search_flows
Query network flows over a recent time window with optional JSON filters and limits to inspect traffic patterns and exposures in Cisco Secure Workload.
Instructions
Search network flows over a recent time window.
Args: filter_json: A CSW flow filter as a JSON string, e.g. '{"type":"eq","field":"dst_port","value":3389}'. Pass an empty string for no filter (all flows in the window). hours: Look-back window in hours (1–720, default 24). limit: Max flow records to return (1–1000).
Runs a read-only POST /openapi/v1/flowsearch with t0 = now-hours, t1 = now.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| hours | No | ||
| limit | No | ||
| filter_json | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |