find-unmanaged-traffic
Identify traffic to or from unmanaged workloads or IP addresses to reveal policy blind spots. Filter by direction, lookback period, and minimum connections.
Instructions
Find traffic involving unmanaged (unlabeled) workloads or IP addresses. These are sources or destinations without app/env labels, representing potential policy blind spots.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| top_n | No | Number of top results to return (default: 50) | |
| direction | No | Filter by traffic direction relative to managed workloads (default: both) | both |
| lookback_days | No | Number of days to look back (default: 30) | |
| min_connections | No | Minimum connections to include (filters noise, default: 1) |