get_top_traffic
Show live FortiView summaries of current firewall sessions grouped by source, destination, application, country, interface, policy, or protocol to identify active traffic and troubleshoot flows.
Instructions
Live FortiView summary of the sessions passing through right now, grouped by source, destination, application, country, interface, policy or protocol. Destinations include the resolved hostname; application IDs are translated to names. Empty when nothing is flowing (it reflects current sessions, not history).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| vdom | No | VDOM (default: FORTIGATE_VDOM, usually root) | |
| count | No | Rows to return (default 10) | |
| dstaddr | No | Only sessions to this IP | |
| sort_by | No | bytes (default), sessions, bandwidth or packets | |
| srcaddr | No | Only sessions from this IP | |
| policyid | No | Only sessions matched by this policy | |
| report_by | No | source, destination (default), application, country, interface, policy or protocol | |
| resolve_vms | No | Label IPs/MACs with the Proxmox VM that owns them (needs PROXMOX_*) |