get_flow_conversations
const url = 'https://example.com/api/v1/flow/conversations';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/api/v1/flow/conversations \ --header 'Authorization: Bearer <token>'Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Query Parameters
Section titled “Query Parameters”Responses
Section titled “Responses”Source→destination pairs ranked by traffic, AS names resolved
A conversation: a src→dst pair with summed traffic. src_asn/dst_asn are the stored
per-flow AS numbers (0 = unknown); the *_as_name fields are resolved from the IP→ASN table
at the API layer (the store leaves them None), mirroring [FlowAsAgg].
object
Bytes.
Destination address.
Destination AS organization name, if resolvable (filled at the API layer).
Destination autonomous-system number (0 = unknown).
Distinct flows.
Packets.
Source address.
Source AS organization name, if resolvable (filled at the API layer).
Source autonomous-system number (0 = unknown).
Examplegenerated
[ { "bytes": 1, "dst": "example", "dst_as_name": "example", "dst_asn": 1, "flows": 1, "packets": 1, "src": "example", "src_as_name": "example", "src_asn": 1 }]No valid bearer token
The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI
document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies
undescribed — a client that has to guess the failure shape ends up parsing the success shape and
reading undefined.
object
object
Stable machine-readable code. Clients branch on this, never on the message.
Operator-facing sentence. Safe to display; never carries an internal error’s own text.
Examplegenerated
{ "error": { "code": "example", "message": "example" }}Role lacks the read permission
The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI
document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies
undescribed — a client that has to guess the failure shape ends up parsing the success shape and
reading undefined.
object
object
Stable machine-readable code. Clients branch on this, never on the message.
Operator-facing sentence. Safe to display; never carries an internal error’s own text.
Examplegenerated
{ "error": { "code": "example", "message": "example" }}Flow monitoring is not enabled (no flow store configured)
The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI
document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies
undescribed — a client that has to guess the failure shape ends up parsing the success shape and
reading undefined.
object
object
Stable machine-readable code. Clients branch on this, never on the message.
Operator-facing sentence. Safe to display; never carries an internal error’s own text.
Examplegenerated
{ "error": { "code": "example", "message": "example" }}