FlowDetail

FlowDetail
Flow Detail

Comprehensive details about a single deduplicated network flow, representing the atomic unit returned by all flow-detail endpoints.

Notes:

  • source contains source-side endpoint metadata (compute, groups, apps, matched rules).
  • destination contains destination-side endpoint metadata including protocol, port, and configured_services.
  • flow_info contains timing (last_session_start_time, last_session_end_time), is_active status, and effective flow_type.
  • Each FlowDetail represents one unique flow deduplicated by the 4-tuple: source VM, destination VM, destination port, and protocol.
JSON Example
{
    "source": {
        "groups": [
            {
                "id": "string",
                "display_name": "string",
                "reference_id": "string"
            }
        ],
        "compute": {
            "compute_type": "string"
        },
        "apps": [
            {
                "association_count": 0,
                "id": "string",
                "reference_id": "string",
                "name": "string",
                "last_updated_time": 0,
                "entity_type": "string",
                "total_incoming_connections": 0,
                "total_outgoing_connections": 0,
                "config_events": [
                    {
                        "event_time": 0
                    }
                ],
                "fw_properties": {
                    "ew_allowed": 0,
                    "ew_blocked": 0,
                    "ew_unmicrosegmented": 0,
                    "ew_vds": 0
                },
                "highlight": false,
                "state": "string",
                "application_type": "CRITICAL",
                "application_workload_type": "string",
                "direct_member_count": 0,
                "tier_member_count": 0
            }
        ],
        "flow_type": "string",
        "rules": [
            {
                "association_count": 0,
                "id": "string",
                "reference_id": "string",
                "name": "string",
                "last_updated_time": 0,
                "sequence_number": 0
            }
        ],
        "jump_to_rules": [
            {
                "association_count": 0,
                "id": "string",
                "reference_id": "string",
                "name": "string",
                "last_updated_time": 0,
                "sequence_number": 0
            }
        ]
    },
    "destination": {
        "groups": [
            {
                "id": "string",
                "display_name": "string",
                "reference_id": "string"
            }
        ],
        "compute": {
            "compute_type": "string"
        },
        "apps": [
            {
                "association_count": 0,
                "id": "string",
                "reference_id": "string",
                "name": "string",
                "last_updated_time": 0,
                "entity_type": "string",
                "total_incoming_connections": 0,
                "total_outgoing_connections": 0,
                "config_events": [
                    {
                        "event_time": 0
                    }
                ],
                "fw_properties": {
                    "ew_allowed": 0,
                    "ew_blocked": 0,
                    "ew_unmicrosegmented": 0,
                    "ew_vds": 0
                },
                "highlight": false,
                "state": "string",
                "application_type": "CRITICAL",
                "application_workload_type": "string",
                "direct_member_count": 0,
                "tier_member_count": 0
            }
        ],
        "configured_services": [
            "string"
        ],
        "protocol": "string",
        "port": 0,
        "flow_type": "string",
        "rules": [
            {
                "association_count": 0,
                "id": "string",
                "reference_id": "string",
                "name": "string",
                "last_updated_time": 0,
                "sequence_number": 0
            }
        ],
        "jump_to_rules": [
            {
                "association_count": 0,
                "id": "string",
                "reference_id": "string",
                "name": "string",
                "last_updated_time": 0,
                "sequence_number": 0
            }
        ]
    },
    "flow_info": {
        "last_session_start_time": 0,
        "last_session_end_time": 0,
        "flow_type": "string",
        "flow_traffic_type": "string",
        "is_active": false
    }
}
source
Optional

Source-side metadata for an aggregated flow record.

Notes:

  • compute is the source VM.
  • groups lists the NSX groups the source compute belongs to within the flow context.
  • apps lists the NSX applications the source compute belongs to.
  • flow_type is the last observed flow type on the source side (e.g., ALLOWED, BLOCKED).
  • rules lists the DFW rules matched on the source side; jump_to_rules lists any jump-to rules.
destination
Optional

Destination-side metadata for an aggregated flow record.

Notes:

  • compute is the destination VM or IP.
  • groups lists the NSX groups the destination compute belongs to within the flow context.
  • apps lists the NSX applications the destination compute belongs to.
  • protocol and port identify the destination transport layer endpoint.
  • configured_services lists the service names configured for this port/protocol on the destination.
  • flow_type is the last observed flow type on the destination side; rules and jump_to_rules list the matched DFW rules.
flow_info
Optional

Summary-level timing and status information about a deduplicated flow record.

Notes:

  • last_session_start_time and last_session_end_time reflect the most recently observed session within the query window.
  • For active flows, last_session_end_time is the time the flow was last reported, not a true end time.
  • is_active is true for currently open sessions and false for completed sessions.
  • flow_type is the effective (most recently observed) flow type (e.g., ALLOWED, BLOCKED, UN_MICROSEGMENTED).
  • flow_traffic_type indicates unicast, broadcast, or multicast traffic.