Actions277
- User Agents Actions
- Url Filters Actions
- Users Actions
- Traffic Reports Actions
- Traffic Reports Qps Active Agents
- Traffic Reports Qps Active Users
- Traffic Reports Qps Active Collections
- Traffic Reports Top Domains
- Traffic Reports Top Categories
- Traffic Reports Top Application Categories
- Traffic Reports Top Organizations
- Traffic Reports Top Networks
- Traffic Reports Top Agents
- Traffic Reports Top Users
- Traffic Reports Top Collections
- Traffic Reports Query Logs
- Traffic Reports Total Organizations Stats
- Traffic Reports Total Domain Stats
- Traffic Reports Total Category Stats
- Traffic Reports Total Organizations Requests
- Traffic Reports Total Domain Requests
- Traffic Reports Top Organizations Requests
- Traffic Reports Total Client Stats
- Traffic Reports Total Deployments
- Traffic Reports Total Roaming Clients
- Traffic Reports Total Applications Stats
- Traffic Reports Total Applications Organizations Stats
- Traffic Reports Total Applications Networks Stats
- Traffic Reports Total Applications Agents Stats
- Traffic Reports Total Applications Users Stats
- Traffic Reports Total Applications Collections Stats
- Traffic Reports Total Requests
- Traffic Reports Total Requests Geo
- Traffic Reports Total Requests Organizations
- Traffic Reports Total Requests Agents
- Traffic Reports Total Requests Users
- Traffic Reports Total Requests Collections
- Traffic Reports Total Threats
- Traffic Reports Total Threats Organizations
- Traffic Reports Total Threats Agents
- Traffic Reports Total Threats Users
- Traffic Reports Total Threats Collections
- Traffic Reports Total Categories
- Traffic Reports Total Categories Organizations
- Traffic Reports Total Categories Agents
- Traffic Reports Total Categories Users
- Traffic Reports Total Categories Collections
- Traffic Reports Total Domains
- Traffic Reports Total Domains Organizations
- Traffic Reports Total Domains Users
- Traffic Reports Total Domains Collections
- Traffic Reports Total Collections
- Traffic Reports Total Collections Organizations
- Traffic Reports Total Collections Agents
- Traffic Reports Total Collections Users
- Traffic Reports Qps
- Traffic Reports Qps Active Organizations
- Trials Actions
- User Agent Bulk Deletes Actions
- User Agent Bulk Updates Actions
- User Agent Cleanups Actions
- User Agent Csv Exports Actions
- Policies Actions
- Policies Add Blacklist Category
- Policies Remove Blacklist Category
- Policies Add Allowed Application
- Policies Remove Allowed Application
- Policies Add Blocked Application
- Policies Remove Blocked Application
- Policies Get Permissive Mode
- Policies Index
- Policies Create
- Policies All
- Policies Show
- Policies Update
- Policies Destroy
- Policies Application
- Policies Application Update
- Policies Add Blacklist Domain
- Policies Remove Blacklist Domain
- Policies Add Whitelist Domain
- Policies Remove Whitelist Domain
- Policies Bulk Actions Actions
- Policy Ips Actions
- Scheduled Policies Actions
- Scheduled Report Previews Actions
- Scheduled Reports Actions
- Networks Actions
- Networks Lookup
- Networks Show
- Networks Update
- Networks Destroy
- Networks Bulk Create
- Networks Bulk Create Status
- Networks Index
- Networks Create
- Networks All
- Networks Msp
- Networks Msp All
- Networks Bulk Update
- Networks Bulk Update Status
- Networks Bulk Destroy
- Networks Bulk Destroy Status
- Networks Generate Secret Key
- Networks Revoke Secret Key
- Networks Rotate Secret Key
- Mac Addresses Actions
- Metrics Actions
- Network Lan Ips Actions
- Network Subnets Actions
- Organizations Actions
- Organization Users Actions
- Distributors Actions
- Distributors Msps Cancel
- Distributors Msps Reactivate
- Distributors Organizations Index
- Distributors Organizations Create
- Distributors Organizations Show
- Distributors Organizations Update
- Distributors Organizations Cancel
- Distributors Organizations Reactivate
- Distributors Organizations Add Sku
- Distributors Organizations Remove Sku
- Distributors Users Index
- Distributors Users Create
- Distributors Users Show
- Distributors Users Add Membership
- Distributors Users Update Membership
- Distributors Users Remove Membership
- Distributors Users Send Reset Password Email
- Distributors Users Reset Password Url
- Distributors Reports Usage By Organization
- Distributors Reports Usage By Sku
- Distributors Reports Covered Users Summary By Organization
- Distributors Distributors Update
- Distributors Msps Index
- Distributors Msps Create
- Distributors Msps Show
- Distributors Msps Update
- Domain Notes Actions
- Domains Actions
- Enterprise Connections Actions
- Invoices Actions
- IP Addresses Actions
- Allowed Urls Actions
- Api Key Actions
- Application Categories Actions
- Applications Actions
- Authentication Actions
- Authentication Sync Tool Actions
- Billings Actions
- Blocked Urls Actions
- Block Pages Actions
- Categories Actions
- Collection Users Actions
- Agent Local User Actions
- Agent Local User Bulk Deletes Actions
Overview
This node fetches aggregated traffic threat data related to agents from a security or network monitoring service. It is designed to generate reports summarizing total threats detected by various user agents over a specified time range and filtered by multiple criteria such as agent IDs, types, applications, networks, and more.
Common scenarios where this node is beneficial include:
- Security analysts wanting to monitor threat activity across different user agents in their network.
- Network administrators generating periodic reports on blocked or allowed traffic incidents.
- Incident response teams filtering threat data by specific agents, applications, or organizational units for detailed investigation.
Practical example:
- Generate a report of all blocked threats detected by specific user agents within the last 7 days, grouped by individual agents, to identify which agents are most frequently targeted.
Properties
| Name | Meaning |
|---|---|
| Additional Query Parameters | Optional filters and parameters to customize the report query. Includes: - Agent Ids: Comma separated list of user agent UUIDs (defaults to all) - Agent Types: Comma separated list of user agent types (defaults to all) - Application Ids: Comma separated list of application IDs (defaults to all) - Bucket Size: Desired bucket size for aggregation ( auto, 15min, 1day), defaults to auto - Collection Ids: Comma separated list of collection IDs (defaults to all) - From: Report start datetime in UTC (format YYYY-MM-DDThh:mm:ss or with Z suffix), defaults to current UTC minus 1 day - Mac Addresses: Comma separated list of MAC addresses without colons (defaults to all) - Network Ids: Comma separated list of network IDs (defaults to all) - Organization Ids: Comma separated list of organization IDs (defaults to user org ID) - Private Ip: Private LAN IP filter - Private Ip From/To: Range for private LAN IPs - Show Individual Agents: Boolean to group results by agent id (default true) - Source: Traffic source filter ( all, networks, agents, proxies), default all - To: Report end datetime in UTC, defaults to current UTC - Type: Report type filter ( all, allowed, blocked), default all - User Ids: Comma separated list of local user IDs (defaults to all) |
Output
The node outputs JSON data containing the aggregated traffic threat report based on the applied filters. The structure typically includes:
- Summary statistics of total threats per agent or grouped entities.
- Time-bucketed counts of threats according to the selected bucket size.
- Breakdown by threat type (allowed, blocked, all).
- Details about agents, applications, networks, or other filtered dimensions depending on input parameters.
If binary data output is supported, it would represent downloadable report files or raw data exports, but this node primarily returns structured JSON data.
Dependencies
- Requires an API key credential for authenticating requests to the external traffic monitoring or security reporting service.
- The node uses a base URL endpoint
https://api.dnsfilter.comindicating dependency on the AvantGuard DNSFilter API or similar service. - Proper configuration of credentials and network access to the API endpoint is necessary.
Troubleshooting
- Invalid Date Format: If the
fromortodate parameters are not in the correct ISO format, the API may reject the request or return unexpected results. Ensure dates followYYYY-MM-DDThh:mm:ssorYYYY-MM-DDThh:mm:ssZ. - Empty Results: Applying overly restrictive filters (e.g., specific agent IDs or date ranges with no data) can result in empty responses. Try broadening filters to verify connectivity and data availability.
- Authentication Errors: Missing or invalid API key credentials will cause authentication failures. Verify that the API key is correctly configured in n8n credentials.
- Network Issues: Connectivity problems to the API endpoint can cause timeouts or errors. Check network settings and firewall rules.
- Unsupported Bucket Size: Using unsupported values for
bucket_sizemay lead to errors or default fallback behavior. Use onlyauto,15min, or1day.
Links and References
- AvantGuard DNSFilter API Documentation (for detailed API usage and parameter descriptions)
- ISO 8601 Date and Time Format (for correct date formatting)
- n8n Documentation on Creating Custom Nodes