Skip to main content
Glama

List unique field combinations

arkime_multiunique
Read-only

List distinct value combinations across multiple Arkime fields, like source.ip and destination.port, to identify scanning hosts or dense traffic sources.

Instructions

List distinct value COMBINATIONS across a tuple of Arkime fields as plain text.

    Like arkime_unique but for a field tuple — e.g. every distinct
    (source.ip, destination.port) pair. Good for spotting a host scanning
    many ports, or a few talkers behind a lot of traffic. For a single field
    use arkime_unique; for a source/destination graph use arkime_connections;
    for a nested hierarchy use arkime_spigraphhierarchy. Returns plain TEXT
    (one combination per line, not JSON).
    

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
countsNoInclude a per-combination occurrence count (default true).
fieldsYesComma-separated Arkime field names forming the tuple, e.g. "source.ip,destination.port".
time_toNoEnd time as EPOCH SECONDS (NOT a dateparser string). Empty = now.
time_fromNoStart time as EPOCH SECONDS (NOT a dateparser string). Empty = Arkime's recent-only default.
expressionNoOptional Arkime expression syntax to scope the data. Empty = all sessions.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true and destructiveHint=false. The description adds that output is plain text (one combination per line, not JSON), which informs the agent about return format beyond annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is brief (a few sentences), front-loaded with the main purpose, and well-structured with examples and alternatives. Every sentence adds value.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the output schema exists, the description completes the picture by stating the return type (plain text) and format. All 5 parameters are documented, and the description covers the tool's role within the sibling set.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so all parameters are documented. The description adds a usage example (e.g., source.ip,destination.port) but no new semantic details beyond the schema. Baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states it lists distinct value combinations across a tuple of Arkime fields as plain text, and distinguishes from siblings like arkime_unique (single field), arkime_connections (graph), and arkime_spigraphhierarchy (nested hierarchy).

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly provides when to use (spotting a host scanning many ports) and alternatives (use arkime_unique for single field, arkime_connections for graph, arkime_spigraphhierarchy for nested hierarchy), offering clear usage context.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Install Server

Other Tools

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/nagameTW/mcp-server-malcolm'

If you have feedback or need assistance with the MCP directory API, please join our Discord server