get_recent_flow_activity
Get a snapshot of the 50 most recent network flows with protocol, region, and blocked/allowed counts to spot current threats or immediate network issues.
Instructions
Get a snapshot of the 50 most recent network flows (one GET /v2/flows request) with protocol, region and blocked/allowed counts; the minutes they span depend on how busy the network is. Use this for: "what's happening right now?", current security threats, immediate network issues. DO NOT use for: historical analysis, more than 50 flows, or daily/weekly patterns; use search_flows with time queries like "ts:>24h" for those. Scoped to FIREWALLA_BOX_ID when set, otherwise every box.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||