add more sankey options
This commit is contained in:
@@ -20,6 +20,17 @@ class InterfaceHostEvidence(BaseModel):
|
||||
destination_on_egress_count: int = Field(..., description="Packets where this endpoint appeared as the destination on egress.")
|
||||
|
||||
|
||||
class ProtocolLayerPathEvidence(BaseModel):
|
||||
ethernet_protocol: Optional[str] = Field(None, description="Ethernet protocol label for this path, if known.")
|
||||
ip_protocol: Optional[str] = Field(None, description="IP protocol label for this path, if known.")
|
||||
packet_count: int = Field(..., description="Packet observations supporting this path.")
|
||||
last_seen: datetime = Field(..., description="Most recent packet timestamp supporting this path.")
|
||||
accept_count: int = Field(0, description="Packets with verdict=accept for this path.")
|
||||
drop_count: int = Field(0, description="Packets with verdict=drop for this path.")
|
||||
reject_count: int = Field(0, description="Packets with verdict=reject for this path.")
|
||||
unknown_count: int = Field(0, description="Packets with verdict pending/unknown or without a verdict.")
|
||||
|
||||
|
||||
class ProtocolEvidence(BaseModel):
|
||||
protocol: str = Field(..., description="Detected application or fallback transport/network protocol.")
|
||||
packet_count: int = Field(..., description="Packet observations supporting this interface-host-protocol mapping.")
|
||||
@@ -30,23 +41,12 @@ class ProtocolEvidence(BaseModel):
|
||||
unknown_count: int = Field(0, description="Packets with verdict pending/unknown or without a verdict.")
|
||||
ethernet_protocol: Optional[str] = Field(None, description="Dominant Ethernet protocol associated with this protocol evidence.")
|
||||
ip_protocol: Optional[str] = Field(None, description="Dominant IP protocol associated with this protocol evidence.")
|
||||
layer_paths: List["ProtocolLayerPathEvidence"] = Field(
|
||||
layer_paths: List[ProtocolLayerPathEvidence] = Field(
|
||||
default_factory=list,
|
||||
description="Optional Ethernet/IP breakdown contributing to this protocol evidence.",
|
||||
)
|
||||
|
||||
|
||||
class ProtocolLayerPathEvidence(BaseModel):
|
||||
ethernet_protocol: Optional[str] = Field(None, description="Ethernet protocol label for this path, if known.")
|
||||
ip_protocol: Optional[str] = Field(None, description="IP protocol label for this path, if known.")
|
||||
packet_count: int = Field(..., description="Packet observations supporting this path.")
|
||||
last_seen: datetime = Field(..., description="Most recent packet timestamp supporting this path.")
|
||||
accept_count: int = Field(0, description="Packets with verdict=accept for this path.")
|
||||
drop_count: int = Field(0, description="Packets with verdict=drop for this path.")
|
||||
reject_count: int = Field(0, description="Packets with verdict=reject for this path.")
|
||||
unknown_count: int = Field(0, description="Packets with verdict pending/unknown or without a verdict.")
|
||||
|
||||
|
||||
class InterfaceHostProtocolEvidence(InterfaceHostEvidence):
|
||||
protocols: List[ProtocolEvidence] = Field(default_factory=list, description="Protocols observed for this host on the interface.")
|
||||
|
||||
|
||||
Reference in New Issue
Block a user