get-traffic-flows
Retrieve traffic flow records from Illumio PCE with filters for sources, destinations, services, and policy decisions. Aggregate by dimensions like process, FQDN, or rule to answer specific connectivity questions.
Instructions
Get traffic flows from the PCE with comprehensive filtering options
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| end_date | Yes | Ending datetime (YYYY-MM-DD or timestamp) | |
| group_by | No | Dimensions to aggregate by. Any of: process, service_name, user, source, source_app, destination, dest_app, fqdn, ip_list, port, proto, policy, rule, direction. Fewer dimensions gives fewer, larger rows - e.g. ['process','fqdn'] answers 'which binary talks to which external name'. Defaults to a full per-flow breakdown. | |
| query_name | No | ||
| start_date | Yes | Starting datetime (YYYY-MM-DD or timestamp) | |
| max_results | No | ||
| exclude_sources | No | Sources to exclude (label/IP list/workload HREFs, FQDNs, IPs) | |
| include_sources | No | Sources to include. Accepts label shorthand 'key=value' (e.g. 'app=vdi'), which the server resolves to a label HREF, as well as label/IP list/workload HREFs, FQDNs and IPs. Omit to match all sources. | |
| exclude_services | No | ||
| include_services | No | ||
| policy_decisions | No | ||
| exclude_destinations | No | Destinations to exclude (label/IP list/workload HREFs, FQDNs, IPs) | |
| include_destinations | No | Destinations to include. Accepts label shorthand 'key=value' (e.g. 'app=vdi'), as well as label/IP list/workload HREFs, FQDNs and IPs. Omit to match all destinations. | |
| exclude_workloads_from_ip_list_query | No |