 most recent flows for immediate analysis. CRITICAL: This is a quick snapshot tool only. Use this for: "what's happening right now?", current security threats, immediate network issues. DO NOT use for: historical analysis (use search_flows), getting more than 50 flows (use search_flows with limit), daily/weekly patterns (use search_flows with time queries like "ts:>24h"). For comprehensive analysis, always prefer search_flows.
Input Schema
Name | Required | Description | Default |
---|---|---|---|
No arguments |