get-traffic-flows-summary
Summarize traffic flows into structured JSON grouped by process, external destination, blocked status, and app-to-app. Provides compact analysis over the full time window, answering common questions directly.
Instructions
Summarize traffic flows as structured JSON. Sections: by_process (which binary talks to which destination, on which port, under which policy, and as which user), external_destinations (traffic leaving the managed estate), blocked (what policy is stopping), app_to_app (coarse view). Prefer this over get-traffic-flows for analysis - it is far smaller and answers the usual questions directly.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| end_date | Yes | Ending datetime (YYYY-MM-DD or timestamp) | |
| query_name | No | ||
| start_date | Yes | Starting datetime (YYYY-MM-DD or timestamp) | |
| max_results | No | ||
| detail_level | No | How much of each section to show. 'standard' (default) shows the top 100 per section; 'full' shows everything that fits the response limit, which can be ~10x the tokens. Analysis always covers the WHOLE window either way -- totals and section_totals are computed over every row, so the numbers are identical; only the displayed rows differ. | |
| exclude_sources | No | Sources to exclude (label/IP list/workload HREFs, FQDNs, IPs). Best case these are hrefs like /orgs/1/labels/57 or similar. Other way is app=env as an example (label key and value) | |
| identity_labels | No | Label dimensions that define an endpoint's identity in app_to_app. Defaults to ['app','env'] because that is how Illumio defines an application, but ANY label this PCE defines works: ['bu'] for a business-unit view, ['compliance','env'] for a compliance view, ['role','loc'] for a tiered one. The response's available_dimensions lists what this PCE actually has. | |
| include_sources | No | Sources to include (label/IP list/workload HREFs, FQDNs, IPs). Best case these are hrefs like /orgs/1/labels/57 or similar. Other way is app=env as an example (label key and value) | |
| exclude_services | No | ||
| include_services | No | ||
| policy_decisions | No | ||
| exclude_destinations | No | Destinations to exclude (label/IP list/workload HREFs, FQDNs, IPs). Best case these are hrefs like /orgs/1/labels/57 or similar. Other way is app=env as an example (label key and value) | |
| include_destinations | No | Destinations to include (label/IP list/workload HREFs, FQDNs, IPs). Best case these are hrefs like /orgs/1/labels/57 or similar. Other way is app=env as an example (label key and value) | |
| exclude_workloads_from_ip_list_query | No |