zins_get_threat_class
Get threat-class distribution (Virus/Spyware, Advanced, Behavioral). Read-only analytics.
Instructions
Get threat-class distribution (Virus/Spyware, Advanced, Behavioral). Read-only analytics.
One row per threat class with its aggregated total. An empty result means no threats of these classes were detected. Window must be a 7- or 14-day historical interval.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | ||
| query | No | Optional JMESPath expression applied to the results after the API call, for client-side filtering and projection. Examples: "[?enabled==`true`]", "[*].{name: name, id: id}", "length(@)". Omit to get the full records. IMPORTANT: field names are the keys of the returned records, which are usually snake_case (`custom_category`) even where the Zscaler API documents camelCase (`customCategory`) — guessing the spelling yields an empty list that looks like a real answer. If you have not already seen a record from this tool, call it once without `query` and read the keys off the response. | |
| end_time | No | ||
| start_time | No | ||
| end_days_ago | No | ||
| traffic_unit | No | TRANSACTIONS | |
| start_days_ago | No |