get_flow_protocols
const url = 'https://example.com/api/v1/flow/protocols';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/api/v1/flow/protocols \ --header 'Authorization: Bearer <token>'Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Query Parameters
Section titled “Query Parameters”Window start, Unix seconds. Defaults to one hour before to.
Window end, Unix seconds. Defaults to now.
Maximum rows for a top-N aggregation. Clamped to 1..=1000.
IP protocol numbers to include, comma-separated (6 or 6,17). At most 8; a value that is
not a protocol number is rejected rather than ignored.
Destination ports to include, comma-separated (443 or 80,443). At most 8; a value that is
not a port is rejected rather than ignored.
Peer addresses to include, comma-separated. A row matches when one of these is its source or its destination. At most 8; a value that is not an IP address is rejected.
AS numbers to include, comma-separated. A row matches when one of these is its source or
destination AS; 0 is the unknown-AS bucket. At most 8; a non-numeric value is rejected.
Which AS side top-as aggregates on: src, or dst (the default).
Responses
Section titled “Responses”IP protocols ranked by traffic
A protocol aggregate.
object
Bytes.
Distinct flows.
Packets.
IP protocol number.
Examplegenerated
[ { "bytes": 1, "flows": 1, "packets": 1, "proto": 1 }]No valid bearer token
The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI
document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies
undescribed — a client that has to guess the failure shape ends up parsing the success shape and
reading undefined.
object
object
Stable machine-readable code. Clients branch on this, never on the message.
Operator-facing sentence. Safe to display; never carries an internal error’s own text.
Examplegenerated
{ "error": { "code": "example", "message": "example" }}Role lacks the read permission
The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI
document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies
undescribed — a client that has to guess the failure shape ends up parsing the success shape and
reading undefined.
object
object
Stable machine-readable code. Clients branch on this, never on the message.
Operator-facing sentence. Safe to display; never carries an internal error’s own text.
Examplegenerated
{ "error": { "code": "example", "message": "example" }}Flow monitoring is not enabled (no flow store configured)
The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI
document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies
undescribed — a client that has to guess the failure shape ends up parsing the success shape and
reading undefined.
object
object
Stable machine-readable code. Clients branch on this, never on the message.
Operator-facing sentence. Safe to display; never carries an internal error’s own text.
Examplegenerated
{ "error": { "code": "example", "message": "example" }}