analyze_blocked_traffic
Analyze firewall logs to identify threats by grouping blocked traffic by source IP, showing hit counts and destination IPs with a simple threat score.
Instructions
Analyze blocked traffic patterns from firewall logs.
Retrieves recent blocked log entries and groups them by source IP, showing hit counts, destination IPs, and a simple threat score. Firewall logs are raw text — IPs are extracted via pattern matching.
WARNING (tracked by upstream PR #860): this endpoint may fail on firewalls with large log files due to a known pfSense REST API bug (server-side OOM at the 512 MB PHP limit). If it fails, suggest reviewing logs via SSH or the pfSense web UI instead.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Number of recent raw log entries to fetch and analyze (max 50); this is not a guaranteed number of blocked entries | |
| group_by_source | No | Group results by source IP with threat scoring |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||