List DLP risks
list_risksRetrieve DLP/rule risk hits for a period, summarized by user or rule. Supports raw details for policy, keyword, USB, and AI violations to identify compliance threats.
Instructions
List or summarize DLP/rule Risks for a period.
Use for: policy/keyword/USB/AI rule hits. Default mode=summary (by_user from Analytics/Overall; by_rule/by_day/sample from Risks/Overall2). Not for idle time (get_idle_summary) or timetable deviations (list_anomalies).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| mode | No | summary = by_user/by_rule rollup; raw = Risks/Overall2 page. | summary |
| limit | No | Max rows to return (1–500). | |
| offset | No | Pagination offset (0-based). | |
| period | No | Relative period: today|yesterday|last_7_days|last_30_days (wins over date_from/date_to when set). | |
| compact | No | ||
| date_to | No | End datetime; date-only covers until 23:59:59 that day. | |
| user_id | No | User filter: AliasID as TreeviewUsers NodeType=1. | |
| group_id | No | Group filter: TreeviewUsers NodeType=14 (console group id). | |
| date_from | No | Start datetime YYYY-MM-DD or YYYY-MM-DD HH:MM:SS (full day if date-only). | |
| fetch_all | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||