get_flow_insights
Analyze network flows by content category to identify top domains, devices, and optionally blocked traffic, providing answers to questions like which sites were accessed.
Instructions
Get category-based flow analysis for a period: top content categories and their domains, top devices by bandwidth, and optionally blocked traffic. Ideal for answering questions like "what porn sites were accessed" or "what social media was used". Computed client-side from the period's largest flows (GET /v2/flows by total bytes: up to 500 for categories, 200 for devices) and, with include_blocked, the 50 most frequent blocked flows, so on a busy network it covers the largest flows, not all of them. Scoped to FIREWALLA_BOX_ID when set, otherwise every box.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| period | No | Time period for analysis (default: 24h) | 24h |
| categories | No | Filter to specific content categories (optional) | |
| include_blocked | No | Include blocked traffic analysis (default: false) |