Actions277
- User Agents Actions
- Url Filters Actions
- Users Actions
- Traffic Reports Actions
- Traffic Reports Qps Active Agents
- Traffic Reports Qps Active Users
- Traffic Reports Qps Active Collections
- Traffic Reports Top Domains
- Traffic Reports Top Categories
- Traffic Reports Top Application Categories
- Traffic Reports Top Organizations
- Traffic Reports Top Networks
- Traffic Reports Top Agents
- Traffic Reports Top Users
- Traffic Reports Top Collections
- Traffic Reports Query Logs
- Traffic Reports Total Organizations Stats
- Traffic Reports Total Domain Stats
- Traffic Reports Total Category Stats
- Traffic Reports Total Organizations Requests
- Traffic Reports Total Domain Requests
- Traffic Reports Top Organizations Requests
- Traffic Reports Total Client Stats
- Traffic Reports Total Deployments
- Traffic Reports Total Roaming Clients
- Traffic Reports Total Applications Stats
- Traffic Reports Total Applications Organizations Stats
- Traffic Reports Total Applications Networks Stats
- Traffic Reports Total Applications Agents Stats
- Traffic Reports Total Applications Users Stats
- Traffic Reports Total Applications Collections Stats
- Traffic Reports Total Requests
- Traffic Reports Total Requests Geo
- Traffic Reports Total Requests Organizations
- Traffic Reports Total Requests Agents
- Traffic Reports Total Requests Users
- Traffic Reports Total Requests Collections
- Traffic Reports Total Threats
- Traffic Reports Total Threats Organizations
- Traffic Reports Total Threats Agents
- Traffic Reports Total Threats Users
- Traffic Reports Total Threats Collections
- Traffic Reports Total Categories
- Traffic Reports Total Categories Organizations
- Traffic Reports Total Categories Agents
- Traffic Reports Total Categories Users
- Traffic Reports Total Categories Collections
- Traffic Reports Total Domains
- Traffic Reports Total Domains Organizations
- Traffic Reports Total Domains Users
- Traffic Reports Total Domains Collections
- Traffic Reports Total Collections
- Traffic Reports Total Collections Organizations
- Traffic Reports Total Collections Agents
- Traffic Reports Total Collections Users
- Traffic Reports Qps
- Traffic Reports Qps Active Organizations
- Trials Actions
- User Agent Bulk Deletes Actions
- User Agent Bulk Updates Actions
- User Agent Cleanups Actions
- User Agent Csv Exports Actions
- Policies Actions
- Policies Add Blacklist Category
- Policies Remove Blacklist Category
- Policies Add Allowed Application
- Policies Remove Allowed Application
- Policies Add Blocked Application
- Policies Remove Blocked Application
- Policies Get Permissive Mode
- Policies Index
- Policies Create
- Policies All
- Policies Show
- Policies Update
- Policies Destroy
- Policies Application
- Policies Application Update
- Policies Add Blacklist Domain
- Policies Remove Blacklist Domain
- Policies Add Whitelist Domain
- Policies Remove Whitelist Domain
- Policies Bulk Actions Actions
- Policy Ips Actions
- Scheduled Policies Actions
- Scheduled Report Previews Actions
- Scheduled Reports Actions
- Networks Actions
- Networks Lookup
- Networks Show
- Networks Update
- Networks Destroy
- Networks Bulk Create
- Networks Bulk Create Status
- Networks Index
- Networks Create
- Networks All
- Networks Msp
- Networks Msp All
- Networks Bulk Update
- Networks Bulk Update Status
- Networks Bulk Destroy
- Networks Bulk Destroy Status
- Networks Generate Secret Key
- Networks Revoke Secret Key
- Networks Rotate Secret Key
- Mac Addresses Actions
- Metrics Actions
- Network Lan Ips Actions
- Network Subnets Actions
- Organizations Actions
- Organization Users Actions
- Distributors Actions
- Distributors Msps Cancel
- Distributors Msps Reactivate
- Distributors Organizations Index
- Distributors Organizations Create
- Distributors Organizations Show
- Distributors Organizations Update
- Distributors Organizations Cancel
- Distributors Organizations Reactivate
- Distributors Organizations Add Sku
- Distributors Organizations Remove Sku
- Distributors Users Index
- Distributors Users Create
- Distributors Users Show
- Distributors Users Add Membership
- Distributors Users Update Membership
- Distributors Users Remove Membership
- Distributors Users Send Reset Password Email
- Distributors Users Reset Password Url
- Distributors Reports Usage By Organization
- Distributors Reports Usage By Sku
- Distributors Reports Covered Users Summary By Organization
- Distributors Distributors Update
- Distributors Msps Index
- Distributors Msps Create
- Distributors Msps Show
- Distributors Msps Update
- Domain Notes Actions
- Domains Actions
- Enterprise Connections Actions
- Invoices Actions
- IP Addresses Actions
- Allowed Urls Actions
- Api Key Actions
- Application Categories Actions
- Applications Actions
- Authentication Actions
- Authentication Sync Tool Actions
- Billings Actions
- Blocked Urls Actions
- Block Pages Actions
- Categories Actions
- Collection Users Actions
- Agent Local User Actions
- Agent Local User Bulk Deletes Actions
Overview
The "Traffic Reports Total Threats" operation in the Traffic Reports resource provides aggregated threat data related to network traffic. This node is useful for security analysts and network administrators who want to monitor and analyze total threats detected over a specified time range, filtered by various criteria such as agents, applications, networks, or organizations.
Typical use cases include:
- Generating reports on blocked or allowed traffic threats within an organization.
- Monitoring specific user agents or devices for suspicious activity.
- Analyzing threat trends over custom time intervals with flexible bucket sizes.
- Filtering threat data by network segments or collections for targeted insights.
For example, a security team could use this node to retrieve all blocked threats from the last 7 days grouped by individual networks, helping them identify which network segments are most affected.
Properties
| Name | Meaning |
|---|---|
| Additional Query Parameters | Optional filters and parameters to customize the report query. Includes: - Agent Ids: Comma separated list of user agent UUIDs (default all) - Agent Types: Comma separated list of user agent types (default all) - Application Ids: Comma separated list of application IDs (default all) - Bucket Size: Desired bucket size for aggregation; options: auto, 15min, 1day (default auto). Auto selects 15min if range < 24h, else 1day. - Collection Ids: Comma separated list of collection IDs (default all) - From: Report start datetime in UTC (format YYYY-MM-DDThh:mm:ss or with Z), defaults to current UTC minus 1 day or if format invalid - Mac Addresses: Comma separated MAC addresses without colons or filter values (default all) - Network Ids: Comma separated list of network IDs (default all) - Organization Ids: Comma separated list of organization IDs (default user org ID) - Private Ip: Private LAN IP filter - Private Ip From: Lower limit of private LAN IP range - Private Ip To: Upper limit of private LAN IP range - Show Individual Networks: Boolean to group results by network id (default true) - Source: Traffic source filter; options: all, networks, agents, proxies (default all) - To: Report end datetime in UTC (format YYYY-MM-DDThh:mm:ss or with Z), defaults to current UTC or if format invalid - Type: Type of report; options: all, allowed, blocked (default all) - User Ids: Comma separated list of local user IDs (default all) |
Output
The node outputs JSON data containing the aggregated total threats report based on the applied filters and time range. The structure typically includes counts or metrics of threats grouped by the selected bucket size and optionally by network if enabled.
If binary data output is supported, it would represent downloadable report files or raw data exports, but this is not indicated in the provided information.
Dependencies
- Requires an API key credential for authenticating with the external traffic reporting service.
- The node sends HTTP requests to the service's API endpoint with query parameters constructed from the input properties.
- Proper configuration of the API authentication token in n8n credentials is necessary.
Troubleshooting
- Invalid Date Format: If the
fromortodate strings are not in the expected ISO 8601 format, the node may default to preset dates or fail. Ensure correct formatting likeYYYY-MM-DDThh:mm:ssZ. - Empty Results: Applying overly restrictive filters (e.g., very specific agent IDs or network IDs) might result in no data returned. Try broadening filters.
- Authentication Errors: Missing or incorrect API key credentials will cause authorization failures. Verify that the API key is correctly set up in n8n.
- API Rate Limits: Frequent or large queries might hit rate limits imposed by the external service. Implement retry logic or reduce query frequency.
- Boolean Property Misuse: The
show_individual_networksproperty defaults to true; setting it incorrectly might change grouping behavior unexpectedly.
Links and References
- No direct links provided in the source code. For more details, consult the official documentation of the traffic reporting API or the service provider’s developer portal.