Get IP Context
get_ip_contextCombines RDAP, GreyNoise/AbuseIPDB reputation, and Loggly traffic into one IP profile, flagging cross-account activity for bot-traffic triage.
Instructions
Combines RDAP, GreyNoise/AbuseIPDB reputation, and Loggly traffic (1h/24h/30d counts, first/last seen, hosts, top paths — checked across every configured Loggly account unless account is given) into one normalized profile for an IP. Flags cross_domain_correlation when the IP shows activity in more than one account, which the bot-traffic-triage playbook treats as the single strongest escalation signal.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ip | Yes | ||
| account | No | ||
| ip_field | No | ||
| host_field | No | ||
| path_field | No |