get_flow_data
Query Firewalla network traffic flows for the last 24 hours, with filters, grouping, and pagination to analyze connections, bandwidth, and blocked activity.
Instructions
Query network traffic flows from the Firewalla MSP API (GET /v2/flows). Without a ts: qualifier the API covers the last 24 hours. Returns up to limit flows and a cursor for the next page, or groups with groupBy. Scoped to FIREWALLA_BOX_ID when set, otherwise every box.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Maximum results (optional, default: 200, API maximum: 500) | |
| query | No | Search query for flows. Supports region:US for geographic filtering, protocol:tcp, status:blocked, domain:*, category:social, etc. | |
| cursor | No | Pagination cursor from previous response | |
| sortBy | No | Sort flows (default: "ts:desc") | |
| groupBy | No | Fields to group by, comma-separated, e.g. "category", "domain", "device", "box" or "device,category". The API then returns groups instead of flows: groups of { key, count, download, upload, total }, where key holds the group fields (gid for box; for device the device with its name, but only its id for "device,category") and the rest are the group's summed connection count and bytes. |