GraphQL

This lists all of the available datasets and fields in Cloudflare's GraphQL API.

AccountAccessLoginRequestsAdaptiveGroups

Access login requests

FieldDescription
avg
confidence ALPHA - DO NOT USE
count Number of access login API events processed
dimensions List of dimensions to group by

AccountAccessLoginRequestsAdaptiveGroupsAvg

FieldDescription
sampleInterval Average sample interval

AccountAccessLoginRequestsAdaptiveGroupsConfidence

FieldDescription
count Number of access login API events processed, with confidence intervals
level Confidence level that was requested

AccountAccessLoginRequestsAdaptiveGroupsDimensions

FieldDescription
appId Access application ID
approvingPolicyId Policy ID that approved the user
cfRayId CF ray id
country Country tag
date The date the access login event was emitted
datetime The date and time the access login event was emitted
datetimeFifteenMinutes The date and time the access login event was emitted truncated to fifteen minutes
datetimeFiveMinutes The date and time the access login event was emitted truncated to five minutes
datetimeHour The date and time the access login event was emitted truncated to the hour
datetimeMinute The date and time the access login event was emitted truncated to the minute
deviceId Device ID
hasExistingJWT Has existing JWT (0 = false, 1 = true)
hasGatewayEnabled Has Gateway enabled (0 = false, 1 = true)
hasWarpEnabled Has WARP enabled (0 = false, 1 = true)
identityProvider Identity provider
ipAddress User IP address
isSuccessfulLogin If the login was successful (0 = false, 1 = true)
mtlsCertSerialId MTLS certificate serial ID
mtlsCommonName MTLS common name
mtlsStatus MTLS status (may show error message if status is not successful)
serviceTokenId Service token ID
serviceTokenVersion Service token version
userUuid User UUID

AccountAdvancedDnsProtectionNetworkAnalyticsAdaptiveGroups

Network analytics data for Advanced DNS Protection

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountAdvancedDnsProtectionNetworkAnalyticsAdaptiveGroupsAvg

FieldDescription
bitRate Sum of bits received, divided by 1 second, providing a per-second bit rate when grouped by datetime
bitRateDay Sum of bits received, divided by 86400 seconds, providing a per-second bit rate when grouped by date
bitRateFifteenMinutes Sum of bits received, divided by 900 seconds, providing a per-second bit rate when grouped by datetimeFifteenMinutes
bitRateFiveMinutes Sum of bits received, divided by 300 seconds, providing a per-second bit rate when grouped by datetimeFiveMinutes
bitRateHour Sum of bits received, divided by 3600 seconds, providing a per-second bit rate when grouped by datetimeHour
bitRateMinute Sum of bits received, divided by 60 seconds, providing a per-second bit rate when grouped by datetimeMinute
bitRateTenSeconds Sum of bits received, divided by 10 seconds, providing a per-second bit rate when grouped by datetimeTenSeconds
packetRate Sum of packets received, divided by 1 second, providing a per-second packet rate when grouped by datetime
packetRateDay Sum of packets received, divided by 86400 seconds, providing a per-second packet rate when grouped by date
packetRateFifteenMinutes Sum of packets received, divided by 900 seconds, providing a per-second packet rate when grouped by datetimeFifteenMinutes
packetRateFiveMinutes Sum of packets received, divided by 300 seconds, providing a per-second packet rate when grouped by datetimeFiveMinutes
packetRateHour Sum of packets received, divided by 3600 seconds, providing a per-second packet rate when grouped by datetimeHour
packetRateMinute Sum of packets received, divided by 60 seconds, providing a per-second packet rate when grouped by datetimeMinute
packetRateTenSeconds Sum of packets received, divided by 10 seconds, providing a per-second packet rate when grouped by datetimeTenSeconds

AccountAdvancedDnsProtectionNetworkAnalyticsAdaptiveGroupsAvgConfidence

FieldDescription
bitRate Confidence interval for the corresponding point estimate
bitRateDay Confidence interval for the corresponding point estimate
bitRateFifteenMinutes Confidence interval for the corresponding point estimate
bitRateFiveMinutes Confidence interval for the corresponding point estimate
bitRateHour Confidence interval for the corresponding point estimate
bitRateMinute Confidence interval for the corresponding point estimate
bitRateTenSeconds Confidence interval for the corresponding point estimate
packetRate Confidence interval for the corresponding point estimate
packetRateDay Confidence interval for the corresponding point estimate
packetRateFifteenMinutes Confidence interval for the corresponding point estimate
packetRateFiveMinutes Confidence interval for the corresponding point estimate
packetRateHour Confidence interval for the corresponding point estimate
packetRateMinute Confidence interval for the corresponding point estimate
packetRateTenSeconds Confidence interval for the corresponding point estimate

AccountAdvancedDnsProtectionNetworkAnalyticsAdaptiveGroupsConfidence

FieldDescription
avg The average of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountAdvancedDnsProtectionNetworkAnalyticsAdaptiveGroupsDimensions

FieldDescription
applicationTag Application tag associated with the packet
coloCity City where the Cloudflare datacenter that received the packet is located
coloCode Cloudflare datacenter that received the packet (nearest IATA airport code)
coloCountry Country where the Cloudflare datacenter that received the packet is located (ISO 3166-1 alpha-2)
coloGeohash Latitude and longitude where the Cloudflare datacenter that received the packet is located (Geohash encoding)
coloName Cloudflare datacenter that received the packet (unique site identifier)
date Date that the packet was received
datetime Date and time that the packet was received
datetimeFifteenMinutes Date and time that the packet was received, rounded to the start of the nearest fifteen minutes
datetimeFiveMinutes Date and time that the packet was received, rounded to the start of the nearest five minutes
datetimeHour Date and time that the packet was received, rounded to the start of the nearest hour
datetimeMinute Date and time that the packet was received, rounded to the start of the nearest minute
datetimeTenSeconds Date and time that the packet was received, rounded to the start of the nearest ten seconds
destinationAsn ASN associated with the destination IP of the packet, or 0 if there was no mapping available
destinationAsnName Name of ASN associated with the destination IP of the packet, if available
destinationCountry Country where the destination IP of the packet is located (ISO 3166-1 alpha-2)
destinationGeohash Latitude and longitude where the destination IP of the packet is located (Geohash encoding)
destinationPort Value of the Destination Port header field in the TCP or UDP packet
direction Direction of the packet relative to the customer network (possible values: inbound, outbound, lateral)
dnsQueryName The requested domain name in the DNS query
dnsQueryType The query type in the DNS query
ethertype Value of the Ethertype header field in the Ethernet packet (2048 for IPv4; 34525 for IPv6)
greChecksum Value of the Checkusm header field in the GRE packet
greEthertype Value of the Ethertype header field in the GRE packet
greHeaderLength Length of the GRE packet header, in bytes
greKey Value of the Key header field in the GRE packet
greSequenceNumber Value of the Sequence Number header field in the GRE packet
greVersion Value of the Version header field in the GRE packet
icmpChecksum Value of the Checkusm header field in the ICMP packet
icmpCode Value of the Code header field in the ICMP packet
icmpType Value of the Type header field in the ICMP packet
ipDestinationAddress Value of the Destination Address header field in the IPv4 or IPv6 packet
ipDestinationSubnet Computed subnet of the Destination Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipFragmentOffset Value of the Fragment Offset header field in the IPv4 or IPv6 packet
ipHeaderLength Length of the IPv4 or IPv6 packet header, in bytes
ipMoreFragments Value of the More Fragments header field in the IPv4 or IPv6 packet
ipProtocol Value of the Protocol header field in the IPv4 or IPv6 packet
ipProtocolName Name of the protocol specified by the Protocol header field in the IPv4 or IPv6 packet
ipSourceAddress Value of the Source Address header field in the IPv4 or IPv6 packet
ipSourceSubnet Computed subnet of the Source Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipTotalLength Total length of the IPv4 or IPv6 packet, in bytes
ipTotalLengthBuckets Total length of the IPv4 or IPv6 packet, in bytes, with the last two digits truncated
ipTtl Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet
ipTtlBuckets Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet, with the last digit truncated
ipv4Checksum Value of the Checksum header field in the IPv4 packet
ipv4DontFragment Value of the Don't Fragment header field in the IPv4 packet
ipv4Dscp Value of the Differentiated Services Code Point header field in the IPv4 packet
ipv4Ecn Value of the Explicit Congestion Notification header field in the IPv4 packet
ipv4Identification Value of the Identification header field in the IPv4 packet
ipv4Options List of Options numbers included in the IPv4 packet header
ipv6Dscp Value of the Differentiated Services Code Point header field in the IPv6 packet
ipv6Ecn Value of the Explicit Congestion Notification header field in the IPv6 packet
ipv6ExtensionHeaders List of Extension Header numbers included in the IPv6 packet header
ipv6FlowLabel Value of the Flow Label header field in the IPv6 packet
ipv6Identification Value of the Identification extension header field in the IPv6 packet
leaseTag IP lease tag associated with the packet
mitigationReason Reason for applying a mitigation to the packet, if any
mitigationScope Whether the packet matched a local or global mitigation, if any (possible values: local, global)
outcome The action that was taken on the packet (possible values: pass, drop)
prefixTag IP prefix tag associated with the packet
sampleInterval ABR sample interval
sourceAsn ASN associated with the source IP of the packet, or 0 if there was no mapping available
sourceAsnName Name of ASN associated with the source IP of the packet, if available
sourceCountry Country where the source IP of the packet is located (ISO 3166-1 alpha-2)
sourceGeohash Latitude and longitude where the source IP of the packet is located (Geohash encoding)
sourcePort Value of the Source Port header field in the TCP or UDP packet
tcpAcknowledgementNumber Value of the Acknowledgement Number header field in the TCP packet
tcpChecksum Value of the Checkusm header field in the TCP packet
tcpDataOffset Value of the Data Offset header field in the TCP packet
tcpFlags Value of the Flags header field in the TCP packet
tcpFlagsString Human-readable string representation of the Flags header field in the TCP packet
tcpMss Value of the MSS option header field in the TCP packet
tcpOptions List of Options numbers included in the TCP packet header
tcpSackBlocks Value of the SACK Blocks option header field in the TCP packet
tcpSackPermitted Value of the SACK Permitted option header field in the TCP packet
tcpSequenceNumber Value of the Sequence Number header field in the TCP packet
tcpTimestampEcr Value of the Timestamp Echo Reply option header field in the TCP packet
tcpTimestampValue Value of the Timestamp option header field in the TCP packet
tcpUrgentPointer Value of the Urgent Pointer header field in the TCP packet
tcpWindowScale Value of the Window Scale option header field in the TCP packet
tcpWindowSize Value of the Window Size header field in the TCP packet
udpChecksum Value of the Checkusm header field in the UDP packet
udpPayloadLength Value of the Payload Length header field in the UDP packet
verdict The action that Cloudflare thinks should be taken on the packet (possible values: pass, drop)

AccountAdvancedDnsProtectionNetworkAnalyticsAdaptiveGroupsSum

FieldDescription
bits Sum of bits received
packets Sum of packets received

AccountAdvancedDnsProtectionNetworkAnalyticsAdaptiveGroupsSumConfidence

FieldDescription
bits Confidence interval for the corresponding point estimate
packets Confidence interval for the corresponding point estimate

AccountAdvancedTcpProtectionNetworkAnalyticsAdaptiveGroups

Network analytics data for Advanced TCP Protection

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountAdvancedTcpProtectionNetworkAnalyticsAdaptiveGroupsAvg

FieldDescription
bitRate Sum of bits received, divided by 1 second, providing a per-second bit rate when grouped by datetime
bitRateDay Sum of bits received, divided by 86400 seconds, providing a per-second bit rate when grouped by date
bitRateFifteenMinutes Sum of bits received, divided by 900 seconds, providing a per-second bit rate when grouped by datetimeFifteenMinutes
bitRateFiveMinutes Sum of bits received, divided by 300 seconds, providing a per-second bit rate when grouped by datetimeFiveMinutes
bitRateHour Sum of bits received, divided by 3600 seconds, providing a per-second bit rate when grouped by datetimeHour
bitRateMinute Sum of bits received, divided by 60 seconds, providing a per-second bit rate when grouped by datetimeMinute
bitRateTenSeconds Sum of bits received, divided by 10 seconds, providing a per-second bit rate when grouped by datetimeTenSeconds
packetRate Sum of packets received, divided by 1 second, providing a per-second packet rate when grouped by datetime
packetRateDay Sum of packets received, divided by 86400 seconds, providing a per-second packet rate when grouped by date
packetRateFifteenMinutes Sum of packets received, divided by 900 seconds, providing a per-second packet rate when grouped by datetimeFifteenMinutes
packetRateFiveMinutes Sum of packets received, divided by 300 seconds, providing a per-second packet rate when grouped by datetimeFiveMinutes
packetRateHour Sum of packets received, divided by 3600 seconds, providing a per-second packet rate when grouped by datetimeHour
packetRateMinute Sum of packets received, divided by 60 seconds, providing a per-second packet rate when grouped by datetimeMinute
packetRateTenSeconds Sum of packets received, divided by 10 seconds, providing a per-second packet rate when grouped by datetimeTenSeconds

AccountAdvancedTcpProtectionNetworkAnalyticsAdaptiveGroupsAvgConfidence

FieldDescription
bitRate Confidence interval for the corresponding point estimate
bitRateDay Confidence interval for the corresponding point estimate
bitRateFifteenMinutes Confidence interval for the corresponding point estimate
bitRateFiveMinutes Confidence interval for the corresponding point estimate
bitRateHour Confidence interval for the corresponding point estimate
bitRateMinute Confidence interval for the corresponding point estimate
bitRateTenSeconds Confidence interval for the corresponding point estimate
packetRate Confidence interval for the corresponding point estimate
packetRateDay Confidence interval for the corresponding point estimate
packetRateFifteenMinutes Confidence interval for the corresponding point estimate
packetRateFiveMinutes Confidence interval for the corresponding point estimate
packetRateHour Confidence interval for the corresponding point estimate
packetRateMinute Confidence interval for the corresponding point estimate
packetRateTenSeconds Confidence interval for the corresponding point estimate

AccountAdvancedTcpProtectionNetworkAnalyticsAdaptiveGroupsConfidence

FieldDescription
avg The average of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountAdvancedTcpProtectionNetworkAnalyticsAdaptiveGroupsDimensions

FieldDescription
applicationTag Application tag associated with the packet
coloCity City where the Cloudflare datacenter that received the packet is located
coloCode Cloudflare datacenter that received the packet (nearest IATA airport code)
coloCountry Country where the Cloudflare datacenter that received the packet is located (ISO 3166-1 alpha-2)
coloGeohash Latitude and longitude where the Cloudflare datacenter that received the packet is located (Geohash encoding)
coloName Cloudflare datacenter that received the packet (unique site identifier)
date Date that the packet was received
datetime Date and time that the packet was received
datetimeFifteenMinutes Date and time that the packet was received, rounded to the start of the nearest fifteen minutes
datetimeFiveMinutes Date and time that the packet was received, rounded to the start of the nearest five minutes
datetimeHour Date and time that the packet was received, rounded to the start of the nearest hour
datetimeMinute Date and time that the packet was received, rounded to the start of the nearest minute
datetimeTenSeconds Date and time that the packet was received, rounded to the start of the nearest ten seconds
destinationAsn ASN associated with the destination IP of the packet, or 0 if there was no mapping available
destinationAsnName Name of ASN associated with the destination IP of the packet, if available
destinationCountry Country where the destination IP of the packet is located (ISO 3166-1 alpha-2)
destinationGeohash Latitude and longitude where the destination IP of the packet is located (Geohash encoding)
destinationPort Value of the Destination Port header field in the TCP or UDP packet
direction Direction of the packet relative to the customer network (possible values: inbound, outbound, lateral)
ethertype Value of the Ethertype header field in the Ethernet packet (2048 for IPv4; 34525 for IPv6)
greChecksum Value of the Checkusm header field in the GRE packet
greEthertype Value of the Ethertype header field in the GRE packet
greHeaderLength Length of the GRE packet header, in bytes
greKey Value of the Key header field in the GRE packet
greSequenceNumber Value of the Sequence Number header field in the GRE packet
greVersion Value of the Version header field in the GRE packet
icmpChecksum Value of the Checkusm header field in the ICMP packet
icmpCode Value of the Code header field in the ICMP packet
icmpType Value of the Type header field in the ICMP packet
ipDestinationAddress Value of the Destination Address header field in the IPv4 or IPv6 packet
ipDestinationSubnet Computed subnet of the Destination Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipFragmentOffset Value of the Fragment Offset header field in the IPv4 or IPv6 packet
ipHeaderLength Length of the IPv4 or IPv6 packet header, in bytes
ipMoreFragments Value of the More Fragments header field in the IPv4 or IPv6 packet
ipProtocol Value of the Protocol header field in the IPv4 or IPv6 packet
ipProtocolName Name of the protocol specified by the Protocol header field in the IPv4 or IPv6 packet
ipSourceAddress Value of the Source Address header field in the IPv4 or IPv6 packet
ipSourceSubnet Computed subnet of the Source Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipTotalLength Total length of the IPv4 or IPv6 packet, in bytes
ipTotalLengthBuckets Total length of the IPv4 or IPv6 packet, in bytes, with the last two digits truncated
ipTtl Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet
ipTtlBuckets Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet, with the last digit truncated
ipv4Checksum Value of the Checksum header field in the IPv4 packet
ipv4DontFragment Value of the Don't Fragment header field in the IPv4 packet
ipv4Dscp Value of the Differentiated Services Code Point header field in the IPv4 packet
ipv4Ecn Value of the Explicit Congestion Notification header field in the IPv4 packet
ipv4Identification Value of the Identification header field in the IPv4 packet
ipv4Options List of Options numbers included in the IPv4 packet header
ipv6Dscp Value of the Differentiated Services Code Point header field in the IPv6 packet
ipv6Ecn Value of the Explicit Congestion Notification header field in the IPv6 packet
ipv6ExtensionHeaders List of Extension Header numbers included in the IPv6 packet header
ipv6FlowLabel Value of the Flow Label header field in the IPv6 packet
ipv6Identification Value of the Identification extension header field in the IPv6 packet
leaseTag IP lease tag associated with the packet
mitigationReason Reason for applying a mitigation to the packet, if any
mitigationScope Whether the packet matched a local or global mitigation, if any (possible values: local, global)
outcome The action that was taken on the packet (possible values: pass, drop)
prefixTag IP prefix tag associated with the packet
protocolState State of the packet in the context of the protocol, if available
sampleInterval ABR sample interval
sourceAsn ASN associated with the source IP of the packet, or 0 if there was no mapping available
sourceAsnName Name of ASN associated with the source IP of the packet, if available
sourceCountry Country where the source IP of the packet is located (ISO 3166-1 alpha-2)
sourceGeohash Latitude and longitude where the source IP of the packet is located (Geohash encoding)
sourcePort Value of the Source Port header field in the TCP or UDP packet
tcpAcknowledgementNumber Value of the Acknowledgement Number header field in the TCP packet
tcpChecksum Value of the Checkusm header field in the TCP packet
tcpDataOffset Value of the Data Offset header field in the TCP packet
tcpFlags Value of the Flags header field in the TCP packet
tcpFlagsString Human-readable string representation of the Flags header field in the TCP packet
tcpMss Value of the MSS option header field in the TCP packet
tcpOptions List of Options numbers included in the TCP packet header
tcpSackBlocks Value of the SACK Blocks option header field in the TCP packet
tcpSackPermitted Value of the SACK Permitted option header field in the TCP packet
tcpSequenceNumber Value of the Sequence Number header field in the TCP packet
tcpTimestampEcr Value of the Timestamp Echo Reply option header field in the TCP packet
tcpTimestampValue Value of the Timestamp option header field in the TCP packet
tcpUrgentPointer Value of the Urgent Pointer header field in the TCP packet
tcpWindowScale Value of the Window Scale option header field in the TCP packet
tcpWindowSize Value of the Window Size header field in the TCP packet
udpChecksum Value of the Checkusm header field in the UDP packet
udpPayloadLength Value of the Payload Length header field in the UDP packet
verdict The action that Cloudflare thinks should be taken on the packet (possible values: pass, drop)

AccountAdvancedTcpProtectionNetworkAnalyticsAdaptiveGroupsSum

FieldDescription
bits Sum of bits received
packets Sum of packets received

AccountAdvancedTcpProtectionNetworkAnalyticsAdaptiveGroupsSumConfidence

FieldDescription
bits Confidence interval for the corresponding point estimate
packets Confidence interval for the corresponding point estimate

AccountAegisIpUtilizationAdaptiveGroups

Beta. Aegis IP utilization metrics

FieldDescription
avg The avg of values for a metric per dimension
dimensions List of dimensions to group by
max The max of values for a metric per dimension

AccountAegisIpUtilizationAdaptiveGroupsAvg

FieldDescription
utilization Average utilization (%)

AccountAegisIpUtilizationAdaptiveGroupsDimensions

FieldDescription
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by 1 hour
datetimeMinute Timestamp bucketed by 1 minute
popUtilizationKey PoP, Aegis IP and origin. Can be used as a grouping key

AccountAegisIpUtilizationAdaptiveGroupsMax

FieldDescription
utilization Maximum utilization (%) in a single datacenter

AccountAiGatewayCacheAdaptiveGroups

AI Gateway Cache

FieldDescription
confidence ALPHA - DO NOT USE
count Total number of requests for an account with caching enabled: including hits and misses
dimensions List of dimensions to group by

AccountAiGatewayCacheAdaptiveGroupsConfidence

FieldDescription
count Total number of requests for an account with caching enabled: including hits and misses, with confidence intervals
level Confidence level that was requested

AccountAiGatewayCacheAdaptiveGroupsDimensions

FieldDescription
cacheOp Cache Hit or Miss: 1 = cache hit, 0 = cache miss
date The date when trigger was triggerd
datetime The date and time the event occurred
datetimeFifteenMinutes The date and time truncated to fifteen minutes
datetimeFiveMinutes The date and time truncated to five minutes
datetimeHour The date and time truncated to the hour
datetimeMinute The date and time truncated to the minute
gateway Gateway name
model Which model was the request sent to
provider Which provider was the request sent to
tokensIn Number of tokens in the request
tokensOut Number of tokens in the response

AccountAiGatewayErrorsAdaptiveGroups

AI Gateway Errors

FieldDescription
confidence ALPHA - DO NOT USE
count Number of errors
dimensions List of dimensions to group by

AccountAiGatewayErrorsAdaptiveGroupsConfidence

FieldDescription
count Number of errors, with confidence intervals
level Confidence level that was requested

AccountAiGatewayErrorsAdaptiveGroupsDimensions

FieldDescription
date The date when trigger was triggerd
datetime The date and time the event occurred
datetimeFifteenMinutes The date and time truncated to fifteen minutes
datetimeFiveMinutes The date and time truncated to five minutes
datetimeHour The date and time truncated to the hour
datetimeMinute The date and time truncated to the minute
gateway Gateway name
model Which models was the request sent to
provider Which provider was the request sent to

AccountAiGatewayRequestsAdaptiveGroups

AI Gateway Requests

FieldDescription
confidence ALPHA - DO NOT USE
count Number of processed requests
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountAiGatewayRequestsAdaptiveGroupsConfidence

FieldDescription
count Number of processed requests, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountAiGatewayRequestsAdaptiveGroupsDimensions

FieldDescription
cached Was the response served from cache?: 1 = cache hit, 0 = cache misss
cost Cost per request
date The date when trigger was triggered
datetime The date and time the event occurred
datetimeFifteenMinutes The date and time truncated to fifteen minutes
datetimeFiveMinutes The date and time truncated to five minutes
datetimeHour The date and time truncated to the hour
datetimeMinute The date and time truncated to the minute
error Was the response an error: 1 , 0 for no error
gateway Gateway name
metadataKeys Metadata keys saved on ai-gateway request
metadataRaw Metadata saved in on ai-gateway request
metadataValues Metadata values saved on ai-gateway request
model Which models was the request sent to
prompts Prompts used on ai-gateway request
promptsIds Prompts Ids used on ai-gateway request
promptsVersions Prompts versions used on ai-gateway request
provider Which provider was the request sent to
rateLimited Was the request rate limited?: 1 = rate limit applied, 0 = rate limit not applied
statusCode HTTP Status Code of provider response
tokensIn Number of tokens in the request
tokensOut Number of tokens in the response
userAgent User-Agent header value sent by the calling SDK or client
wholesale Was the request use wholesale: 1 = applied, 0 = not applied

AccountAiGatewayRequestsAdaptiveGroupsSum

FieldDescription
cachedRequests Sum of cached requests
cachedTokensIn Sum of cached tokens in
cachedTokensOut Sum of cached tokens out
cost Total cost"
erroredRequests Sum of errored requests
uncachedTokensIn Sum of uncached tokens in
uncachedTokensOut Sum of uncached tokens out

AccountAiGatewayRequestsAdaptiveGroupsSumConfidence

FieldDescription
cachedRequests Confidence interval for the corresponding point estimate
cachedTokensIn Confidence interval for the corresponding point estimate
cachedTokensOut Confidence interval for the corresponding point estimate
cost Confidence interval for the corresponding point estimate
erroredRequests Confidence interval for the corresponding point estimate
uncachedTokensIn Confidence interval for the corresponding point estimate
uncachedTokensOut Confidence interval for the corresponding point estimate

AccountAiGatewaySizeAdaptiveGroups

AI Gateway Stored Rows

FieldDescription
dimensions List of dimensions to group by
max The max of values for a metric per dimension

AccountAiGatewaySizeAdaptiveGroupsDimensions

FieldDescription
date The date when trigger was triggerd
datetime The date and time the event occurred
datetimeFifteenMinutes The date and time truncated to fifteen minutes
datetimeFiveMinutes The date and time truncated to five minutes
datetimeHour The date and time truncated to the hour
datetimeMinute The date and time truncated to the minute
gateway Gateway name
logManagement Log Management active or not: 1 = active, 0 = not active
rows Number of rows stored in a gateway

AccountAiGatewaySizeAdaptiveGroupsMax

FieldDescription
rows Max of stored rows

AccountAiInferenceAdaptive

AI Inference logs with adaptive sampling

FieldDescription
audioSeconds Audio seconds
costMetricName1 Name for cost metric 1
costMetricName2 Name for cost metric 2
costMetricValue1 Value for cost metric 1
costMetricValue2 Value for cost metric 2
datetime The date when inferance was triggered
errorCode Error code
inferenceSteps Inference steps
inferenceTimeMs Inference time ms
inputLength Input length
inputTokens Input tokens
modelId ModelId that was trigger to inference
modelIsBeta Model that was trigger to inference is Beta
neurons Monetization unit
outputTokens Output tokens
processedPixels Processed pixels
processedTiles Processed tiles
requestBytesIn Request size in bytes
requestBytesOut Request size out bytes
requestSource Source who triggered (worker binding, pages binding, rest api)
sampleInterval ABR sample interval
tag Individual elements from the tags string
totalTiles Total tiles

AccountAiInferenceAdaptiveGroups

Aggregated AI Inference logs with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Total number of inferences for an account
dimensions List of dimensions to group by
sum

AccountAiInferenceAdaptiveGroupsConfidence

FieldDescription
count Total number of inferences for an account, with confidence intervals
level Confidence level that was requested
sum

AccountAiInferenceAdaptiveGroupsDimensions

FieldDescription
costMetricName1 Name for cost metric 1
costMetricName2 Name for cost metric 2
costMetricValue1 Value for cost metric 1
costMetricValue2 Value for cost metric 2
date The date when the inference starts
datetime The date when the inference starts
datetimeFifteenMinutes The date and time truncated to fifteen minutes
datetimeFiveMinutes The date and time truncated to five minutes
datetimeHour The date and time truncated to the hour
datetimeMinute The date and time truncated to the minute
datetimeSixHours The date and time truncated to six hours
errorCode Error code
inferenceTimeMs Inference time ms
modelId ModelId that was trigger to inference
modelIsBeta Model that was trigger to inference is Beta
neurons Monetization unit
requestBytesIn Request size in bytes
requestBytesOut Request size out bytes
requestSource Source who triggered (worker binding, pages binding, rest api)
tag Individual elements from the tags string

AccountAiInferenceAdaptiveGroupsSum

FieldDescription
totalAudioSeconds Total audio seconds
totalCostMetricValue1 Total value for cost metric 1
totalCostMetricValue2 Total value for cost metric 2
totalInferenceSteps Total inference steps
totalInferenceTimeMs Total inference time ms
totalInputLength Total input length
totalInputTokens Total input tokens
totalNeurons Total neurons
totalOutputTokens Total output tokens
totalProcessedPixels Total processed pixels
totalProcessedTiles Total processed tiles
totalRequestBytesIn Total bytes in per request
totalRequestBytesOut Total bytes out per request
totalTiles Total tiles

AccountAiInferenceAdaptiveGroupsSumConfidence

FieldDescription
totalAudioSeconds Confidence interval for the corresponding point estimate
totalCostMetricValue1 Confidence interval for the corresponding point estimate
totalCostMetricValue2 Confidence interval for the corresponding point estimate
totalInferenceSteps Confidence interval for the corresponding point estimate
totalInferenceTimeMs Confidence interval for the corresponding point estimate
totalInputLength Confidence interval for the corresponding point estimate
totalInputTokens Confidence interval for the corresponding point estimate
totalNeurons Confidence interval for the corresponding point estimate
totalOutputTokens Confidence interval for the corresponding point estimate
totalProcessedPixels Confidence interval for the corresponding point estimate
totalProcessedTiles Confidence interval for the corresponding point estimate
totalRequestBytesIn Confidence interval for the corresponding point estimate
totalRequestBytesOut Confidence interval for the corresponding point estimate
totalTiles Confidence interval for the corresponding point estimate

AccountAiSearchAPIAdaptiveGroups

AI Search API Search Analytics

FieldDescription
confidence ALPHA - DO NOT USE
count Total number of search events
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountAiSearchAPIAdaptiveGroupsConfidence

FieldDescription
count Total number of search events, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountAiSearchAPIAdaptiveGroupsDimensions

FieldDescription
aiPromptIncluded Whether the prompt for AI Search is included (0 = false, 1 = true)
aiSearchDurationMs The time in milliseconds it took to generate a response with AI Search
aiSearchInputSizeTokens The size in tokens of the input for response generation with AI Search
aiSearchModel The model used for AI Search, if it was used
aiSearchResultSizeTokens The size in tokens of the AI Search generated response
chunkOverlap How much overlap exists between contiguous chunks
chunkSize The size of text chunks
date The date of the search event
datetime The date and time the event occurred
datetimeFifteenMinutes The date and time truncated to fifteen minutes
datetimeFiveMinutes The date and time truncated to five minutes
datetimeHour The date and time truncated to the hour
datetimeMinute The date and time truncated to the minute
doReranking Whether re-ranking was used when performing this search task (0 = false, 1 = true)
doRewrite Whether to do query rewriting when performing searches with this AI Search instance (0 = false, 1 = true)
embeddingModel The model used to generate embeddings
enableChunking Whether chunking is enabled for this AI Search instance (0 = false, 1 = true)
getFilesDurationMs The time in milliseconds it took to retrieve files for this search
getQueryVectorsAvgDurationMs The time in milliseconds it took to generate embeddings for this search's query
getResultVectorsAvgDurationMs The time in milliseconds it took to retrieve stored file embeddings
instanceId AI Search Instance Id
isStream Whether the search response was streamed or not (0 = false, 1 = true)
maxResults The max number of results that can be returned
numChunksToRetrieve The number of chunks to retrieve from the vector store, calculated based on the configured number of results to retrieve
numResults The number of returned results
querySizeTokens The size of the given query in tokens
regenerateMarkdown Whether this search implied regenerating markdown for returned results (0 = false, 1 = true)
rerankingDurationMs The time in milliseconds it took to re-rank results based on this search's query
rerankingModel The reranking model used in this search
rewriteDurationMs The time in milliseconds that it took to rewrite the query
rewriteInputSizeTokens The size in tokens of the rewritten input
rewriteModel The model used for rewriting queries
rewritePromptIncluded Whether the rewrite prompt is included (0 = false, 1 = true)
rewriteResultSizeTokens The size in tokens of the rewritten query
scoreThreshold The score threshold over which matches are included in the result
searchType AI Search Type
totalDurationMs The total time in milliseconds that performing this search took

AccountAiSearchAPIAdaptiveGroupsSum

FieldDescription
aiSearchCount The number of AI searches for this AI Search instance
searchCount The number of Searches for this AI Search instance

AccountAiSearchAPIAdaptiveGroupsSumConfidence

FieldDescription
aiSearchCount Confidence interval for the corresponding point estimate
searchCount Confidence interval for the corresponding point estimate

AccountAiSearchIngestedItemsAdaptiveGroups

AI Search Ingested Items Analytics

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
count Total number of ingestion item events
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountAiSearchIngestedItemsAdaptiveGroupsAvg

FieldDescription
chunkingDurationMs Average chunking duration in milliseconds
embeddingDurationMs Average embedding duration in milliseconds
fileSizeBytes Average file size in bytes
numChunks Average number of chunks
totalDurationMs Average duration in milliseconds for processing items
totalTokens Average number of tokens
vectorizeDurationMs Average vectorize duration in milliseconds

AccountAiSearchIngestedItemsAdaptiveGroupsConfidence

FieldDescription
count Total number of ingestion item events, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountAiSearchIngestedItemsAdaptiveGroupsDimensions

FieldDescription
chunkOverlap How much overlap exists between contiguous chunks
chunkSize The size of text chunks
date The date of the ingestion event
datetime The date and time the event occurred
datetimeFifteenMinutes The date and time truncated to fifteen minutes
datetimeFiveMinutes The date and time truncated to five minutes
datetimeHour The date and time truncated to the hour
datetimeMinute The date and time truncated to the minute
embeddingModel The model used to generate embeddings
error Whether an error occurred during ingestion (0 = false, 1 = true)
fileKey The file key identifier
indexId The index identifier
instanceId AI Search Instance Id

AccountAiSearchIngestedItemsAdaptiveGroupsSum

FieldDescription
chunkingDurationMs Total chunking duration in milliseconds
embeddingDurationMs Total embedding duration in milliseconds
fileSizeBytes Total file size in bytes
numChunks Total number of chunks
totalDurationMs Total duration in milliseconds for processing items
totalTokens Total number of tokens
vectorizeDurationMs Total vectorize duration in milliseconds

AccountAiSearchIngestedItemsAdaptiveGroupsSumConfidence

FieldDescription
chunkingDurationMs Confidence interval for the corresponding point estimate
embeddingDurationMs Confidence interval for the corresponding point estimate
fileSizeBytes Confidence interval for the corresponding point estimate
numChunks Confidence interval for the corresponding point estimate
totalDurationMs Confidence interval for the corresponding point estimate
totalTokens Confidence interval for the corresponding point estimate
vectorizeDurationMs Confidence interval for the corresponding point estimate

AccountArtifactsEventsAdaptiveGroups

Artifacts events with adaptive sampling

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count The number of artifact events
dimensions List of dimensions to group by
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension

AccountArtifactsEventsAdaptiveGroupsAvg

FieldDescription
durationMs Average duration of artifact operations in milliseconds

AccountArtifactsEventsAdaptiveGroupsConfidence

FieldDescription
count The number of artifact events, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountArtifactsEventsAdaptiveGroupsDimensions

FieldDescription
date The date the artifact event occurred
datetime The date and time the artifact event occurred
datetimeFifteenMinutes The date and time the artifact event occurred truncated to fifteen minutes
datetimeFiveMinutes The date and time the artifact event occurred truncated to five minutes
datetimeHour The date and time the artifact event occurred truncated to the hour
datetimeMinute The date and time the artifact event occurred truncated to the minute
datetimeSixHours The date and time the artifact event occurred truncated to start of six hour window
errorMessage The error message if the operation failed
eventKind Top-level event category: 'action' for successful operations, 'error' for failures
eventType Specific event type within the eventKind. For actions: create, fork, push, pull, delete. For errors: storageLimitReached, serverError, clientError, rateLimited
repository The fully-qualified repository path in the form '{namespace}/{name}' (max 96 chars). Filter with exact match (e.g. 'my-ns/my-repo') or use repository_like for prefix queries (e.g. 'my-ns/%').
repositoryName The name of the repository within its namespace
repositoryNamespace The namespace of the repository

AccountArtifactsEventsAdaptiveGroupsQuantiles

FieldDescription
durationMsP25 Duration in milliseconds (25th percentile)
durationMsP50 Duration in milliseconds (50th percentile)
durationMsP75 Duration in milliseconds (75th percentile)
durationMsP90 Duration in milliseconds (90th percentile)
durationMsP95 Duration in milliseconds (95th percentile)
durationMsP99 Duration in milliseconds (99th percentile)
durationMsP999 Duration in milliseconds (99.9th percentile)

AccountArtifactsEventsAdaptiveGroupsSum

FieldDescription
durationMs Total duration of artifact operations in milliseconds

AccountArtifactsEventsAdaptiveGroupsSumConfidence

FieldDescription
durationMs Confidence interval for the corresponding point estimate

AccountAutoRAGConfigAPIAdaptiveGroups

AutoRAG Config API Search Analytics

FieldDescription
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountAutoRAGConfigAPIAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountAutoRAGConfigAPIAdaptiveGroupsDimensions

FieldDescription
aiPromptIncluded Whether the prompt for AI Search is included (0 = false, 1 = true)
aiSearchDurationMs The time in milliseconds it took to do generate a response with AI Search
aiSearchInputSizeTokens The size in tokens of the input for response generation with AI Search
aiSearchModel The model used for AI Search, if it was used
aiSearchResultSizeTokens The size in tokens of the AI Search generated response
chuckSizeTokensArray An array of file sizes of the files returned in this search
chunkOverlap How much overlap exists between contiguous chunks
chunkSize The size of text chunks
date The date when trigger was triggered
datetime The date and time the event occurred
datetimeFifteenMinutes The date and time truncated to fifteen minutes
datetimeFiveMinutes The date and time truncated to five minutes
datetimeHour The date and time truncated to the hour
datetimeMinute The date and time truncated to the minute
doReranking Whether re-ranking was used when performing this search task (0 = false, 1 = true)
doRewrite Whether to do query rewriting when performing searches with this RAG (0 = false, 1 = true)
embeddingModel The model used to generate embeddings
enableChunking Whether chunking is enabled for this AutoRAG (0 = false, 1 = true)
fileIdArray An array of IDs of the files returned in this search
filenameArray An array of names of the files returned in this search
getFilesDurationMs The time in milliseconds it took to retrieve files for this search
getQueryVectorsAvgDurationMs The time in milliseconds it took to generate embeddings for this search's query
getResultVectorsAvgDurationMs The time in milliseconds it took to retrieve stored file embeddings
isStream Whether the search response was streamed or not (0 = false, 1 = true)
maxResults THe max number of results that can be returned
numChunksToRetrieve The number of chunks to retrieve from the vector store, calculated based on the configured number of results to retrieve
numResults The number of returned results
querySizeTokens The size of the given query in tokens
rag AutoRAG Id
regenerateMarkdown Whether to this search implied regenerating markdown for returned results (0 = false, 1 = true)
rerankingDurationMs The time in milliseconds it took to re-rank results based on this search's query
rerankingModel The reranking model used in this search
rewriteDurationMs The time in milliseconds that it took to rewrite the query
rewriteInputSizeTokens The size in tokens of the rewritten input
rewriteModel The model used for rewriting queries
rewritePromptIncluded Whether the rewrite prompt is included (0 = false, 1 = true)
rewriteResultSizeTokens The size in tokens of the rewritten query
scoreArray An array of matching scores of the files returned in this search
scoreThreshold The score threshold over which matches are included in the result
searchType AutoRAG Search Type
totalDurationMs The total time in milliseconds that performing this search took

AccountAutoRAGConfigAPIAdaptiveGroupsSum

FieldDescription
aiSearchCount The number of AI Searches for this RAG
searchCount The number of Searches for this RAG

AccountAutoRAGConfigAPIAdaptiveGroupsSumConfidence

FieldDescription
aiSearchCount Confidence interval for the corresponding point estimate
searchCount Confidence interval for the corresponding point estimate

AccountAutoRAGEngineAdaptiveGroups

AutoRAG Engine Ingestion Analytics

FieldDescription
dimensions List of dimensions to group by
max The max of values for a metric per dimension

AccountAutoRAGEngineAdaptiveGroupsDimensions

FieldDescription
completed Number of completed items
date The date when trigger was triggered
datetime The date and time the event occurred
datetimeFifteenMinutes The date and time truncated to fifteen minutes
datetimeFiveMinutes The date and time truncated to five minutes
datetimeHour The date and time truncated to the hour
datetimeMinute The date and time truncated to the minute
errored Number of errored items
queued Number of queued items
rag AutoRAG Id
running Number of running items
sourceType AutoRAG Source Type

AccountAutoRAGEngineAdaptiveGroupsMax

FieldDescription
completed Max of completed items
errored Max of errored items
queued Max of queued items
running Max of running items

AccountBrowserIsolationSessionsAdaptiveGroups

Aggregated count of Browser Isolation sessions

FieldDescription
confidence ALPHA - DO NOT USE
count Number of browser sessions
dimensions List of dimensions to group by

AccountBrowserIsolationSessionsAdaptiveGroupsConfidence

FieldDescription
count Number of browser sessions, with confidence intervals
level Confidence level that was requested

AccountBrowserIsolationSessionsAdaptiveGroupsDimensions

FieldDescription
date Timestamp truncated to the start of a day
datetime
datetimeFifteenMinutes Timestamp truncated to fifteen minutes
datetimeFiveMinutes Timestamp truncated to five minutes
datetimeHour Timestamp truncated to the hour
datetimeMinute Timestamp truncated to the minute

AccountBrowserIsolationUserActionsAdaptiveGroups

Aggregated count of Browser Isolation User Actions matches

FieldDescription
confidence ALPHA - DO NOT USE
count Number of user actions
dimensions List of dimensions to group by

AccountBrowserIsolationUserActionsAdaptiveGroupsConfidence

FieldDescription
count Number of user actions, with confidence intervals
level Confidence level that was requested

AccountBrowserIsolationUserActionsAdaptiveGroupsDimensions

FieldDescription
date Timestamp truncated to the start of a day
datetime
datetimeFifteenMinutes Timestamp truncated to fifteen minutes
datetimeFiveMinutes Timestamp truncated to five minutes
datetimeHour Timestamp truncated to the hour
datetimeMinute Timestamp truncated to the minute
decision Decision applied to user action. Possible values are allow | block
type User action type. Possible values are copy | paste | download | upload | print

AccountBrowserRenderingApiAdaptive

Browser Run API events with adaptive sampling

FieldDescription
browserSessionEndTime End date and time of the browser session pertaining to the request
browserSessionStartTime Start date and time of the browser session pertaining to the request
crawlJobId Job ID of a request to the Browser Run crawl endpoints
datetime The time of the event
endpoint Browser Run REST API endpoint of the request
requestEndTime End date and time of the request
requestId Browser Run REST API unique request ID
requestStartTime Start date and time of the request
sampleInterval ABR sample interval
sessionId Browser session ID
status HTTP response status code
targetUrl Target URL of the request

AccountBrowserRenderingApiAdaptiveGroups

Aggregated Browser Run API events with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Total number of Browser Run REST API requests for an account
dimensions List of dimensions to group by

AccountBrowserRenderingApiAdaptiveGroupsConfidence

FieldDescription
count Total number of Browser Run REST API requests for an account, with confidence intervals
level Confidence level that was requested

AccountBrowserRenderingApiAdaptiveGroupsDimensions

FieldDescription
browserSessionEndTime End date and time of the browser session pertaining to the request
browserSessionStartTime Start date and time of the browser session pertaining to the request
crawlJobId Job ID of a request to the Browser Run crawl endpoints
date The date of the event
datetime The date and time the event occurred
datetimeFifteenMinutes The date and time of the event truncated to fifteen minutes
datetimeFiveMinutes The date and time of the event truncated to five minutes
datetimeHour The date and time of the event truncated to the hour
datetimeMinute The date and time of the event truncated to the minute
endpoint Browser Run REST API endpoint of the request
requestEndTime End date and time of the request
requestId Browser Run REST API unique request ID
requestStartTime Start date and time of the request
sessionId Browser session ID
status HTTP response status code
targetUrl Target URL of the request

AccountBrowserRenderingBindingSessionsAdaptiveGroups

Aggregated Browser Run worker binding sessions with adaptive sampling

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count Total number of sessions for an account
dimensions List of dimensions to group by
max The maximum value for a metric per dimension
uniq

AccountBrowserRenderingBindingSessionsAdaptiveGroupsAvg

FieldDescription
avgConcurrentSessions Average concurrent browser sessions

AccountBrowserRenderingBindingSessionsAdaptiveGroupsConfidence

FieldDescription
count Total number of sessions for an account, with confidence intervals
level Confidence level that was requested

AccountBrowserRenderingBindingSessionsAdaptiveGroupsDimensions

FieldDescription
concurrentSessions Number of browser sessions used concurrently at the time of the event
date The date of the event
datetime The date and time the event occurred
datetimeFifteenMinutes The date and time of the event truncated to fifteen minutes
datetimeFiveMinutes The date and time of the event truncated to five minutes
datetimeHour The date and time of the event truncated to the hour
datetimeMinute The date and time of the event truncated to the minute
sessionId Browser session ID

AccountBrowserRenderingBindingSessionsAdaptiveGroupsMax

FieldDescription
maxConcurrentSessions Maximum concurrent browser sessions

AccountBrowserRenderingBindingSessionsAdaptiveGroupsUniq

FieldDescription
sessionIdCount Unique browser sessions

AccountBrowserRenderingBrowserTimeUsageAdaptiveGroups

Aggregated Browser Run and Browser Run REST API browser sessions with adaptive sampling

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count Total number of Browser Run and Browser Run REST API browser sessions for an account
dimensions List of dimensions to group by
max The maximum value for a metric per dimension
min The minimum value for a metric per dimension
sum The total value for a metric per dimension

AccountBrowserRenderingBrowserTimeUsageAdaptiveGroupsAvg

FieldDescription
avgSessionDurationMs Average browser session duration in ms

AccountBrowserRenderingBrowserTimeUsageAdaptiveGroupsConfidence

FieldDescription
count Total number of Browser Run and Browser Run REST API browser sessions for an account, with confidence intervals
level Confidence level that was requested
sum The total value for a metric per dimension, with confidence intervals

AccountBrowserRenderingBrowserTimeUsageAdaptiveGroupsDimensions

FieldDescription
date The date of the event
datetime The date and time the event occurred
datetimeFifteenMinutes The date and time of the event truncated to fifteen minutes
datetimeFiveMinutes The date and time of the event truncated to five minutes
datetimeHour The date and time of the event truncated to the hour
datetimeMinute The date and time of the event truncated to the minute
sessionDurationMs Browser session duration in ms
sessionEnd End date and time of the browser session
sessionId Browser session ID
sessionStart Start date and time of the browser session

AccountBrowserRenderingBrowserTimeUsageAdaptiveGroupsMax

FieldDescription
maxSessionDurationMs Max browser session duration in ms

AccountBrowserRenderingBrowserTimeUsageAdaptiveGroupsMin

FieldDescription
minSessionDurationMs Min browser session duration in ms

AccountBrowserRenderingBrowserTimeUsageAdaptiveGroupsSum

FieldDescription
totalSessionDurationMs Total browser sessions duration in ms

AccountBrowserRenderingBrowserTimeUsageAdaptiveGroupsSumConfidence

FieldDescription
totalSessionDurationMs Confidence interval for the corresponding point estimate

AccountBrowserRenderingEventsAdaptive

Browser Run events with adaptive sampling

FieldDescription
browserCloseReason Browser session close code. Enum (-1, N/A) (0, Unknown) (1, NormalClosure) (2, BrowserIdle) (3, ClientClosedEarly) (4, ChromiumChrashed) (5, ClientAbnormalClosure) (6, ServerAbnormalClosure) (7, ClientError) (8, ServerError) (9, WorkerError) (10, ClientNeverConnected) (11, BrowserSessionEvicted) (12, UsedBrowserTimeLimitExceeded)
browserEndTime Browser session end time
browserStartTime Browser session start time
clientLibrary Library used to launch the browser session
concurrentSessions Number of browser sessions used concurrently at the time of the event
connectionEndTime When worker ended devtools connection to browser session
connectionId Worker connection ID, when available
connectionStartTime When worker started devtools connection to browser session
datetime The time of the event
recordingMode Browser session recording mode: 'unknown', 'enabled', or 'disabled'
sampleInterval ABR sample interval
scriptName Name of worker who initiated the request
sessionId Browser session ID

AccountBrowserRenderingEventsAdaptiveGroups

Aggregated Browser Run events with adaptive sampling

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count Total number of events for an account
dimensions List of dimensions to group by
max The maximum value for a metric per dimension
min The minimum value for a metric per dimension
uniq

AccountBrowserRenderingEventsAdaptiveGroupsAvg

FieldDescription
avgConcurrentSessions Average concurrent browser sessions

AccountBrowserRenderingEventsAdaptiveGroupsConfidence

FieldDescription
count Total number of events for an account, with confidence intervals
level Confidence level that was requested

AccountBrowserRenderingEventsAdaptiveGroupsDimensions

FieldDescription
browserCloseReason Browser session close code. Enum (-1, N/A) (0, Unknown) (1, NormalClosure) (2, BrowserIdle) (3, ClientClosedEarly) (4, ChromiumChrashed) (5, ClientAbnormalClosure) (6, ServerAbnormalClosure) (7, ClientError) (8, ServerError) (9, WorkerError) (10, ClientNeverConnected) (11, BrowserSessionEvicted) (12, UsedBrowserTimeLimitExceeded)
clientLibrary Library used to launch the browser session
concurrentSessions Number of browser sessions used concurrently at the time of the event
connectionId Worker connection ID, when available
date The date of the event
datetime The date and time the event occurred
datetimeFifteenMinutes The date and time of the event truncated to fifteen minutes
datetimeFiveMinutes The date and time of the event truncated to five minutes
datetimeHour The date and time of the event truncated to the hour
datetimeMinute The date and time of the event truncated to the minute
recordingMode Browser session recording mode: 'unknown', 'enabled', or 'disabled'
scriptName Name of worker who initiated the request
sessionId Browser session ID

AccountBrowserRenderingEventsAdaptiveGroupsMax

FieldDescription
finalBrowserCloseReason Browser close reason
latestBrowserEndTime Browser end time

AccountBrowserRenderingEventsAdaptiveGroupsMin

FieldDescription
earliestBrowserStartTime Browser start time

AccountBrowserRenderingEventsAdaptiveGroupsUniq

FieldDescription
connectionIdCount Unique worker connections
sessionIdCount Unique browser sessions

AccountCallsStatusAdaptive

(TESTING ONLY, NOT FOR PRODUCTION) Raw Calls events with adaptive sampling

FieldDescription
appId The appId that generated traffic
datetime The date and time the event was recorded
event The description of the event related to a session or a track
sessionId The generated string that identifies a PeerConnection
trackId The track identifier provided to us within a PeerConnection

AccountCallsTurnUsageAdaptiveGroups

Aggregated Calls TURN bandwidth usage with adaptive sampling"

FieldDescription
avg
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountCallsTurnUsageAdaptiveGroupsAvg

FieldDescription
concurrentConnectionsFifteenMinutes Average concurrent connections when grouped by datetimeFifteenMinutes
concurrentConnectionsFiveMinutes Average concurrent connections when grouped by datetimeFiveMinutes
concurrentConnectionsHour Average concurrent connections when grouped by datetimeHour
concurrentConnectionsMinute Average concurrent connections when grouped by datetimeMinute

AccountCallsTurnUsageAdaptiveGroupsAvgConfidence

FieldDescription
concurrentConnectionsFifteenMinutes Confidence interval for the corresponding point estimate
concurrentConnectionsFiveMinutes Confidence interval for the corresponding point estimate
concurrentConnectionsHour Confidence interval for the corresponding point estimate
concurrentConnectionsMinute Confidence interval for the corresponding point estimate

AccountCallsTurnUsageAdaptiveGroupsConfidence

FieldDescription
avg
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountCallsTurnUsageAdaptiveGroupsDimensions

FieldDescription
customIdentifier The customIdentifier (provided when credential was generated) that generated traffic
datacenterCity City of the Cloudflare datacenter
datacenterCode IATA airport code of the Cloudflare datacenter
datacenterCountry Country of the Cloudflare datacenter
datacenterRegion Region of the Cloudflare datacenter
date Calls TURN bandwidth metrics date
datetime Calls TURN bandwidth metrics timestamp
datetimeFifteenMinutes Calls TURN bandwidth metrics timestamp, truncated to fifteen minutes
datetimeFiveMinutes Calls TURN bandwidth metrics timestamp, truncated to five minutes
datetimeHour Calls TURN bandwidth metrics timestamp, truncated to the hour
datetimeMinute Calls TURN bandwidth metrics timestamp, truncated to the minute
keyId The credentials created by this keyId that generated traffic
username The username from credential that generated traffic

AccountCallsTurnUsageAdaptiveGroupsSum

FieldDescription
egressBytes The total bytes sent by Calls TURN, observed over the queried time period
ingressBytes The total bytes received by Calls TURN, observed over the queried time period

AccountCallsTurnUsageAdaptiveGroupsSumConfidence

FieldDescription
egressBytes Confidence interval for the corresponding point estimate
ingressBytes Confidence interval for the corresponding point estimate

AccountCallsUsageAdaptiveGroups

Beta. Aggregated Calls SFU bandwidth usage with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountCallsUsageAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountCallsUsageAdaptiveGroupsDimensions

FieldDescription
appId The appId that generated traffic
date Calls bandwidth metrics date
datetime Calls bandwidth metrics timestamp
datetimeFifteenMinutes Calls bandwidth metrics timestamp, truncated to fifteen minutes
datetimeFiveMinutes Calls bandwidth metrics timestamp, truncated to five minutes
datetimeHour Calls bandwidth metrics timestamp, truncated to the hour
datetimeMinute Calls bandwidth metrics timestamp, truncated to the minute
sessionId The generated string that identifies a PeerConnection
trackId The track identifier provided to us within a PeerConnection
trackType Describes if the track contains video, audio, or data

AccountCallsUsageAdaptiveGroupsSum

FieldDescription
egressBytes The total bytes sent by Calls, observed over the queried time period
ingressBytes The total bytes received by Calls, observed over the queried time period

AccountCallsUsageAdaptiveGroupsSumConfidence

FieldDescription
egressBytes Confidence interval for the corresponding point estimate
ingressBytes Confidence interval for the corresponding point estimate

AccountCdnNetworkAnalyticsAdaptiveGroups

Network analytics data for Cloudflare CDN traffic

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountCdnNetworkAnalyticsAdaptiveGroupsAvg

FieldDescription
bitRate Sum of bits received, divided by 1 second, providing a per-second bit rate when grouped by datetime
bitRateDay Sum of bits received, divided by 86400 seconds, providing a per-second bit rate when grouped by date
bitRateFifteenMinutes Sum of bits received, divided by 900 seconds, providing a per-second bit rate when grouped by datetimeFifteenMinutes
bitRateFiveMinutes Sum of bits received, divided by 300 seconds, providing a per-second bit rate when grouped by datetimeFiveMinutes
bitRateHour Sum of bits received, divided by 3600 seconds, providing a per-second bit rate when grouped by datetimeHour
bitRateMinute Sum of bits received, divided by 60 seconds, providing a per-second bit rate when grouped by datetimeMinute
bitRateTenSeconds Sum of bits received, divided by 10 seconds, providing a per-second bit rate when grouped by datetimeTenSeconds
packetRate Sum of packets received, divided by 1 second, providing a per-second packet rate when grouped by datetime
packetRateDay Sum of packets received, divided by 86400 seconds, providing a per-second packet rate when grouped by date
packetRateFifteenMinutes Sum of packets received, divided by 900 seconds, providing a per-second packet rate when grouped by datetimeFifteenMinutes
packetRateFiveMinutes Sum of packets received, divided by 300 seconds, providing a per-second packet rate when grouped by datetimeFiveMinutes
packetRateHour Sum of packets received, divided by 3600 seconds, providing a per-second packet rate when grouped by datetimeHour
packetRateMinute Sum of packets received, divided by 60 seconds, providing a per-second packet rate when grouped by datetimeMinute
packetRateTenSeconds Sum of packets received, divided by 10 seconds, providing a per-second packet rate when grouped by datetimeTenSeconds

AccountCdnNetworkAnalyticsAdaptiveGroupsAvgConfidence

FieldDescription
bitRate Confidence interval for the corresponding point estimate
bitRateDay Confidence interval for the corresponding point estimate
bitRateFifteenMinutes Confidence interval for the corresponding point estimate
bitRateFiveMinutes Confidence interval for the corresponding point estimate
bitRateHour Confidence interval for the corresponding point estimate
bitRateMinute Confidence interval for the corresponding point estimate
bitRateTenSeconds Confidence interval for the corresponding point estimate
packetRate Confidence interval for the corresponding point estimate
packetRateDay Confidence interval for the corresponding point estimate
packetRateFifteenMinutes Confidence interval for the corresponding point estimate
packetRateFiveMinutes Confidence interval for the corresponding point estimate
packetRateHour Confidence interval for the corresponding point estimate
packetRateMinute Confidence interval for the corresponding point estimate
packetRateTenSeconds Confidence interval for the corresponding point estimate

AccountCdnNetworkAnalyticsAdaptiveGroupsConfidence

FieldDescription
avg The average of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountCdnNetworkAnalyticsAdaptiveGroupsDimensions

FieldDescription
applicationTag Application tag associated with the packet
coloCity City where the Cloudflare datacenter that received the packet is located
coloCode Cloudflare datacenter that received the packet (nearest IATA airport code)
coloCountry Country where the Cloudflare datacenter that received the packet is located (ISO 3166-1 alpha-2)
coloGeohash Latitude and longitude where the Cloudflare datacenter that received the packet is located (Geohash encoding)
coloName Cloudflare datacenter that received the packet (unique site identifier)
date Date that the packet was received
datetime Date and time that the packet was received
datetimeFifteenMinutes Date and time that the packet was received, rounded to the start of the nearest fifteen minutes
datetimeFiveMinutes Date and time that the packet was received, rounded to the start of the nearest five minutes
datetimeHour Date and time that the packet was received, rounded to the start of the nearest hour
datetimeMinute Date and time that the packet was received, rounded to the start of the nearest minute
datetimeTenSeconds Date and time that the packet was received, rounded to the start of the nearest ten seconds
destinationAsn ASN associated with the destination IP of the packet, or 0 if there was no mapping available
destinationAsnName Name of ASN associated with the destination IP of the packet, if available
destinationCountry Country where the destination IP of the packet is located (ISO 3166-1 alpha-2)
destinationDeviceTag Device tag associated with the destination IP of the packet
destinationGeohash Latitude and longitude where the destination IP of the packet is located (Geohash encoding)
destinationPort Value of the Destination Port header field in the TCP or UDP packet
direction Direction of the packet relative to the customer network (possible values: inbound, outbound, lateral)
ethertype Value of the Ethertype header field in the Ethernet packet (2048 for IPv4; 34525 for IPv6)
greChecksum Value of the Checkusm header field in the GRE packet
greEthertype Value of the Ethertype header field in the GRE packet
greHeaderLength Length of the GRE packet header, in bytes
greKey Value of the Key header field in the GRE packet
greSequenceNumber Value of the Sequence Number header field in the GRE packet
greVersion Value of the Version header field in the GRE packet
icmpChecksum Value of the Checkusm header field in the ICMP packet
icmpCode Value of the Code header field in the ICMP packet
icmpType Value of the Type header field in the ICMP packet
ipDestinationAddress Value of the Destination Address header field in the IPv4 or IPv6 packet
ipDestinationSubnet Computed subnet of the Destination Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipFragmentOffset Value of the Fragment Offset header field in the IPv4 or IPv6 packet
ipHeaderLength Length of the IPv4 or IPv6 packet header, in bytes
ipMoreFragments Value of the More Fragments header field in the IPv4 or IPv6 packet
ipProtocol Value of the Protocol header field in the IPv4 or IPv6 packet
ipProtocolName Name of the protocol specified by the Protocol header field in the IPv4 or IPv6 packet
ipSourceAddress Value of the Source Address header field in the IPv4 or IPv6 packet
ipSourceSubnet Computed subnet of the Source Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipTotalLength Total length of the IPv4 or IPv6 packet, in bytes
ipTotalLengthBuckets Total length of the IPv4 or IPv6 packet, in bytes, with the last two digits truncated
ipTtl Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet
ipTtlBuckets Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet, with the last digit truncated
ipv4Checksum Value of the Checksum header field in the IPv4 packet
ipv4DontFragment Value of the Don't Fragment header field in the IPv4 packet
ipv4Dscp Value of the Differentiated Services Code Point header field in the IPv4 packet
ipv4Ecn Value of the Explicit Congestion Notification header field in the IPv4 packet
ipv4Identification Value of the Identification header field in the IPv4 packet
ipv4Options List of Options numbers included in the IPv4 packet header
ipv6Dscp Value of the Differentiated Services Code Point header field in the IPv6 packet
ipv6Ecn Value of the Explicit Congestion Notification header field in the IPv6 packet
ipv6ExtensionHeaders List of Extension Header numbers included in the IPv6 packet header
ipv6FlowLabel Value of the Flow Label header field in the IPv6 packet
ipv6Identification Value of the Identification extension header field in the IPv6 packet
leaseTag IP lease tag associated with the packet
mitigationSystem Which system dropped the packet (possible values: dosd, flowtrackd, magic-firewall)
outcome The action that was taken on the packet (possible values: pass, drop)
popName Cloudflare PoP that received the packet (unique site identifier)
prefixTag IP prefix tag associated with the packet
sampleInterval ABR sample interval
sourceAsn ASN associated with the source IP of the packet, or 0 if there was no mapping available
sourceAsnName Name of ASN associated with the source IP of the packet, if available
sourceCountry Country where the source IP of the packet is located (ISO 3166-1 alpha-2)
sourceDeviceTag Device tag associated with the source IP of the packet
sourceGeohash Latitude and longitude where the source IP of the packet is located (Geohash encoding)
sourcePort Value of the Source Port header field in the TCP or UDP packet
tcpAcknowledgementNumber Value of the Acknowledgement Number header field in the TCP packet
tcpChecksum Value of the Checkusm header field in the TCP packet
tcpDataOffset Value of the Data Offset header field in the TCP packet
tcpFlags Value of the Flags header field in the TCP packet
tcpFlagsString Human-readable string representation of the Flags header field in the TCP packet
tcpMss Value of the MSS option header field in the TCP packet
tcpOptions List of Options numbers included in the TCP packet header
tcpSackBlocks Value of the SACK Blocks option header field in the TCP packet
tcpSackPermitted Value of the SACK Permitted option header field in the TCP packet
tcpSequenceNumber Value of the Sequence Number header field in the TCP packet
tcpTimestampEcr Value of the Timestamp Echo Reply option header field in the TCP packet
tcpTimestampValue Value of the Timestamp option header field in the TCP packet
tcpUrgentPointer Value of the Urgent Pointer header field in the TCP packet
tcpWindowScale Value of the Window Scale option header field in the TCP packet
tcpWindowSize Value of the Window Size header field in the TCP packet
udpChecksum Value of the Checkusm header field in the UDP packet
udpPayloadLength Value of the Payload Length header field in the UDP packet

AccountCdnNetworkAnalyticsAdaptiveGroupsSum

FieldDescription
bits Sum of bits received
packets Sum of packets received

AccountCdnNetworkAnalyticsAdaptiveGroupsSumConfidence

FieldDescription
bits Confidence interval for the corresponding point estimate
packets Confidence interval for the corresponding point estimate

AccountCf1AccessLogins1dGroups

CF1 Access login analytics - 1 day rollup (up to 90d window, 365d back)

FieldDescription
dimensions List of dimensions to group by
sum
uniq

AccountCf1AccessLogins1dGroupsDimensions

FieldDescription
allowed Whether the login was allowed or denied
appName Application name
appType Application type
country Source country code
datetime Day start timestamp (daily granularity)
idp Identity provider
loginType Login event type (login, logout, sso)

AccountCf1AccessLogins1dGroupsSum

FieldDescription
logins Total login attempts

AccountCf1AccessLogins1dGroupsUniq

FieldDescription
users Unique users

AccountCf1AccessLogins1hGroups

CF1 Access login analytics - 1 hour rollup (up to 31d window, 62d back). Use cf1AccessLogins1dGroups for 10d+ ranges.

FieldDescription
dimensions List of dimensions to group by
sum
uniq

AccountCf1AccessLogins1hGroupsDimensions

FieldDescription
allowed Whether the login was allowed or denied
appName Application name
appType Application type
country Source country code
datetime Hour start timestamp (hourly granularity)
idp Identity provider
loginType Login event type (login, logout, sso)

AccountCf1AccessLogins1hGroupsSum

FieldDescription
logins Total login attempts

AccountCf1AccessLogins1hGroupsUniq

FieldDescription
users Unique users

AccountCf1AccessLoginsRawGroups

CF1 Access login analytics - raw data (max 3h window, up to 31d back). Supports unique user counts. Use cf1AccessLogins1hGroups for longer ranges.

FieldDescription
dimensions List of dimensions to group by
sum
uniq

AccountCf1AccessLoginsRawGroupsDimensions

FieldDescription
allowed Whether the login was allowed or denied
appName Application name
appType Application type
country Source country code
datetime Login timestamp
datetimeFiveMinutes Login timestamp truncated to five minutes
datetimeHour Login timestamp truncated to hour
idp Identity provider
loginType Login event type (login, logout, sso)

AccountCf1AccessLoginsRawGroupsSum

FieldDescription
logins Total login attempts

AccountCf1AccessLoginsRawGroupsUniq

FieldDescription
users Unique users

AccountCf1GatewayDns1dGroups

CF1 Gateway DNS analytics - 1 day rollup

FieldDescription
dimensions List of dimensions to group by
sum
uniq

AccountCf1GatewayDns1dGroupsDimensions

FieldDescription
coloName Cloudflare colo code
country Source country code
datetime Day start timestamp (daily granularity)
deviceId Device ID. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal \"REDACTED\"
edeErrors Union of EDE codes observed in the group (rollup of raw edeErrors via groupUniqArrayArray; sorted ascending for deterministic output)
email User email address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal \"REDACTED\"
location Gateway location ID
matchedCategoryIds Union of matched categories observed in the group (rollup of raw matchedCategoryIds via groupUniqArrayArray; sorted ascending for deterministic output)
policyId Policy ID
protocol DNS protocol
queryApplicationIds Union of application IDs observed in the group (rollup of raw queryApplicationIds via groupUniqArrayArray; sorted ascending for deterministic output)
queryCategoryIds Union of query categories observed in the group (rollup of raw queryCategoryIds via groupUniqArrayArray; sorted ascending for deterministic output)
queryType DNS query type
rcode DNS response code
resolverDecision Gateway resolver decision. To filter for all "block" outcomes, use resolverDecision_in with ["blockedRule", "blockedByQueryName", "blockedByCategory"]. Other values: allowedOnNoPolicyMatch, allowedOnPolicyMatch, allowedByQueryName, overrideRule, safesearchRule, ytRestrictedModeRule, allowedOnNoLocation, allowedOnNoRule, overrideOnlyRule.
sourceIP Source IP address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal \"REDACTED\"

AccountCf1GatewayDns1dGroupsSum

FieldDescription
edeErrorArray EDE codes observed in the group, for EDE Codes Over Time. Elements correspond to edeErrorCountArray by index.
edeErrorCountArray Query counts per EDE code. Elements correspond to edeErrorArray by index.
queries Total DNS queries
queryApplicationIdArray Application IDs observed in the group, for Top Apps by query count. Elements correspond to queryApplicationIdCountArray by index.
queryApplicationIdCountArray Query counts per application ID. Elements correspond to queryApplicationIdArray by index.
queryBytes Total query bytes
queryCategoryIdArray Query-category IDs observed in the group, for DNS Queries by Category. Elements correspond to queryCategoryIdCountArray by index.
queryCategoryIdCountArray Query counts per query-category ID. Elements correspond to queryCategoryIdArray by index.
responseBytes Total response bytes
topQueryNameCounts Query counts for topQueryNames, most frequent first. Elements correspond to topQueryNames by index.
topQueryNames Top query names (hostnames) by query count, most frequent first (up to 100; backed by a stored top-1000 approx_top_k for merge accuracy). Elements correspond to topQueryNameCounts by index.

AccountCf1GatewayDns1dGroupsUniq

FieldDescription
devices Unique devices
users Unique users

AccountCf1GatewayDns1hGroups

CF1 Gateway DNS analytics - 1 hour rollup

FieldDescription
dimensions List of dimensions to group by
sum
uniq

AccountCf1GatewayDns1hGroupsDimensions

FieldDescription
coloName Cloudflare colo code
country Source country code
datetime Hour start timestamp (hourly granularity)
deviceId Device ID. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
edeErrors Union of EDE codes observed in the group (rollup of raw edeErrors via groupUniqArrayArray; sorted ascending for deterministic output)
email User email address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
location Gateway location ID
matchedCategoryIds Union of matched categories observed in the group (rollup of raw matchedCategoryIds via groupUniqArrayArray; sorted ascending for deterministic output)
policyId Policy ID
protocol DNS protocol
queryApplicationIds Union of application IDs observed in the group (rollup of raw queryApplicationIds via groupUniqArrayArray; sorted ascending for deterministic output)
queryCategoryIds Union of query categories observed in the group (rollup of raw queryCategoryIds via groupUniqArrayArray; sorted ascending for deterministic output)
queryType DNS query type
rcode DNS response code
resolverDecision Gateway resolver decision. To filter for all "block" outcomes, use resolverDecision_in with ["blockedRule", "blockedByQueryName", "blockedByCategory"]. Other values: allowedOnNoPolicyMatch, allowedOnPolicyMatch, allowedByQueryName, overrideRule, safesearchRule, ytRestrictedModeRule, allowedOnNoLocation, allowedOnNoRule, overrideOnlyRule.
sourceIP Source IP address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"

AccountCf1GatewayDns1hGroupsSum

FieldDescription
edeErrorArray EDE codes observed in the group, for EDE Codes Over Time. Elements correspond to edeErrorCountArray by index.
edeErrorCountArray Query counts per EDE code. Elements correspond to edeErrorArray by index.
queries Total DNS queries
queryApplicationIdArray Application IDs observed in the group, for Top Apps by query count. Elements correspond to queryApplicationIdCountArray by index.
queryApplicationIdCountArray Query counts per application ID. Elements correspond to queryApplicationIdArray by index.
queryBytes Total query bytes
queryCategoryIdArray Query-category IDs observed in the group, for DNS Queries by Category. Elements correspond to queryCategoryIdCountArray by index.
queryCategoryIdCountArray Query counts per query-category ID. Elements correspond to queryCategoryIdArray by index.
responseBytes Total response bytes
topQueryNameCounts Query counts for topQueryNames, most frequent first. Elements correspond to topQueryNames by index.
topQueryNames Top query names (hostnames) by query count, most frequent first (up to 100; backed by a stored top-1000 approx_top_k for merge accuracy). Elements correspond to topQueryNameCounts by index.

AccountCf1GatewayDns1hGroupsUniq

FieldDescription
devices Unique devices
users Unique users

AccountCf1GatewayDnsLuga1dGroups

CF1 Gateway DNS LUGA analytics - 1 day rollup

FieldDescription
dimensions List of dimensions to group by
sum
uniq

AccountCf1GatewayDnsLuga1dGroupsDimensions

FieldDescription
coloName Cloudflare colo code
country Source country code
datetime Day start timestamp (daily granularity)
deviceId Device ID. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal \"REDACTED\"
email User email address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal \"REDACTED\"
location Gateway location ID
policyId Policy ID
protocol DNS protocol
queryType DNS query type
rcode DNS response code
resolverDecision Gateway resolver decision
sourceIP Source IP address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal \"REDACTED\"

AccountCf1GatewayDnsLuga1dGroupsSum

FieldDescription
queries Total DNS queries
queryBytes Total query bytes
responseBytes Total response bytes

AccountCf1GatewayDnsLuga1dGroupsUniq

FieldDescription
devices Unique devices
users Unique users

AccountCf1GatewayDnsLuga1hGroups

CF1 Gateway DNS LUGA analytics - 1 hour rollup

FieldDescription
dimensions List of dimensions to group by
sum
uniq

AccountCf1GatewayDnsLuga1hGroupsDimensions

FieldDescription
coloName Cloudflare colo code
country Source country code
datetime Hour start timestamp (hourly granularity)
deviceId Device ID. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal \"REDACTED\"
email User email address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal \"REDACTED\"
location Gateway location ID
policyId Policy ID
protocol DNS protocol
queryType DNS query type
rcode DNS response code
resolverDecision Gateway resolver decision
sourceIP Source IP address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal \"REDACTED\"

AccountCf1GatewayDnsLuga1hGroupsSum

FieldDescription
queries Total DNS queries
queryBytes Total query bytes
responseBytes Total response bytes

AccountCf1GatewayDnsLuga1hGroupsUniq

FieldDescription
devices Unique devices
users Unique users

AccountCf1GatewayDnsLugaRawGroups

CF1 Gateway DNS LUGA analytics - raw data (max 3h query window). Use cf1GatewayDnsLuga1hGroups for longer ranges, or cf1GatewayDnsLuga1dGroups for 10d+

FieldDescription
dimensions List of dimensions to group by
sum
uniq

AccountCf1GatewayDnsLugaRawGroupsDimensions

FieldDescription
coloName Cloudflare colo code
country Source country code
datetime Query timestamp
datetimeFiveMinutes Query timestamp truncated to five minutes
datetimeHour Query timestamp truncated to hour
destination Query name (destination domain)
deviceId Device ID. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal \"REDACTED\"
email User email address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal \"REDACTED\"
location Gateway location ID
policyId Policy ID
protocol DNS protocol
queryType DNS query type
rcode DNS response code
resolverDecision Gateway resolver decision
sourceIP Source IP address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal \"REDACTED\"

AccountCf1GatewayDnsLugaRawGroupsSum

FieldDescription
queries Total DNS queries
queryBytes Total query bytes
responseBytes Total response bytes

AccountCf1GatewayDnsLugaRawGroupsUniq

FieldDescription
devices Unique devices
users Unique users

AccountCf1GatewayDnsRawGroups

CF1 Gateway DNS analytics - raw data (max 3h query window). Use cf1GatewayDns1hGroups for longer ranges, or cf1GatewayDns1dGroups for 10d+

FieldDescription
dimensions List of dimensions to group by
sum
uniq

AccountCf1GatewayDnsRawGroupsDimensions

FieldDescription
coloName Cloudflare colo code
country Source country code
datetime Query timestamp
datetimeFiveMinutes Query timestamp truncated to five minutes
datetimeHour Query timestamp truncated to hour
destination Query name (destination domain)
deviceId Device ID. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
edeErrors Extended DNS Error (EDE) codes returned in the response
email User email address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
location Gateway location ID
matchedCategoryIds Categories that matched the applied policy (subset of queryCategoryIds)
policyId Policy ID
protocol DNS protocol
queryApplicationIds Application IDs associated with the query name
queryApplicationNames Application names associated with the query name (raw node only)
queryCategoryIds Categories that the query name belongs to, as Cloudflare category taxonomy IDs
queryType DNS query type
rcode DNS response code
resolverDecision Gateway resolver decision. To filter for all "block" outcomes, use resolverDecision_in with ["blockedRule", "blockedByQueryName", "blockedByCategory"]. Other values: allowedOnNoPolicyMatch, allowedOnPolicyMatch, allowedByQueryName, overrideRule, safesearchRule, ytRestrictedModeRule, allowedOnNoLocation, allowedOnNoRule, overrideOnlyRule.
sourceIP Source IP address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"

AccountCf1GatewayDnsRawGroupsSum

FieldDescription
queries Total DNS queries
queryBytes Total query bytes
responseBytes Total response bytes

AccountCf1GatewayDnsRawGroupsUniq

FieldDescription
devices Unique devices
users Unique users

AccountCf1GatewayHttp1dGroups

CF1 Gateway HTTP analytics - 1 day rollup (up to 90d window, 365d back)

FieldDescription
dimensions List of dimensions to group by
sum
uniq

AccountCf1GatewayHttp1dGroupsDimensions

FieldDescription
action Gateway action taken
avBlockedFileHashes SHA-256 (hex) set of files blocked by Gateway AV in the window
avResult AV outcome: blocked, scannedClean, or notScanned
blockedFileReason Reason a file was blocked: avscan, sandboxScan, or none (no file blocked)
country Source country code
datetime Day start timestamp (daily granularity)
deviceId Device ID. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
directApplicationIds Application IDs seen in the window
directApplicationStatuses Application approval statuses seen in the window
directApplicationTypeIds Application type IDs seen in the window
email User email address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
httpHost HTTP hostname
isIsolated Whether the request was served through Browser Isolation (1 = yes)
isolatedApplicationCounts Isolated request counts per application (index-aligned with isolatedApplicationIds)
isolatedApplicationIds Application IDs for isolated requests (index-aligned with isolatedApplicationNames and isolatedApplicationCounts)
isolatedApplicationNames Application names for isolated requests (index-aligned with isolatedApplicationIds and isolatedApplicationCounts)
isolatedCategoryCounts Isolated request counts per category (index-aligned with isolatedCategoryIds)
isolatedCategoryIds URL category IDs for isolated requests, sorted ascending (index-aligned with isolatedCategoryCounts)
requestAntivirusScanned Whether the request body was scanned by Gateway AV (1 = scanned)
responseAntivirusScanned Whether the response body was scanned by Gateway AV (1 = scanned)
sandboxResult Sandbox outcome: blocked, scanned, or notScanned
sandboxScanned Whether the request was submitted to Gateway sandbox detonation (1 = yes)
sourceIP Source IP address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"

AccountCf1GatewayHttp1dGroupsSum

FieldDescription
antivirusRequestScans Requests with request-body AV scanning
antivirusResponseScans Requests with response-body AV scanning
avBlockedFiles Files blocked by Gateway AV
bodyBytesRcvd Total body bytes received
bodyBytesSent Total body bytes sent
dlpProfileMatchesTotal Total DLP profile matches
filesScanned Total files scanned by Gateway AV
httpHostBytesRcvd Total bytes received per host
httpHostBytesSent Total bytes sent per host
isolatedRequests Total requests served through Browser Isolation
mcpUrlCountTotal Total MCP-path URL accesses across requests
requests Total HTTP requests
sandboxBlocks Files blocked by Gateway sandbox
sandboxScans Requests submitted to Gateway sandbox detonation

AccountCf1GatewayHttp1dGroupsUniq

FieldDescription
applications Unique applications
mcpDistinctUsers Unique users with MCP activity
users Unique users

AccountCf1GatewayHttp1hGroups

CF1 Gateway HTTP analytics - 1 hour rollup (up to 31d window, 62d back)

FieldDescription
dimensions List of dimensions to group by
sum
uniq

AccountCf1GatewayHttp1hGroupsDimensions

FieldDescription
action Gateway action taken
avBlockedFileHashes SHA-256 (hex) set of files blocked by Gateway AV in the window
avResult AV outcome: blocked, scannedClean, or notScanned
blockedFileReason Reason a file was blocked: avscan, sandboxScan, or none (no file blocked)
country Source country code
datetime Hour start timestamp (hourly granularity)
deviceId Device ID. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
directApplicationIds Application IDs seen in the window
directApplicationStatuses Application approval statuses seen in the window
directApplicationTypeIds Application type IDs seen in the window
email User email address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
httpHost HTTP hostname
isIsolated Whether the request was served through Browser Isolation (1 = yes)
isolatedApplicationCounts Isolated request counts per application (index-aligned with isolatedApplicationIds)
isolatedApplicationIds Application IDs for isolated requests (index-aligned with isolatedApplicationNames and isolatedApplicationCounts)
isolatedApplicationNames Application names for isolated requests (index-aligned with isolatedApplicationIds and isolatedApplicationCounts)
isolatedCategoryCounts Isolated request counts per category (index-aligned with isolatedCategoryIds)
isolatedCategoryIds URL category IDs for isolated requests, sorted ascending (index-aligned with isolatedCategoryCounts)
requestAntivirusScanned Whether the request body was scanned by Gateway AV (1 = scanned)
responseAntivirusScanned Whether the response body was scanned by Gateway AV (1 = scanned)
sandboxResult Sandbox outcome: blocked, scanned, or notScanned
sandboxScanned Whether the request was submitted to Gateway sandbox detonation (1 = yes)
sourceIP Source IP address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"

AccountCf1GatewayHttp1hGroupsSum

FieldDescription
antivirusRequestScans Requests with request-body AV scanning
antivirusResponseScans Requests with response-body AV scanning
avBlockedFiles Files blocked by Gateway AV
bodyBytesRcvd Total body bytes received
bodyBytesSent Total body bytes sent
dlpProfileMatchesTotal Total DLP profile matches
filesScanned Total files scanned by Gateway AV
httpHostBytesRcvd Total bytes received per host
httpHostBytesSent Total bytes sent per host
isolatedRequests Total requests served through Browser Isolation
mcpUrlCountTotal Total MCP-path URL accesses across requests
requests Total HTTP requests
sandboxBlocks Files blocked by Gateway sandbox
sandboxScans Requests submitted to Gateway sandbox detonation

AccountCf1GatewayHttp1hGroupsUniq

FieldDescription
applications Unique applications
mcpDistinctUsers Unique users with MCP activity
users Unique users

AccountCf1GatewayHttpRawGroups

CF1 Gateway HTTP analytics - raw data (max 3h query window, 4d lookback). Use cf1GatewayHttp1hGroups for longer ranges, or cf1GatewayHttp1dGroups for 10d+

FieldDescription
dimensions List of dimensions to group by
sum
uniq

AccountCf1GatewayHttpRawGroupsDimensions

FieldDescription
action Gateway action taken
avBlockedFileHash SHA-256 (hex) of the file blocked by Gateway AV; empty when no AV-blocked file hash is available
avResult AV outcome: blocked, scannedClean, or notScanned
blockedFileReason Reason a file was blocked: avscan, sandboxScan, or none (no file blocked)
categoryIds URL category IDs matched by the request
categoryNames URL category names
country Source country code
datetime Request timestamp
datetimeFiveMinutes Request timestamp truncated to five minutes
datetimeHour Request timestamp truncated to hour
deviceId Device ID. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
directApplicationIds Application IDs matched on the request hostname
directApplicationNames Application names for the matched applications
directApplicationStatuses Approval statuses for the matched applications
directApplicationTypeIds Application type IDs for the matched applications
email User email address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
hasDlpScans Whether the request had any DLP scans (1 = yes)
httpHost HTTP hostname
isIsolated Whether the request was served through Browser Isolation (1 = yes)
mcpUrlCount Number of MCP URLs in the request
proxyEndpoint Proxy endpoint through which the request was forwarded
requestAntivirusScanned Whether the request body was scanned by Gateway AV (1 = scanned)
responseAntivirusScanned Whether the response body was scanned by Gateway AV (1 = scanned)
sandboxResult Sandbox outcome: blocked, scanned, or notScanned
sandboxScanned Whether the request was submitted to Gateway sandbox detonation (1 = yes)
sourceIP Source IP address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"

AccountCf1GatewayHttpRawGroupsSum

FieldDescription
antivirusRequestScans Requests with request-body AV scanning
antivirusResponseScans Requests with response-body AV scanning
avBlockedFiles Files blocked by Gateway AV
bodyBytesRcvd Total body bytes received
bodyBytesSent Total body bytes sent
dlpProfileMatchesTotal Total DLP profile matches across uploaded and downloaded content
filesScanned Total files scanned by Gateway AV
httpHostBytesRcvd Total bytes received per host
httpHostBytesSent Total bytes sent per host
isolatedRequests Total requests served through Browser Isolation
mcpUrlCountTotal Total MCP-path URL accesses across requests
requests Total HTTP requests
sandboxBlocks Files blocked by Gateway sandbox
sandboxScans Requests submitted to Gateway sandbox detonation

AccountCf1GatewayHttpRawGroupsUniq

FieldDescription
mcpDistinctUsers Unique users with MCP activity
users Unique users

AccountCf1GatewayNetwork1dGroups

CF1 Gateway Network analytics (L4 firewall events) - 1 day rollup (up to 90d window, 365d back)

FieldDescription
dimensions List of dimensions to group by
sum
uniq

AccountCf1GatewayNetwork1dGroupsDimensions

FieldDescription
action Gateway firewall decision
applicationIds Union of application IDs observed in the group (rollup of raw applicationIds via groupUniqArrayArray; sorted ascending for deterministic output)
applicationTypeIds Union of application type IDs observed in the group (rollup of raw applicationTypeIds via groupUniqArrayArray; sorted ascending for deterministic output)
categoryIds Union of category IDs observed in the group (rollup of raw categoryIds via groupUniqArrayArray; sorted ascending for deterministic output)
coloName Cloudflare colo code
datetime Day start timestamp (daily granularity)
destinationCountry Destination country code (ISO 3166-1 alpha-2)
deviceId Device ID. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
email User email address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
ruleId Policy rule ID
sni Server Name Indication from TLS handshake
sourceCountry Source country code (ISO 3166-1 alpha-2)
sourceIP Source IP address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
transport Transport protocol

AccountCf1GatewayNetwork1dGroupsSum

FieldDescription
requests Total network firewall events

AccountCf1GatewayNetwork1dGroupsUniq

FieldDescription
devices Unique devices
sessions Unique Gateway sessions (deduplicated across firewall-decision re-evaluations and across rollup buckets when not grouped by datetime)
users Unique users

AccountCf1GatewayNetwork1hGroups

CF1 Gateway Network analytics (L4 firewall events) - 1 hour rollup (up to 31d window, 62d back)

FieldDescription
dimensions List of dimensions to group by
sum
uniq

AccountCf1GatewayNetwork1hGroupsDimensions

FieldDescription
action Gateway firewall decision
applicationIds Union of application IDs observed in the group (rollup of raw applicationIds via groupUniqArrayArray; sorted ascending for deterministic output)
applicationTypeIds Union of application type IDs observed in the group (rollup of raw applicationTypeIds via groupUniqArrayArray; sorted ascending for deterministic output)
categoryIds Union of category IDs observed in the group (rollup of raw categoryIds via groupUniqArrayArray; sorted ascending for deterministic output)
coloName Cloudflare colo code
datetime Hour start timestamp (hourly granularity)
destinationCountry Destination country code (ISO 3166-1 alpha-2)
deviceId Device ID. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
email User email address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
ruleId Policy rule ID
sni Server Name Indication from TLS handshake
sourceCountry Source country code (ISO 3166-1 alpha-2)
sourceIP Source IP address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
transport Transport protocol

AccountCf1GatewayNetwork1hGroupsSum

FieldDescription
requests Total network firewall events

AccountCf1GatewayNetwork1hGroupsUniq

FieldDescription
devices Unique devices
sessions Unique Gateway sessions (deduplicated across firewall-decision re-evaluations and across rollup buckets when not grouped by datetime)
users Unique users

AccountCf1GatewayNetworkRawGroups

CF1 Gateway Network analytics (L4 firewall events) - raw data (max 3h query window, 4d lookback). Use cf1GatewayNetwork1hGroups for longer ranges, or cf1GatewayNetwork1dGroups for 10d+

FieldDescription
dimensions List of dimensions to group by
sum
uniq

AccountCf1GatewayNetworkRawGroupsDimensions

FieldDescription
action Gateway firewall decision
applicationIds Application IDs detected on the session (Cloudflare application taxonomy)
applicationTypeIds Application Type IDs detected on the session (Cloudflare application-type taxonomy)
categoryIds Category IDs detected on the session (Cloudflare category taxonomy)
coloName Cloudflare colo code
datetime Event timestamp
datetimeFiveMinutes Event timestamp truncated to five minutes
datetimeHour Event timestamp truncated to hour
destinationCountry Destination country code (ISO 3166-1 alpha-2)
destinationIP Destination IP address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
destinationPort Destination TCP/UDP port
detectedProtocol Detected L7 protocol (Citadel). Note: column is sparse — empty when detection inconclusive.
deviceId Device ID. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
email User email address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
hostApplicationId Host application ID associated with the session (empty when unknown). Complements applicationIds.
proxyEndpoint Gateway proxy endpoint that received the session
ruleId Policy rule ID
sni Server Name Indication from TLS handshake
sourceCountry Source country code (ISO 3166-1 alpha-2)
sourceIP Source IP address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
transport Transport protocol

AccountCf1GatewayNetworkRawGroupsSum

FieldDescription
requests Total network firewall events

AccountCf1GatewayNetworkRawGroupsUniq

FieldDescription
devices Unique devices
sessions Unique Gateway sessions (deduplicated across firewall-decision re-evaluations within a session)
users Unique users

AccountCf1GatewayNetworkSession1dGroups

CF1 Gateway Network Session Log analytics - 1 day rollup (up to 90d window, 365d back)

FieldDescription
avg
dimensions List of dimensions to group by
sum
uniq

AccountCf1GatewayNetworkSession1dGroupsAvg

FieldDescription
tcpHandshakeMs Average client TCP handshake duration in milliseconds

AccountCf1GatewayNetworkSession1dGroupsDimensions

FieldDescription
clientTlsVersion TLS version negotiated with client
connectionCloseReason Reason the connection was closed
datetime Day start timestamp (daily granularity)
destinationPort Destination port number
destinationTunnelId Destination tunnel ID
egressColoName Egress Cloudflare colo code
egressIPv4 Egress IPv4 address
egressIPv6 Egress IPv6 address
egressRuleId Egress policy rule ID
ingressColoName Ingress Cloudflare colo code
offramp Egress offramp type
onRamp Ingress onramp type (derived from flowPath)
originTlsCertificateValidationResult Result of origin TLS certificate validation
originTlsCipher TLS cipher used to connect to origin
protocol L4 protocol
sni Server Name Indication from TLS handshake
sourceCountry Source country code (ISO 3166-1 alpha-2)

AccountCf1GatewayNetworkSession1dGroupsSum

FieldDescription
bytesDownload Total bytes downloaded (origin to client)
bytesTotal Total bytes transferred (upload + download)
bytesUpload Total bytes uploaded (client to origin)
sessions Total network sessions

AccountCf1GatewayNetworkSession1dGroupsUniq

FieldDescription
devices Unique devices
users Unique users

AccountCf1GatewayNetworkSession1hGroups

CF1 Gateway Network Session Log analytics - 1 hour rollup (up to 31d window, 62d back)

FieldDescription
avg
dimensions List of dimensions to group by
sum
uniq

AccountCf1GatewayNetworkSession1hGroupsAvg

FieldDescription
tcpHandshakeMs Average client TCP handshake duration in milliseconds

AccountCf1GatewayNetworkSession1hGroupsDimensions

FieldDescription
clientTlsVersion TLS version negotiated with client
connectionCloseReason Reason the connection was closed
datetime Hour start timestamp (hourly granularity)
destinationPort Destination port number
destinationTunnelId Destination tunnel ID
egressColoName Egress Cloudflare colo code
egressIPv4 Egress IPv4 address
egressIPv6 Egress IPv6 address
egressRuleId Egress policy rule ID
ingressColoName Ingress Cloudflare colo code
offramp Egress offramp type
onRamp Ingress onramp type (derived from flowPath)
originTlsCertificateValidationResult Result of origin TLS certificate validation
originTlsCipher TLS cipher used to connect to origin
protocol L4 protocol
sni Server Name Indication from TLS handshake
sourceCountry Source country code (ISO 3166-1 alpha-2)

AccountCf1GatewayNetworkSession1hGroupsSum

FieldDescription
bytesDownload Total bytes downloaded (origin to client)
bytesTotal Total bytes transferred (upload + download)
bytesUpload Total bytes uploaded (client to origin)
sessions Total network sessions

AccountCf1GatewayNetworkSession1hGroupsUniq

FieldDescription
devices Unique devices
users Unique users

AccountCf1GatewayNetworkSessionRawGroups

CF1 Gateway Network Session Log (L4 sessions with bandwidth) - raw data (max 3h query window, 4d lookback). Use cf1GatewayNetworkSession1hGroups for longer ranges, or cf1GatewayNetworkSession1dGroups for 10d+

FieldDescription
avg
dimensions List of dimensions to group by
sum
uniq

AccountCf1GatewayNetworkSessionRawGroupsAvg

FieldDescription
tcpHandshakeMs Average client TCP handshake duration in milliseconds

AccountCf1GatewayNetworkSessionRawGroupsDimensions

FieldDescription
clientTlsVersion TLS version negotiated with client
connectionCloseReason Reason the connection was closed
datetime Session close timestamp
datetimeFiveMinutes Session close timestamp truncated to five minutes
datetimeHour Session close timestamp truncated to hour
destinationPort Destination port number
destinationTunnelId Destination tunnel ID
egressColoName Egress Cloudflare colo code
egressIPv4 Egress IPv4 address
egressIPv6 Egress IPv6 address
egressRuleId Egress policy rule ID
ingressColoName Ingress Cloudflare colo code
offramp Egress offramp type
onRamp Ingress onramp type (derived from flowPath)
originTlsCertificateValidationResult Result of origin TLS certificate validation
originTlsCipher TLS cipher used to connect to origin
protocol L4 protocol
sni Server Name Indication from TLS handshake
sourceCountry Source country code (ISO 3166-1 alpha-2)

AccountCf1GatewayNetworkSessionRawGroupsSum

FieldDescription
bytesDownload Total bytes downloaded (origin to client)
bytesTotal Total bytes transferred (upload + download)
bytesUpload Total bytes uploaded (client to origin)
sessions Total network sessions

AccountCf1GatewayNetworkSessionRawGroupsUniq

FieldDescription
devices Unique devices
users Unique users

AccountCf1McpHost1dGroups

CF1 MCP host analytics - 1 day rollup (up to 90d window, 365d back). Groups MCP URL activity by host and source country per day.

FieldDescription
dimensions List of dimensions to group by
sum
uniq

AccountCf1McpHost1dGroupsDimensions

FieldDescription
country Source country code
datetime Day start timestamp (daily granularity)
httpHost HTTP hostname

AccountCf1McpHost1dGroupsSum

FieldDescription
mcpUrlCount Total MCP-path URL accesses across requests

AccountCf1McpHost1dGroupsUniq

FieldDescription
mcpDistinctUsers Unique users with MCP activity

AccountCloudchamberMetricsAdaptiveGroups

Metrics for Cloudchamber applications and deployments

FieldDescription
avg The average value of a metric per dimension
confidence ALPHA - DO NOT USE
count Number of metrics received
dimensions List of dimensions to group by
max Maximum value of a metric per dimension
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension

AccountCloudchamberMetricsAdaptiveGroupsAvg

FieldDescription
containerUptime Average container uptime, in milliseconds
cpuLoad DEPRECATED (Replaced by cpuUtilization or sum { cpuTimeSec }): Average CPU load
cpuUtilization Average CPU utilization
gpuMemory Average GPU memory usage
memory Average memory usage
rxBandwidth DEPRECATED (Replaced by rxBandwidthBps): Average RX bandwidth
rxBandwidthBps Average RX bandwidth in bps
txBandwidth DEPRECATED (Replaced by txBandwidthBps): Average TX bandwidth
txBandwidthBps Average TX bandwidth in bps

AccountCloudchamberMetricsAdaptiveGroupsConfidence

FieldDescription
count Number of metrics received, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountCloudchamberMetricsAdaptiveGroupsDimensions

FieldDescription
active DEPRECATED (Filtered implicitly to 1): Whether the container is active or not
applicationId The application ID
date The date the metric was received
datetime The date and time the metric was received
datetimeFifteenMinutes The date and time the metric was received, truncated to fifteen minutes
datetimeFiveMinutes The date and time the metric was received, truncated to five minutes
datetimeHour The date and time the metric was received, truncated to one hour
datetimeMinute The date and time the metric was received, truncated to one minute
datetimeSixHours The date and time the metric was received, truncated to six hours
deploymentId DEPRECATED (Replaced by instanceId): The deployment ID
durableObjectId DEPRECATED (Replaced by instanceId): If set, this metric was emitted while assigned to a durable object
instanceId The ID of the container
label Value of a specific container label. Requires the name argument.
location Location
placementId The placement ID
procType DEPRECATED (Filtered implicitly to user): Process type
region Region

AccountCloudchamberMetricsAdaptiveGroupsMax

FieldDescription
containerUptime Maximum container uptime, in milliseconds
cpuLoad DEPRECATED (Replaced by max { cpuUtilization } or sum { cpuTimeSec }): Maximum CPU load
cpuUtilization Maximum CPU utilization
diskAvailable Total disk space available, in bytes
diskUsage Disk usage, in bytes
diskUsagePercentage Disk usage as a percentage of total disk space
gpuMemory Maximum GPU memory usage
memory Maximum memory usage
rxBandwidth DEPRECATED (Replaced by rxBandwidthBps): Maximum RX bandwidth
rxBandwidthBps Maximum RX bandwidth
rxBytes DEPRECATED (Replaced by sum { rxBytes }): Total bytes received
txBandwidth DEPRECATED (Replaced by txBandwidthBps): Maximum TX bandwidth
txBandwidthBps Maximum TX bandwidth
txBytes DEPRECATED (Replaced by sum { txBytes }): Total bytes transmitted

AccountCloudchamberMetricsAdaptiveGroupsQuantiles

FieldDescription
containerUptimeP25 Container uptime (25th percentile), in milliseconds
containerUptimeP50 Container uptime (50th percentile), in milliseconds
containerUptimeP75 Container uptime (75th percentile), in milliseconds
containerUptimeP90 Container uptime (90th percentile), in milliseconds
containerUptimeP95 Container uptime (95th percentile), in milliseconds
containerUptimeP99 Container uptime (99th percentile), in milliseconds
containerUptimeP999 Container uptime (99.9th percentile), in milliseconds
cpuLoadP25 DEPRECATED (Replaced by cpuUtilizationP25): CPU load (25th percentile)
cpuLoadP50 DEPRECATED (Replaced by cpuUtilizationP50): CPU load (50th percentile)
cpuLoadP75 DEPRECATED (Replaced by cpuUtilizationP75): CPU load (75th percentile)
cpuLoadP90 DEPRECATED (Replaced by cpuUtilizationP90): CPU load (90th percentile)
cpuLoadP95 DEPRECATED (Replaced by cpuUtilizationP95): CPU load (95th percentile)
cpuLoadP99 DEPRECATED (Replaced by cpuUtilizationP99): CPU load (99th percentile)
cpuLoadP999 DEPRECATED (Replaced by cpuUtilizationP999): CPU load (99.9th percentile)
cpuUtilizationP25 CPU utilization (25th percentile)
cpuUtilizationP50 CPU utilization (50th percentile)
cpuUtilizationP75 CPU utilization (75th percentile)
cpuUtilizationP90 CPU utilization (90th percentile)
cpuUtilizationP95 CPU utilization (95th percentile)
cpuUtilizationP99 CPU utilization (99th percentile)
cpuUtilizationP999 CPU utilization (99.9th percentile)
diskUsageP25 Disk usage in bytes (25th percentile)
diskUsageP50 Disk usage in bytes (50th percentile)
diskUsageP75 Disk usage in bytes (75th percentile)
diskUsageP90 Disk usage in bytes (90th percentile)
diskUsageP95 Disk usage in bytes (95th percentile)
diskUsageP99 Disk usage in bytes (99th percentile)
diskUsageP999 Disk usage in bytes (99.9th percentile)
diskUsagePercentageP25 Disk usage as a percentage of total disk space (25th percentile)
diskUsagePercentageP50 Disk usage as a percentage of total disk space (50th percentile)
diskUsagePercentageP75 Disk usage as a percentage of total disk space (75th percentile)
diskUsagePercentageP90 Disk usage as a percentage of total disk space (90th percentile)
diskUsagePercentageP95 Disk usage as a percentage of total disk space (95th percentile)
diskUsagePercentageP99 Disk usage as a percentage of total disk space (99th percentile)
diskUsagePercentageP999 Disk usage as a percentage of total disk space (99.9th percentile)
gpuMemoryP25 GPU memory usage (25th percentile)
gpuMemoryP50 GPU memory usage (50th percentile)
gpuMemoryP75 GPU memory usage (75th percentile)
gpuMemoryP90 GPU memory usage (90th percentile)
gpuMemoryP95 GPU memory usage (95th percentile)
gpuMemoryP99 GPU memory usage (99th percentile)
gpuMemoryP999 GPU memory usage (99.9th percentile)
memoryP25 Memory usage (25th percentile)
memoryP50 Memory usage (50th percentile)
memoryP75 Memory usage (75th percentile)
memoryP90 Memory usage (90th percentile)
memoryP95 Memory usage (95th percentile)
memoryP99 Memory usage (99th percentile)
memoryP999 Memory usage (99.9th percentile)
rxBandwidthBpsP25 RX bandwidth (25th percentile)
rxBandwidthBpsP50 RX bandwidth (50th percentile)
rxBandwidthBpsP75 RX bandwidth (75th percentile)
rxBandwidthBpsP90 RX bandwidth (90th percentile)
rxBandwidthBpsP95 RX bandwidth (95th percentile)
rxBandwidthBpsP99 RX bandwidth (99th percentile)
rxBandwidthBpsP999 RX bandwidth (99.9th percentile)
rxBandwidthP25 DEPRECATED (Replaced by rxBandwidthBpsP25): RX bandwidth (25th percentile)
rxBandwidthP50 DEPRECATED (Replaced by rxBandwidthBpsP50): RX bandwidth (50th percentile)
rxBandwidthP75 DEPRECATED (Replaced by rxBandwidthBpsP75): RX bandwidth (75th percentile)
rxBandwidthP90 DEPRECATED (Replaced by rxBandwidthBpsP90): RX bandwidth (90th percentile)
rxBandwidthP95 DEPRECATED (Replaced by rxBandwidthBpsP95): RX bandwidth (95th percentile)
rxBandwidthP99 DEPRECATED (Replaced by rxBandwidthBpsP99): RX bandwidth (99th percentile)
rxBandwidthP999 DEPRECATED (Replaced by rxBandwidthBpsP999): RX bandwidth (99.9th percentile)
txBandwidthBpsP25 TX bandwidth (25th percentile)
txBandwidthBpsP50 TX bandwidth (50th percentile)
txBandwidthBpsP75 TX bandwidth (75th percentile)
txBandwidthBpsP90 TX bandwidth (90th percentile)
txBandwidthBpsP95 TX bandwidth (95th percentile)
txBandwidthBpsP99 TX bandwidth (99th percentile)
txBandwidthBpsP999 TX bandwidth (99.9th percentile)
txBandwidthP25 DEPRECATED (Replaced by txBandwidthBpsP25): TX bandwidth (25th percentile)
txBandwidthP50 DEPRECATED (Replaced by txBandwidthBpsP50): TX bandwidth (50th percentile)
txBandwidthP75 DEPRECATED (Replaced by txBandwidthBpsP75): TX bandwidth (75th percentile)
txBandwidthP90 DEPRECATED (Replaced by txBandwidthBpsP90): TX bandwidth (90th percentile)
txBandwidthP95 DEPRECATED (Replaced by txBandwidthBpsP95): TX bandwidth (95th percentile)
txBandwidthP99 DEPRECATED (Replaced by txBandwidthBpsP99): TX bandwidth (99th percentile)
txBandwidthP999 DEPRECATED (Replaced by txBandwidthBpsP999): TX bandwidth (99.9th percentile)

AccountCloudchamberMetricsAdaptiveGroupsSum

FieldDescription
allocatedCpu Sum of allocated vCPU in vCPU-seconds
allocatedDisk Sum of allocated disk in byte-seconds
allocatedMemory Sum of allocated memory in byte-seconds
containerUptime Total container uptime, in milliseconds
cpuTimeSec Sum of CPU time in seconds
rxBytes Sum of bytes received
txBytes Sum of bytes transmitted

AccountCloudchamberMetricsAdaptiveGroupsSumConfidence

FieldDescription
allocatedCpu Confidence interval for the corresponding point estimate
allocatedDisk Confidence interval for the corresponding point estimate
allocatedMemory Confidence interval for the corresponding point estimate
containerUptime Confidence interval for the corresponding point estimate
cpuTimeSec Confidence interval for the corresponding point estimate
rxBytes Confidence interval for the corresponding point estimate
txBytes Confidence interval for the corresponding point estimate

AccountCloudflareTunnelsAnalyticsAdaptiveGroups

Cloudflare tunnel Device Analytics

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountCloudflareTunnelsAnalyticsAdaptiveGroupsAvg

FieldDescription
bitRate Sum of bits received, divided by 1 second, providing a per-second bit rate when grouped by datetime
bitRateDay Sum of bits received, divided by 86400 seconds, providing a per-second bit rate when grouped by date
bitRateFifteenMinutes Sum of bits received, divided by 900 seconds, providing a per-second bit rate when grouped by datetimeFifteenMinutes
bitRateFiveMinutes Sum of bits received, divided by 300 seconds, providing a per-second bit rate when grouped by datetimeFiveMinutes
bitRateHour Sum of bits received, divided by 3600 seconds, providing a per-second bit rate when grouped by datetimeHour
bitRateMinute Sum of bits received, divided by 60 seconds, providing a per-second bit rate when grouped by datetimeMinute
bitRateTenSeconds Sum of bits received, divided by 10 seconds, providing a per-second bit rate when grouped by datetimeTenSeconds
egressBitRate Sum of egress bits received, divided by 1 second, providing a per-second egress bit rate when grouped by datetime
egressBitRateDay Sum of egress bits received, divided by 86400 seconds, providing a per-second egress bit rate when grouped by date
egressBitRateFifteenMinutes Sum of egress bits received, divided by 900 seconds, providing a per-second egress bit rate when grouped by datetimeFifteenMinutes
egressBitRateFiveMinutes Sum of egress bits received, divided by 300 seconds, providing a per-second egress bit rate when grouped by datetimeFiveMinutes
egressBitRateHour Sum of egress bits received, divided by 3600 seconds, providing a per-second egress bit rate when grouped by datetimeHour
egressBitRateMinute Sum of egress bits received, divided by 60 seconds, providing a per-second egress bit rate when grouped by datetimeMinute
egressBitRateTenSeconds Sum of egress bits received, divided by 10 seconds, providing a per-second egress bit rate when grouped by datetimeTenSeconds
sampleInterval Average sample interval applied to the data

AccountCloudflareTunnelsAnalyticsAdaptiveGroupsAvgConfidence

FieldDescription
bitRate Confidence interval for the corresponding point estimate
bitRateDay Confidence interval for the corresponding point estimate
bitRateFifteenMinutes Confidence interval for the corresponding point estimate
bitRateFiveMinutes Confidence interval for the corresponding point estimate
bitRateHour Confidence interval for the corresponding point estimate
bitRateMinute Confidence interval for the corresponding point estimate
bitRateTenSeconds Confidence interval for the corresponding point estimate
egressBitRate Confidence interval for the corresponding point estimate
egressBitRateDay Confidence interval for the corresponding point estimate
egressBitRateFifteenMinutes Confidence interval for the corresponding point estimate
egressBitRateFiveMinutes Confidence interval for the corresponding point estimate
egressBitRateHour Confidence interval for the corresponding point estimate
egressBitRateMinute Confidence interval for the corresponding point estimate
egressBitRateTenSeconds Confidence interval for the corresponding point estimate

AccountCloudflareTunnelsAnalyticsAdaptiveGroupsConfidence

FieldDescription
avg The average of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountCloudflareTunnelsAnalyticsAdaptiveGroupsDimensions

FieldDescription
connectionDuration Duration of the network connection in milliseconds.
date Date that the connection was started
datetime Date and time the connection was started
datetimeFifteenMinutes Date and time that the connection was started, rounded to the start of the nearest fifteen minutes
datetimeFiveMinutes Date and time that the connection was started, rounded to the start of the nearest five minutes
datetimeHour Date and time that the connection was started, rounded to the start of the nearest hour
datetimeMinute Date and time that the connection was started, rounded to the start of the nearest minute
datetimeTenSeconds Date and time that the connection was started rounded to the start of the nearest ten seconds
destinationCountry Destination country for the network connection. Only available for public addresses.
destinationIP Destination IP of the network connection.
destinationPort Destination port of the network connection.
deviceID Identifier of the Cloudflare tunnel connector to which the network session was routed to.
deviceName Name of the Cloudflare tunnel connector to which the network session was routed to.
onRamp On ramp path to the Cloudflare tunnel: Warp, Magic Tunnel
protocol Network Protocol of the network connection. Available values: [UDP,TCP,ICMP,ICMPv6]
sourceCountry Source country for the network connection. Only available for public addresses.
sourceIP Source IP of the network connection.
sourcePort Source port of the network connection.
tcpHandshakeDuration Duration of the TCP Handshake for TCP connections in milliseconds.

AccountCloudflareTunnelsAnalyticsAdaptiveGroupsSum

FieldDescription
bits Sum of bits
egressBits Sum of egress bits

AccountCloudflareTunnelsAnalyticsAdaptiveGroupsSumConfidence

FieldDescription
bits Confidence interval for the corresponding point estimate
egressBits Confidence interval for the corresponding point estimate

AccountCloudforceOneDetectionsAdaptiveGroups

Cloudforce One detection events for Workers for Platforms scripts with adaptive sampling. Each row represents a single detection rule hit.

FieldDescription
avg
confidence ALPHA - DO NOT USE
count Total number of detection rule hits
dimensions List of dimensions to group by

AccountCloudforceOneDetectionsAdaptiveGroupsAvg

FieldDescription
sampleInterval Average sample interval

AccountCloudforceOneDetectionsAdaptiveGroupsConfidence

FieldDescription
count Total number of detection rule hits, with confidence intervals
level Confidence level that was requested

AccountCloudforceOneDetectionsAdaptiveGroupsDimensions

FieldDescription
date Detection event date
datetime Detection event timestamp
datetimeFiveMinutes Detection event timestamp, truncated to five minutes
datetimeHour Detection event timestamp, truncated to hour
datetimeMinute Detection event timestamp, truncated to minute
detection Name of the detection rule that was triggered
detectionType Detection type: 'static' for workers/customer_workers_scans and 'dynamic' for worker_invocations
dispatchNamespace Workers for Platforms dispatch namespace name
resource The name of the Workers script
source Detection rule source: 'managed' for Cloudflare-authored rules, 'custom' for customer-created rules

AccountCloudforceOneDetectionsStagingAdaptiveGroups

Cloudforce One detection events for Workers for Platforms scripts with adaptive sampling (staging). Each row represents a single detection rule hit.

FieldDescription
avg
confidence ALPHA - DO NOT USE
count Total number of detection rule hits
dimensions List of dimensions to group by

AccountCloudforceOneDetectionsStagingAdaptiveGroupsAvg

FieldDescription
sampleInterval Average sample interval

AccountCloudforceOneDetectionsStagingAdaptiveGroupsConfidence

FieldDescription
count Total number of detection rule hits, with confidence intervals
level Confidence level that was requested

AccountCloudforceOneDetectionsStagingAdaptiveGroupsDimensions

FieldDescription
date Detection event date
datetime Detection event timestamp
datetimeFiveMinutes Detection event timestamp, truncated to five minutes
datetimeHour Detection event timestamp, truncated to hour
datetimeMinute Detection event timestamp, truncated to minute
detection Name of the detection rule that was triggered
detectionType Detection type: 'static' for workers/customer_workers_scans and 'dynamic' for worker_invocations
dispatchNamespace Workers for Platforms dispatch namespace name
resource The name of the Workers script
source Detection rule source: 'managed' for Cloudflare-authored rules, 'custom' for customer-created rules

AccountContainersMetricsAdaptiveGroups

Metrics for Cloudchamber applications and deployments

FieldDescription
avg The average value of a metric per dimension
confidence ALPHA - DO NOT USE
count Number of metrics received
dimensions List of dimensions to group by
max Maximum value of a metric per dimension
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension

AccountContainersMetricsAdaptiveGroupsAvg

FieldDescription
containerUptime Average container uptime, in milliseconds
cpuLoad DEPRECATED (Replaced by cpuUtilization or sum { cpuTimeSec }): Average CPU load
cpuUtilization Average CPU utilization
gpuMemory Average GPU memory usage
memory Average memory usage
rxBandwidth DEPRECATED (Replaced by rxBandwidthBps): Average RX bandwidth
rxBandwidthBps Average RX bandwidth in bps
txBandwidth DEPRECATED (Replaced by txBandwidthBps): Average TX bandwidth
txBandwidthBps Average TX bandwidth in bps

AccountContainersMetricsAdaptiveGroupsConfidence

FieldDescription
count Number of metrics received, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountContainersMetricsAdaptiveGroupsDimensions

FieldDescription
active DEPRECATED (Filtered implicitly to 1): Whether the container is active or not
applicationId The application ID
date The date the metric was received
datetime The date and time the metric was received
datetimeFifteenMinutes The date and time the metric was received, truncated to fifteen minutes
datetimeFiveMinutes The date and time the metric was received, truncated to five minutes
datetimeHour The date and time the metric was received, truncated to one hour
datetimeMinute The date and time the metric was received, truncated to one minute
datetimeSixHours The date and time the metric was received, truncated to six hours
deploymentId DEPRECATED (Replaced by instanceId): The deployment ID
durableObjectId DEPRECATED (Replaced by instanceId): If set, this metric was emitted while assigned to a durable object
instanceId The ID of the container
label Value of a specific container label. Requires the name argument.
location Location
placementId The placement ID
procType DEPRECATED (Filtered implicitly to user): Process type
region Region

AccountContainersMetricsAdaptiveGroupsMax

FieldDescription
containerUptime Maximum container uptime, in milliseconds
cpuLoad DEPRECATED (Replaced by max { cpuUtilization } or sum { cpuTimeSec }): Maximum CPU load
cpuUtilization Maximum CPU utilization
diskAvailable Total disk space available, in bytes
diskUsage Disk usage, in bytes
diskUsagePercentage Disk usage as a percentage of total disk space
gpuMemory Maximum GPU memory usage
memory Maximum memory usage
rxBandwidth DEPRECATED (Replaced by rxBandwidthBps): Maximum RX bandwidth
rxBandwidthBps Maximum RX bandwidth
rxBytes DEPRECATED (Replaced by sum { rxBytes }): Total bytes received
txBandwidth DEPRECATED (Replaced by txBandwidthBps): Maximum TX bandwidth
txBandwidthBps Maximum TX bandwidth
txBytes DEPRECATED (Replaced by sum { txBytes }): Total bytes transmitted

AccountContainersMetricsAdaptiveGroupsQuantiles

FieldDescription
containerUptimeP25 Container uptime (25th percentile), in milliseconds
containerUptimeP50 Container uptime (50th percentile), in milliseconds
containerUptimeP75 Container uptime (75th percentile), in milliseconds
containerUptimeP90 Container uptime (90th percentile), in milliseconds
containerUptimeP95 Container uptime (95th percentile), in milliseconds
containerUptimeP99 Container uptime (99th percentile), in milliseconds
containerUptimeP999 Container uptime (99.9th percentile), in milliseconds
cpuLoadP25 DEPRECATED (Replaced by cpuUtilizationP25): CPU load (25th percentile)
cpuLoadP50 DEPRECATED (Replaced by cpuUtilizationP50): CPU load (50th percentile)
cpuLoadP75 DEPRECATED (Replaced by cpuUtilizationP75): CPU load (75th percentile)
cpuLoadP90 DEPRECATED (Replaced by cpuUtilizationP90): CPU load (90th percentile)
cpuLoadP95 DEPRECATED (Replaced by cpuUtilizationP95): CPU load (95th percentile)
cpuLoadP99 DEPRECATED (Replaced by cpuUtilizationP99): CPU load (99th percentile)
cpuLoadP999 DEPRECATED (Replaced by cpuUtilizationP999): CPU load (99.9th percentile)
cpuUtilizationP25 CPU utilization (25th percentile)
cpuUtilizationP50 CPU utilization (50th percentile)
cpuUtilizationP75 CPU utilization (75th percentile)
cpuUtilizationP90 CPU utilization (90th percentile)
cpuUtilizationP95 CPU utilization (95th percentile)
cpuUtilizationP99 CPU utilization (99th percentile)
cpuUtilizationP999 CPU utilization (99.9th percentile)
diskUsageP25 Disk usage in bytes (25th percentile)
diskUsageP50 Disk usage in bytes (50th percentile)
diskUsageP75 Disk usage in bytes (75th percentile)
diskUsageP90 Disk usage in bytes (90th percentile)
diskUsageP95 Disk usage in bytes (95th percentile)
diskUsageP99 Disk usage in bytes (99th percentile)
diskUsageP999 Disk usage in bytes (99.9th percentile)
diskUsagePercentageP25 Disk usage as a percentage of total disk space (25th percentile)
diskUsagePercentageP50 Disk usage as a percentage of total disk space (50th percentile)
diskUsagePercentageP75 Disk usage as a percentage of total disk space (75th percentile)
diskUsagePercentageP90 Disk usage as a percentage of total disk space (90th percentile)
diskUsagePercentageP95 Disk usage as a percentage of total disk space (95th percentile)
diskUsagePercentageP99 Disk usage as a percentage of total disk space (99th percentile)
diskUsagePercentageP999 Disk usage as a percentage of total disk space (99.9th percentile)
gpuMemoryP25 GPU memory usage (25th percentile)
gpuMemoryP50 GPU memory usage (50th percentile)
gpuMemoryP75 GPU memory usage (75th percentile)
gpuMemoryP90 GPU memory usage (90th percentile)
gpuMemoryP95 GPU memory usage (95th percentile)
gpuMemoryP99 GPU memory usage (99th percentile)
gpuMemoryP999 GPU memory usage (99.9th percentile)
memoryP25 Memory usage (25th percentile)
memoryP50 Memory usage (50th percentile)
memoryP75 Memory usage (75th percentile)
memoryP90 Memory usage (90th percentile)
memoryP95 Memory usage (95th percentile)
memoryP99 Memory usage (99th percentile)
memoryP999 Memory usage (99.9th percentile)
rxBandwidthBpsP25 RX bandwidth (25th percentile)
rxBandwidthBpsP50 RX bandwidth (50th percentile)
rxBandwidthBpsP75 RX bandwidth (75th percentile)
rxBandwidthBpsP90 RX bandwidth (90th percentile)
rxBandwidthBpsP95 RX bandwidth (95th percentile)
rxBandwidthBpsP99 RX bandwidth (99th percentile)
rxBandwidthBpsP999 RX bandwidth (99.9th percentile)
rxBandwidthP25 DEPRECATED (Replaced by rxBandwidthBpsP25): RX bandwidth (25th percentile)
rxBandwidthP50 DEPRECATED (Replaced by rxBandwidthBpsP50): RX bandwidth (50th percentile)
rxBandwidthP75 DEPRECATED (Replaced by rxBandwidthBpsP75): RX bandwidth (75th percentile)
rxBandwidthP90 DEPRECATED (Replaced by rxBandwidthBpsP90): RX bandwidth (90th percentile)
rxBandwidthP95 DEPRECATED (Replaced by rxBandwidthBpsP95): RX bandwidth (95th percentile)
rxBandwidthP99 DEPRECATED (Replaced by rxBandwidthBpsP99): RX bandwidth (99th percentile)
rxBandwidthP999 DEPRECATED (Replaced by rxBandwidthBpsP999): RX bandwidth (99.9th percentile)
txBandwidthBpsP25 TX bandwidth (25th percentile)
txBandwidthBpsP50 TX bandwidth (50th percentile)
txBandwidthBpsP75 TX bandwidth (75th percentile)
txBandwidthBpsP90 TX bandwidth (90th percentile)
txBandwidthBpsP95 TX bandwidth (95th percentile)
txBandwidthBpsP99 TX bandwidth (99th percentile)
txBandwidthBpsP999 TX bandwidth (99.9th percentile)
txBandwidthP25 DEPRECATED (Replaced by txBandwidthBpsP25): TX bandwidth (25th percentile)
txBandwidthP50 DEPRECATED (Replaced by txBandwidthBpsP50): TX bandwidth (50th percentile)
txBandwidthP75 DEPRECATED (Replaced by txBandwidthBpsP75): TX bandwidth (75th percentile)
txBandwidthP90 DEPRECATED (Replaced by txBandwidthBpsP90): TX bandwidth (90th percentile)
txBandwidthP95 DEPRECATED (Replaced by txBandwidthBpsP95): TX bandwidth (95th percentile)
txBandwidthP99 DEPRECATED (Replaced by txBandwidthBpsP99): TX bandwidth (99th percentile)
txBandwidthP999 DEPRECATED (Replaced by txBandwidthBpsP999): TX bandwidth (99.9th percentile)

AccountContainersMetricsAdaptiveGroupsSum

FieldDescription
allocatedCpu Sum of allocated vCPU in vCPU-seconds
allocatedDisk Sum of allocated disk in byte-seconds
allocatedMemory Sum of allocated memory in byte-seconds
containerUptime Total container uptime, in milliseconds
cpuTimeSec Sum of CPU time in seconds
rxBytes Sum of bytes received
txBytes Sum of bytes transmitted

AccountContainersMetricsAdaptiveGroupsSumConfidence

FieldDescription
allocatedCpu Confidence interval for the corresponding point estimate
allocatedDisk Confidence interval for the corresponding point estimate
allocatedMemory Confidence interval for the corresponding point estimate
containerUptime Confidence interval for the corresponding point estimate
cpuTimeSec Confidence interval for the corresponding point estimate
rxBytes Confidence interval for the corresponding point estimate
txBytes Confidence interval for the corresponding point estimate

AccountContainersUsageAdaptiveGroups

Used to compute usage queries for billing estimates in Dash

FieldDescription
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountContainersUsageAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountContainersUsageAdaptiveGroupsDimensions

FieldDescription
applicationId The application ID
date The date the metric was received
datetime The date and time the metric was received
datetimeFifteenMinutes The date and time the metric was received, truncated to fifteen minutes
datetimeFiveMinutes The date and time the metric was received, truncated to five minutes
datetimeHour The date and time the metric was received, truncated to one hour
datetimeMinute The date and time the metric was received, truncated to one minute
datetimeSixHours The date and time the metric was received, truncated to six hours
instanceId The ID of the container
label Value of a specific container label. Requires the name argument.
location Location
placementId The placement ID
region Region

AccountContainersUsageAdaptiveGroupsSum

FieldDescription
allocatedDisk Sum of allocated disk in byte-seconds
allocatedMemory Sum of allocated memory in byte-seconds
cpuTimeSec Sum of CPU time in seconds
txBytes Sum of bytes transmitted

AccountContainersUsageAdaptiveGroupsSumConfidence

FieldDescription
allocatedDisk Confidence interval for the corresponding point estimate
allocatedMemory Confidence interval for the corresponding point estimate
cpuTimeSec Confidence interval for the corresponding point estimate
txBytes Confidence interval for the corresponding point estimate

AccountD1AnalyticsAdaptiveGroups

Aggregated D1 analytics with adaptive sampling

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count Number of requests to D1 processed
dimensions List of dimensions to group by
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension

AccountD1AnalyticsAdaptiveGroupsAvg

FieldDescription
queryBatchResponseBytes The total number of bytes in the response, including all returned rows and metadata (average/mean).
queryBatchTimeMs Query batch response time in milliseconds (average/mean).
sampleInterval The average value used for sample interval

AccountD1AnalyticsAdaptiveGroupsConfidence

FieldDescription
count Number of requests to D1 processed, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountD1AnalyticsAdaptiveGroupsDimensions

FieldDescription
databaseId The UUID of a D1 database
databaseRole The role of the D1 database that served the request. One of [primary, replica]
date The date the D1 request was received
datetime The date and time the D1 request was received
datetimeFifteenMinutes The date and time the D1 request was received truncated to fifteen minutes
datetimeFiveMinutes The date and time the D1 request was received truncated to five minutes
datetimeHour The date and time the D1 request was received truncated to the hour
datetimeMinute The date and time the D1 request was received truncated to the minute
datetimeSixHours The date and time the D1 request was received truncated to start of six hour window
servedByInstance A consistent identifier of the D1 database instance (whether primary or replica) that served the request.
servedByRegion The region of the D1 database that served the request. One of [WNAM, ENAM, WEUR, EEUR, APAC, OC]

AccountD1AnalyticsAdaptiveGroupsQuantiles

FieldDescription
queryBatchResponseBytesP25 The total number of bytes in the response, including all returned rows and metadata (25th percentile).
queryBatchResponseBytesP50 The total number of bytes in the response, including all returned rows and metadata (50th percentile).
queryBatchResponseBytesP75 The total number of bytes in the response, including all returned rows and metadata (75th percentile).
queryBatchResponseBytesP90 The total number of bytes in the response, including all returned rows and metadata (90th percentile).
queryBatchResponseBytesP95 The total number of bytes in the response, including all returned rows and metadata (95th percentile).
queryBatchResponseBytesP99 The total number of bytes in the response, including all returned rows and metadata (99th percentile).
queryBatchResponseBytesP999 The total number of bytes in the response, including all returned rows and metadata (99.9th percentile).
queryBatchTimeMsP25 Query batch response time in milliseconds (25th percentile).
queryBatchTimeMsP50 Query batch response time in milliseconds (50th percentile).
queryBatchTimeMsP75 Query batch response time in milliseconds (75th percentile).
queryBatchTimeMsP90 Query batch response time in milliseconds (90th percentile).
queryBatchTimeMsP95 Query batch response time in milliseconds (95th percentile).
queryBatchTimeMsP99 Query batch response time in milliseconds (99th percentile).
queryBatchTimeMsP999 Query batch response time in milliseconds (99.9th percentile).

AccountD1AnalyticsAdaptiveGroupsSum

FieldDescription
queryBatchResponseBytes The total number of bytes in the response, including all returned rows and metadata.
readQueries The number of read queries.
rowsRead The number of rows your queries read.
rowsWritten The number of rows your queries wrote.
writeQueries The number of write queries.

AccountD1AnalyticsAdaptiveGroupsSumConfidence

FieldDescription
queryBatchResponseBytes Confidence interval for the corresponding point estimate
readQueries Confidence interval for the corresponding point estimate
rowsRead Confidence interval for the corresponding point estimate
rowsWritten Confidence interval for the corresponding point estimate
writeQueries Confidence interval for the corresponding point estimate

AccountD1QueriesAdaptiveGroups

D1 query metrics with adaptive sampling

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count Number of D1 queries processed
dimensions List of dimensions to group by
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension

AccountD1QueriesAdaptiveGroupsAvg

FieldDescription
queryDurationMs The average duration queries in D1 took, observed over the queried time period.
rowsRead The average number of rows scanned, observed over the queried time period.
rowsReturned The average number of rows returned, observed over the queried time period.
rowsWritten The average number of rows written, observed over the queried time period.
sampleInterval The average value used for sample interval

AccountD1QueriesAdaptiveGroupsConfidence

FieldDescription
count Number of D1 queries processed, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountD1QueriesAdaptiveGroupsDimensions

FieldDescription
databaseId The UUID of a D1 database
databaseRole The role of the D1 database that served the request. One of [primary, replica]
date D1 query sample timestamp
datetime D1 query sample timestamp
datetimeFifteenMinutes D1 query sample timestamp, truncated to fifteen minutes
datetimeFiveMinutes D1 query sample timestamp, truncated to five minutes
datetimeHour D1 query sample timestamp, truncated to the hour
datetimeMinute D1 query sample timestamp, truncated to the minute
datetimeSixHours D1 query sample timestamp, truncated to start of six hour window
error The error D1 returned (if any) after attempting to run a query.
query The SQL query that ran on a D1 database, with parameterized values replaced with placeholders.
servedByInstance A consistent identifier of the D1 database instance (whether primary or replica) that served the request.
servedByRegion The region of the D1 database that served the request. One of [WNAM, ENAM, WEUR, EEUR, APAC, OC]

AccountD1QueriesAdaptiveGroupsQuantiles

FieldDescription
queryDurationMsP25 25th percentile Query Duration (milliseconds)
queryDurationMsP50 50th percentile Query Duration (milliseconds)
queryDurationMsP75 75th percentile Query Duration (milliseconds)
queryDurationMsP90 90th percentile Query Duration (milliseconds)
queryDurationMsP95 95th percentile Query Duration (milliseconds)
queryDurationMsP99 99th percentile Query Duration (milliseconds)
queryDurationMsP999 99.9th percentile Query Duration (milliseconds)

AccountD1QueriesAdaptiveGroupsSum

FieldDescription
queryDurationMs The total duration queries in D1 took, observed over the queried time period.
rowsRead The total number of rows scanned, observed over the queried time period.
rowsReturned The total number of rows returned, observed over the queried time period.
rowsWritten The total number of rows written, observed over the queried time period.

AccountD1QueriesAdaptiveGroupsSumConfidence

FieldDescription
queryDurationMs Confidence interval for the corresponding point estimate
rowsRead Confidence interval for the corresponding point estimate
rowsReturned Confidence interval for the corresponding point estimate
rowsWritten Confidence interval for the corresponding point estimate

AccountD1StorageAdaptiveGroups

D1 storage with adaptive sampling

FieldDescription
dimensions List of dimensions to group by
max The max of values for a metric per dimension

AccountD1StorageAdaptiveGroupsDimensions

FieldDescription
databaseId The UUID of a D1 database
date D1 storage sample timestamp
datetime D1 storage sample timestamp
datetimeFifteenMinutes D1 storage sample timestamp, truncated to fifteen minutes
datetimeFiveMinutes D1 storage sample timestamp, truncated to five minutes
datetimeHour D1 storage sample timestamp, truncated to the hour
datetimeMinute D1 storage sample timestamp, truncated to the minute
datetimeSixHours D1 storage sample timestamp, truncated to start of six hour window

AccountD1StorageAdaptiveGroupsMax

FieldDescription
databaseSizeBytes The maximum size of the database (measured in bytes) observed over the queried time period.

AccountDnsAnalyticsAdaptive

Analytics data for DNS queries

FieldDescription
coloName IATA airport code of the data center that processed the query
date Date on which the query was received
datetime Time at which the query was received
destinationIP Cloudflare edge IP address that the query was received at
ipVersion Internet Protocol version over which the query was received
protocol Transport protocol over which the query was received
queryName DNS query name without trailing dot
querySize Size of the DNS query in bytes
queryType DNS query type
responseCached Whether the DNS response was served from cache
responseCode DNS response code
responseSize Size of the DNS response in bytes
responseStale Whether a stale DNS response was served from cache
sampleInterval ABR sample interval
sourceIP IP address of the client that sent the query (usually this is the resolver's IP address)
upstreamIP Upstream server that the query was forwarded to
zoneTag Zone query attributed to

AccountDnsAnalyticsAdaptiveGroups

Analytics data for DNS queries

FieldDescription
avg Average of a metric per dimension
confidence ALPHA - DO NOT USE
count Number of queries per dimension
dimensions List of dimensions to group by
quantiles Quantiles of a metric per dimension

AccountDnsAnalyticsAdaptiveGroupsAvg

FieldDescription
processingTimeUs Average processing time in microseconds
sampleInterval Average sample interval

AccountDnsAnalyticsAdaptiveGroupsConfidence

FieldDescription
count Number of queries per dimension, with confidence intervals
level Confidence level that was requested

AccountDnsAnalyticsAdaptiveGroupsDimensions

FieldDescription
coloName IATA airport code of the data center that processed the query
date Date on which the query was received
datetime Time at which the query was received
datetimeFifteenMinutes Time at which the query was received, truncated to multiple of 15 minutes
datetimeFiveMinutes Time at which the query was received, truncated to multiple of 5 minutes
datetimeHalfOfHour Time at which the query was received, truncated to multiple of 30 minutes
datetimeHour Time at which the query was received, truncated to the hour
datetimeMinute Time at which the query was received, truncated to the minute
destinationIP Cloudflare edge IP address that the query was received at
ipVersion Internet Protocol version over which the query was received
protocol Transport protocol over which the query was received
queryName DNS query name without trailing dot
querySizeBucket Size of the DNS query in bytes (in multiples of 16)
queryType DNS query type
responseCached Whether the DNS response was served from cache
responseCode DNS response code
responseSizeBucket Size of the DNS response in bytes (in multiples of 16)
responseStale Whether a stale DNS response was served from cache
sourceIP IP address of the client that sent the query (usually this is the resolver's IP address)
upstreamIP Upstream server that the query was forwarded to
zoneTag Zone query attributed to

AccountDnsAnalyticsAdaptiveGroupsQuantiles

FieldDescription
processingTimeUsP25 25th percentile processing time in microseconds
processingTimeUsP50 50th percentile processing time in microseconds (median)
processingTimeUsP75 75th percentile processing time in microseconds
processingTimeUsP90 90th percentile processing time in microseconds
processingTimeUsP95 95th percentile processing time in microseconds
processingTimeUsP99 99th percentile processing time in microseconds
processingTimeUsP999 99.9th percentile processing time in microseconds

AccountDnsFirewallAnalyticsAdaptive

Analytics data for DNS Firewall queries

FieldDescription
clusterName DNS Firewall cluster name
clusterTag DNS Firewall cluster tag
coloName IATA airport code of the data center that processed the query
date Date on which the query was received
datetime Time at which the query was received
destinationIP Cloudflare edge IP address that the query was received at, this will be one of your cluster IPs.
ipVersion Internet Protocol version over which the query was received
protocol Transport protocol over which the query was received
queryName DNS query name without trailing dot
querySize Size of the DNS query in bytes
queryType DNS query type
responseCached Whether the DNS response was served from cache
responseCode DNS response code
responseReason Indicates why the DNS Firewall responded to the query in the way it did
responseSize Size of the DNS response in bytes
responseStale Whether a stale DNS response was served from cache
sampleInterval ABR sample interval
sourceIP IP address of the client that sent the query (usually this is the resolver's IP address)
upstreamIP Upstream server that the query was forwarded to

AccountDnsFirewallAnalyticsAdaptiveGroups

Analytics data for DNS Firewall queries

FieldDescription
avg Average of a metric per dimension
confidence ALPHA - DO NOT USE
count Number of queries per dimension
dimensions List of dimensions to group by
quantiles Quantiles of a metric per dimension

AccountDnsFirewallAnalyticsAdaptiveGroupsAvg

FieldDescription
processingTimeUs Average processing time in microseconds
sampleInterval Average sample interval

AccountDnsFirewallAnalyticsAdaptiveGroupsConfidence

FieldDescription
count Number of queries per dimension, with confidence intervals
level Confidence level that was requested

AccountDnsFirewallAnalyticsAdaptiveGroupsDimensions

FieldDescription
clusterName DNS Firewall cluster name
clusterTag ID of DNS Firewall cluster
coloName IATA airport code of the data center that processed the query
date Date on which the query was received
datetime Time at which the query was received
datetimeFifteenMinutes Time at which the query was received, truncated to multiple of 15 minutes
datetimeFiveMinutes Time at which the query was received, truncated to multiple of 5 minutes
datetimeHalfOfHour Time at which the query was received, truncated to multiple of 30 minutes
datetimeHour Time at which the query was received, truncated to the hour
datetimeMinute Time at which the query was received, truncated to the minute
destinationIP Cloudflare edge IP address that the query was received at, this will be one of your cluster IPs.
ipVersion Internet Protocol version over which the query was received
protocol Transport protocol over which the query was received
queryName DNS query name without trailing dot
querySizeBucket Size of the DNS query in bytes (in multiples of 16)
queryType DNS query type
responseCached Whether the DNS response was served from cache
responseCode DNS response code
responseReason Indicates why the DNS Firewall responded to the query in the way it did
responseSizeBucket Size of the DNS response in bytes (in multiples of 16)
responseStale Whether a stale DNS response was served from cache
sourceIP IP address of the client that sent the query (usually this is the resolver's IP address)
upstreamIP Upstream server that the query was forwarded to

AccountDnsFirewallAnalyticsAdaptiveGroupsQuantiles

FieldDescription
processingTimeUsP25 25th percentile processing time in microseconds
processingTimeUsP50 50th percentile processing time in microseconds (median)
processingTimeUsP75 75th percentile processing time in microseconds
processingTimeUsP90 90th percentile processing time in microseconds
processingTimeUsP95 95th percentile processing time in microseconds
processingTimeUsP99 99th percentile processing time in microseconds
processingTimeUsP999 99.9th percentile processing time in microseconds

AccountDosdAttackAnalyticsGroups

Attack analytics metadata for attacks detected by dosd

FieldDescription
attackId Unique identifier of the mitigation that matched the packet, if any
attackType DEPRECATED (Use attackVector for a richer description of the attack): Type of attack traffic
attackVector Description of attack vector
bits Sum of bits received during the attack
commonTcpFlags Common TCP flags used by attack traffic, if any
commonTcpFlagsNames Names of common TCP flags used by attack traffic, if any
destinationIp Fixed destination IP used by attack traffic, if any
destinationPort Fixed destination port used by attack traffic, if any
droppedBits Sum of bits dropped during the attack
droppedPackets Sum of packets dropped during the attack
endDatetime Date and time that the attack ended; not available for ongoing attacks
ipProtocol Fixed protocol used by attack traffic, if any
ipProtocolName Fixed protocol used by attack traffic, if any
mitigationReason Type of mitigation applied to attack traffic
mitigationScope Whether mitigation was applied in only some locations or globally
mitigationType Type of mitigation applied to attack traffic
packets Sum of packets received during the attack
ruleId Unique identifier of the rule that matched the packet, if any
ruleName Human-readable name of the rule that matched the packet, if any
rulesetId Unique identifier of the ruleset containing the rule that matched the packet, if any
rulesetOverrideId Unique identifier of the ruleset override containing the rule that matched the packet, if any
sourceIp Fixed source IP used by attack traffic, if any
sourcePort Fixed source port used by attack traffic, if any
startDatetime Date and time that the attack started
tcpFlags Fixed TCP flags used by attack traffic, if any
tcpFlagsNames Names of fixed TCP flags used by attack traffic, if any

AccountDosdNetworkAnalyticsAdaptiveGroups

Network analytics data for dosd

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountDosdNetworkAnalyticsAdaptiveGroupsAvg

FieldDescription
bitRate Sum of bits received, divided by 1 second, providing a per-second bit rate when grouped by datetime
bitRateDay Sum of bits received, divided by 86400 seconds, providing a per-second bit rate when grouped by date
bitRateFifteenMinutes Sum of bits received, divided by 900 seconds, providing a per-second bit rate when grouped by datetimeFifteenMinutes
bitRateFiveMinutes Sum of bits received, divided by 300 seconds, providing a per-second bit rate when grouped by datetimeFiveMinutes
bitRateHour Sum of bits received, divided by 3600 seconds, providing a per-second bit rate when grouped by datetimeHour
bitRateMinute Sum of bits received, divided by 60 seconds, providing a per-second bit rate when grouped by datetimeMinute
bitRateTenSeconds Sum of bits received, divided by 10 seconds, providing a per-second bit rate when grouped by datetimeTenSeconds
packetRate Sum of packets received, divided by 1 second, providing a per-second packet rate when grouped by datetime
packetRateDay Sum of packets received, divided by 86400 seconds, providing a per-second packet rate when grouped by date
packetRateFifteenMinutes Sum of packets received, divided by 900 seconds, providing a per-second packet rate when grouped by datetimeFifteenMinutes
packetRateFiveMinutes Sum of packets received, divided by 300 seconds, providing a per-second packet rate when grouped by datetimeFiveMinutes
packetRateHour Sum of packets received, divided by 3600 seconds, providing a per-second packet rate when grouped by datetimeHour
packetRateMinute Sum of packets received, divided by 60 seconds, providing a per-second packet rate when grouped by datetimeMinute
packetRateTenSeconds Sum of packets received, divided by 10 seconds, providing a per-second packet rate when grouped by datetimeTenSeconds

AccountDosdNetworkAnalyticsAdaptiveGroupsAvgConfidence

FieldDescription
bitRate Confidence interval for the corresponding point estimate
bitRateDay Confidence interval for the corresponding point estimate
bitRateFifteenMinutes Confidence interval for the corresponding point estimate
bitRateFiveMinutes Confidence interval for the corresponding point estimate
bitRateHour Confidence interval for the corresponding point estimate
bitRateMinute Confidence interval for the corresponding point estimate
bitRateTenSeconds Confidence interval for the corresponding point estimate
packetRate Confidence interval for the corresponding point estimate
packetRateDay Confidence interval for the corresponding point estimate
packetRateFifteenMinutes Confidence interval for the corresponding point estimate
packetRateFiveMinutes Confidence interval for the corresponding point estimate
packetRateHour Confidence interval for the corresponding point estimate
packetRateMinute Confidence interval for the corresponding point estimate
packetRateTenSeconds Confidence interval for the corresponding point estimate

AccountDosdNetworkAnalyticsAdaptiveGroupsConfidence

FieldDescription
avg The average of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountDosdNetworkAnalyticsAdaptiveGroupsDimensions

FieldDescription
applicationTag Application tag associated with the packet
attackId Unique identifier of the mitigation that matched the packet, if any
attackVector Attack vector of the rule that matched the packet, if any
coloCity City where the Cloudflare datacenter that received the packet is located
coloCode Cloudflare datacenter that received the packet (nearest IATA airport code)
coloCountry Country where the Cloudflare datacenter that received the packet is located (ISO 3166-1 alpha-2)
coloGeohash Latitude and longitude where the Cloudflare datacenter that received the packet is located (Geohash encoding)
coloName Cloudflare datacenter that received the packet (unique site identifier)
date Date that the packet was received
datetime Date and time that the packet was received
datetimeFifteenMinutes Date and time that the packet was received, rounded to the start of the nearest fifteen minutes
datetimeFiveMinutes Date and time that the packet was received, rounded to the start of the nearest five minutes
datetimeHour Date and time that the packet was received, rounded to the start of the nearest hour
datetimeMinute Date and time that the packet was received, rounded to the start of the nearest minute
datetimeTenSeconds Date and time that the packet was received, rounded to the start of the nearest ten seconds
destinationAsn ASN associated with the destination IP of the packet, or 0 if there was no mapping available
destinationAsnName Name of ASN associated with the destination IP of the packet, if available
destinationCountry Country where the destination IP of the packet is located (ISO 3166-1 alpha-2)
destinationGeohash Latitude and longitude where the destination IP of the packet is located (Geohash encoding)
destinationPort Value of the Destination Port header field in the TCP or UDP packet
direction Direction of the packet relative to the customer network (possible values: inbound, outbound, lateral)
ethertype Value of the Ethertype header field in the Ethernet packet (2048 for IPv4; 34525 for IPv6)
greChecksum Value of the Checkusm header field in the GRE packet
greEthertype Value of the Ethertype header field in the GRE packet
greHeaderLength Length of the GRE packet header, in bytes
greKey Value of the Key header field in the GRE packet
greSequenceNumber Value of the Sequence Number header field in the GRE packet
greVersion Value of the Version header field in the GRE packet
icmpChecksum Value of the Checkusm header field in the ICMP packet
icmpCode Value of the Code header field in the ICMP packet
icmpType Value of the Type header field in the ICMP packet
ipDestinationAddress Value of the Destination Address header field in the IPv4 or IPv6 packet
ipDestinationSubnet Computed subnet of the Destination Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipFragmentOffset Value of the Fragment Offset header field in the IPv4 or IPv6 packet
ipHeaderLength Length of the IPv4 or IPv6 packet header, in bytes
ipMoreFragments Value of the More Fragments header field in the IPv4 or IPv6 packet
ipProtocol Value of the Protocol header field in the IPv4 or IPv6 packet
ipProtocolName Name of the protocol specified by the Protocol header field in the IPv4 or IPv6 packet
ipSourceAddress Value of the Source Address header field in the IPv4 or IPv6 packet
ipSourceSubnet Computed subnet of the Source Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipTotalLength Total length of the IPv4 or IPv6 packet, in bytes
ipTotalLengthBuckets Total length of the IPv4 or IPv6 packet, in bytes, with the last two digits truncated
ipTtl Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet
ipTtlBuckets Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet, with the last digit truncated
ipv4Checksum Value of the Checksum header field in the IPv4 packet
ipv4DontFragment Value of the Don't Fragment header field in the IPv4 packet
ipv4Dscp Value of the Differentiated Services Code Point header field in the IPv4 packet
ipv4Ecn Value of the Explicit Congestion Notification header field in the IPv4 packet
ipv4Identification Value of the Identification header field in the IPv4 packet
ipv4Options List of Options numbers included in the IPv4 packet header
ipv6Dscp Value of the Differentiated Services Code Point header field in the IPv6 packet
ipv6Ecn Value of the Explicit Congestion Notification header field in the IPv6 packet
ipv6ExtensionHeaders List of Extension Header numbers included in the IPv6 packet header
ipv6FlowLabel Value of the Flow Label header field in the IPv6 packet
ipv6Identification Value of the Identification extension header field in the IPv6 packet
leaseTag IP lease tag associated with the packet
mitigationReason Reason for applying a mitigation to the packet, if any
mitigationScope Whether the packet matched a local or global mitigation, if any (possible values: local, global)
outcome The action that was taken on the packet (possible values: pass, drop)
prefixTag IP prefix tag associated with the packet
protocolState State of the packet in the context of the protocol, if available
ruleId Unique identifier of the rule that matched the packet, if any
ruleName Human-readable name of the rule that matched the packet, if any
rulesetId Unique identifier of the ruleset containing the rule that matched the packet, if any
rulesetOverrideId Unique identifier of the ruleset override containing the rule that matched the packet, if any
sampleInterval ABR sample interval
sourceAsn ASN associated with the source IP of the packet, or 0 if there was no mapping available
sourceAsnName Name of ASN associated with the source IP of the packet, if available
sourceCountry Country where the source IP of the packet is located (ISO 3166-1 alpha-2)
sourceGeohash Latitude and longitude where the source IP of the packet is located (Geohash encoding)
sourcePort Value of the Source Port header field in the TCP or UDP packet
tcpAcknowledgementNumber Value of the Acknowledgement Number header field in the TCP packet
tcpChecksum Value of the Checkusm header field in the TCP packet
tcpDataOffset Value of the Data Offset header field in the TCP packet
tcpFlags Value of the Flags header field in the TCP packet
tcpFlagsString Human-readable string representation of the Flags header field in the TCP packet
tcpMss Value of the MSS option header field in the TCP packet
tcpOptions List of Options numbers included in the TCP packet header
tcpSackBlocks Value of the SACK Blocks option header field in the TCP packet
tcpSackPermitted Value of the SACK Permitted option header field in the TCP packet
tcpSequenceNumber Value of the Sequence Number header field in the TCP packet
tcpTimestampEcr Value of the Timestamp Echo Reply option header field in the TCP packet
tcpTimestampValue Value of the Timestamp option header field in the TCP packet
tcpUrgentPointer Value of the Urgent Pointer header field in the TCP packet
tcpWindowScale Value of the Window Scale option header field in the TCP packet
tcpWindowSize Value of the Window Size header field in the TCP packet
udpChecksum Value of the Checkusm header field in the UDP packet
udpPayloadLength Value of the Payload Length header field in the UDP packet
verdict The action that Cloudflare thinks should be taken on the packet (possible values: pass, drop)

AccountDosdNetworkAnalyticsAdaptiveGroupsSum

FieldDescription
bits Sum of bits received
packets Sum of packets received

AccountDosdNetworkAnalyticsAdaptiveGroupsSumConfidence

FieldDescription
bits Confidence interval for the corresponding point estimate
packets Confidence interval for the corresponding point estimate

AccountDurableObjectsInvocationsAdaptiveGroups

Durable Objects invocations with adaptive sampling

FieldDescription
avg The average value for a metric
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
max The max value for a metric
min The min value for a metric
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension

AccountDurableObjectsInvocationsAdaptiveGroupsAvg

FieldDescription
sampleInterval Average sample interval

AccountDurableObjectsInvocationsAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountDurableObjectsInvocationsAdaptiveGroupsDimensions

FieldDescription
date Request datetime, truncated to start of a day
datetime Request datetime
datetimeFifteenMinutes Request datetime, truncated to start of a minute
datetimeFiveMinutes Request datetime, truncated to start of a minute
datetimeHour Request datetime, truncated to start of an hour
datetimeMinute Request datetime, truncated to start of a minute
datetimeSixHours Request datetime, truncated to start of six hour window
environmentName The name of the script environment
isPreview Whether this invocation is for a preview. 1 if preview, 0 if not.
name The name the Durable Object was created with
namespaceId Durable Object namespace ID
objectId Durable Object ID as a hex string
previewSlug The name (slug) of the preview script
scriptName The name of the script
status Status of the worker invocation
type Type of invocation

AccountDurableObjectsInvocationsAdaptiveGroupsMax

FieldDescription
datetime Maximum request datetime
responseBodySize Maximum response body size for one request - bytes
wallTime Maximum wall time for one request - microseconds

AccountDurableObjectsInvocationsAdaptiveGroupsMin

FieldDescription
responseBodySize Minimum response body size for one request - bytes
wallTime Minimum wall time for one request - microseconds

AccountDurableObjectsInvocationsAdaptiveGroupsQuantiles

FieldDescription
responseBodySizeP25 Response body size 25th percentile - bytes
responseBodySizeP50 Response body size 50th percentile - bytes
responseBodySizeP75 Response body size 75th percentile - bytes
responseBodySizeP90 Response body size 90th percentile - bytes
responseBodySizeP95 Response body size 95th percentile - bytes
responseBodySizeP99 Response body size 99th percentile - bytes
responseBodySizeP999 Response body size 99.9th percentile - bytes
wallTimeP25 Wall time 25th percentile - microseconds
wallTimeP50 Wall time 50th percentile - microseconds
wallTimeP75 Wall time 75th percentile - microseconds
wallTimeP90 Wall time 90th percentile - microseconds
wallTimeP95 Wall time 95th percentile - microseconds
wallTimeP99 Wall time 99th percentile - microseconds
wallTimeP999 Wall time 99.9th percentile - microseconds

AccountDurableObjectsInvocationsAdaptiveGroupsSum

FieldDescription
errors Sum of errors
requests Sum of requests
responseBodySize Sum of response body sizes
wallTime Sum of wall time

AccountDurableObjectsInvocationsAdaptiveGroupsSumConfidence

FieldDescription
errors Confidence interval for the corresponding point estimate
requests Confidence interval for the corresponding point estimate
responseBodySize Confidence interval for the corresponding point estimate
wallTime Confidence interval for the corresponding point estimate

AccountDurableObjectsPeriodicGroups

Durable Objects periodic metrics

FieldDescription
avg The average value for a metric
confidence ALPHA - DO NOT USE
count Count of periodic metric events
dimensions List of dimensions to group by
max The max value for a metric
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension

AccountDurableObjectsPeriodicGroupsAvg

FieldDescription
sampleInterval Average sample interval

AccountDurableObjectsPeriodicGroupsConfidence

FieldDescription
count Count of periodic metric events, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountDurableObjectsPeriodicGroupsDimensions

FieldDescription
date Datetime the metrics period started, truncated to start of a day
datetime Datetime the metrics period started
datetimeFifteenMinutes Datetime the metrics period started, truncated to start of a minute
datetimeFiveMinutes Datetime the metrics period started, truncated to start of a minute
datetimeHour Datetime the metrics period started, truncated to start of an hour
datetimeMinute Datetime the metrics period started, truncated to start of a minute
datetimeSixHours Datetime the metrics period started, truncated to start of six hour window
name The name the Durable Object was created with
namespaceId Durable Object namespace ID
objectId Durable Object ID as a hex string

AccountDurableObjectsPeriodicGroupsMax

FieldDescription
activeWebsocketConnections Maximum active websocket connections in the time window
memoryUsageBytes Maximum isolate memory usage reported by Durable Object periodic metrics - bytes

AccountDurableObjectsPeriodicGroupsQuantiles

FieldDescription
memoryUsageBytesP25 Isolate memory usage 25th percentile across Durable Object periodic metrics - bytes
memoryUsageBytesP50 Isolate memory usage 50th percentile across Durable Object periodic metrics - bytes
memoryUsageBytesP75 Isolate memory usage 75th percentile across Durable Object periodic metrics - bytes
memoryUsageBytesP90 Isolate memory usage 90th percentile across Durable Object periodic metrics - bytes
memoryUsageBytesP95 Isolate memory usage 95th percentile across Durable Object periodic metrics - bytes
memoryUsageBytesP99 Isolate memory usage 99th percentile across Durable Object periodic metrics - bytes
memoryUsageBytesP999 Isolate memory usage 99.9th percentile across Durable Object periodic metrics - bytes

AccountDurableObjectsPeriodicGroupsSum

FieldDescription
activeTime Sum of active time - microseconds
cpuTime Sum of CPU time - microseconds
duration Sum of Duration - GB*s
exceededCpuErrors Sum of CPU exceeded errors
exceededMemoryErrors Sum of memory exceeded errors
fatalInternalErrors Sum of fatal internal server errors
inboundWebsocketMsgCount Sum of incoming websocket messages
outboundWebsocketMsgCount Sum of outbound websocket messages
rowsRead Sum of rows read (by sqlite backed DOs)
rowsWritten Sum of rows written (by sqlite backed DOs)
storageDeletes Sum of storage deletes (by non-sqlite backed DOs)
storageReadUnits Sum of storage reads - in 4KB units (by non-sqlite backed DOs)
storageWriteUnits Sum of storage writes - in 4KB units (by non-sqlite backed DOs)
subrequests Sum of subrequests

AccountDurableObjectsPeriodicGroupsSumConfidence

FieldDescription
activeTime Confidence interval for the corresponding point estimate
cpuTime Confidence interval for the corresponding point estimate
duration Confidence interval for the corresponding point estimate
exceededCpuErrors Confidence interval for the corresponding point estimate
exceededMemoryErrors Confidence interval for the corresponding point estimate
fatalInternalErrors Confidence interval for the corresponding point estimate
inboundWebsocketMsgCount Confidence interval for the corresponding point estimate
outboundWebsocketMsgCount Confidence interval for the corresponding point estimate
rowsRead Confidence interval for the corresponding point estimate
rowsWritten Confidence interval for the corresponding point estimate
storageDeletes Confidence interval for the corresponding point estimate
storageReadUnits Confidence interval for the corresponding point estimate
storageWriteUnits Confidence interval for the corresponding point estimate
subrequests Confidence interval for the corresponding point estimate

AccountDurableObjectsSqlStorageGroups

Storage metrics for SQL-backed Durable Objects.

FieldDescription
dimensions List of dimensions to group by
max The max value for a metric

AccountDurableObjectsSqlStorageGroupsDimensions

FieldDescription
date Datetime that the storage usage was recorded, truncated to start of a day
datetime Datetime that the storage usage was recorded
datetimeFifteenMinutes Datetime that the storage usage was recorded, truncated to fifteen minutes
datetimeFiveMinutes Datetime that the storage usage was recorded, truncated to five minutes
datetimeHour Datetime that the storage usage was recorded, truncated to start of an hour
datetimeMinute Datetime that the storage usage was recorded, truncated to start of a minute
datetimeSixHours Datetime that the storage usage was recorded, truncated to start of six hour window
namespaceId Durable Object namespace ID

AccountDurableObjectsSqlStorageGroupsMax

FieldDescription
storedBytes Max of stored bytes

AccountDurableObjectsStorageGroups

Durable Objects storage metrics

FieldDescription
dimensions List of dimensions to group by
max The max value for a metric

AccountDurableObjectsStorageGroupsDimensions

FieldDescription
date Datetime that the storage usage was recorded, truncated to start of a day
datetime Datetime that the storage usage was recorded
datetimeFifteenMinutes Datetime that the storage usage was recorded, truncated to fifteen minutes
datetimeFiveMinutes Datetime that the storage usage was recorded, truncated to five minutes
datetimeHour Datetime that the storage usage was recorded, truncated to start of an hour
datetimeMinute Datetime that the storage usage was recorded, truncated to start of a minute

AccountDurableObjectsStorageGroupsMax

FieldDescription
storedBytes Max of stored bytes

AccountDurableObjectsSubrequestsAdaptiveGroups

Durable Objects subrequests with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountDurableObjectsSubrequestsAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountDurableObjectsSubrequestsAdaptiveGroupsDimensions

FieldDescription
date Request datetime, truncated to start of a day
datetime Request datetime
datetimeFifteenMinutes Request datetime, truncated to start of fifteen minutes
datetimeFiveMinutes Request datetime, truncated to start of five minutes
datetimeHour Request datetime, truncated to start of an hour
datetimeMinute Request datetime, truncated to start of a minute
datetimeSixHours Request datetime, truncated to start of six hour window
environmentName The name of the script environment
name The name the Durable Object was created with
namespaceId Durable Object namespace ID
objectId Durable Object ID as a hex string
scriptName The name of the script

AccountDurableObjectsSubrequestsAdaptiveGroupsSum

FieldDescription
requestBodySizeUncached Outgoing Durable Objects fetch request body size in bytes where the request was not cached

AccountDurableObjectsSubrequestsAdaptiveGroupsSumConfidence

FieldDescription
requestBodySizeUncached Confidence interval for the corresponding point estimate

AccountFbmAttackAnalyticsGroups

FBM analytics metadata for attacks detected by dosd

FieldDescription
attackId Unique identifier of the mitigation that matched the packet, if any
attackType DEPRECATED (Use attackVector for a richer description of the attack): Type of attack traffic
attackVector Description of attack vector
bits Sum of bits received during the attack
commonTcpFlags Common TCP flags used by attack traffic, if any
commonTcpFlagsNames Names of common TCP flags used by attack traffic, if any
destinationIp Fixed destination IP used by attack traffic, if any
destinationPort Fixed destination port used by attack traffic, if any
droppedBits Sum of bits dropped during the attack
droppedPackets Sum of packets dropped during the attack
endDatetime Date and time that the attack ended; not available for ongoing attacks
ipProtocol Fixed protocol used by attack traffic, if any
ipProtocolName Fixed protocol used by attack traffic, if any
mitigationReason Type of mitigation applied to attack traffic
mitigationScope Whether mitigation was applied in only some locations or globally
mitigationType Type of mitigation applied to attack traffic
packets Sum of packets received during the attack
ruleId Unique identifier of the rule that matched the packet, if any
ruleName Human-readable name of the rule that matched the packet, if any
rulesetId Unique identifier of the ruleset containing the rule that matched the packet, if any
rulesetOverrideId Unique identifier of the ruleset override containing the rule that matched the packet, if any
sourceIp Fixed source IP used by attack traffic, if any
sourcePort Fixed source port used by attack traffic, if any
startDatetime Date and time that the attack started
tcpFlags Fixed TCP flags used by attack traffic, if any
tcpFlagsNames Names of fixed TCP flags used by attack traffic, if any

AccountFilter_InputObject

FieldDescription

AccountFirewallEventsAdaptive

Raw Firewall events with adaptive sampling

FieldDescription
action The code of the first-class action the Cloudflare Firewall took on this request
apiGatewayMatchedEndpoint API Gateway (Web Assets) endpoint matched at the edge
apiGatewayMatchedHost API Gateway (Web Assets) host matched at the edge
botDetectionIds Array of detections ids that matched this request
botDetectionTags Array of detections tags that matched this request
botScore The final score originated from bot management detections.
botScoreSrcName Name of the source detection which generated the bot management score.
clientASNDescription The ASN of the visitor as string
clientAsn The ASN number of the visitor
clientCountryName Country from which request originated
clientIP The visitor's IP address (IPv4 or IPv6)
clientIPClass The classification of the visitor's IP address, possible values are: unknown | clean | badHost | searchEngine | allowlist | greylist | monitoringService | securityScanner | noRecord | scan | backupService | mobilePlatform | tor
clientRefererHost The referer host
clientRefererPath The referer path requested by visitor
clientRefererQuery The referer query-string was requested by the visitor
clientRefererScheme The referer url scheme requested by the visitor
clientRequestHTTPHost The HTTP hostname requested by the visitor
clientRequestHTTPMethodName The HTTP method used by the visitor
clientRequestHTTPProtocol The version of HTTP protocol requested by the visitor
clientRequestPath The path requested by visitor
clientRequestQuery The query-string was requested by the visitor
clientRequestScheme The url scheme requested by the visitor
contentScanHasFailed 1 if not all contents for this request where successfully scanned, else 0
contentScanNumMaliciousObj Number of scannable content objects that are malicious
contentScanNumObj Number of scannable content objects
contentScanObjResults Array of scan results in order of detection
contentScanObjSizes Array of scan sizes in order of detection
contentScanObjTypes Array of content types in order of detection
date The date the event occurred at the edge
datetime The date and time the event occurred at the edge
datetimeFifteenMinutes The date and time the event occurred at the edge truncated to a multiple of 15 minutes
datetimeFiveMinutes The date and time the event occurred at the edge truncated to a multiple of 5 minutes
datetimeHour The date and time the event occurred at the edge truncated to hours
datetimeMinute The date and time the event occurred at the edge truncated to the minute
description The description of the rule triggered by this request
edgeColoName The airport code of the Cloudflare datacenter that served this request
edgeResponseStatus HTTP response status code returned to browser
firewallForAiAnyPiiCategory Whether firewallForAiPiiCategories is non empty. 0 if empty, 1 if not empty.
firewallForAiCustomTopicCategories Corresponds to the Ruleset field cf.llm.prompt.custom_topic_categories.
firewallForAiCustomTopicCategoriesScoresMin Minimum score across all the defined firewall for ai custom topics; 100 if empty.
firewallForAiInjectionScore Corresponds to the Ruleset field cf.llm.prompt.injection_score.
firewallForAiPiiCategories Corresponds to the Ruleset field cf.llm.prompt.pii_categories.
firewallForAiUnsafeTopicCategories Corresponds to the Ruleset field cf.llm.prompt.unsafe_data_categories.
fraudAttack The primary attack or use case detected in the request by Fraud detections
fraudDetectionIds Array of fraud detections ids that matched this request
fraudDetectionTags Array of fraud detections tags that matched this request
fraudEmailRisk Risk of a specific email address in account signup attempts
fraudEventType Identifies action that a given user is performing. Possible values are login, signup.
fraudUserId A unique identifier generated by the Fraud Detection system for each user, generated during any action determined by the fraud event type.
httpApplicationVersion DEPRECATED (Field is replaced with zoneVersion): Version associated with HTTP Application
ja3Hash MD5 hash of the JA3 TLS fingerprint
ja4 JA4 TLS fingerprint
ja4Signals Inter-request statistics computed for this JA4 across Cloudflare's entire global edge network
jsDetectionPassed Whether the request passed background JavaScript Detection
kind The kind of event, currently only possible values are: firewall
leakedCredentialCheckResult The distinct result of checking for leaked credentials
matchIndex Rules match index in the chain
metadata Additional product-specific information. Metadata is organized in key:value pairs
originResponseStatus HTTP origin response status code returned to browser
originatorRayName The RayId of the request that issued the challenge/jschallenge
rayName The RayId of the request
ref The ref-field is a user-defined rule identifier that can be set via the API for some firewall products and allows users to label their rules individually alongside cloudflare provided identifiers (only available to entitled customers)
ruleId The Cloudflare security product-specific RuleId triggered by this request
rulesetId The Cloudflare security product-specific RulesetId triggered by this request
sampleInterval ABR sample interval
source The Cloudflare security product triggered by this request
userAgent visitor's user-agent string
verifiedBotCategory The category of verified bot
wafAttackScore Beta. Overall request score generated by the WAF detection module
wafAttackScoreClass Beta. Overall request score class generated by the WAF detection module
wafMlAttackScore DEPRECATED (Field is replaced with wafAttackScore): Beta. Overall request score generated by the WAF detection module
wafMlSqliAttackScore DEPRECATED (Field is replaced with wafSqliAttackScore): Beta. WAF ML score for an SQLi attack
wafMlXssAttackScore DEPRECATED (Field is replaced with wafXssAttackScore): Beta. WAF ML score for an XSS attack
wafPathTraversalAttackScore Beta. WAF score for a Path Traversal attack
wafRceAttackScore Beta. WAF score for a RCE attack
wafRequestSignatureCategories 1-D array of the categories associated with the rules ref in wafRequestSignatureRefs
wafRequestSignatureRefs cf.waf.signature.request.refs Ruleset field truncated to maximum 10 elements.
wafSqliAttackScore Beta. WAF score for a SQLi attack
wafXssAttackScore Beta. WAF score for a XSS attack
zoneTag Associated zone
zoneVersion The version of a zone

AccountFirewallEventsAdaptiveFirewallForAiCustomTopicCategoriesElem

FieldDescription
score Topic score
topicLabel Topic label

AccountFirewallEventsAdaptiveGroups

Aggregated Firewall events with adaptive sampling

FieldDescription
avg The average value used for sample interval
confidence ALPHA - DO NOT USE
count The sum of sample interval values
dimensions List of dimensions to group by
sum

AccountFirewallEventsAdaptiveGroupsAvg

FieldDescription
sampleInterval

AccountFirewallEventsAdaptiveGroupsConfidence

FieldDescription
count The sum of sample interval values, with confidence intervals
level Confidence level that was requested

AccountFirewallEventsAdaptiveGroupsDimensions

FieldDescription
action The code of the first-class action the Cloudflare Firewall took on this request
apiGatewayMatchedEndpoint API Gateway (Web Assets) endpoint matched at the edge
apiGatewayMatchedHost API Gateway (Web Assets) host matched at the edge
botDetectionIds Array of detections ids that matched this request
botDetectionTags Array of detections tags that matched this request
botScore The final score originated from bot management detections.
botScoreSrcName Name of the source detection which generated the bot management score.
clientASNDescription The ASN of the visitor as string
clientAsn The ASN number of the visitor
clientCountryName Country from which request originated
clientIP The visitor's IP address (IPv4 or IPv6)
clientIPClass The classification of the visitor's IP address, possible values are: unknown | clean | badHost | searchEngine | allowlist | greylist | monitoringService | securityScanner | noRecord | scan | backupService | mobilePlatform | tor
clientRefererHost The referer host
clientRefererPath The referer path requested by visitor
clientRefererQuery The referer query-string was requested by the visitor
clientRefererScheme The referer url scheme requested by the visitor
clientRequestHTTPHost The HTTP hostname requested by the visitor
clientRequestHTTPMethodName The HTTP method used by the visitor
clientRequestHTTPProtocol The version of HTTP protocol requested by the visitor
clientRequestPath The path requested by visitor
clientRequestQuery The query-string was requested by the visitor
clientRequestScheme The url scheme requested by the visitor
contentScanHasFailed 1 if not all contents for this request where successfully scanned, else 0
contentScanNumMaliciousObj Number of scannable content objects that are malicious
contentScanNumObj Number of scannable content objects
contentScanObjResults Array of scan results in order of detection
contentScanObjSizes Array of scan sizes in order of detection
contentScanObjTypes Array of content types in order of detection
date The date the event occurred at the edge
datetime The date and time the event occurred at the edge
datetimeFifteenMinutes The date and time the event occurred at the edge truncated to a multiple of 15 minutes
datetimeFiveMinutes The date and time the event occurred at the edge truncated to a multiple of 5 minutes
datetimeHour The date and time the event occurred at the edge truncated to hours
datetimeMinute The date and time the event occurred at the edge truncated to the minute
description The description of the rule triggered by this request
edgeColoName The airport code of the Cloudflare datacenter that served this request
edgeResponseStatus HTTP response status code returned to browser
firewallForAiAnyPiiCategory Whether firewallForAiPiiCategories is non empty. 0 if empty, 1 if not empty.
firewallForAiCustomTopicCategoriesScoresMin Minimum score across all the defined firewall for ai custom topics; 100 if empty.
firewallForAiInjectionScore Corresponds to the Ruleset field cf.llm.prompt.injection_score.
firewallForAiPiiCategories Corresponds to the Ruleset field cf.llm.prompt.pii_categories.
firewallForAiUnsafeTopicCategories Corresponds to the Ruleset field cf.llm.prompt.unsafe_data_categories.
fraudAttack The primary attack or use case detected in the request by Fraud detections
fraudDetectionIds Array of fraud detections ids that matched this request
fraudDetectionTags Array of fraud detections tags that matched this request
fraudEmailRisk Risk of a specific email address in account signup attempts
fraudEventType Identifies action that a given user is performing. Possible values are login, signup.
fraudUserId A unique identifier generated by the Fraud Detection system for each user, generated during any action determined by the fraud event type.
httpApplicationVersion DEPRECATED (Field is replaced with zoneVersion): Version associated with HTTP Application
ja3Hash MD5 hash of the JA3 TLS fingerprint
ja4 JA4 TLS fingerprint
jsDetectionPassed Whether the request passed background JavaScript Detection
kind The kind of event, currently only possible values are: firewall
matchIndex Rules match index in the chain
originResponseStatus HTTP origin response status code returned to browser
originatorRayName The RayId of the request that issued the challenge/jschallenge
rayName The RayId of the request
ref The ref-field is a user-defined rule identifier that can be set via the API for some firewall products and allows users to label their rules individually alongside cloudflare provided identifiers (only available to entitled customers)
ruleId The Cloudflare security product-specific RuleId triggered by this request
rulesetId The Cloudflare security product-specific RulesetId triggered by this request
sampleInterval ABR sample interval
source The Cloudflare security product triggered by this request
userAgent visitor's user-agent string
verifiedBotCategory The category of verified bot
wafAttackScore Beta. Overall request score generated by the WAF detection module
wafAttackScoreClass Beta. Overall request score class generated by the WAF detection module
wafMlAttackScore DEPRECATED (Field is replaced with wafAttackScore): Beta. Overall request score generated by the WAF ML detection module
wafMlSqliAttackScore DEPRECATED (Field is replaced with wafSqliAttackScore): Beta. WAF ML score for an SQLi attack
wafMlXssAttackScore DEPRECATED (Field is replaced with wafXssAttackScore): Beta. WAF ML score for an XSS attack
wafPathTraversalAttackScore Beta. WAF score for a Path Traversal attack
wafRceAttackScore Beta. WAF score for a RCE attack
wafRequestSignatureCategories 1-D array of the categories associated with the rules ref in wafRequestSignatureRefs
wafRequestSignatureRefs cf.waf.signature.request.refs Ruleset field truncated to maximum 10 elements.
wafSqliAttackScore Beta. WAF score for a SQLi attack
wafXssAttackScore Beta. WAF score for a XSS attack
zoneTag Associated zone
zoneVersion The version of a zone

AccountFirewallEventsAdaptiveGroupsSum

FieldDescription
botDetectionIdArray Array of bot management detection ids
botDetectionIdCountArray Count array of bot management detection ids. Elements in this array correspond to elements in botDetectionIdArray by index.
botDetectionTagArray Array of bot management detection tags
botDetectionTagCountArray Count array of bot management detection tags. Elements in this array correspond to elements in botDetectionTagArray by index.
fraudDetectionIdArray Array of fraud detection ids
fraudDetectionIdCountArray Count array of fraud detection ids. Elements in this array correspond to elements in fraudDetectionIdArray by index.
fraudDetectionTagArray Array of fraud detection tags
fraudDetectionTagCountArray Count array of fraud detection tags. Elements in this array correspond to elements in fraudDetectionTagArray by index.

AccountFirewallEventsAdaptiveJa4SignalsElem

FieldDescription
signalName Signal name
signalValue Signal value

AccountFirewallEventsAdaptiveMetadataElem

FieldDescription
key The key of the metadata. Key format can vary by Cloudflare security product and can change over time.
value The value of the metadata. Value format can vary by Cloudflare security product and can change over time.

AccountFlagshipFlagEvaluationsAdaptive

Flagship feature flag evaluations with adaptive sampling. Each row represents an individual flag evaluation.

FieldDescription
appId The Flagship application identifier the evaluation belongs to
colo The Cloudflare colo that served the evaluation
datetime The time the flag evaluation occurred
durationMs End-to-end evaluation duration in milliseconds
evaluationContext The evaluation context (per-evaluation attributes supplied by the caller)
evaluationReason The reason the flag resolved to this value (for example: targeting match, default, fallback)
flagEnabled Whether the flag was enabled for this evaluation ('true' or 'false')
flagKey The key of the feature flag that was evaluated
flagValue The value returned by the flag evaluation. Note: high-cardinality - prefer filtering over grouping for large time windows
matchedRulePriority Priority of the targeting rule that matched (NaN if no rule matched)
sampleInterval ABR sample interval used for this row
variant The variant returned by the evaluation (for multi-variant flags)

AccountFlagshipFlagEvaluationsAdaptiveGroups

Aggregated Flagship feature flag evaluations with adaptive sampling. Use this to build dashboards over evaluation volume, latency, and error rates.

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count The number of flag evaluations
dimensions List of dimensions to group by
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension
uniq Exact count of unique values per dimension

AccountFlagshipFlagEvaluationsAdaptiveGroupsAvg

FieldDescription
durationMs The average end-to-end evaluation duration in milliseconds
sampleInterval The average value used for sample interval

AccountFlagshipFlagEvaluationsAdaptiveGroupsConfidence

FieldDescription
count The number of flag evaluations, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountFlagshipFlagEvaluationsAdaptiveGroupsDimensions

FieldDescription
appId The Flagship application identifier the evaluation belongs to
colo The Cloudflare colo that served the evaluation
date The date the flag evaluation occurred
datetime The date and time the flag evaluation occurred
datetimeFifteenMinutes The date and time the flag evaluation occurred truncated to fifteen minutes
datetimeFiveMinutes The date and time the flag evaluation occurred truncated to five minutes
datetimeHour The date and time the flag evaluation occurred truncated to the hour
datetimeMinute The date and time the flag evaluation occurred truncated to the minute
datetimeSixHours The date and time the flag evaluation occurred truncated to start of six hour window
evaluationReason The reason the flag resolved to this value (for example: targeting match, default, fallback)
flagEnabled Whether the flag was enabled for this evaluation ('true' or 'false')
flagKey The key of the feature flag that was evaluated
flagValue The value returned by the flag evaluation. Note: high-cardinality - prefer filtering over grouping for large time windows
variant The variant returned by the evaluation (for multi-variant flags)

AccountFlagshipFlagEvaluationsAdaptiveGroupsQuantiles

FieldDescription
durationMsP25 Evaluation duration in milliseconds (25th percentile)
durationMsP50 Evaluation duration in milliseconds (50th percentile)
durationMsP75 Evaluation duration in milliseconds (75th percentile)
durationMsP90 Evaluation duration in milliseconds (90th percentile)
durationMsP95 Evaluation duration in milliseconds (95th percentile)
durationMsP99 Evaluation duration in milliseconds (99th percentile)
durationMsP999 Evaluation duration in milliseconds (99.9th percentile)

AccountFlagshipFlagEvaluationsAdaptiveGroupsSum

FieldDescription
durationMs The total end-to-end evaluation duration in milliseconds
errors The number of flag evaluations that resulted in an error

AccountFlagshipFlagEvaluationsAdaptiveGroupsSumConfidence

FieldDescription
durationMs Confidence interval for the corresponding point estimate
errors Confidence interval for the corresponding point estimate

AccountFlagshipFlagEvaluationsAdaptiveGroupsUniq

FieldDescription
appId The number of distinct Flagship applications
flagKey The number of distinct flag keys evaluated

AccountFlowtrackdNetworkAnalyticsAdaptiveGroups

Network analytics data for flowtrackd

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountFlowtrackdNetworkAnalyticsAdaptiveGroupsAvg

FieldDescription
bitRate Sum of bits received, divided by 1 second, providing a per-second bit rate when grouped by datetime
bitRateDay Sum of bits received, divided by 86400 seconds, providing a per-second bit rate when grouped by date
bitRateFifteenMinutes Sum of bits received, divided by 900 seconds, providing a per-second bit rate when grouped by datetimeFifteenMinutes
bitRateFiveMinutes Sum of bits received, divided by 300 seconds, providing a per-second bit rate when grouped by datetimeFiveMinutes
bitRateHour Sum of bits received, divided by 3600 seconds, providing a per-second bit rate when grouped by datetimeHour
bitRateMinute Sum of bits received, divided by 60 seconds, providing a per-second bit rate when grouped by datetimeMinute
bitRateTenSeconds Sum of bits received, divided by 10 seconds, providing a per-second bit rate when grouped by datetimeTenSeconds
packetRate Sum of packets received, divided by 1 second, providing a per-second packet rate when grouped by datetime
packetRateDay Sum of packets received, divided by 86400 seconds, providing a per-second packet rate when grouped by date
packetRateFifteenMinutes Sum of packets received, divided by 900 seconds, providing a per-second packet rate when grouped by datetimeFifteenMinutes
packetRateFiveMinutes Sum of packets received, divided by 300 seconds, providing a per-second packet rate when grouped by datetimeFiveMinutes
packetRateHour Sum of packets received, divided by 3600 seconds, providing a per-second packet rate when grouped by datetimeHour
packetRateMinute Sum of packets received, divided by 60 seconds, providing a per-second packet rate when grouped by datetimeMinute
packetRateTenSeconds Sum of packets received, divided by 10 seconds, providing a per-second packet rate when grouped by datetimeTenSeconds

AccountFlowtrackdNetworkAnalyticsAdaptiveGroupsAvgConfidence

FieldDescription
bitRate Confidence interval for the corresponding point estimate
bitRateDay Confidence interval for the corresponding point estimate
bitRateFifteenMinutes Confidence interval for the corresponding point estimate
bitRateFiveMinutes Confidence interval for the corresponding point estimate
bitRateHour Confidence interval for the corresponding point estimate
bitRateMinute Confidence interval for the corresponding point estimate
bitRateTenSeconds Confidence interval for the corresponding point estimate
packetRate Confidence interval for the corresponding point estimate
packetRateDay Confidence interval for the corresponding point estimate
packetRateFifteenMinutes Confidence interval for the corresponding point estimate
packetRateFiveMinutes Confidence interval for the corresponding point estimate
packetRateHour Confidence interval for the corresponding point estimate
packetRateMinute Confidence interval for the corresponding point estimate
packetRateTenSeconds Confidence interval for the corresponding point estimate

AccountFlowtrackdNetworkAnalyticsAdaptiveGroupsConfidence

FieldDescription
avg The average of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountFlowtrackdNetworkAnalyticsAdaptiveGroupsDimensions

FieldDescription
applicationTag Application tag associated with the packet
coloCity City where the Cloudflare datacenter that received the packet is located
coloCode Cloudflare datacenter that received the packet (nearest IATA airport code)
coloCountry Country where the Cloudflare datacenter that received the packet is located (ISO 3166-1 alpha-2)
coloGeohash Latitude and longitude where the Cloudflare datacenter that received the packet is located (Geohash encoding)
coloName Cloudflare datacenter that received the packet (unique site identifier)
date Date that the packet was received
datetime Date and time that the packet was received
datetimeFifteenMinutes Date and time that the packet was received, rounded to the start of the nearest fifteen minutes
datetimeFiveMinutes Date and time that the packet was received, rounded to the start of the nearest five minutes
datetimeHour Date and time that the packet was received, rounded to the start of the nearest hour
datetimeMinute Date and time that the packet was received, rounded to the start of the nearest minute
datetimeTenSeconds Date and time that the packet was received, rounded to the start of the nearest ten seconds
destinationAsn ASN associated with the destination IP of the packet, or 0 if there was no mapping available
destinationAsnName Name of ASN associated with the destination IP of the packet, if available
destinationCountry Country where the destination IP of the packet is located (ISO 3166-1 alpha-2)
destinationGeohash Latitude and longitude where the destination IP of the packet is located (Geohash encoding)
destinationPort Value of the Destination Port header field in the TCP or UDP packet
direction Direction of the packet relative to the customer network (possible values: inbound, outbound, lateral)
ethertype Value of the Ethertype header field in the Ethernet packet (2048 for IPv4; 34525 for IPv6)
greChecksum Value of the Checkusm header field in the GRE packet
greEthertype Value of the Ethertype header field in the GRE packet
greHeaderLength Length of the GRE packet header, in bytes
greKey Value of the Key header field in the GRE packet
greSequenceNumber Value of the Sequence Number header field in the GRE packet
greVersion Value of the Version header field in the GRE packet
icmpChecksum Value of the Checkusm header field in the ICMP packet
icmpCode Value of the Code header field in the ICMP packet
icmpType Value of the Type header field in the ICMP packet
ipDestinationAddress Value of the Destination Address header field in the IPv4 or IPv6 packet
ipDestinationSubnet Computed subnet of the Destination Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipFragmentOffset Value of the Fragment Offset header field in the IPv4 or IPv6 packet
ipHeaderLength Length of the IPv4 or IPv6 packet header, in bytes
ipMoreFragments Value of the More Fragments header field in the IPv4 or IPv6 packet
ipProtocol Value of the Protocol header field in the IPv4 or IPv6 packet
ipProtocolName Name of the protocol specified by the Protocol header field in the IPv4 or IPv6 packet
ipSourceAddress Value of the Source Address header field in the IPv4 or IPv6 packet
ipSourceSubnet Computed subnet of the Source Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipTotalLength Total length of the IPv4 or IPv6 packet, in bytes
ipTotalLengthBuckets Total length of the IPv4 or IPv6 packet, in bytes, with the last two digits truncated
ipTtl Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet
ipTtlBuckets Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet, with the last digit truncated
ipv4Checksum Value of the Checksum header field in the IPv4 packet
ipv4DontFragment Value of the Don't Fragment header field in the IPv4 packet
ipv4Dscp Value of the Differentiated Services Code Point header field in the IPv4 packet
ipv4Ecn Value of the Explicit Congestion Notification header field in the IPv4 packet
ipv4Identification Value of the Identification header field in the IPv4 packet
ipv4Options List of Options numbers included in the IPv4 packet header
ipv6Dscp Value of the Differentiated Services Code Point header field in the IPv6 packet
ipv6Ecn Value of the Explicit Congestion Notification header field in the IPv6 packet
ipv6ExtensionHeaders List of Extension Header numbers included in the IPv6 packet header
ipv6FlowLabel Value of the Flow Label header field in the IPv6 packet
ipv6Identification Value of the Identification extension header field in the IPv6 packet
leaseTag IP lease tag associated with the packet
mitigationReason Reason for applying a mitigation to the packet, if any
mitigationScope Whether the packet matched a local or global mitigation, if any (possible values: local, global)
outcome The action that was taken on the packet (possible values: pass, drop)
prefixTag IP prefix tag associated with the packet
protocolState State of the packet in the context of the protocol, if available
sampleInterval ABR sample interval
sourceAsn ASN associated with the source IP of the packet, or 0 if there was no mapping available
sourceAsnName Name of ASN associated with the source IP of the packet, if available
sourceCountry Country where the source IP of the packet is located (ISO 3166-1 alpha-2)
sourceGeohash Latitude and longitude where the source IP of the packet is located (Geohash encoding)
sourcePort Value of the Source Port header field in the TCP or UDP packet
tcpAcknowledgementNumber Value of the Acknowledgement Number header field in the TCP packet
tcpChecksum Value of the Checkusm header field in the TCP packet
tcpDataOffset Value of the Data Offset header field in the TCP packet
tcpFlags Value of the Flags header field in the TCP packet
tcpFlagsString Human-readable string representation of the Flags header field in the TCP packet
tcpMss Value of the MSS option header field in the TCP packet
tcpOptions List of Options numbers included in the TCP packet header
tcpSackBlocks Value of the SACK Blocks option header field in the TCP packet
tcpSackPermitted Value of the SACK Permitted option header field in the TCP packet
tcpSequenceNumber Value of the Sequence Number header field in the TCP packet
tcpTimestampEcr Value of the Timestamp Echo Reply option header field in the TCP packet
tcpTimestampValue Value of the Timestamp option header field in the TCP packet
tcpUrgentPointer Value of the Urgent Pointer header field in the TCP packet
tcpWindowScale Value of the Window Scale option header field in the TCP packet
tcpWindowSize Value of the Window Size header field in the TCP packet
udpChecksum Value of the Checkusm header field in the UDP packet
udpPayloadLength Value of the Payload Length header field in the UDP packet
verdict The action that Cloudflare thinks should be taken on the packet (possible values: pass, drop)

AccountFlowtrackdNetworkAnalyticsAdaptiveGroupsSum

FieldDescription
bits Sum of bits received
packets Sum of packets received

AccountFlowtrackdNetworkAnalyticsAdaptiveGroupsSumConfidence

FieldDescription
bits Confidence interval for the corresponding point estimate
packets Confidence interval for the corresponding point estimate

AccountGatewayL4DownstreamSessionsAdaptiveGroups

Aggregated metrics about downstream (client to edge) L4 Gateway Sessions. Metrics are reported on TCP or UDP session close

FieldDescription
confidence ALPHA - DO NOT USE
count The number of downstream sessions
dimensions List of dimensions to group by
quantiles
sum

AccountGatewayL4DownstreamSessionsAdaptiveGroupsConfidence

FieldDescription
count The number of downstream sessions, with confidence intervals
level Confidence level that was requested
sum

AccountGatewayL4DownstreamSessionsAdaptiveGroupsDimensions

FieldDescription
coloCode IATA Airport code that represents the city in which a Cloudflare data center (colo) is located
coloCountry ISO 3166-1 alpha-2 code that represents the country in which a Cloudflare data center (colo) is located
date Start timestamp of this session, truncated to date
datetimeFifteenMinutes Start timestamp of this session, truncated to multiple of 15 minutes
datetimeFiveMinutes Start timestamp of this session, truncated to multiple of 5 minutes
datetimeHour Start timestamp of this session, truncated to the hour
datetimeMinute Start timestamp of this session, truncated to the minute
quicErrorCode QUIC specific error code. Possible values are https://www.iana.org/assignments/quic/quic.xhtml#quic-transport-error-codes
rttUs Last Round Trip Time estimation for this session in microseconds
sessionId Identifier for this session
sourceIP IP address of the client making this session
tokenAuthStatus Client token authentication status. Possible values are success | failed with invalid token and upto date token key ID | failed with invalid token due to outdated/missing token key ID | failed due to reused token
tokenSigningRegion Broad location assigned to client in this session
transport Transport protocol used for this session. Possible values are tcp | quic | udp
transportHandshakeDurationUs Time taken for TCP/TLS or QUIC handshake in microsecond
transportStatus Transport Status. Possible values are unknown | success | failure

AccountGatewayL4DownstreamSessionsAdaptiveGroupsQuantiles

FieldDescription
tokenAuthDurationUsP25 Time taken for Client Token Authentication in microseconds (25th percentile)
tokenAuthDurationUsP50 Time taken for Client Token Authentication in microseconds (50th percentile)
tokenAuthDurationUsP75 Time taken for Client Token Authentication in microseconds (75th percentile)
tokenAuthDurationUsP90 Time taken for Client Token Authentication in microseconds (90th percentile)
tokenAuthDurationUsP95 Time taken for Client Token Authentication in microseconds (95th percentile)
tokenAuthDurationUsP99 Time taken for Client Token Authentication in microseconds (99th percentile)
tokenAuthDurationUsP999 Time taken for Client Token Authentication in microseconds (99.9th percentile)
transportHandshakeDurationUsP25 Time taken for TCP/TLS or QUIC handshake in microseconds (25th percentile)
transportHandshakeDurationUsP50 Time taken for TCP/TLS or QUIC handshake in microseconds (50th percentile)
transportHandshakeDurationUsP75 Time taken for TCP/TLS or QUIC handshake in microseconds (75th percentile)
transportHandshakeDurationUsP90 Time taken for TCP/TLS or QUIC handshake in microseconds (90th percentile)
transportHandshakeDurationUsP95 Time taken for TCP/TLS or QUIC handshake in microseconds (95th percentile)
transportHandshakeDurationUsP99 Time taken for TCP/TLS or QUIC handshake in microseconds (99th percentile)
transportHandshakeDurationUsP999 Time taken for TCP/TLS or QUIC handshake in microseconds (99.9th percentile)

AccountGatewayL4DownstreamSessionsAdaptiveGroupsSum

FieldDescription
bytesRecvd Total bytes received in this session
bytesSent Total bytes sent in this session
clientBytesRetransmitted Total bytes retransmitted by client in this session
packetsRecvd Total number of packets received in this session
packetsSent Total number of packets sent in this session
tokenAuthDurationUs Time taken for client token authentication in microseconds

AccountGatewayL4DownstreamSessionsAdaptiveGroupsSumConfidence

FieldDescription
bytesRecvd Confidence interval for the corresponding point estimate
bytesSent Confidence interval for the corresponding point estimate
clientBytesRetransmitted Confidence interval for the corresponding point estimate
packetsRecvd Confidence interval for the corresponding point estimate
packetsSent Confidence interval for the corresponding point estimate
tokenAuthDurationUs Confidence interval for the corresponding point estimate

AccountGatewayL4SessionsAdaptiveGroups

BETA - Aggregate counts of Gateway L4 sessions with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count The number of Gateway L4 sessions
dimensions List of dimensions to group by

AccountGatewayL4SessionsAdaptiveGroupsConfidence

FieldDescription
count The number of Gateway L4 sessions, with confidence intervals
level Confidence level that was requested

AccountGatewayL4SessionsAdaptiveGroupsDimensions

FieldDescription
action action taken by gateway
applicationIds IDs of the applications that matched the session parameters
applicationNames Names of the applications that matched the session parameters
categoryIds IDs of the categories that matched the session parameters
categoryNames Names of the categories that matched the session parameters
coloCode Colo Code of edge server
date Date that the session was started, truncated to the start of a day
datetime Datetime that the session was started
datetimeFifteenMinutes Datetime that the session was started truncated to fifteen minutes
datetimeFiveMinutes Datetime that the session was started truncated to five minutes
datetimeHour Datetime that the session was started truncated to hours
datetimeMinute Datetime that the session was started truncated to minutes
destinationIp The destination IP address for the session
destinationPort The destination port for the session
detectedProtocol The detected protocol of network traffic
deviceId The device ID of the gateway user who initiated the session
dstIpContinent Continent code of the session destination IP address
dstIpCountry Country code of the session destination IP address
email The email address of the gateway user who initiated the session
proxyEndpoint The proxy endpoint used on this session
sessionId The network session unique identifier
sni The SNI pulled from the session tls handshake, if present
sourceInternalIp Local LAN IP of the device. Only available when connected via a GRE/IPsec tunnel on-ramp
sourceIp The source IP address for the session
sourcePort The source port for the session
srcIpContinent Continent code of the session source IP address
srcIpCountry Country code of the session source IP address
tenantId The tenant ID the session belongs to, if applicable
transport DEPRECATED (Field is replaced with transportProtocol): The transport protocol used in the session, one of (0, tcp) (1, quic) (2, udp). Deprecated, please use transportProtocol
transportProtocol The transport protocol used in the session, one of (0, tcp) (1, quic) (2, udp)
userId The ID of the gateway user who initiated the session
virtualNetworkId The ID of the virtual nework the device was connected to
virtualNetworkName The name of the virtual nework the device was connected to

AccountGatewayL4UpstreamSessionsAdaptiveGroups

Aggregated metrics about upstream (edge to client) L4 Gateway Sessions. Metrics are reported on TCP, QUIC or UDP session close

FieldDescription
confidence ALPHA - DO NOT USE
count The number of upstream sessions
dimensions List of dimensions to group by
quantiles
sum

AccountGatewayL4UpstreamSessionsAdaptiveGroupsConfidence

FieldDescription
count The number of upstream sessions, with confidence intervals
level Confidence level that was requested
sum

AccountGatewayL4UpstreamSessionsAdaptiveGroupsDimensions

FieldDescription
coloCode IATA Airport code that represents the city in which a Cloudflare data center (colo) is located
coloCountry ISO 3166-1 alpha-2 code that represents the country in which a Cloudflare data center (colo) is located
date Start timestamp of this session, truncated to date
datetimeFifteenMinutes Start timestamp of this session, truncated to multiple of 15 minutes
datetimeFiveMinutes Start timestamp of this session, truncated to multiple of 5 minutes
datetimeHour Start timestamp of this session, truncated to the hour
datetimeMinute Start timestamp of this session, truncated to the minute
destinationIP IP address of the origin server
domainName SNI domain name for this session
downstreamSessionId Downstream session identifier of this session
httpConnectReqStatus Client HTTP CONNECT request status. Possible values are unknown | success | failure
quicErrorCode QUIC error code. Possible values are https://www.iana.org/assignments/quic/quic.xhtml#quic-transport-error-codes
rttUs Last Round Trip Time estimation for this session in microseconds
tokenSigningRegion Broad location assigned to client in this session
totalTunnelSetupDurationUs Total time taken for tunnel setup in microseconds
transport Transport protocol used for this session. Possible values are tcp | quic | udp
transportStatus Transport status. Possible values are unknown | success | failure

AccountGatewayL4UpstreamSessionsAdaptiveGroupsQuantiles

FieldDescription
connectReqHandlingDurationUsP25 Time taken for CONNECT request handling in microseconds (25th percentile)
connectReqHandlingDurationUsP50 Time taken for CONNECT request handling in microseconds (50th percentile)
connectReqHandlingDurationUsP75 Time taken for CONNECT request handling in microseconds (75th percentile)
connectReqHandlingDurationUsP90 Time taken for CONNECT request handling in microseconds (90th percentile)
connectReqHandlingDurationUsP95 Time taken for CONNECT request handling in microseconds (95th percentile)
connectReqHandlingDurationUsP99 Time taken for CONNECT request handling in microseconds (99th percentile)
connectReqHandlingDurationUsP999 Time taken for CONNECT request handling in microseconds (99.9th percentile)
totalTunnelSetupDurationUsP25 Total time taken for tunnel setup in microseconds (25th percentile)
totalTunnelSetupDurationUsP50 Total time taken for tunnel setup in microseconds (50th percentile)
totalTunnelSetupDurationUsP75 Total time taken for tunnel setup in microseconds (75th percentile)
totalTunnelSetupDurationUsP90 Total time taken for tunnel setup in microseconds (90th percentile)
totalTunnelSetupDurationUsP95 Total time taken for tunnel setup in microseconds (95th percentile)
totalTunnelSetupDurationUsP99 Total time taken for tunnel setup in microseconds (99th percentile)
totalTunnelSetupDurationUsP999 Total time taken for tunnel setup in microseconds (99.9th percentile)
tunnelSetupDurationUsP25 Time taken to setup the tunnel in microseconds (25th percentile)
tunnelSetupDurationUsP50 Time taken to setup the tunnel in microseconds (50th percentile)
tunnelSetupDurationUsP75 Time taken to setup the tunnel in microseconds (75th percentile)
tunnelSetupDurationUsP90 Time taken to setup the tunnel in microseconds (90th percentile)
tunnelSetupDurationUsP95 Time taken to setup the tunnel in microseconds (95th percentile)
tunnelSetupDurationUsP99 Time taken to setup the tunnel in microseconds (99th percentile)
tunnelSetupDurationUsP999 Time taken to setup the tunnel in microseconds (99.9th percentile)

AccountGatewayL4UpstreamSessionsAdaptiveGroupsSum

FieldDescription
bytesRecvd Total bytes received in this session
bytesSent Total bytes sent in this session
connectReqHandlingDurationUs Time taken for CONNECT request handling in microseconds
originBytesRetransmitted Total bytes retransmitted by origin in this session
packetsRecvd Total number of packets received in this session
packetsSent Total number of packets sent in this session
totalTunnelSetupDurationUs Total time taken for tunnel setup in microseconds
tunnelSetupDurationUs Time taken for tunnel setup in microseconds

AccountGatewayL4UpstreamSessionsAdaptiveGroupsSumConfidence

FieldDescription
bytesRecvd Confidence interval for the corresponding point estimate
bytesSent Confidence interval for the corresponding point estimate
connectReqHandlingDurationUs Confidence interval for the corresponding point estimate
originBytesRetransmitted Confidence interval for the corresponding point estimate
packetsRecvd Confidence interval for the corresponding point estimate
packetsSent Confidence interval for the corresponding point estimate
totalTunnelSetupDurationUs Confidence interval for the corresponding point estimate
tunnelSetupDurationUs Confidence interval for the corresponding point estimate

AccountGatewayL7RequestsAdaptiveGroups

BETA - Aggregate counts of Gateway L7 requests with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count The number of Gateway L7 requests
dimensions List of dimensions to group by

AccountGatewayL7RequestsAdaptiveGroupsConfidence

FieldDescription
count The number of Gateway L7 requests, with confidence intervals
level Confidence level that was requested

AccountGatewayL7RequestsAdaptiveGroupsDimensions

FieldDescription
action action taken by gateway
applicationIds IDs of the applications that matched the request parameters
applicationNames Names of the applications that matched the request parameters
categoryIds IDs of the categories that matched the request parameters
categoryNames Names of the categories that matched the request parameters
coloCode Colo Code of edge server
date Date that the request happened, truncated to the start of a day
datetime Datetime that the request happened
datetimeFifteenMinutes Datetime that the request happened truncated to fifteen minutes
datetimeFiveMinutes Datetime that the request happened truncated to five minutes
datetimeHour Datetime that the request happened truncated to hours
datetimeMinute Datetime that the request happened truncated to minutes
deviceId The device ID of the gateway user who made the request
dstIpContinent Continent code of the request destination IP address
dstIpCountry Country code of the request destination IP address
email The email address of the gateway user who made the request
httpHost The destination host for the request
httpStatusCode HTTP status code gateway returned to the user. 0 if nothing was returned(e.g client disconnected)
isIsolated Indicates whether this request was made through an isolated link
privateAppAUD Access private app AUD
proxyEndpoint The proxy endpoint used on this request
quarantined Indicates if the request content was quarantined
redirectTargetURI The URI to which the user was redirected
requestId The request unique identifier
sourceInternalIp Local LAN IP of the device. Only available when connected via a GRE/IPsec tunnel on-ramp
srcIpContinent Continent code of the request source IP address
srcIpCountry Country code of the request source IP address
tenantId The tenant ID the request belongs to, if applicable
untrustedCertificateAction Action taken when an untrusted origin certificate error occurs
url The request URL
userId The ID of the gateway user who made the request
virtualNetworkId The ID of the virtual nework the device was connected to
virtualNetworkName The name of the virtual nework the device was connected to

AccountGatewayResolverByCategoryAdaptiveGroups

BETA - Aggregate counts of Gateway Resolver queries by category with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count The number of Gateway Resolver queries
dimensions List of dimensions to group by

AccountGatewayResolverByCategoryAdaptiveGroupsConfidence

FieldDescription
count The number of Gateway Resolver queries, with confidence intervals
level Confidence level that was requested

AccountGatewayResolverByCategoryAdaptiveGroupsDimensions

FieldDescription
authoritativeNameserverIps List of IPs of the authoritative nameservers that provided the answers, if any
categoryId ID of the category that was assigned to the domain
cnames List of resolved intermediate cname domains
customResolverAddress Address at which the custom resolver query was resolved at
customResolverCacheStatus Whether the custom resolver response was cached or not
customResolverResponseCode Response code recieved from the custom resolver 0 => unknown 27 => dnsFirewallSuccess 29 => dnsFirewallCustomerRatelimit 31 => dnsFirewallUpstreamFailure 32 => dnsFirewallUpstreamServfail
date The date the DNS query was resolved, truncated to the start of a day
datetime The date and time the DNS query was resolved
datetimeFifteenMinutes The date and time the event occurred at the edge truncated to fifteen minutes
datetimeFiveMinutes The date and time the event occurred at the edge truncated to five minutes
datetimeHour The date and time the event occurred at the edge truncated to hours
datetimeMinute The date and time the event occurred at the edge truncated to minutes
dohSubdomain The destination DoH subdomain the DNS query was made to
dotSubdomain The destination DoT subdomain the DNS query was made to
edeErrors List of returned Extended DNS Error Codes
internalDnsFallbackStrategy The fallback strategy applied over the internal DNS response. Empty if no fallback strategy was applied
internalDnsRCode The return code sent back by the internal DNS service
internalDnsViewId The DNS internal view identifier that was sent to the internal DNS service
internalDnsZoneId The DNS zone identifier returned by the internal DNS service
locationId The uuid identifying the customer Location used when resolving
matchedApplicationId ID of the application the domain belongs to
matchedApplicationName Name of the application the domain belongs to
policyId ID of the policy/rule that was applied, if any
policyName Name of the policy that was applied, if any
resolvedIpContinents Continent code of each resolved IP, if any
resolvedIpCountries Country code of each resolved IP, if any
resolvedIps List of resolved IPs in the response, if any
resolverDecision Enum identifier for the decision made by gateway-resolver, one of: (0, unknown) (1, allowedByQueryName) (2, blockedByQueryName) (3, blockedByCategory) (4, allowedOnNoLocation) (5, allowedOnNoPolicyMatch) (6, blockedAlwaysCategory) (7, overrideForSafeSearch) (8, overrideApplied) (9, blockedRule) (10, allowedRule)
resolverPolicyId ID of the resolver policy/rule that was applied, if any
resolverPolicyName Name of the resolver policy that was applied, if any
resourceRecordClasses Resource records' classes
resourceRecordNames Resource records' names
resourceRecordRDatas Resource records' rdata values
resourceRecordTTLs Resource records' TTL values
resourceRecordTypes Resource records' types
srcIpContinent Continent code of the source IP address making the DNS query
srcIpCountry Country code of the source IP address making the DNS query

AccountGatewayResolverByCustomResolverGroups

Stats on dns custom resolvers

FieldDescription
avg The average value for a metric
confidence ALPHA - DO NOT USE
count The number of Gateway Resolver queries
dimensions List of dimensions to group by
max Maximum response time

AccountGatewayResolverByCustomResolverGroupsAvg

FieldDescription
customResolverTimeInMs Average latency
sampleInterval Average sample interval

AccountGatewayResolverByCustomResolverGroupsConfidence

FieldDescription
count The number of Gateway Resolver queries, with confidence intervals
level Confidence level that was requested

AccountGatewayResolverByCustomResolverGroupsDimensions

FieldDescription
cacheStatus whether the response was cached or not
customResolverAddress address at which custom resolver query was resolved at
customResolverResponseCode Response code recieved from the custom resolver 0 => unknown 27 => dnsFirewallSuccess 29 => dnsFirewallCustomerRatelimit 31 => dnsFirewallUpstreamFailure 32 => dnsFirewallUpstreamServfail
customResolverTimeInMs time took for custom resolver to respond
date The date the DNS query was resolved, truncated to the start of a day
datetime The date and time the DNS query was resolved
datetimeFifteenMinutes The date and time the event occurred at the edge truncated to fifteen minutes
datetimeFiveMinutes The date and time the event occurred at the edge truncated to five minutes
datetimeHour The date and time the event occurred at the edge truncated to hours
datetimeMinute The date and time the event occurred at the edge truncated to minutes
locationId The uuid identifying the customer Location used when resolving
queryName Name of the query, e.g. one.dash.cloudflare.com
resolverDecision Enum identifier for the decision made by gateway-resolver, one of: (0, unknown) (1, allowedByQueryName) (2, blockedByQueryName) (3, blockedByCategory) (4, allowedOnNoLocation) (5, allowedOnNoPolicyMatch) (6, blockedAlwaysCategory) (7, overrideForSafeSearch) (8, overrideApplied) (9, blockedRule) (10, allowedRule)

AccountGatewayResolverByCustomResolverGroupsMax

FieldDescription
customResolverTimeInMs Maximum response time

AccountGatewayResolverByRuleExecutionPerformanceAdaptiveGroups

Total time spent on executing firewall rules at the edge

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count The number of Gateway Resolver queries
dimensions List of dimensions to group by
max Maximum execution time
quantiles Quantiles of a rule execution performance

AccountGatewayResolverByRuleExecutionPerformanceAdaptiveGroupsAvg

FieldDescription
sampleInterval Average sample interval

AccountGatewayResolverByRuleExecutionPerformanceAdaptiveGroupsConfidence

FieldDescription
count The number of Gateway Resolver queries, with confidence intervals
level Confidence level that was requested

AccountGatewayResolverByRuleExecutionPerformanceAdaptiveGroupsDimensions

FieldDescription
date Request date, truncated to the start of a day
datetime Request timestamp
datetimeFifteenMinutes Request timestamp truncated to fifteen minutes
datetimeFiveMinutes Request timestamp truncated to five minutes
datetimeHour Request timestamp truncated to hours
datetimeMinute Request timestamp truncated to minutes
datetimeMonth Request timestamp month

AccountGatewayResolverByRuleExecutionPerformanceAdaptiveGroupsMax

FieldDescription
executionTime Maximum execution time

AccountGatewayResolverByRuleExecutionPerformanceAdaptiveGroupsQuantiles

FieldDescription
executionTimeMsP25 Execution time performance of 25th percentile in milliseconds
executionTimeMsP50 Execution time performance of 50th percentile in milliseconds
executionTimeMsP75 Execution time performance of 75th percentile in milliseconds
executionTimeMsP90 Execution time performance of 90th percentile in milliseconds
executionTimeMsP95 Execution time performance of 95th percentile in milliseconds
executionTimeMsP98 Execution time performance of 98th percentile in milliseconds
executionTimeMsP99 Execution time performance of 99th percentile in milliseconds
executionTimeMsP999 Execution time performance of 99.9th percentile in milliseconds

AccountGatewayResolverQueriesAdaptiveGroups

BETA - Aggregate counts of Gateway Resolver queries with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count The number of Gateway Resolver queries
dimensions List of dimensions to group by

AccountGatewayResolverQueriesAdaptiveGroupsConfidence

FieldDescription
count The number of Gateway Resolver queries, with confidence intervals
level Confidence level that was requested

AccountGatewayResolverQueriesAdaptiveGroupsDimensions

FieldDescription
authoritativeNameserverIps List of IPs of the authoritative nameservers that provided the answers, if any
categoryIds Json array of categories for this query
categoryNames List of matching categories names for this query
cnames List of resolved intermediate cname domains
customResolverAddress Address at which the custom resolver query was resolved at
customResolverCacheStatus Whether the custom resolver response was cached or not
customResolverResponseCode Response code recieved from the custom resolver 0 => unknown 27 => dnsFirewallSuccess 29 => dnsFirewallCustomerRatelimit 31 => dnsFirewallUpstreamFailure 32 => dnsFirewallUpstreamServfail
date The date the DNS query was resolved, truncated to the start of a day
datetime The date and time the DNS query was resolved
datetimeFifteenMinutes The date and time the event occurred at the edge truncated to fifteen minutes
datetimeFiveMinutes The date and time the event occurred at the edge truncated to five minutes
datetimeHour The date and time the event occurred at the edge truncated to hours
datetimeMinute The date and time the event occurred at the edge truncated to minutes
dohSubdomain The destination DoH subdomain the DNS query was made to
dotSubdomain The destination DoT subdomain the DNS query was made to
edeErrors List of returned Extended DNS Error Codes
internalDnsFallbackStrategy The fallback strategy applied over the internal DNS response. Empty if no fallback strategy was applied
internalDnsRCode The return code sent back by the internal DNS service
internalDnsViewId The DNS internal view identifier that was sent to the internal DNS service
internalDnsZoneId The DNS zone identifier returned by the internal DNS service
locationId The uuid identifying the customer Location used when resolving
locationName The name identifying the customer Location used when resolving
matchedApplicationId ID of the application the domain belongs to
matchedApplicationName Name of the application the domain belongs to
matchedIndicatorFeedIds Json array of indicator feed IDs for this query that matched rule
matchedIndicatorFeedNames List of indicator feed names for this query
policyId ID of the policy/rule that was applied, if any
policyName Name of the policy that was applied, if any
queryName Name of the query, e.g. one.dash.cloudflare.com
queryNameReversed Name of the query in reverse order, e.g. com.cloudflare.dash.one
resolvedIpContinents Continent code of each resolved IP, if any
resolvedIpCountries Country code of each resolved IP, if any
resolvedIps List of resolved IPs in the response, if any
resolverDecision Enum identifier for the decision made by gateway-resolver, one of: (0, unknown) (1, allowedByQueryName) (2, blockedByQueryName) (3, blockedByCategory) (4, allowedOnNoLocation) (5, allowedOnNoPolicyMatch) (6, blockedAlwaysCategory) (7, overrideForSafeSearch) (8, overrideApplied) (9, blockedRule) (10, allowedRule)
resolverPolicyId ID of the resolver policy/rule that was applied, if any
resolverPolicyName Name of the resolver policy that was applied, if any
resourceRecordClasses Resource records' classes
resourceRecordNames Resource records' names
resourceRecordRDatas Resource records' rdata values
resourceRecordTTLs Resource records' TTL values
resourceRecordTypes Resource records' types
scheduleInfo Json object of schedule releated information
srcIpContinent Continent code of the source IP address making the DNS query
srcIpCountry Country code of the source IP address making the DNS query

AccountHttpRequests1dGroups

Daily rollups of request data

FieldDescription
avg The average value for a metric per dimension
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension
uniq The number of unique values for a metric per dimension

AccountHttpRequests1dGroupsAvg

FieldDescription
bytes
edgeRequestBytes
sampleInterval Average sample interval

AccountHttpRequests1dGroupsBrowserMapElem

FieldDescription
pageViews Successful requests for HTML content
uaBrowserFamily Browser type

AccountHttpRequests1dGroupsClientHTTPVersionMapElem

FieldDescription
clientHTTPProtocol HTTP version
requests

AccountHttpRequests1dGroupsClientSSLMapElem

FieldDescription
clientSSLProtocol Protocol version
requests

AccountHttpRequests1dGroupsContentTypeMapElem

FieldDescription
bytes Bytes returned to client
edgeResponseContentTypeName Content type returned to client
requests

AccountHttpRequests1dGroupsCountryMapElem

FieldDescription
bytes Bytes returned to client
clientCountryName Country from which request originated
requests
threats DEPRECATED (Replaced by more granular information in firewallEventsAdaptive* nodes): Requests classified as threats

AccountHttpRequests1dGroupsDimensions

FieldDescription
date Request date

AccountHttpRequests1dGroupsIpClassMapElem

FieldDescription
ipType IP class
requests

AccountHttpRequests1dGroupsResponseStatusMapElem

FieldDescription
edgeResponseStatus HTTP response status code returned to client
requests

AccountHttpRequests1dGroupsSum

FieldDescription
browserMap
bytes Bytes returned to client
cachedBytes Bytes returned to client from cache
cachedRequests Requests served from cache
clientHTTPVersionMap
clientSSLMap
contentTypeMap
countryMap
edgeRequestBytes Bytes sent from client
encryptedBytes Bytes returned to client using SSL/TLS protocol
encryptedRequests Requests served using SSL/TLS protocol
ipClassMap
pageViews Successful requests for HTML content
requests
responseStatusMap
threatPathingMap
threats DEPRECATED (Replaced by more granular information in firewallEventsAdaptive* nodes): Requests classified as threats

AccountHttpRequests1dGroupsThreatPathingMapElem

FieldDescription
requests
threatPathingName Threat type

AccountHttpRequests1dGroupsUniq

FieldDescription
uniques A number of unique IPs

AccountHttpRequests1hGroups

Hourly rollups of request data

FieldDescription
avg The average value for a metric per dimension
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension
uniq The number of unique values for a metric per dimension

AccountHttpRequests1hGroupsAvg

FieldDescription
bytes
edgeRequestBytes
sampleInterval Average sample interval

AccountHttpRequests1hGroupsBrowserMapElem

FieldDescription
pageViews Successful requests for HTML content
uaBrowserFamily Browser type

AccountHttpRequests1hGroupsClientHTTPVersionMapElem

FieldDescription
clientHTTPProtocol HTTP version
requests

AccountHttpRequests1hGroupsClientSSLMapElem

FieldDescription
clientSSLProtocol Protocol version
requests

AccountHttpRequests1hGroupsContentTypeMapElem

FieldDescription
bytes Bytes returned to client
edgeResponseContentTypeName Content type returned to client
requests

AccountHttpRequests1hGroupsCountryMapElem

FieldDescription
bytes Bytes returned to client
clientCountryName Country from which request originated
requests
threats DEPRECATED (Replaced by more granular information in firewallEventsAdaptive* nodes): Requests classified as threats

AccountHttpRequests1hGroupsDimensions

FieldDescription
date Request date
datetime Request datetime truncated to the hour

AccountHttpRequests1hGroupsIpClassMapElem

FieldDescription
ipType IP class
requests

AccountHttpRequests1hGroupsResponseStatusMapElem

FieldDescription
edgeResponseStatus HTTP response status code returned to client
requests

AccountHttpRequests1hGroupsSum

FieldDescription
browserMap
bytes Bytes returned to client
cachedBytes Bytes returned to client from cache
cachedRequests Requests served from cache
clientHTTPVersionMap
clientSSLMap
contentTypeMap
countryMap
edgeRequestBytes Bytes sent from client
encryptedBytes Bytes returned to client using SSL/TLS protocol
encryptedRequests Requests served using SSL/TLS protocol
ipClassMap
pageViews Successful requests for HTML content
requests
responseStatusMap
threatPathingMap
threats DEPRECATED (Replaced by more granular information in firewallEventsAdaptive* nodes): Requests classified as threats

AccountHttpRequests1hGroupsThreatPathingMapElem

FieldDescription
requests
threatPathingName Threat type

AccountHttpRequests1hGroupsUniq

FieldDescription
uniques A number of unique IPs

AccountHttpRequests1mGroups

Minutely rollups of request data

FieldDescription
avg The average value for a metric per dimension
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension
uniq The number of unique values for a metric per dimension

AccountHttpRequests1mGroupsAvg

FieldDescription
bytes
edgeRequestBytes
sampleInterval Average sample interval

AccountHttpRequests1mGroupsBrowserMapElem

FieldDescription
pageViews Successful requests for HTML content
uaBrowserFamily Browser type

AccountHttpRequests1mGroupsClientHTTPVersionMapElem

FieldDescription
clientHTTPProtocol HTTP version
requests

AccountHttpRequests1mGroupsClientSSLMapElem

FieldDescription
clientSSLProtocol Protocol version
requests

AccountHttpRequests1mGroupsContentTypeMapElem

FieldDescription
bytes Bytes returned to client
edgeResponseContentTypeName Content type returned to client
requests

AccountHttpRequests1mGroupsCountryMapElem

FieldDescription
bytes Bytes returned to client
clientCountryName Country from which request originated
requests
threats DEPRECATED (Replaced by more granular information in firewallEventsAdaptive* nodes): Requests classified as threats

AccountHttpRequests1mGroupsDimensions

FieldDescription
date Request date
datetime Request datetime, truncated to the minute
datetimeDay Request datetime truncated to the day
datetimeFifteenMinutes Request datetime truncated to multiple of 15 minutes
datetimeFiveMinutes Request datetime truncated to multiple of 5 minutes
datetimeHalfOfHour Request datetime truncated to multiple of 30 minutes
datetimeHour Request datetime truncated to the hour
datetimeMinute DEPRECATED (Field is replaced with datetime): Request datetime truncated to the minute

AccountHttpRequests1mGroupsIpClassMapElem

FieldDescription
ipType IP class
requests

AccountHttpRequests1mGroupsResponseStatusMapElem

FieldDescription
edgeResponseStatus HTTP response status code returned to client
requests

AccountHttpRequests1mGroupsSum

FieldDescription
browserMap
bytes Bytes returned to client
cachedBytes Bytes returned to client from cache
cachedRequests Requests served from cache
clientHTTPVersionMap
clientSSLMap
contentTypeMap
countryMap
edgeRequestBytes Bytes sent from client
encryptedBytes Bytes returned to client using SSL/TLS protocol
encryptedRequests Requests served using SSL/TLS protocol
ipClassMap
pageViews Successful requests for HTML content
requests
responseStatusMap
threatPathingMap
threats DEPRECATED (Replaced by more granular information in firewallEventsAdaptive* nodes): Requests classified as threats

AccountHttpRequests1mGroupsThreatPathingMapElem

FieldDescription
requests
threatPathingName Threat type

AccountHttpRequests1mGroupsUniq

FieldDescription
uniques A number of unique IPs

AccountHttpRequestsAdaptive

Raw HTTP requests with adaptive sampling

FieldDescription
apiGatewayMatchedEndpoint API Gateway (Web Assets) endpoint matched at the edge
apiGatewayMatchedHost API Gateway (Web Assets) host matched at the edge
botDetectionIds Array of detections ids that matched this request
botDetectionTags Array of detections tags that matched this request
botManagementDecision Judgement of the bot management system
botScore The final score originated from bot management detections.
botScoreBucketBy10 Range of the bot management score
botScoreSrcName Name of the source detection which generated the bot management score.
cacheReserveUsed Used Cache Reserve to serve the response
cacheStatus Cache status
clientASNDescription The ASN of the visitor as string
clientAsn The ASN number of the visitor
clientCountryName Country from which request originated
clientDeviceType
clientIP The visitor's IP address (IPv4 or IPv6)
clientRefererHost The referrer host
clientRequestAcceptContentTypeNames List of MIME content type extension names accepted by the visitor (including wildcards)
clientRequestAcceptContentTypes List of MIME content types accepted by the visitor (including wildcards)
clientRequestHTTPHost The HTTP hostname requested by the visitor
clientRequestHTTPMethodName HTTP method of client request
clientRequestHTTPProtocol The version of HTTP protocol requested by the visitor
clientRequestPath The path requested by visitor
clientRequestQuery Query parameters of client request
clientRequestReferer HTTP request referrer
clientRequestScheme The url scheme requested by the visitor
clientSSLProtocol SSL protocol version
coloCode
contentScanHasFailed 1 if not all contents for this request where successfully scanned, else 0
contentScanNumMaliciousObj Number of scannable content objects that are malicious
contentScanNumObj Number of scannable content objects
contentScanObjResults Array of scan results in order of detection
contentScanObjSizes Array of scan sizes in order of detection
contentScanObjTypes Array of content types in order of detection
date The date the event occurred at the edge
datetime The date and time the event occurred at the edge
datetimeFifteenMinutes The date and time the event occurred at the edge truncated to a multiple of 15 minutes
datetimeFiveMinutes The date and time the event occurred at the edge truncated to a multiple of 5 minutes
datetimeHour The date and time the event occurred at the edge truncated to hours
datetimeMinute The date and time the event occurred at the edge truncated to the minute
edgeDnsResponseTimeMs The time elapsed resolving a CNAME if it was required to reach your origin
edgeResponseContentType MIME type of the response
edgeResponseContentTypeMatched 1 if the MIME type of the response is one of the MIME content types accepted by the visitor (including wildcards), 0 otherwise
edgeResponseContentTypeMatchedByWildcard 1 if the MIME type of the response matched only via a wildcard in the content types accepted by the visitor (not an exact match), 0 otherwise
edgeResponseContentTypeName
edgeResponseStatus HTTP response status code returned to browser
edgeTimeToFirstByteMs The time elapsed between processing the first byte of the request until when we started sending a response
firewallForAiAnyPiiCategory Whether firewallForAiPiiCategories is non empty. 0 if empty, 1 if not empty.
firewallForAiCustomTopicCategories Corresponds to the Ruleset field cf.llm.prompt.custom_topic_categories.
firewallForAiCustomTopicCategoriesScoresMin Minimum score across all the defined firewall for ai custom topics; 100 if empty.
firewallForAiInjectionScore Corresponds to the Ruleset field cf.llm.prompt.injection_score.
firewallForAiPiiCategories Corresponds to the Ruleset field cf.llm.prompt.pii_categories.
firewallForAiUnsafeTopicCategories Corresponds to the Ruleset field cf.llm.prompt.unsafe_data_categories.
fraudAttack The primary attack or use case detected in the request by Fraud detections
fraudDetectionIds Array of fraud detections ids that matched this request
fraudDetectionTags Array of fraud detections tags that matched this request
fraudEmailRisk Risk of a specific email address in account signup attempts
fraudEventType Identifies action that a given user is performing. Possible values are login, signup.
fraudUserId A unique identifier generated by the Fraud Detection system for each user, generated during any action determined by the fraud event type.
httpApplicationVersion DEPRECATED (Field is replaced with zoneVersion): Version associated with HTTP Application
isCrossZoneSubrequest '1' if a request was inititiated by a Cloudflare Worker on another zone; '0' otherwise.
ja3Hash MD5 hash of the JA3 TLS fingerprint
ja4 JA4 TLS fingerprint
ja4Signals Inter-request statistics computed for this JA4 across Cloudflare's entire global edge network
jsDetectionPassed Whether the request passed background JavaScript Detection
leakedCredentialCheckResult The distinct result of checking for leaked credentials
originASN
originASNDescription ASN associated with origin
originIP
originResponseDurationMs
originResponseHeaderReceiveDurationMs The time elapsed between completing the TLS handshake and receiving the origin response headers
originResponseStatus HTTP origin response status code returned to browser
originTcpHandshakeDurationMs The time elapsed between the start and completion of the TCP handshake with the origin
originTlsHandshakeDurationMs The time elapsed between the start and completion of the TLS handshake with the origin
payPerCrawlStatus Pay Per Crawl outcome, when applicable (e.g. request enabled for charging and not blocked by a WAF rule)
productMatches Cloudflare products (Snippets, Transform Rules, Cloud Connector Rules, etc.) whose rulesets matched this request
rayName The RayId of the request
requestSource
rulesMetadata Key-value metadata annotations attached to rules that matched this request
schemaValidationLearnedOutcome The outcome of running API Shield Managed Schema Validation for this request against the Cloudflare-learned schema (e.g. valid or violated; empty when managed schema validation did not run for the request)
schemaValidationLearnedViolations Schema Validation violations recorded for this request against the Cloudflare-learned schema. Each entry describes a single violation.
schemaValidationUploadedOutcome The outcome of running API Shield Schema Validation for this request against the customer-uploaded schema (e.g. valid or violated; empty when schema validation did not run for the request)
schemaValidationUploadedViolations Schema Validation violations recorded for this request against the customer-uploaded schema. Each entry describes a single violation.
securityAction The code of the first-class action the Cloudflare Firewall took on this request
securitySource The Cloudflare security product triggered by this request
sessionIdHash API Security Session ID hash
threatIntelIpDatasets Threat Intelligence dataset(s) that matched the visitor IP address (e.g. ddos, waf)
threatIntelIpEventIds UUIDv4 identifiers linking to Threat Intelligence events that matched the visitor IP address
upperTierColoName
userAgent visitor's user-agent string
userAgentBrowser Browser parsed from the user agent
userAgentOS OS parsed from the user agent
verifiedBotCategory The category of verified bot
wafAttackScore Beta. Overall request score generated by the WAF detection module
wafAttackScoreClass Beta. Overall request score class generated by the WAF detection module
wafPathTraversalAttackScore Beta. WAF score for a Path Traversal attack
wafRceAttackScore Beta. WAF score for a RCE attack
wafRequestSignatureCategories 1-D array of the categories associated with the rules ref in wafRequestSignatureRefs
wafRequestSignatureRefs cf.waf.signature.request.refs Ruleset field truncated to maximum 10 elements.
wafSqliAttackScore Beta. WAF score for a SQLi attack
wafXssAttackScore Beta. WAF score for a XSS attack
webAssetsLabelsManaged Managed Web Asset Labels (Cloudflare-defined labels, e.g. cf-log-in, cf-llm)
webAssetsOperationId Web Asset Operation ID
xRequestedWith The X-Requested-With header of the client request
zoneTag Associated zone
zoneVersion The version of a zone

AccountHttpRequestsAdaptiveFirewallForAiCustomTopicCategoriesElem

FieldDescription
score Topic score
topicLabel Topic label

AccountHttpRequestsAdaptiveGroups

Aggregated HTTP requests data with adaptive sampling

FieldDescription
avg The average value used for sample interval
confidence ALPHA - DO NOT USE
count The number of values for a metric per dimension
dimensions List of dimensions to group by
quantiles Quantiles of a metric per dimension
ratio The ratio of a range of status codes, between 0 and 1
sum The sum of values for a metric per dimension

AccountHttpRequestsAdaptiveGroupsAvg

FieldDescription
crossZoneSubrequests The proportion of requests that were inititiated by a Cloudflare Worker on another zone
edgeDnsResponseTimeMs
edgeTimeToFirstByteMs
originResponseDurationMs The average originResponseDuration, in milliseconds, excluding 0 values (i.e. cached ones)
originResponseHeaderReceiveDurationMs The average originResponseHeaderReceiveDuration, in milliseconds, excluding 0 values
originTcpHandshakeDurationMs The average originTcpHandshakeDuration, in milliseconds, excluding 0 values
originTlsHandshakeDurationMs The average originTlsHandshakeDuration, in milliseconds, excluding 0 values
sampleInterval

AccountHttpRequestsAdaptiveGroupsConfidence

FieldDescription
count The number of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountHttpRequestsAdaptiveGroupsDimensions

FieldDescription
apiGatewayMatchedEndpoint API Gateway (Web Assets) endpoint matched at the edge
apiGatewayMatchedHost API Gateway (Web Assets) host matched at the edge
botDetectionIds Array of detections ids that matched this request
botDetectionTags Array of detections tags that matched this request
botManagementDecision Judgement of the bot management system
botScore The final score originated from bot management detections.
botScoreBucketBy10 Range of the bot management score
botScoreSrcName Name of the source detection which generated the bot management score.
cacheReserveUsed Used Cache Reserve to serve the response
cacheStatus
clientASNDescription The ASN of the visitor as string
clientAsn
clientCountryName Country from which request originated
clientDeviceType
clientIP
clientRefererHost The referrer host
clientRequestAcceptContentTypeCategories List of high-level content type categories (e.g. html, json, images, javascript) accepted by the client, grouped from the Accept request header's MIME types.
clientRequestAcceptContentTypeCategory High-level content type category (e.g. html, json, images, javascript) accepted by the client, grouped from the Accept request header's MIME types. A request that accepts multiple categories is counted under each.
clientRequestAcceptContentTypeNames List of MIME content type extension names accepted by the client (including wildcards)
clientRequestAcceptContentTypes List of MIME content types accepted by the client (including wildcards)
clientRequestHTTPHost Host requested by the client
clientRequestHTTPMethodName HTTP method of client request
clientRequestHTTPProtocol HTTP protocol version
clientRequestPath Path of client request
clientRequestQuery Query parameters of client request
clientRequestQueryParameterNames Beta. Query parameter names of client request
clientRequestReferer HTTP request referrer
clientRequestScheme HTTP request URI scheme (http/https)
clientSSLProtocol SSL protocol version
coloCode
contentScanHasFailed 1 if not all contents for this request where successfully scanned, else 0
contentScanNumMaliciousObj Number of scannable content objects that are malicious
contentScanNumObj Number of scannable content objects
contentScanObjResults Array of scan results in order of detection
contentScanObjSizes Array of scan sizes in order of detection
contentScanObjTypes Array of content types in order of detection
date The date the event occurred at the edge
datetime The date and time the event occurred at the edge
datetimeFifteenMinutes The date and time the event occurred at the edge truncated to a multiple of 15 minutes
datetimeFiveMinutes The date and time the event occurred at the edge truncated to a multiple of 5 minutes
datetimeHour The date and time the event occurred at the edge truncated to hours
datetimeMinute The date and time the event occurred at the edge truncated to the minute
edgeDnsResponseTimeMs The time elapsed resolving a CNAME if it was required to reach your origin
edgeResponseContentType MIME type of the response
edgeResponseContentTypeMatched 1 if the MIME type of the response is one of the MIME content types accepted by the client (including wildcards), 0 otherwise
edgeResponseContentTypeMatchedByWildcard 1 if the MIME type of the response matched only via a wildcard in the content types accepted by the client (not an exact match), 0 otherwise
edgeResponseContentTypeName
edgeResponseStatus
edgeTimeToFirstByteMs The time elapsed between processing the first byte of the request until when we started sending a response
firewallForAiAnyPiiCategory Whether firewallForAiPiiCategories is non empty. 0 if empty, 1 if not empty.
firewallForAiCustomTopicCategoriesScoresMin Minimum score across all the defined firewall for ai custom topics; 100 if empty.
firewallForAiInjectionScore Corresponds to the Ruleset field cf.llm.prompt.injection_score.
firewallForAiPiiCategories Corresponds to the Ruleset field cf.llm.prompt.pii_categories.
firewallForAiUnsafeTopicCategories Corresponds to the Ruleset field cf.llm.prompt.unsafe_data_categories.
fraudAttack The primary attack or use case detected in the request by Fraud detections
fraudDetectionIds Array of fraud detections ids that matched this request
fraudDetectionTags Array of fraud detections tags that matched this request
fraudEmailRisk Risk of a specific email address in account signup attempts
fraudEventType Identifies action that a given user is performing. Possible values are login, signup.
fraudUserId A unique identifier generated by the Fraud Detection system for each user, generated during any action determined by the fraud event type.
httpApplicationVersion DEPRECATED (Field is replaced with zoneVersion): Version associated with HTTP Application
isCrossZoneSubrequest '1' if a request was inititiated by a Cloudflare Worker on another zone; '0' otherwise.
ja3Hash MD5 hash of the JA3 TLS fingerprint
ja4 JA4 TLS fingerprint
jsDetectionPassed Whether the request passed background JavaScript Detection
leakedCredentialCheckResult The distinct result of checking for leaked credentials
originASN
originASNDescription ASN associated with origin
originIP
originResponseDurationMs
originResponseHeaderReceiveDurationMs The time elapsed between completing the TLS handshake and receiving the origin response headers
originResponseStatus HTTP response status code returned by the origin
originTcpHandshakeDurationMs The time elapsed between the start and completion of the TCP handshake with the origin
originTlsHandshakeDurationMs The time elapsed between the start and completion of the TLS handshake with the origin
payPerCrawlStatus Pay Per Crawl outcome, when applicable (e.g. request enabled for charging and not blocked by a WAF rule)
requestSource
sampleInterval ABR sample interval
schemaValidationLearnedOutcome The outcome of running API Shield Managed Schema Validation for this request against the Cloudflare-learned schema (e.g. valid or violated; empty when managed schema validation did not run for the request)
schemaValidationUploadedOutcome The outcome of running API Shield Schema Validation for this request against the customer-uploaded schema (e.g. valid or violated; empty when schema validation did not run for the request)
securityAction The code of the first-class action the Cloudflare Firewall took on this request
securitySource The Cloudflare security product triggered by this request
sessionIdHash API Security Session ID hash
threatIntelIpDatasets Threat Intelligence dataset(s) that matched the visitor IP address (e.g. ddos, waf)
threatIntelIpEventIds UUIDv4 identifiers linking to Threat Intelligence events that matched the visitor IP address
upperTierColoName
userAgent
userAgentBrowser Browser parsed from the user agent
userAgentOS OS parsed from the user agent
verifiedBotCategory The category of verified bot
wafAttackScore Beta. Overall request score generated by the WAF detection module
wafAttackScoreClass Beta. Overall request score class generated by the WAF detection module
wafPathTraversalAttackScore Beta. WAF score for a Path Traversal attack
wafRceAttackScore Beta. WAF score for a RCE attack
wafRequestSignatureCategories 1-D array of the categories associated with the rules ref in wafRequestSignatureRefs
wafRequestSignatureRefs cf.waf.signature.request.refs Ruleset field truncated to maximum 10 elements.
wafSqliAttackScore Beta. WAF score for a SQLi attack
wafXssAttackScore Beta. WAF score for a XSS attack
webAssetsLabelsManaged Managed Web Asset Labels (Cloudflare-defined labels, e.g. cf-log-in, cf-llm)
webAssetsOperationId Web Asset Operation ID
xRequestedWith The X-Requested-With header of the client request
zoneTag Associated zone
zoneVersion The version of a zone

AccountHttpRequestsAdaptiveGroupsQuantiles

FieldDescription
edgeDnsResponseTimeMsP25 25th percentile DNS Response Time (milliseconds)
edgeDnsResponseTimeMsP50 50th percentile DNS Response Time (milliseconds)
edgeDnsResponseTimeMsP75 75th percentile DNS Response Time (milliseconds)
edgeDnsResponseTimeMsP90 90th percentile DNS Response Time (milliseconds)
edgeDnsResponseTimeMsP95 95th percentile DNS Response Time (milliseconds)
edgeDnsResponseTimeMsP99 99th percentile DNS Response Time (milliseconds)
edgeDnsResponseTimeMsP999 99.9th percentile DNS Response Time (milliseconds)
edgeResponseBytesP25 25th percentile Bytes returned to client
edgeResponseBytesP50 50th percentile Bytes returned to client
edgeResponseBytesP75 75th percentile Bytes returned to client
edgeResponseBytesP90 90th percentile Bytes returned to client
edgeResponseBytesP95 95th percentile Bytes returned to client
edgeResponseBytesP99 99th percentile Bytes returned to client
edgeResponseBytesP999 99.9th percentile Bytes returned to client
edgeTimeToFirstByteMsP25 25th percentile Time To First Byte (milliseconds)
edgeTimeToFirstByteMsP50 50th percentile Time To First Byte (milliseconds)
edgeTimeToFirstByteMsP75 75th percentile Time To First Byte (milliseconds)
edgeTimeToFirstByteMsP90 90th percentile Time To First Byte (milliseconds)
edgeTimeToFirstByteMsP95 95th percentile Time To First Byte (milliseconds)
edgeTimeToFirstByteMsP99 99th percentile Time To First Byte (milliseconds)
edgeTimeToFirstByteMsP999 99.9th percentile Time To First Byte (milliseconds)
originResponseDurationMsP25 25th percentile Origin Response Duration (milliseconds)
originResponseDurationMsP50 50th percentile Origin Response Duration (milliseconds)
originResponseDurationMsP75 75th percentile Origin Response Duration (milliseconds)
originResponseDurationMsP90 90th percentile Origin Response Duration (milliseconds)
originResponseDurationMsP95 95th percentile Origin Response Duration (milliseconds)
originResponseDurationMsP99 99th percentile Origin Response Duration (milliseconds)
originResponseDurationMsP999 99.9th percentile Origin Response Duration (milliseconds)
originResponseHeaderReceiveDurationMsP25 25th percentile Origin Response Header Receive Duration (milliseconds)
originResponseHeaderReceiveDurationMsP50 50th percentile Origin Response Header Receive Duration (milliseconds)
originResponseHeaderReceiveDurationMsP75 75th percentile Origin Response Header Receive Duration (milliseconds)
originResponseHeaderReceiveDurationMsP90 90th percentile Origin Response Header Receive Duration (milliseconds)
originResponseHeaderReceiveDurationMsP95 95th percentile Origin Response Header Receive Duration (milliseconds)
originResponseHeaderReceiveDurationMsP99 99th percentile Origin Response Header Receive Duration (milliseconds)
originResponseHeaderReceiveDurationMsP999 99.9th percentile Origin Response Header Receive Duration (milliseconds)
originTcpHandshakeDurationMsP25 25th percentile Origin TCP Handshake Duration (milliseconds)
originTcpHandshakeDurationMsP50 50th percentile Origin TCP Handshake Duration (milliseconds)
originTcpHandshakeDurationMsP75 75th percentile Origin TCP Handshake Duration (milliseconds)
originTcpHandshakeDurationMsP90 90th percentile Origin TCP Handshake Duration (milliseconds)
originTcpHandshakeDurationMsP95 95th percentile Origin TCP Handshake Duration (milliseconds)
originTcpHandshakeDurationMsP99 99th percentile Origin TCP Handshake Duration (milliseconds)
originTcpHandshakeDurationMsP999 99.9th percentile Origin TCP Handshake Duration (milliseconds)
originTlsHandshakeDurationMsP25 25th percentile Origin TLS Handshake Duration (milliseconds)
originTlsHandshakeDurationMsP50 50th percentile Origin TLS Handshake Duration (milliseconds)
originTlsHandshakeDurationMsP75 75th percentile Origin TLS Handshake Duration (milliseconds)
originTlsHandshakeDurationMsP90 90th percentile Origin TLS Handshake Duration (milliseconds)
originTlsHandshakeDurationMsP95 95th percentile Origin TLS Handshake Duration (milliseconds)
originTlsHandshakeDurationMsP99 99th percentile Origin TLS Handshake Duration (milliseconds)
originTlsHandshakeDurationMsP999 99.9th percentile Origin TLS Handshake Duration (milliseconds)

AccountHttpRequestsAdaptiveGroupsRatio

FieldDescription
status4xx
status5xx

AccountHttpRequestsAdaptiveGroupsSum

FieldDescription
botDetectionIdArray Array of bot management detection ids
botDetectionIdCountArray Count array of bot management detection ids. Elements in this array correspond to elements in botDetectionIdArray by index.
botDetectionTagArray Array of bot management detection tags
botDetectionTagCountArray Count array of bot management detection tags. Elements in this array correspond to elements in botDetectionTagArray by index.
clientRequestAcceptContentTypeCategoryArray Array of Accept content type category slugs (e.g. html, json, images) aggregated independently across requests, ordered by request count descending and capped at 50 entries. Each category is counted separately — a request accepting both text/html and application/json contributes to both html and json totals.
clientRequestAcceptContentTypeCategoryCountArray Count array of per-category Accept content type aggregations, ordered by request count descending and capped at 50 entries. Elements correspond to clientRequestAcceptContentTypeCategoryArray by index. Each count represents the total number of requests that included any MIME type belonging to that category in their Accept header.
crossZoneSubrequests The number of requests that were inititiated by a Cloudflare Worker on another zone
edgeDnsResponseTimeMs
edgeRequestBytes
edgeResponseBytes
edgeTimeToFirstByteMs
fraudDetectionIdArray Array of fraud detection ids
fraudDetectionIdCountArray Count array of fraud detection ids. Elements in this array correspond to elements in fraudDetectionIdArray by index.
fraudDetectionTagArray Array of fraud detection tags
fraudDetectionTagCountArray Count array of fraud detection tags. Elements in this array correspond to elements in fraudDetectionTagArray by index.
originResponseDurationMs
originResponseHeaderReceiveDurationMs The sum of originResponseHeaderReceiveDuration, in milliseconds
originTcpHandshakeDurationMs The sum of originTcpHandshakeDuration, in milliseconds
originTlsHandshakeDurationMs The sum of originTlsHandshakeDuration, in milliseconds
productMatchProductArray Distinct Cloudflare product IDs whose rulesets matched across aggregated requests
productMatchProductCountArray Estimated request count per product ID. Elements correspond to productMatchProductArray by index.
productMatchRulesetIdArray Distinct ruleset UUIDs (hex-encoded) that matched across aggregated requests
productMatchRulesetIdCountArray Estimated request count per ruleset ID. Elements correspond to productMatchRulesetIdArray by index.
rulesMetadataKeyArray Distinct rule metadata keys observed across aggregated requests
rulesMetadataKeyCountArray Estimated request count per metadata key. Elements correspond to rulesMetadataKeyArray by index.
visits The number of requests by end-users that were initiated from a different website (i.e. where the request HTTP Referer header does not match the host in the HTTP Host header)

AccountHttpRequestsAdaptiveGroupsSumConfidence

FieldDescription
crossZoneSubrequests Confidence interval for the corresponding point estimate
edgeDnsResponseTimeMs Confidence interval for the corresponding point estimate
edgeRequestBytes Confidence interval for the corresponding point estimate
edgeResponseBytes Confidence interval for the corresponding point estimate
edgeTimeToFirstByteMs Confidence interval for the corresponding point estimate
originResponseDurationMs Confidence interval for the corresponding point estimate
originResponseHeaderReceiveDurationMs Confidence interval for the corresponding point estimate
originTcpHandshakeDurationMs Confidence interval for the corresponding point estimate
originTlsHandshakeDurationMs Confidence interval for the corresponding point estimate
visits Confidence interval for the corresponding point estimate

AccountHttpRequestsAdaptiveJa4SignalsElem

FieldDescription
signalName Signal name
signalValue Signal value

AccountHttpRequestsAdaptiveProductMatchesElem

FieldDescription
product Numeric identifier of the Cloudflare product whose ruleset matched (e.g. WAF, Bot Management)
ruleIds Hex-encoded UUIDs of individual rules within the ruleset that matched this request
rulesetId Unique identifier of the ruleset that matched, as a hex-encoded UUID
rulesetVersion Version number of the ruleset that was evaluated against the request

AccountHttpRequestsAdaptiveRulesMetadataElem

FieldDescription
metadataKey Key of the metadata annotation on the matched rule (e.g. action, category)
metadataValue Value of the metadata annotation on the matched rule
ruleId Hex-encoded UUID of the rule this metadata entry belongs to

AccountHttpRequestsAdaptiveSchemaValidationLearnedViolationsElem

FieldDescription
errorClass The class/category of the schema validation violation error
errorDetail Finer grained detail describing the schema validation violation error
location Where in the request the violation was detected (e.g. path)
target The schema element or parameter targeted by the violated rule

AccountHttpRequestsAdaptiveSchemaValidationUploadedViolationsElem

FieldDescription
errorClass The class/category of the schema validation violation error
errorDetail Finer grained detail describing the schema validation violation error
location Where in the request the violation was detected (e.g. path)
target The schema element or parameter targeted by the violated rule

AccountHttpRequestsOverviewAdaptiveGroups

A high-level summary of HTTP requests made by end users.

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
ratio The ratio of a metric in comparison to the rest of the traffic, between 0 and 1
sum The sum of values for a metric per dimension

AccountHttpRequestsOverviewAdaptiveGroupsAvg

FieldDescription
originResponseDurationMs The average originResponseDuration, in milliseconds, excluding 0 values (i.e. cached ones)
originResponseHeaderReceiveDurationMs The average originResponseHeaderReceiveDuration, in milliseconds, excluding 0 values
originTcpHandshakeDurationMs The average originTcpHandshakeDuration, in milliseconds, excluding 0 values
originTlsHandshakeDurationMs The average originTlsHandshakeDuration, in milliseconds, excluding 0 values
sampleInterval Average sample interval

AccountHttpRequestsOverviewAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountHttpRequestsOverviewAdaptiveGroupsDimensions

FieldDescription
clientCountryName Country from which request originated
clientRequestHTTPProtocol HTTP protocol version
clientSSLProtocol SSL protocol version
date The date the event occurred at the edge
datetime The date and time the event occurred at the edge
datetimeFifteenMinutes The date and time the event occurred at the edge truncated to a multiple of 15 minutes
datetimeFiveMinutes The date and time the event occurred at the edge truncated to a multiple of 5 minutes
datetimeHour The date and time the event occurred at the edge truncated to hours
datetimeMinute The date and time the event occurred at the edge truncated to the minute
edgeResponseContentTypeName Content type returned to client
edgeResponseStatus HTTP response status code returned to client
httpApplicationVersion DEPRECATED (Field is replaced with zoneVersion): Version associated with HTTP Application
userAgentBrowser Browser parsed from the user agent
zoneTag Associated zone
zoneVersion The version of a zone

AccountHttpRequestsOverviewAdaptiveGroupsRatio

FieldDescription
cachedBytes
cachedRequests
encryptedBytes
encryptedRequests
status4xx
status5xx

AccountHttpRequestsOverviewAdaptiveGroupsSum

FieldDescription
bytes
cachedBytes Bytes returned to client from cache
cachedRequests Requests served from cache
pageViews Successful requests for HTML content
requests
visits The number of requests by end-users that were initiated from a different website (i.e. where the request HTTP Referer header does not match the host in the HTTP Host header)

AccountHttpRequestsOverviewAdaptiveGroupsSumConfidence

FieldDescription
bytes Confidence interval for the corresponding point estimate
cachedBytes Confidence interval for the corresponding point estimate
cachedRequests Confidence interval for the corresponding point estimate
pageViews Confidence interval for the corresponding point estimate
requests Confidence interval for the corresponding point estimate
visits Confidence interval for the corresponding point estimate

AccountHyperdrivePoolSizesAdaptiveGroups

Hyperdrive connection pool size snapshots with adaptive sampling.

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count Total number of Hyperdrive pool size snapshots
dimensions List of dimensions to group by
max The maximum value for a metric per dimension

AccountHyperdrivePoolSizesAdaptiveGroupsAvg

FieldDescription
availablePoolSlots Average number of pool connections available for checkout
currentPoolSize Average number of connections currently open in the pool
sampleInterval The average value used for sample interval
waitingClients Average number of clients waiting for a connection from the pool

AccountHyperdrivePoolSizesAdaptiveGroupsConfidence

FieldDescription
count Total number of Hyperdrive pool size snapshots, with confidence intervals
level Confidence level that was requested

AccountHyperdrivePoolSizesAdaptiveGroupsDimensions

FieldDescription
coloCode IATA airport code for the Cloudflare datacenter where the pool resides
configId The ID of the Hyperdrive Config
databaseType The type of database targeted by the Hyperdrive Config: 'Postgres' or 'MySQL'
date Pool size snapshot timestamp, truncated to start of a day
datetime Pool size snapshot timestamp
datetimeHour Pool size snapshot timestamp, truncated to start of hour
datetimeMinute Pool size snapshot timestamp, truncated to start of minute
poolShardId Opaque per-query identifier for a pool shard. Use only as a GROUP BY dimension; values are not stable across queries.

AccountHyperdrivePoolSizesAdaptiveGroupsMax

FieldDescription
currentPoolSize Peak number of connections open in the pool
maxPoolSize Configured maximum size of the connection pool
waitingClients Peak number of clients waiting for a connection from the pool

AccountHyperdriveQueriesAdaptiveGroups

Hyperdrive query events with adaptive sampling.

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count Total number of Hyperdrive queries
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountHyperdriveQueriesAdaptiveGroupsAvg

FieldDescription
connectionLatency Average latency (in milliseconds) of retrieving a connection to the origin database
queryBytes Average size (in bytes) of queries handled by Hyperdrive
queryLatency Average latency (in milliseconds) of serving a query using Hyperdrive
resultBytes Average size (in bytes) of query results served by Hyperdrive
sampleInterval The average value used for sample interval

AccountHyperdriveQueriesAdaptiveGroupsConfidence

FieldDescription
count Total number of Hyperdrive queries, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountHyperdriveQueriesAdaptiveGroupsDimensions

FieldDescription
cacheStatus The cache status of the Hyperdrive query event
coloCode IATA airport code for the Cloudflare datacenter where the query was handled.
configId The ID of the Hyperdrive Config
date Hyperdrive query event timestamp, truncated to start of a day
datetime Hyperdrive query event timestamp
datetimeFifteenMinutes Hyperdrive query event timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Hyperdrive query event timestamp, truncated to start of five minutes
datetimeHour Hyperdrive query event timestamp, truncated to start of hour
datetimeMinute Hyperdrive query event timestamp, truncated to start of minute
eventStatus The result of the Hyperdrive event: 'error' or 'complete'. Error events may not have complete data.
isFree Whether the query originates from a Hyperdrive config on the free tier

AccountHyperdriveQueriesAdaptiveGroupsSum

FieldDescription
clientWriteLatency Total latency (in milliseconds) of sending query results back to client
connectionLatency Total latency (in milliseconds) of retrieving a connection to the origin database
originReadLatency Total latency (in milliseconds) of receiving responses from origin to Hyperdrive
originWriteLatency Total latency (in milliseconds) of sending queries to origin from Hyperdrive
queryBytes Total size (in bytes) of queries handled by Hyperdrive
queryLatency Total latency (in milliseconds) of serving a query using Hyperdrive
resultBytes Total size (in bytes) of query results served by Hyperdrive

AccountHyperdriveQueriesAdaptiveGroupsSumConfidence

FieldDescription
clientWriteLatency Confidence interval for the corresponding point estimate
connectionLatency Confidence interval for the corresponding point estimate
originReadLatency Confidence interval for the corresponding point estimate
originWriteLatency Confidence interval for the corresponding point estimate
queryBytes Confidence interval for the corresponding point estimate
queryLatency Confidence interval for the corresponding point estimate
resultBytes Confidence interval for the corresponding point estimate

AccountImagesRequestsAdaptiveGroups

A high-level summary of Cloudflare Images served to end users.

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountImagesRequestsAdaptiveGroupsAvg

FieldDescription
sampleInterval

AccountImagesRequestsAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountImagesRequestsAdaptiveGroupsDimensions

FieldDescription
date The date the event occurred at the edge
datetime The date and time the event occurred at the edge
datetimeFifteenMinutes The date and time the event occurred at the edge truncated to a multiple of 15 minutes
datetimeFiveMinutes The date and time the event occurred at the edge truncated to a multiple of 5 minutes
datetimeHour The date and time the event occurred at the edge truncated to hours
datetimeMinute The date and time the event occurred at the edge truncated to the minute

AccountImagesRequestsAdaptiveGroupsSum

FieldDescription
requests

AccountImagesRequestsAdaptiveGroupsSumConfidence

FieldDescription
requests Confidence interval for the corresponding point estimate

AccountImagesUniqueTransformations

Image unique transfromations per day

FieldDescription
date The date uniques are calculated for
transformations Number of unique image transformations per day in sliding window

AccountImagesUniqueTransformationsAccumulatedSinceStartOfMonth

Image unique transformations accumulated since start of month

FieldDescription
date The date uniques are calculated for
transformations Accumulated number of unique image transformations since start of month per day in sliding window

AccountKvOperationsAdaptiveGroups

KV operations data with adaptive sampling

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count Number of requests
dimensions List of dimensions to group by
max The max of values for a metric per dimension
min The min of values for a metric per dimension
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension

AccountKvOperationsAdaptiveGroupsAvg

FieldDescription
sampleInterval The average value used for sample interval

AccountKvOperationsAdaptiveGroupsConfidence

FieldDescription
count Number of requests, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountKvOperationsAdaptiveGroupsDimensions

FieldDescription
actionType The type of the action (read, write, delete, list)
date Message operation timestamp, truncated to start of a day
datetime Message operation timestamp
datetimeFifteenMinutes Message operation timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Message operation timestamp, truncated to start of five minutes
datetimeHour Message operation timestamp, truncated to start of an hour
datetimeMinute Message operation timestamp, truncated to start of an minute
namespaceId The hexa-encoded namespace id
responseStatusCode The http status code of the response.
result The result of the action (hot_read, cold_read, deleted, uploaded, error, not_found)

AccountKvOperationsAdaptiveGroupsMax

FieldDescription
latencyMs Max latency
objectBytes Max object bytes

AccountKvOperationsAdaptiveGroupsMin

FieldDescription
latencyMs Min latency
objectBytes Min object bytes

AccountKvOperationsAdaptiveGroupsQuantiles

FieldDescription
latencyMsP25 25th percentile latency (milliseconds)
latencyMsP50 50th percentile latency (milliseconds)
latencyMsP75 75th percentile latency (milliseconds)
latencyMsP90 90th percentile latency (milliseconds)
latencyMsP95 95th percentile latency (milliseconds)
latencyMsP99 99th percentile latency (milliseconds)
latencyMsP999 99.9th percentile latency (milliseconds)

AccountKvOperationsAdaptiveGroupsSum

FieldDescription
objectBytes Total bytes of all objects
requests Total number of requests

AccountKvOperationsAdaptiveGroupsSumConfidence

FieldDescription
objectBytes Confidence interval for the corresponding point estimate
requests Confidence interval for the corresponding point estimate

AccountKvStorageAdaptiveGroups

KV stored data with adaptive sampling

FieldDescription
dimensions List of dimensions to group by
max The max of values for a metric per dimension

AccountKvStorageAdaptiveGroupsDimensions

FieldDescription
date Message operation timestamp, truncated to start of a day
datetime Message operation timestamp
datetimeFifteenMinutes Message operation timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Message operation timestamp, truncated to start of five minutes
datetimeHour Message operation timestamp, truncated to start of an hour
datetimeMinute Message operation timestamp, truncated to start of an minute
namespaceId The hexa-encoded namespace id

AccountKvStorageAdaptiveGroupsMax

FieldDescription
byteCount Max number of bytes
keyCount Max number of keys

AccountLiveInputEventsAdaptive

Live input events with adaptive sampling

FieldDescription
coloCode Ingest colo
datetime The time of the event
eventCode Event code
eventDescription Event description
inputId Live input ID

AccountLiveInputEventsAdaptiveGroups

Aggregated live input events with adaptive sampling

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
count Number of segments stored
dimensions List of dimensions to group by
max The maximum value for a metric per dimension
min The minimum value for a metric per dimension

AccountLiveInputEventsAdaptiveGroupsAvg

FieldDescription
bitRate Per-second bit rate when grouped by datetime
bitRateFifteenMinutes Per-second bit rate when grouped by datetimeFifteenMinutes
bitRateFiveMinutes Per-second bit rate when grouped by datetimeFiveMinutes
bitRateHour Per-second bit rate when grouped by datetimeHour
bitRateMinute Per-second bit rate when grouped by datetimeMinute
gopByteSize Average GOP size in bytes
gopDuration Average GOP duration in ms
gopUploadTime Average GOP upload time in ms
uploadDurationRatio Average upload to duration ratio

AccountLiveInputEventsAdaptiveGroupsAvgConfidence

FieldDescription
bitRate Confidence interval for the corresponding point estimate
bitRateFifteenMinutes Confidence interval for the corresponding point estimate
bitRateFiveMinutes Confidence interval for the corresponding point estimate
bitRateHour Confidence interval for the corresponding point estimate
bitRateMinute Confidence interval for the corresponding point estimate

AccountLiveInputEventsAdaptiveGroupsConfidence

FieldDescription
avg The average of values for a metric per dimension, with confidence intervals
count Number of segments stored, with confidence intervals
level Confidence level that was requested

AccountLiveInputEventsAdaptiveGroupsDimensions

FieldDescription
date Live input events date, truncated to the start of a day
datetime Live input events timestamp
datetimeFifteenMinutes The date and time of the event truncated to fifteen minutes
datetimeFiveMinutes The date and time of the event truncated to five minutes
datetimeHour The date and time of the event truncated to the hour
datetimeMinute The date and time of the event truncated to the minute
eventCode Event code
inputId Live input ID

AccountLiveInputEventsAdaptiveGroupsMax

FieldDescription
gopByteSize Max GOP size in bytes
gopDuration Max GOP duration in ms
gopUploadTime Max GOP upload time in ms
uploadDurationRatio Max upload to duration ratio

AccountLiveInputEventsAdaptiveGroupsMin

FieldDescription
gopByteSize Min GOP size in bytes
gopDuration Min GOP duration in ms
gopUploadTime Min GOP upload time in ms
uploadDurationRatio Min upload to duration ratio

AccountLogExplorerIngestionAdaptiveGroups

Ingestion metrics for Log Explorer

FieldDescription
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum

AccountLogExplorerIngestionAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum

AccountLogExplorerIngestionAdaptiveGroupsDimensions

FieldDescription
dataset The dataset name
date Ingestion date
datetimeFifteenMinutes Ingestion time, truncated to multiple of 15 minutes
datetimeFiveMinutes Ingestion time, truncated to multiple of 5 minutes
datetimeHour Ingestion time, truncated to the hour
datetimeMinute Ingestion time, truncated to the minute
zoneTag Zone associated with the ingestion

AccountLogExplorerIngestionAdaptiveGroupsSum

FieldDescription
billableBytes Total billable bytes ingested to Log Explorer
totalBytes Total bytes ingested to Log Explorer

AccountLogExplorerIngestionAdaptiveGroupsSumConfidence

FieldDescription
billableBytes Confidence interval for the corresponding point estimate
totalBytes Confidence interval for the corresponding point estimate

AccountLogpushHealthAdaptiveGroups

Beta. Logpush job health metrics

FieldDescription
avg
confidence ALPHA - DO NOT USE
count The number of values for a metric per dimension
dimensions List of dimensions to group by
max Maximum value of a metric per dimension
sum The sum of values for a metric per dimension

AccountLogpushHealthAdaptiveGroupsAvg

FieldDescription
sampleInterval Average sample interval
uploadDuration Average upload duration in seconds

AccountLogpushHealthAdaptiveGroupsConfidence

FieldDescription
count The number of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountLogpushHealthAdaptiveGroupsDimensions

FieldDescription
date Date that we completed pushing the log batch
datetime Datetime that we completed pushing the log batch
datetimeFifteenMinutes Datetime that we completed pushing the log batch, truncated to multiple of 15 minutes
datetimeFiveMinutes Datetime that we completed pushing the log batch, truncated to multiple of 5 minutes
datetimeHour Datetime that we completed pushing the log batch, truncated to the hour
datetimeMinute Datetime that we completed pushing the log batch, truncated to the minute
destinationType Destination type, e.g. 'S3' or 'GCS'
error Error message
final Cloudflare may attempt to push a batch of logs multiple times if we encounter a failure. This field will be set to 1 if this was the last push attempt for this batch of logs. If this field is set to 0, it means the push failed but another retry was attempted. If this field is set to 1 and status >= 300, then the batch of logs failed to push and log data was lost. If you want to count the total number of logs that succeeded or failed, you should always set final = 1.
jobId The Logpush Job ID
status HTTP response status code of the log destination
success 1 when the upload was successful without error, otherwise 0

AccountLogpushHealthAdaptiveGroupsMax

FieldDescription
timestamp Latest timestamp of upload attempts

AccountLogpushHealthAdaptiveGroupsSum

FieldDescription
bytes Bytes of uncompressed log data in upload attempts
bytesCompressed Bytes of compressed log data in upload attempts
records A count of the total number of records in upload attempts.
uploads A count of the total number of upload attempts

AccountLogpushHealthAdaptiveGroupsSumConfidence

FieldDescription
bytes Confidence interval for the corresponding point estimate
bytesCompressed Confidence interval for the corresponding point estimate
records Confidence interval for the corresponding point estimate
uploads Confidence interval for the corresponding point estimate

AccountLogpushTransformersAdaptiveGroups

Beta. Logpush transformer health metrics

FieldDescription
avg
confidence ALPHA - DO NOT USE
count The number of transformer executions
dimensions List of dimensions to group by
max Maximum value of a metric per dimension
sum The sum of values for a metric per dimension

AccountLogpushTransformersAdaptiveGroupsAvg

FieldDescription
durationSeconds Average transformer execution duration in seconds
sampleInterval Average sample interval

AccountLogpushTransformersAdaptiveGroupsConfidence

FieldDescription
count The number of transformer executions, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountLogpushTransformersAdaptiveGroupsDimensions

FieldDescription
date Date of the transformer execution
datetime Datetime of the transformer execution
datetimeFifteenMinutes Datetime of the transformer execution, truncated to multiple of 15 minutes
datetimeFiveMinutes Datetime of the transformer execution, truncated to multiple of 5 minutes
datetimeHour Datetime of the transformer execution, truncated to the hour
datetimeMinute Datetime of the transformer execution, truncated to the minute
errorCode Error code. 0 = success, 1300+ = transformer error codes
jobId The Logpush Job ID
product Product being transformed (e.g. http_requests)
success 1 when the transformer executed successfully, otherwise 0
transformerId The Transformer ID

AccountLogpushTransformersAdaptiveGroupsMax

FieldDescription
timestamp Latest timestamp of transformer executions

AccountLogpushTransformersAdaptiveGroupsSum

FieldDescription
bytesIn Input bytes before transformation
bytesOut Output bytes after transformation
records Number of records processed by transformer

AccountLogpushTransformersAdaptiveGroupsSumConfidence

FieldDescription
bytesIn Confidence interval for the corresponding point estimate
bytesOut Confidence interval for the corresponding point estimate
records Confidence interval for the corresponding point estimate

AccountMagicEndpointHealthCheckAdaptiveGroups

Magic Endpoint Healthcheck events with adaptive sampling.

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count Total number of health checks
dimensions List of dimensions to group by
sum The sum of value for a metric per dimension

AccountMagicEndpointHealthCheckAdaptiveGroupsAvg

FieldDescription
lossPercentage Average calculated percentage (0-100) for endpoint healthchecks
sampleInterval The average value used for sample interval

AccountMagicEndpointHealthCheckAdaptiveGroupsConfidence

FieldDescription
count Total number of health checks, with confidence intervals
level Confidence level that was requested

AccountMagicEndpointHealthCheckAdaptiveGroupsDimensions

FieldDescription
checkId The ID of the check associated with the healthcheck
checkType The type of check associated with the healthcheck
date Healthcheck event timestamp, truncated to the day
datetime Healthcheck event timestamp
datetimeFifteenMinutes Healthcheck event timestamp, truncated to multiple of 15 minutes
datetimeFiveMinutes Calculation event timestamp, truncated to multiple of 5 minutes
datetimeHalfOfHour Healthcheck event timestamp, truncated to multiple of 30 minutes
datetimeHour Healthcheck event timestamp, truncated to the hour
datetimeMinute Healthcheck event timestamp, truncated to the minute
endpoint The endpoint of the check associated with the healthcheck
name The name associated with the healthcheck

AccountMagicEndpointHealthCheckAdaptiveGroupsSum

FieldDescription
failures Total failures
total Total number of health check events

AccountMagicFirewallNetworkAnalyticsAdaptiveGroups

Network analytics data for Magic Firewall

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountMagicFirewallNetworkAnalyticsAdaptiveGroupsAvg

FieldDescription
bitRate Sum of bits received, divided by 1 second, providing a per-second bit rate when grouped by datetime
bitRateDay Sum of bits received, divided by 86400 seconds, providing a per-second bit rate when grouped by date
bitRateFifteenMinutes Sum of bits received, divided by 900 seconds, providing a per-second bit rate when grouped by datetimeFifteenMinutes
bitRateFiveMinutes Sum of bits received, divided by 300 seconds, providing a per-second bit rate when grouped by datetimeFiveMinutes
bitRateHour Sum of bits received, divided by 3600 seconds, providing a per-second bit rate when grouped by datetimeHour
bitRateMinute Sum of bits received, divided by 60 seconds, providing a per-second bit rate when grouped by datetimeMinute
bitRateTenSeconds Sum of bits received, divided by 10 seconds, providing a per-second bit rate when grouped by datetimeTenSeconds
packetRate Sum of packets received, divided by 1 second, providing a per-second packet rate when grouped by datetime
packetRateDay Sum of packets received, divided by 86400 seconds, providing a per-second packet rate when grouped by date
packetRateFifteenMinutes Sum of packets received, divided by 900 seconds, providing a per-second packet rate when grouped by datetimeFifteenMinutes
packetRateFiveMinutes Sum of packets received, divided by 300 seconds, providing a per-second packet rate when grouped by datetimeFiveMinutes
packetRateHour Sum of packets received, divided by 3600 seconds, providing a per-second packet rate when grouped by datetimeHour
packetRateMinute Sum of packets received, divided by 60 seconds, providing a per-second packet rate when grouped by datetimeMinute
packetRateTenSeconds Sum of packets received, divided by 10 seconds, providing a per-second packet rate when grouped by datetimeTenSeconds

AccountMagicFirewallNetworkAnalyticsAdaptiveGroupsAvgConfidence

FieldDescription
bitRate Confidence interval for the corresponding point estimate
bitRateDay Confidence interval for the corresponding point estimate
bitRateFifteenMinutes Confidence interval for the corresponding point estimate
bitRateFiveMinutes Confidence interval for the corresponding point estimate
bitRateHour Confidence interval for the corresponding point estimate
bitRateMinute Confidence interval for the corresponding point estimate
bitRateTenSeconds Confidence interval for the corresponding point estimate
packetRate Confidence interval for the corresponding point estimate
packetRateDay Confidence interval for the corresponding point estimate
packetRateFifteenMinutes Confidence interval for the corresponding point estimate
packetRateFiveMinutes Confidence interval for the corresponding point estimate
packetRateHour Confidence interval for the corresponding point estimate
packetRateMinute Confidence interval for the corresponding point estimate
packetRateTenSeconds Confidence interval for the corresponding point estimate

AccountMagicFirewallNetworkAnalyticsAdaptiveGroupsConfidence

FieldDescription
avg The average of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountMagicFirewallNetworkAnalyticsAdaptiveGroupsDimensions

FieldDescription
applicationTag Application tag associated with the packet
coloCity City where the Cloudflare datacenter that received the packet is located
coloCode Cloudflare datacenter that received the packet (nearest IATA airport code)
coloCountry Country where the Cloudflare datacenter that received the packet is located (ISO 3166-1 alpha-2)
coloGeohash Latitude and longitude where the Cloudflare datacenter that received the packet is located (Geohash encoding)
coloName Cloudflare datacenter that received the packet (unique site identifier)
date Date that the packet was received
datetime Date and time that the packet was received
datetimeFifteenMinutes Date and time that the packet was received, rounded to the start of the nearest fifteen minutes
datetimeFiveMinutes Date and time that the packet was received, rounded to the start of the nearest five minutes
datetimeHour Date and time that the packet was received, rounded to the start of the nearest hour
datetimeMinute Date and time that the packet was received, rounded to the start of the nearest minute
datetimeTenSeconds Date and time that the packet was received, rounded to the start of the nearest ten seconds
destinationAsn ASN associated with the destination IP of the packet, or 0 if there was no mapping available
destinationAsnName Name of ASN associated with the destination IP of the packet, if available
destinationCountry Country where the destination IP of the packet is located (ISO 3166-1 alpha-2)
destinationDeviceTag Device tag associated with the destination IP of the packet
destinationGeohash Latitude and longitude where the destination IP of the packet is located (Geohash encoding)
destinationPort Value of the Destination Port header field in the TCP or UDP packet
direction Direction of the packet relative to the customer network (possible values: inbound, outbound, lateral)
ethertype Value of the Ethertype header field in the Ethernet packet (2048 for IPv4; 34525 for IPv6)
greChecksum Value of the Checkusm header field in the GRE packet
greEthertype Value of the Ethertype header field in the GRE packet
greHeaderLength Length of the GRE packet header, in bytes
greKey Value of the Key header field in the GRE packet
greSequenceNumber Value of the Sequence Number header field in the GRE packet
greVersion Value of the Version header field in the GRE packet
icmpChecksum Value of the Checkusm header field in the ICMP packet
icmpCode Value of the Code header field in the ICMP packet
icmpType Value of the Type header field in the ICMP packet
ipDestinationAddress Value of the Destination Address header field in the IPv4 or IPv6 packet
ipDestinationSubnet Computed subnet of the Destination Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipFragmentOffset Value of the Fragment Offset header field in the IPv4 or IPv6 packet
ipHeaderLength Length of the IPv4 or IPv6 packet header, in bytes
ipMoreFragments Value of the More Fragments header field in the IPv4 or IPv6 packet
ipProtocol Value of the Protocol header field in the IPv4 or IPv6 packet
ipProtocolName Name of the protocol specified by the Protocol header field in the IPv4 or IPv6 packet
ipSourceAddress Value of the Source Address header field in the IPv4 or IPv6 packet
ipSourceSubnet Computed subnet of the Source Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipTotalLength Total length of the IPv4 or IPv6 packet, in bytes
ipTotalLengthBuckets Total length of the IPv4 or IPv6 packet, in bytes, with the last two digits truncated
ipTtl Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet
ipTtlBuckets Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet, with the last digit truncated
ipv4Checksum Value of the Checksum header field in the IPv4 packet
ipv4DontFragment Value of the Don't Fragment header field in the IPv4 packet
ipv4Dscp Value of the Differentiated Services Code Point header field in the IPv4 packet
ipv4Ecn Value of the Explicit Congestion Notification header field in the IPv4 packet
ipv4Identification Value of the Identification header field in the IPv4 packet
ipv4Options List of Options numbers included in the IPv4 packet header
ipv6Dscp Value of the Differentiated Services Code Point header field in the IPv6 packet
ipv6Ecn Value of the Explicit Congestion Notification header field in the IPv6 packet
ipv6ExtensionHeaders List of Extension Header numbers included in the IPv6 packet header
ipv6FlowLabel Value of the Flow Label header field in the IPv6 packet
ipv6Identification Value of the Identification extension header field in the IPv6 packet
leaseTag IP lease tag associated with the packet
outcome The action that was taken on the packet (possible values: pass, drop)
prefixTag IP prefix tag associated with the packet
ruleId Unique identifier of the rule that matched the packet, if any
rulesetId Unique identifier of the ruleset containing the rule that matched the packet, if any
sampleInterval ABR sample interval
sourceAsn ASN associated with the source IP of the packet, or 0 if there was no mapping available
sourceAsnName Name of ASN associated with the source IP of the packet, if available
sourceCountry Country where the source IP of the packet is located (ISO 3166-1 alpha-2)
sourceDeviceTag Device tag associated with the source IP of the packet
sourceGeohash Latitude and longitude where the source IP of the packet is located (Geohash encoding)
sourcePort Value of the Source Port header field in the TCP or UDP packet
tcpAcknowledgementNumber Value of the Acknowledgement Number header field in the TCP packet
tcpChecksum Value of the Checkusm header field in the TCP packet
tcpDataOffset Value of the Data Offset header field in the TCP packet
tcpFlags Value of the Flags header field in the TCP packet
tcpFlagsString Human-readable string representation of the Flags header field in the TCP packet
tcpMss Value of the MSS option header field in the TCP packet
tcpOptions List of Options numbers included in the TCP packet header
tcpSackBlocks Value of the SACK Blocks option header field in the TCP packet
tcpSackPermitted Value of the SACK Permitted option header field in the TCP packet
tcpSequenceNumber Value of the Sequence Number header field in the TCP packet
tcpTimestampEcr Value of the Timestamp Echo Reply option header field in the TCP packet
tcpTimestampValue Value of the Timestamp option header field in the TCP packet
tcpUrgentPointer Value of the Urgent Pointer header field in the TCP packet
tcpWindowScale Value of the Window Scale option header field in the TCP packet
tcpWindowSize Value of the Window Size header field in the TCP packet
udpChecksum Value of the Checkusm header field in the UDP packet
udpPayloadLength Value of the Payload Length header field in the UDP packet
verdict The action that Cloudflare thinks should be taken on the packet (possible values: pass, drop)

AccountMagicFirewallNetworkAnalyticsAdaptiveGroupsSum

FieldDescription
bits Sum of bits received
packets Sum of packets received

AccountMagicFirewallNetworkAnalyticsAdaptiveGroupsSumConfidence

FieldDescription
bits Confidence interval for the corresponding point estimate
packets Confidence interval for the corresponding point estimate

AccountMagicFirewallRateLimitNetworkAnalyticsAdaptiveGroups

Network analytics data for Magic Firewall Ratelimiting

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountMagicFirewallRateLimitNetworkAnalyticsAdaptiveGroupsAvg

FieldDescription
bitRate Sum of bits received, divided by 1 second, providing a per-second bit rate when grouped by datetime
bitRateDay Sum of bits received, divided by 86400 seconds, providing a per-second bit rate when grouped by date
bitRateFifteenMinutes Sum of bits received, divided by 900 seconds, providing a per-second bit rate when grouped by datetimeFifteenMinutes
bitRateFiveMinutes Sum of bits received, divided by 300 seconds, providing a per-second bit rate when grouped by datetimeFiveMinutes
bitRateHour Sum of bits received, divided by 3600 seconds, providing a per-second bit rate when grouped by datetimeHour
bitRateMinute Sum of bits received, divided by 60 seconds, providing a per-second bit rate when grouped by datetimeMinute
bitRateTenSeconds Sum of bits received, divided by 10 seconds, providing a per-second bit rate when grouped by datetimeTenSeconds
packetRate Sum of packets received, divided by 1 second, providing a per-second packet rate when grouped by datetime
packetRateDay Sum of packets received, divided by 86400 seconds, providing a per-second packet rate when grouped by date
packetRateFifteenMinutes Sum of packets received, divided by 900 seconds, providing a per-second packet rate when grouped by datetimeFifteenMinutes
packetRateFiveMinutes Sum of packets received, divided by 300 seconds, providing a per-second packet rate when grouped by datetimeFiveMinutes
packetRateHour Sum of packets received, divided by 3600 seconds, providing a per-second packet rate when grouped by datetimeHour
packetRateMinute Sum of packets received, divided by 60 seconds, providing a per-second packet rate when grouped by datetimeMinute
packetRateTenSeconds Sum of packets received, divided by 10 seconds, providing a per-second packet rate when grouped by datetimeTenSeconds

AccountMagicFirewallRateLimitNetworkAnalyticsAdaptiveGroupsAvgConfidence

FieldDescription
bitRate Confidence interval for the corresponding point estimate
bitRateDay Confidence interval for the corresponding point estimate
bitRateFifteenMinutes Confidence interval for the corresponding point estimate
bitRateFiveMinutes Confidence interval for the corresponding point estimate
bitRateHour Confidence interval for the corresponding point estimate
bitRateMinute Confidence interval for the corresponding point estimate
bitRateTenSeconds Confidence interval for the corresponding point estimate
packetRate Confidence interval for the corresponding point estimate
packetRateDay Confidence interval for the corresponding point estimate
packetRateFifteenMinutes Confidence interval for the corresponding point estimate
packetRateFiveMinutes Confidence interval for the corresponding point estimate
packetRateHour Confidence interval for the corresponding point estimate
packetRateMinute Confidence interval for the corresponding point estimate
packetRateTenSeconds Confidence interval for the corresponding point estimate

AccountMagicFirewallRateLimitNetworkAnalyticsAdaptiveGroupsConfidence

FieldDescription
avg The average of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountMagicFirewallRateLimitNetworkAnalyticsAdaptiveGroupsDimensions

FieldDescription
applicationTag Application tag associated with the packet
coloCity City where the Cloudflare datacenter that received the packet is located
coloCode Cloudflare datacenter that received the packet (nearest IATA airport code)
coloCountry Country where the Cloudflare datacenter that received the packet is located (ISO 3166-1 alpha-2)
coloGeohash Latitude and longitude where the Cloudflare datacenter that received the packet is located (Geohash encoding)
coloName Cloudflare datacenter that received the packet (unique site identifier)
date Date that the packet was received
datetime Date and time that the packet was received
datetimeFifteenMinutes Date and time that the packet was received, rounded to the start of the nearest fifteen minutes
datetimeFiveMinutes Date and time that the packet was received, rounded to the start of the nearest five minutes
datetimeHour Date and time that the packet was received, rounded to the start of the nearest hour
datetimeMinute Date and time that the packet was received, rounded to the start of the nearest minute
datetimeTenSeconds Date and time that the packet was received, rounded to the start of the nearest ten seconds
destinationAsn ASN associated with the destination IP of the packet, or 0 if there was no mapping available
destinationAsnName Name of ASN associated with the destination IP of the packet, if available
destinationCountry Country where the destination IP of the packet is located (ISO 3166-1 alpha-2)
destinationDeviceTag Device tag associated with the destination IP of the packet
destinationGeohash Latitude and longitude where the destination IP of the packet is located (Geohash encoding)
destinationPort Value of the Destination Port header field in the TCP or UDP packet
direction Direction of the packet relative to the customer network (possible values: inbound, outbound, lateral)
ethertype Value of the Ethertype header field in the Ethernet packet (2048 for IPv4; 34525 for IPv6)
greChecksum Value of the Checkusm header field in the GRE packet
greEthertype Value of the Ethertype header field in the GRE packet
greHeaderLength Length of the GRE packet header, in bytes
greKey Value of the Key header field in the GRE packet
greSequenceNumber Value of the Sequence Number header field in the GRE packet
greVersion Value of the Version header field in the GRE packet
icmpChecksum Value of the Checkusm header field in the ICMP packet
icmpCode Value of the Code header field in the ICMP packet
icmpType Value of the Type header field in the ICMP packet
ipDestinationAddress Value of the Destination Address header field in the IPv4 or IPv6 packet
ipDestinationSubnet Computed subnet of the Destination Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipFragmentOffset Value of the Fragment Offset header field in the IPv4 or IPv6 packet
ipHeaderLength Length of the IPv4 or IPv6 packet header, in bytes
ipMoreFragments Value of the More Fragments header field in the IPv4 or IPv6 packet
ipProtocol Value of the Protocol header field in the IPv4 or IPv6 packet
ipProtocolName Name of the protocol specified by the Protocol header field in the IPv4 or IPv6 packet
ipSourceAddress Value of the Source Address header field in the IPv4 or IPv6 packet
ipSourceSubnet Computed subnet of the Source Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipTotalLength Total length of the IPv4 or IPv6 packet, in bytes
ipTotalLengthBuckets Total length of the IPv4 or IPv6 packet, in bytes, with the last two digits truncated
ipTtl Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet
ipTtlBuckets Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet, with the last digit truncated
ipv4Checksum Value of the Checksum header field in the IPv4 packet
ipv4DontFragment Value of the Don't Fragment header field in the IPv4 packet
ipv4Dscp Value of the Differentiated Services Code Point header field in the IPv4 packet
ipv4Ecn Value of the Explicit Congestion Notification header field in the IPv4 packet
ipv4Identification Value of the Identification header field in the IPv4 packet
ipv4Options List of Options numbers included in the IPv4 packet header
ipv6Dscp Value of the Differentiated Services Code Point header field in the IPv6 packet
ipv6Ecn Value of the Explicit Congestion Notification header field in the IPv6 packet
ipv6ExtensionHeaders List of Extension Header numbers included in the IPv6 packet header
ipv6FlowLabel Value of the Flow Label header field in the IPv6 packet
ipv6Identification Value of the Identification extension header field in the IPv6 packet
leaseTag IP lease tag associated with the packet
outcome The action that was taken on the packet (possible values: pass, drop)
prefixTag IP prefix tag associated with the packet
ruleId Unique identifier of the rule that matched the packet, if any
rulesetId Unique identifier of the ruleset containing the rule that matched the packet, if any
sampleInterval ABR sample interval
sourceAsn ASN associated with the source IP of the packet, or 0 if there was no mapping available
sourceAsnName Name of ASN associated with the source IP of the packet, if available
sourceCountry Country where the source IP of the packet is located (ISO 3166-1 alpha-2)
sourceDeviceTag Device tag associated with the source IP of the packet
sourceGeohash Latitude and longitude where the source IP of the packet is located (Geohash encoding)
sourcePort Value of the Source Port header field in the TCP or UDP packet
tcpAcknowledgementNumber Value of the Acknowledgement Number header field in the TCP packet
tcpChecksum Value of the Checkusm header field in the TCP packet
tcpDataOffset Value of the Data Offset header field in the TCP packet
tcpFlags Value of the Flags header field in the TCP packet
tcpFlagsString Human-readable string representation of the Flags header field in the TCP packet
tcpMss Value of the MSS option header field in the TCP packet
tcpOptions List of Options numbers included in the TCP packet header
tcpSackBlocks Value of the SACK Blocks option header field in the TCP packet
tcpSackPermitted Value of the SACK Permitted option header field in the TCP packet
tcpSequenceNumber Value of the Sequence Number header field in the TCP packet
tcpTimestampEcr Value of the Timestamp Echo Reply option header field in the TCP packet
tcpTimestampValue Value of the Timestamp option header field in the TCP packet
tcpUrgentPointer Value of the Urgent Pointer header field in the TCP packet
tcpWindowScale Value of the Window Scale option header field in the TCP packet
tcpWindowSize Value of the Window Size header field in the TCP packet
udpChecksum Value of the Checkusm header field in the UDP packet
udpPayloadLength Value of the Payload Length header field in the UDP packet
verdict The action that Cloudflare thinks should be taken on the packet (possible values: pass, drop)

AccountMagicFirewallRateLimitNetworkAnalyticsAdaptiveGroupsSum

FieldDescription
bits Sum of bits received
packets Sum of packets received

AccountMagicFirewallRateLimitNetworkAnalyticsAdaptiveGroupsSumConfidence

FieldDescription
bits Confidence interval for the corresponding point estimate
packets Confidence interval for the corresponding point estimate

AccountMagicFirewallSamplesAdaptiveGroups

Data to visualize traffic allowed and blocked by Magic Firewall rules

FieldDescription
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountMagicFirewallSamplesAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountMagicFirewallSamplesAdaptiveGroupsDimensions

FieldDescription
date Date that the packet was received, truncated to the start of a day
datetime Date and time that the packet was received
datetimeFifteenMinutes Date and time that the packet was received, rounded to the start of the nearest fifteen minutes
datetimeFiveMinute DEPRECATED (Deprecated in favor of datetimeFiveMinutes): Date and time that the packet was received, rounded to the start of the nearest five minutes
datetimeFiveMinutes Date and time that the packet was received, rounded to the start of the nearest five minutes
datetimeHour Date and time that the packet was received, rounded to the start of the nearest hour
datetimeMinute Date and time that the packet was received, rounded to the start of the nearest minute
ruleId Unique identifier of the rule that matched the packet, if any

AccountMagicFirewallSamplesAdaptiveGroupsSum

FieldDescription
bits Sum of bits received
packets Sum of packets received

AccountMagicFirewallSamplesAdaptiveGroupsSumConfidence

FieldDescription
bits Confidence interval for the corresponding point estimate
packets Confidence interval for the corresponding point estimate

AccountMagicIDPSNetworkAnalyticsAdaptiveGroups

Network analytics data for Magic IDS

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountMagicIDPSNetworkAnalyticsAdaptiveGroupsAvg

FieldDescription
bitRate Sum of bits received, divided by 1 second, providing a per-second bit rate when grouped by datetime
bitRateDay Sum of bits received, divided by 86400 seconds, providing a per-second bit rate when grouped by date
bitRateFifteenMinutes Sum of bits received, divided by 900 seconds, providing a per-second bit rate when grouped by datetimeFifteenMinutes
bitRateFiveMinutes Sum of bits received, divided by 300 seconds, providing a per-second bit rate when grouped by datetimeFiveMinutes
bitRateHour Sum of bits received, divided by 3600 seconds, providing a per-second bit rate when grouped by datetimeHour
bitRateMinute Sum of bits received, divided by 60 seconds, providing a per-second bit rate when grouped by datetimeMinute
bitRateTenSeconds Sum of bits received, divided by 10 seconds, providing a per-second bit rate when grouped by datetimeTenSeconds
packetRate Sum of packets received, divided by 1 second, providing a per-second packet rate when grouped by datetime
packetRateDay Sum of packets received, divided by 86400 seconds, providing a per-second packet rate when grouped by date
packetRateFifteenMinutes Sum of packets received, divided by 900 seconds, providing a per-second packet rate when grouped by datetimeFifteenMinutes
packetRateFiveMinutes Sum of packets received, divided by 300 seconds, providing a per-second packet rate when grouped by datetimeFiveMinutes
packetRateHour Sum of packets received, divided by 3600 seconds, providing a per-second packet rate when grouped by datetimeHour
packetRateMinute Sum of packets received, divided by 60 seconds, providing a per-second packet rate when grouped by datetimeMinute
packetRateTenSeconds Sum of packets received, divided by 10 seconds, providing a per-second packet rate when grouped by datetimeTenSeconds

AccountMagicIDPSNetworkAnalyticsAdaptiveGroupsAvgConfidence

FieldDescription
bitRate Confidence interval for the corresponding point estimate
bitRateDay Confidence interval for the corresponding point estimate
bitRateFifteenMinutes Confidence interval for the corresponding point estimate
bitRateFiveMinutes Confidence interval for the corresponding point estimate
bitRateHour Confidence interval for the corresponding point estimate
bitRateMinute Confidence interval for the corresponding point estimate
bitRateTenSeconds Confidence interval for the corresponding point estimate
packetRate Confidence interval for the corresponding point estimate
packetRateDay Confidence interval for the corresponding point estimate
packetRateFifteenMinutes Confidence interval for the corresponding point estimate
packetRateFiveMinutes Confidence interval for the corresponding point estimate
packetRateHour Confidence interval for the corresponding point estimate
packetRateMinute Confidence interval for the corresponding point estimate
packetRateTenSeconds Confidence interval for the corresponding point estimate

AccountMagicIDPSNetworkAnalyticsAdaptiveGroupsConfidence

FieldDescription
avg The average of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountMagicIDPSNetworkAnalyticsAdaptiveGroupsDimensions

FieldDescription
coloCity City where the Cloudflare datacenter that received the packet is located
coloCode Cloudflare datacenter that received the packet (nearest IATA airport code)
coloCountry Country where the Cloudflare datacenter that received the packet is located (ISO 3166-1 alpha-2)
coloGeohash Latitude and longitude where the Cloudflare datacenter that received the packet is located (Geohash encoding)
coloName Cloudflare datacenter that received the packet (unique site identifier)
date Date that the packet was received
datetime Date and time that the packet was received
datetimeFifteenMinutes Date and time that the packet was received, rounded to the start of the nearest fifteen minutes
datetimeFiveMinutes Date and time that the packet was received, rounded to the start of the nearest five minutes
datetimeHour Date and time that the packet was received, rounded to the start of the nearest hour
datetimeMinute Date and time that the packet was received, rounded to the start of the nearest minute
datetimeTenSeconds Date and time that the packet was received, rounded to the start of the nearest ten seconds
destinationAsn ASN associated with the destination IP of the packet, or 0 if there was no mapping available
destinationAsnName Name of ASN associated with the destination IP of the packet, if available
destinationCountry Country where the destination IP of the packet is located (ISO 3166-1 alpha-2)
destinationDeviceTag Device tag associated with the destination IP of the packet
destinationGeohash Latitude and longitude where the destination IP of the packet is located (Geohash encoding)
destinationPort Value of the Destination Port header field in the TCP or UDP packet
direction Direction of the packet relative to the customer network (possible values: inbound, outbound, lateral)
ethertype Value of the Ethertype header field in the Ethernet packet (2048 for IPv4; 34525 for IPv6)
greChecksum Value of the Checkusm header field in the GRE packet
greEthertype Value of the Ethertype header field in the GRE packet
greHeaderLength Length of the GRE packet header, in bytes
greKey Value of the Key header field in the GRE packet
greSequenceNumber Value of the Sequence Number header field in the GRE packet
greVersion Value of the Version header field in the GRE packet
icmpChecksum Value of the Checkusm header field in the ICMP packet
icmpCode Value of the Code header field in the ICMP packet
icmpType Value of the Type header field in the ICMP packet
ipDestinationAddress Value of the Destination Address header field in the IPv4 or IPv6 packet
ipDestinationSubnet Computed subnet of the Destination Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipFragmentOffset Value of the Fragment Offset header field in the IPv4 or IPv6 packet
ipHeaderLength Length of the IPv4 or IPv6 packet header, in bytes
ipMoreFragments Value of the More Fragments header field in the IPv4 or IPv6 packet
ipProtocol Value of the Protocol header field in the IPv4 or IPv6 packet
ipProtocolName Name of the protocol specified by the Protocol header field in the IPv4 or IPv6 packet
ipSourceAddress Value of the Source Address header field in the IPv4 or IPv6 packet
ipSourceSubnet Computed subnet of the Source Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipTotalLength Total length of the IPv4 or IPv6 packet, in bytes
ipTotalLengthBuckets Total length of the IPv4 or IPv6 packet, in bytes, with the last two digits truncated
ipTtl Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet
ipTtlBuckets Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet, with the last digit truncated
ipv4Checksum Value of the Checksum header field in the IPv4 packet
ipv4DontFragment Value of the Don't Fragment header field in the IPv4 packet
ipv4Dscp Value of the Differentiated Services Code Point header field in the IPv4 packet
ipv4Ecn Value of the Explicit Congestion Notification header field in the IPv4 packet
ipv4Identification Value of the Identification header field in the IPv4 packet
ipv4Options List of Options numbers included in the IPv4 packet header
ipv6Dscp Value of the Differentiated Services Code Point header field in the IPv6 packet
ipv6Ecn Value of the Explicit Congestion Notification header field in the IPv6 packet
ipv6ExtensionHeaders List of Extension Header numbers included in the IPv6 packet header
ipv6FlowLabel Value of the Flow Label header field in the IPv6 packet
ipv6Identification Value of the Identification extension header field in the IPv6 packet
outcome The action that was taken on the packet (possible values: pass, drop)
sampleInterval ABR sample interval
sourceAsn ASN associated with the source IP of the packet, or 0 if there was no mapping available
sourceAsnName Name of ASN associated with the source IP of the packet, if available
sourceCountry Country where the source IP of the packet is located (ISO 3166-1 alpha-2)
sourceDeviceTag Device tag associated with the source IP of the packet
sourceGeohash Latitude and longitude where the source IP of the packet is located (Geohash encoding)
sourcePort Value of the Source Port header field in the TCP or UDP packet
tcpAcknowledgementNumber Value of the Acknowledgement Number header field in the TCP packet
tcpChecksum Value of the Checkusm header field in the TCP packet
tcpDataOffset Value of the Data Offset header field in the TCP packet
tcpFlags Value of the Flags header field in the TCP packet
tcpFlagsString Human-readable string representation of the Flags header field in the TCP packet
tcpMss Value of the MSS option header field in the TCP packet
tcpOptions List of Options numbers included in the TCP packet header
tcpSackBlocks Value of the SACK Blocks option header field in the TCP packet
tcpSackPermitted Value of the SACK Permitted option header field in the TCP packet
tcpSequenceNumber Value of the Sequence Number header field in the TCP packet
tcpTimestampEcr Value of the Timestamp Echo Reply option header field in the TCP packet
tcpTimestampValue Value of the Timestamp option header field in the TCP packet
tcpUrgentPointer Value of the Urgent Pointer header field in the TCP packet
tcpWindowScale Value of the Window Scale option header field in the TCP packet
tcpWindowSize Value of the Window Size header field in the TCP packet
udpChecksum Value of the Checkusm header field in the UDP packet
udpPayloadLength Value of the Payload Length header field in the UDP packet
verdict The action that Cloudflare thinks should be taken on the packet (possible values: pass, drop)

AccountMagicIDPSNetworkAnalyticsAdaptiveGroupsSum

FieldDescription
bits Sum of bits received
packets Sum of packets received

AccountMagicIDPSNetworkAnalyticsAdaptiveGroupsSumConfidence

FieldDescription
bits Confidence interval for the corresponding point estimate
packets Confidence interval for the corresponding point estimate

AccountMagicTransitNetworkAnalyticsAdaptiveGroups

Network analytics data for Magic Transit traffic

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountMagicTransitNetworkAnalyticsAdaptiveGroupsAvg

FieldDescription
bitRate Sum of bits received, divided by 1 second, providing a per-second bit rate when grouped by datetime
bitRateDay Sum of bits received, divided by 86400 seconds, providing a per-second bit rate when grouped by date
bitRateFifteenMinutes Sum of bits received, divided by 900 seconds, providing a per-second bit rate when grouped by datetimeFifteenMinutes
bitRateFiveMinutes Sum of bits received, divided by 300 seconds, providing a per-second bit rate when grouped by datetimeFiveMinutes
bitRateHour Sum of bits received, divided by 3600 seconds, providing a per-second bit rate when grouped by datetimeHour
bitRateMinute Sum of bits received, divided by 60 seconds, providing a per-second bit rate when grouped by datetimeMinute
bitRateTenSeconds Sum of bits received, divided by 10 seconds, providing a per-second bit rate when grouped by datetimeTenSeconds
packetRate Sum of packets received, divided by 1 second, providing a per-second packet rate when grouped by datetime
packetRateDay Sum of packets received, divided by 86400 seconds, providing a per-second packet rate when grouped by date
packetRateFifteenMinutes Sum of packets received, divided by 900 seconds, providing a per-second packet rate when grouped by datetimeFifteenMinutes
packetRateFiveMinutes Sum of packets received, divided by 300 seconds, providing a per-second packet rate when grouped by datetimeFiveMinutes
packetRateHour Sum of packets received, divided by 3600 seconds, providing a per-second packet rate when grouped by datetimeHour
packetRateMinute Sum of packets received, divided by 60 seconds, providing a per-second packet rate when grouped by datetimeMinute
packetRateTenSeconds Sum of packets received, divided by 10 seconds, providing a per-second packet rate when grouped by datetimeTenSeconds

AccountMagicTransitNetworkAnalyticsAdaptiveGroupsAvgConfidence

FieldDescription
bitRate Confidence interval for the corresponding point estimate
bitRateDay Confidence interval for the corresponding point estimate
bitRateFifteenMinutes Confidence interval for the corresponding point estimate
bitRateFiveMinutes Confidence interval for the corresponding point estimate
bitRateHour Confidence interval for the corresponding point estimate
bitRateMinute Confidence interval for the corresponding point estimate
bitRateTenSeconds Confidence interval for the corresponding point estimate
packetRate Confidence interval for the corresponding point estimate
packetRateDay Confidence interval for the corresponding point estimate
packetRateFifteenMinutes Confidence interval for the corresponding point estimate
packetRateFiveMinutes Confidence interval for the corresponding point estimate
packetRateHour Confidence interval for the corresponding point estimate
packetRateMinute Confidence interval for the corresponding point estimate
packetRateTenSeconds Confidence interval for the corresponding point estimate

AccountMagicTransitNetworkAnalyticsAdaptiveGroupsConfidence

FieldDescription
avg The average of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountMagicTransitNetworkAnalyticsAdaptiveGroupsDimensions

FieldDescription
applicationTag Application tag associated with the packet
coloCity City where the Cloudflare datacenter that received the packet is located
coloCode Cloudflare datacenter that received the packet (nearest IATA airport code)
coloCountry Country where the Cloudflare datacenter that received the packet is located (ISO 3166-1 alpha-2)
coloGeohash Latitude and longitude where the Cloudflare datacenter that received the packet is located (Geohash encoding)
coloName Cloudflare datacenter that received the packet (unique site identifier)
date Date that the packet was received
datetime Date and time that the packet was received
datetimeFifteenMinutes Date and time that the packet was received, rounded to the start of the nearest fifteen minutes
datetimeFiveMinutes Date and time that the packet was received, rounded to the start of the nearest five minutes
datetimeHour Date and time that the packet was received, rounded to the start of the nearest hour
datetimeMinute Date and time that the packet was received, rounded to the start of the nearest minute
datetimeTenSeconds Date and time that the packet was received, rounded to the start of the nearest ten seconds
destinationAsn ASN associated with the destination IP of the packet, or 0 if there was no mapping available
destinationAsnName Name of ASN associated with the destination IP of the packet, if available
destinationCountry Country where the destination IP of the packet is located (ISO 3166-1 alpha-2)
destinationGeohash Latitude and longitude where the destination IP of the packet is located (Geohash encoding)
destinationPort Value of the Destination Port header field in the TCP or UDP packet
direction Direction of the packet relative to the customer network (possible values: inbound, outbound, lateral)
egressTunnelID GRE or IPSec Egress Tunnel ID for Magic WAN and Magic Transit traffic
egressTunnelName GRE or IPSec Egress Tunnel name for Magic WAN and Magic Transit traffic
ethertype Value of the Ethertype header field in the Ethernet packet (2048 for IPv4; 34525 for IPv6)
greChecksum Value of the Checkusm header field in the GRE packet
greEthertype Value of the Ethertype header field in the GRE packet
greHeaderLength Length of the GRE packet header, in bytes
greKey Value of the Key header field in the GRE packet
greSequenceNumber Value of the Sequence Number header field in the GRE packet
greVersion Value of the Version header field in the GRE packet
icmpChecksum Value of the Checkusm header field in the ICMP packet
icmpCode Value of the Code header field in the ICMP packet
icmpType Value of the Type header field in the ICMP packet
ingressTunnelID GRE or IPSec Ingress Tunnel ID for Magic WAN and Magic Transit traffic
ingressTunnelName GRE or IPSec Ingress Tunnel name for Magic WAN and Magic Transit traffic
ipDestinationAddress Value of the Destination Address header field in the IPv4 or IPv6 packet
ipDestinationSubnet Computed subnet of the Destination Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipFragmentOffset Value of the Fragment Offset header field in the IPv4 or IPv6 packet
ipHeaderLength Length of the IPv4 or IPv6 packet header, in bytes
ipMoreFragments Value of the More Fragments header field in the IPv4 or IPv6 packet
ipProtocol Value of the Protocol header field in the IPv4 or IPv6 packet
ipProtocolName Name of the protocol specified by the Protocol header field in the IPv4 or IPv6 packet
ipSourceAddress Value of the Source Address header field in the IPv4 or IPv6 packet
ipSourceSubnet Computed subnet of the Source Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipTotalLength Total length of the IPv4 or IPv6 packet, in bytes
ipTotalLengthBuckets Total length of the IPv4 or IPv6 packet, in bytes, with the last two digits truncated
ipTtl Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet
ipTtlBuckets Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet, with the last digit truncated
ipv4Checksum Value of the Checksum header field in the IPv4 packet
ipv4DontFragment Value of the Don't Fragment header field in the IPv4 packet
ipv4Dscp Value of the Differentiated Services Code Point header field in the IPv4 packet
ipv4Ecn Value of the Explicit Congestion Notification header field in the IPv4 packet
ipv4Identification Value of the Identification header field in the IPv4 packet
ipv4Options List of Options numbers included in the IPv4 packet header
ipv6Dscp Value of the Differentiated Services Code Point header field in the IPv6 packet
ipv6Ecn Value of the Explicit Congestion Notification header field in the IPv6 packet
ipv6ExtensionHeaders List of Extension Header numbers included in the IPv6 packet header
ipv6FlowLabel Value of the Flow Label header field in the IPv6 packet
ipv6Identification Value of the Identification extension header field in the IPv6 packet
leaseTag IP lease tag associated with the packet
mitigationSystem Which system dropped the packet (possible values: dosd, flowtrackd, magic-firewall)
offRamp Offramp method for Magic WAN and Magic Transit traffic - GRE, IPSec, CNI, Warp, Cloudflared
onRamp Onramp method for Magic WAN and Magic Transit traffic - GRE, IPSec, CNI, Warp, Cloudflared
outcome The action that was taken on the packet (possible values: pass, drop)
prefixTag IP prefix tag associated with the packet
sampleInterval ABR sample interval
sourceAsn ASN associated with the source IP of the packet, or 0 if there was no mapping available
sourceAsnName Name of ASN associated with the source IP of the packet, if available
sourceCountry Country where the source IP of the packet is located (ISO 3166-1 alpha-2)
sourceGeohash Latitude and longitude where the source IP of the packet is located (Geohash encoding)
sourcePort Value of the Source Port header field in the TCP or UDP packet
tcpAcknowledgementNumber Value of the Acknowledgement Number header field in the TCP packet
tcpChecksum Value of the Checkusm header field in the TCP packet
tcpDataOffset Value of the Data Offset header field in the TCP packet
tcpFlags Value of the Flags header field in the TCP packet
tcpFlagsString Human-readable string representation of the Flags header field in the TCP packet
tcpMss Value of the MSS option header field in the TCP packet
tcpOptions List of Options numbers included in the TCP packet header
tcpSackBlocks Value of the SACK Blocks option header field in the TCP packet
tcpSackPermitted Value of the SACK Permitted option header field in the TCP packet
tcpSequenceNumber Value of the Sequence Number header field in the TCP packet
tcpTimestampEcr Value of the Timestamp Echo Reply option header field in the TCP packet
tcpTimestampValue Value of the Timestamp option header field in the TCP packet
tcpUrgentPointer Value of the Urgent Pointer header field in the TCP packet
tcpWindowScale Value of the Window Scale option header field in the TCP packet
tcpWindowSize Value of the Window Size header field in the TCP packet
trafficType Custom protocol or traffic type for Magic Wan and Magic Transit traffic - Unidirectional and Bidirectional Tunnel Health Check
udpChecksum Value of the Checkusm header field in the UDP packet
udpPayloadLength Value of the Payload Length header field in the UDP packet

AccountMagicTransitNetworkAnalyticsAdaptiveGroupsSum

FieldDescription
bits Sum of bits received
packets Sum of packets received

AccountMagicTransitNetworkAnalyticsAdaptiveGroupsSumConfidence

FieldDescription
bits Confidence interval for the corresponding point estimate
packets Confidence interval for the corresponding point estimate

AccountMagicTransitTunnelHealthCheckSLOsAdaptiveGroups

Magic Transit Tunnel Health Check SLO events with adaptive sampling.

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count Total number of SLO calculations
dimensions List of dimensions to group by
max The maximum value for a metric per dimension

AccountMagicTransitTunnelHealthCheckSLOsAdaptiveGroupsAvg

FieldDescription
effectiveSlo Average calculated SLI for tunnel health checks
sampleInterval The average value used for sample interval
slo Average target SLO

AccountMagicTransitTunnelHealthCheckSLOsAdaptiveGroupsConfidence

FieldDescription
count Total number of SLO calculations, with confidence intervals
level Confidence level that was requested

AccountMagicTransitTunnelHealthCheckSLOsAdaptiveGroupsDimensions

FieldDescription
alertType The alert type of the notification policy
date SLO calculation event timestamp, truncated to the day
datetime SLO calculation event timestamp
datetimeFifteenMinutes SLO calculation event timestamp, truncated to multiple of 15 minutes
datetimeFiveMinutes SLO calculation event timestamp, truncated to multiple of 5 minutes
datetimeHalfOfHour SLO calculation event timestamp, truncated to multiple of 30 minutes
datetimeHour SLO calculation event timestamp, truncated to the hour
datetimeMinute SLO calculation event timestamp, truncated to the minute
policyId The ID of the notification policy associated with the calculation
siteName The name of the site the tunnel is associated with
status The health status of the tunnel
tunnelId The ID of the tunnel
tunnelName The name of the tunnel

AccountMagicTransitTunnelHealthCheckSLOsAdaptiveGroupsMax

FieldDescription
slo Maximum target SLO

AccountMagicTransitTunnelHealthChecksAdaptiveGroups

Beta. Magic Transit Health check results for customer GRE Tunnels with adaptive sampling (ABR).

FieldDescription
avg
confidence ALPHA - DO NOT USE
count Total number of healthcheck results
dimensions List of dimensions to group by

AccountMagicTransitTunnelHealthChecksAdaptiveGroupsAvg

FieldDescription
sampleInterval Average sample interval per dimension
tunnelState Combined Tunnel State aggregated from multiple results. 0 is down, 0.5 is degraded and 1 is healthy

AccountMagicTransitTunnelHealthChecksAdaptiveGroupsConfidence

FieldDescription
count Total number of healthcheck results, with confidence intervals
level Confidence level that was requested

AccountMagicTransitTunnelHealthChecksAdaptiveGroupsDimensions

FieldDescription
active Returns 1 if the colo had traffic for this tunnel in the last 6 hours, otherwise 0
date The date the healthcheck request was sent, truncated to the start of a day
datetime The time the healthcheck request was sent
datetimeFifteenMinutes The time the healthcheck request was sent, truncated to multiple of 15 minutes
datetimeFiveMinutes The time the healthcheck request was sent, truncated to multiple of 5 minutes
datetimeHalfOfHour The time the healthcheck request was sent, truncated to multiple of 30 minutes
datetimeHour The time the healthcheck request was sent, truncated to the hour
datetimeMinute The time the healthcheck request was sent, truncated to the last minute
edgeColoCity City of the Cloudflare datacenter from where the healthcheck was run
edgeColoCode IATA airport code of the Cloudflare datacenter from where the healthcheck was run
edgeColoCountry Country of the Cloudflare datacenter from where the healthcheck was run
edgeColoName The name of the Cloudflare datacenter from where the healthcheck was run
edgeColoRegion Region of the Cloudflare datacenter from where the healthcheck was run
edgePopName The name of the Cloudflare POP from where the healthcheck was run
remoteTunnelIPv4 IP address of the remote end of the tunnel
resultStatus The status of the request
siteName Human friendly site name associated with the tunnel
tunnelName Human friendly tunnel name

AccountMagicTransitTunnelTrafficAdaptiveGroups

Bandwidth usage metric of a Magic Transit tunnel.

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountMagicTransitTunnelTrafficAdaptiveGroupsAvg

FieldDescription
bitRate Sum of bits received, divided by 1 second, providing a per-second bit rate when grouped by datetime
bitRateDay Sum of bits received, divided by 86400 seconds, providing a per-second bit rate when grouped by date
bitRateFifteenMinutes Sum of bits received, divided by 900 seconds, providing a per-second bit rate when grouped by datetimeFifteenMinutes
bitRateFiveMinutes Sum of bits received, divided by 300 seconds, providing a per-second bit rate when grouped by datetimeFiveMinutes
bitRateHour Sum of bits received, divided by 3600 seconds, providing a per-second bit rate when grouped by datetimeHour
bitRateMinute Sum of bits received, divided by 60 seconds, providing a per-second bit rate when grouped by datetimeMinute
bitRateTenSeconds Sum of bits received, divided by 10 seconds, providing a per-second bit rate when grouped by datetimeTenSeconds
packetRate Sum of packets received, divided by 1 second, providing a per-second packet rate when grouped by datetime
packetRateDay Sum of packets received, divided by 86400 seconds, providing a per-second packet rate when grouped by date
packetRateFifteenMinutes Sum of packets received, divided by 900 seconds, providing a per-second packet rate when grouped by datetimeFifteenMinutes
packetRateFiveMinutes Sum of packets received, divided by 300 seconds, providing a per-second packet rate when grouped by datetimeFiveMinutes
packetRateHour Sum of packets received, divided by 3600 seconds, providing a per-second packet rate when grouped by datetimeHour
packetRateMinute Sum of packets received, divided by 60 seconds, providing a per-second packet rate when grouped by datetimeMinute
packetRateTenSeconds Sum of packets received, divided by 10 seconds, providing a per-second packet rate when grouped by datetimeTenSeconds

AccountMagicTransitTunnelTrafficAdaptiveGroupsAvgConfidence

FieldDescription
bitRate Confidence interval for the corresponding point estimate
bitRateDay Confidence interval for the corresponding point estimate
bitRateFifteenMinutes Confidence interval for the corresponding point estimate
bitRateFiveMinutes Confidence interval for the corresponding point estimate
bitRateHour Confidence interval for the corresponding point estimate
bitRateMinute Confidence interval for the corresponding point estimate
bitRateTenSeconds Confidence interval for the corresponding point estimate
packetRate Confidence interval for the corresponding point estimate
packetRateDay Confidence interval for the corresponding point estimate
packetRateFifteenMinutes Confidence interval for the corresponding point estimate
packetRateFiveMinutes Confidence interval for the corresponding point estimate
packetRateHour Confidence interval for the corresponding point estimate
packetRateMinute Confidence interval for the corresponding point estimate
packetRateTenSeconds Confidence interval for the corresponding point estimate

AccountMagicTransitTunnelTrafficAdaptiveGroupsConfidence

FieldDescription
avg The average of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountMagicTransitTunnelTrafficAdaptiveGroupsDimensions

FieldDescription
date Date that the packet was received
datetime Date and time that the packet was received
datetimeFifteenMinutes Date and time that the packet was received, rounded to the start of the nearest fifteen minutes
datetimeFiveMinutes Date and time that the packet was received, rounded to the start of the nearest five minutes
datetimeHour Date and time that the packet was received, rounded to the start of the nearest hour
datetimeMinute Date and time that the packet was received, rounded to the start of the nearest minute
direction Direction of the packet relative to the customer network (possible values: inbound, outbound, lateral)
edgeColoCity City where the Cloudflare datacenter that received the packet is located
edgeColoCode Cloudflare datacenter that received the packet (nearest IATA airport code)
edgeColoCountry Country where the Cloudflare datacenter that received the packet is located (ISO 3166-1 alpha-2)
edgeColoGeohash Latitude and longitude where the Cloudflare datacenter that received the packet is located (Geohash encoding)
edgeColoName Cloudflare datacenter that received the packet (unique site identifier)
edgePopName Cloudflare PoP that received the packet (unique site identifier)
egressTunnelID GRE, IPSec or CNI Egress Tunnel ID for Magic WAN and Magic Transit traffic
egressTunnelName GRE, IPSec or CNIec Egress Tunnel name for Magic WAN and Magic Transit traffic
ingressTunnelID GRE, IPSec or CNI Ingress Tunnel ID for Magic WAN and Magic Transit traffic
ingressTunnelName GRE, IPSec or CNI Ingress Tunnel name for Magic WAN and Magic Transit traffic
offRamp Offramp method for Magic WAN and Magic Transit traffic - GRE, IPSec, CNI, Warp, Cloudflared
onRamp Onramp method for Magic WAN and Magic Transit traffic - GRE, IPSec, CNI, Warp, Cloudflared
tunnelName Tunnel device name

AccountMagicTransitTunnelTrafficAdaptiveGroupsSum

FieldDescription
bits Sum of bits received
packets Sum of packets received

AccountMagicTransitTunnelTrafficAdaptiveGroupsSumConfidence

FieldDescription
bits Confidence interval for the corresponding point estimate
packets Confidence interval for the corresponding point estimate

AccountMagicWANConnectorMetricsAdaptiveGroups

Magic WAN Connector Metrics (deprecated)

FieldDescription
avg
dimensions List of dimensions to group by
max

AccountMagicWANConnectorMetricsAdaptiveGroupsAvg

FieldDescription
cpuLoadPercentage Average CPU load percentage
cpuTemperature Average CPU temperature
diskUsagePercentage Average Disk usage percentage
memoryUsagePercentage Average Memory usage percentage
rxBitrateFiveMinute Rx Bitrate over 5 minutes
rxBitrateMinute Rx Bitrate over 1 minute
rxPacketrateFiveMinute Rx Packet rate over 5 minutes
rxPacketrateMinute Rx Packet rate over 1 minute
txBitrateFiveMinute Tx Bitrate over 5 minutes
txBitrateMinute Tx Bitrate over 1 minute
txPacketrateFiveMinute Tx Packet rate over 5 minutes
txPacketrateMinute Tx Packet rate over 1 minute

AccountMagicWANConnectorMetricsAdaptiveGroupsDimensions

FieldDescription
date The date the event was recorded, truncated to the start of a day
datetime The date and time the event was recorded
datetimeFifteenMinutes The date and time the event occurred at the edge truncated to fifteen minutes
datetimeFiveMinutes The date and time the event occurred at the edge truncated to a multiple of 5 minutes
datetimeHour The date and time the event occurred at the edge truncated to an hour
datetimeMinute The date and time the event occurred at the edge truncated to the minute
mconnConnectorID Customer connector identifier
mconnInterfaceName Name of connector interface
mconnInterfaceType Interface type LAN, WAN or IPSEC
mconnSiteID Customer site identifier

AccountMagicWANConnectorMetricsAdaptiveGroupsMax

FieldDescription
haState current connector ha state
interfaceCount Number of interfaces of a given Type

AccountMconnTelemetryEventsAdaptiveGroups

Aggregated Magic WAN Connector events with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Recorded Event count
dimensions List of dimensions to group by

AccountMconnTelemetryEventsAdaptiveGroupsConfidence

FieldDescription
count Recorded Event count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetryEventsAdaptiveGroupsDimensions

FieldDescription
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
kind Event kind
payload JSON-encoded data extracted from the event

AccountMconnTelemetryEventsStagingAdaptiveGroups

Aggregated Magic WAN Connector events with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Recorded Event count
dimensions List of dimensions to group by

AccountMconnTelemetryEventsStagingAdaptiveGroupsConfidence

FieldDescription
count Recorded Event count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetryEventsStagingAdaptiveGroupsDimensions

FieldDescription
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
kind Event kind
payload JSON-encoded data extracted from the event

AccountMconnTelemetrySnapshotDhcpLeasesAdaptiveGroups

Aggregated Magic WAN Connector snapshots of DHCP leases with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Snapshot DHCP lease count
dimensions List of dimensions to group by
max

AccountMconnTelemetrySnapshotDhcpLeasesAdaptiveGroupsConfidence

FieldDescription
count Snapshot DHCP lease count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetrySnapshotDhcpLeasesAdaptiveGroupsDimensions

FieldDescription
clientId Client ID of the device the IP Address was leased to
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
hostname Hostname of the device the IP Address was leased to
interfaceName Name of the network interface
ipAddress IP Address that was leased
macAddress MAC Address of the device the IP Address was leased to

AccountMconnTelemetrySnapshotDhcpLeasesAdaptiveGroupsMax

FieldDescription
expiryTime Expiry time of the DHCP lease (seconds since the Unix epoch)

AccountMconnTelemetrySnapshotDhcpLeasesStagingAdaptiveGroups

Aggregated Magic WAN Connector snapshots of DHCP leases with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Snapshot DHCP lease count
dimensions List of dimensions to group by
max

AccountMconnTelemetrySnapshotDhcpLeasesStagingAdaptiveGroupsConfidence

FieldDescription
count Snapshot DHCP lease count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetrySnapshotDhcpLeasesStagingAdaptiveGroupsDimensions

FieldDescription
clientId Client ID of the device the IP Address was leased to
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
hostname Hostname of the device the IP Address was leased to
interfaceName Name of the network interface
ipAddress IP Address that was leased
macAddress MAC Address of the device the IP Address was leased to

AccountMconnTelemetrySnapshotDhcpLeasesStagingAdaptiveGroupsMax

FieldDescription
expiryTime Expiry time of the DHCP lease (seconds since the Unix epoch)

AccountMconnTelemetrySnapshotDisksAdaptiveGroups

Aggregated Magic WAN Connector disk snapshots with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Snapshot Disk count
dimensions List of dimensions to group by
max
sum

AccountMconnTelemetrySnapshotDisksAdaptiveGroupsConfidence

FieldDescription
count Snapshot Disk count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetrySnapshotDisksAdaptiveGroupsDimensions

FieldDescription
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
name Device name

AccountMconnTelemetrySnapshotDisksAdaptiveGroupsMax

FieldDescription
inProgress I/Os currently in progress
major Device major number
minor Device minor number

AccountMconnTelemetrySnapshotDisksAdaptiveGroupsSum

FieldDescription
discards Discards completed successfully (delta)
discardsMerged Discards merged (delta)
flushes Flushes completed successfully (delta)
merged Reads merged (delta)
reads Reads completed successfully (delta)
sectorsDiscarded Sectors discarded (delta)
sectorsRead Sectors read successfully (delta)
sectorsWritten Sectors written successfully (delta)
writes Writes completed (delta)
writesMerged Writes merged (delta)

AccountMconnTelemetrySnapshotDisksStagingAdaptiveGroups

Aggregated Magic WAN Connector disk snapshots with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Snapshot Disk count
dimensions List of dimensions to group by
max
sum

AccountMconnTelemetrySnapshotDisksStagingAdaptiveGroupsConfidence

FieldDescription
count Snapshot Disk count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetrySnapshotDisksStagingAdaptiveGroupsDimensions

FieldDescription
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
name Device name

AccountMconnTelemetrySnapshotDisksStagingAdaptiveGroupsMax

FieldDescription
inProgress I/Os currently in progress
major Device major number
minor Device minor number

AccountMconnTelemetrySnapshotDisksStagingAdaptiveGroupsSum

FieldDescription
discards Discards completed successfully (delta)
discardsMerged Discards merged (delta)
flushes Flushes completed successfully (delta)
merged Reads merged (delta)
reads Reads completed successfully (delta)
sectorsDiscarded Sectors discarded (delta)
sectorsRead Sectors read successfully (delta)
sectorsWritten Sectors written successfully (delta)
writes Writes completed (delta)
writesMerged Writes merged (delta)

AccountMconnTelemetrySnapshotInterfaceAddressesAdaptiveGroups

Aggregated Magic WAN Connector interface address snapshots with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Snapshot Interface Address count
dimensions List of dimensions to group by

AccountMconnTelemetrySnapshotInterfaceAddressesAdaptiveGroupsConfidence

FieldDescription
count Snapshot Interface Address count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetrySnapshotInterfaceAddressesAdaptiveGroupsDimensions

FieldDescription
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
interfaceName Name of the network interface
ipAddress IP address of the network interface

AccountMconnTelemetrySnapshotInterfaceAddressesStagingAdaptiveGroups

Aggregated Magic WAN Connector interface address snapshots with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Snapshot Interface Address count
dimensions List of dimensions to group by

AccountMconnTelemetrySnapshotInterfaceAddressesStagingAdaptiveGroupsConfidence

FieldDescription
count Snapshot Interface Address count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetrySnapshotInterfaceAddressesStagingAdaptiveGroupsDimensions

FieldDescription
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
interfaceName Name of the network interface
ipAddress IP address of the network interface

AccountMconnTelemetrySnapshotInterfacesAdaptiveGroups

Aggregated Magic WAN Connector interface snapshots with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Snapshot Interface count
dimensions List of dimensions to group by
max

AccountMconnTelemetrySnapshotInterfacesAdaptiveGroupsConfidence

FieldDescription
count Snapshot Interface count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetrySnapshotInterfacesAdaptiveGroupsDimensions

FieldDescription
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
name Name of the network interface
operstate UP/DOWN state of the network interface

AccountMconnTelemetrySnapshotInterfacesAdaptiveGroupsMax

FieldDescription
speed Speed of the network interface (bits per second)

AccountMconnTelemetrySnapshotInterfacesStagingAdaptiveGroups

Aggregated Magic WAN Connector interface snapshots with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Snapshot Interface count
dimensions List of dimensions to group by
max

AccountMconnTelemetrySnapshotInterfacesStagingAdaptiveGroupsConfidence

FieldDescription
count Snapshot Interface count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetrySnapshotInterfacesStagingAdaptiveGroupsDimensions

FieldDescription
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
name Name of the network interface
operstate UP/DOWN state of the network interface

AccountMconnTelemetrySnapshotInterfacesStagingAdaptiveGroupsMax

FieldDescription
speed Speed of the network interface (bits per second)

AccountMconnTelemetrySnapshotMountsAdaptiveGroups

Aggregated Magic WAN Connector mount snapshots with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Snapshot Mount count
dimensions List of dimensions to group by
max

AccountMconnTelemetrySnapshotMountsAdaptiveGroupsConfidence

FieldDescription
count Snapshot Mount count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetrySnapshotMountsAdaptiveGroupsDimensions

FieldDescription
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
fileSystem File system on disk (EXT4, NTFS, etc.)
kind Kind of disk (HDD, SSD, etc.)
mountPoint Path where disk is mounted
name Name of the disk mount

AccountMconnTelemetrySnapshotMountsAdaptiveGroupsMax

FieldDescription
availableBytes Available disk size (bytes)
isReadOnly Determines whether the disk is read-only
isRemovable Determines whether the disk is removable
totalBytes Total disk size (bytes)

AccountMconnTelemetrySnapshotMountsStagingAdaptiveGroups

Aggregated Magic WAN Connector mount snapshots with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Snapshot Mount count
dimensions List of dimensions to group by
max

AccountMconnTelemetrySnapshotMountsStagingAdaptiveGroupsConfidence

FieldDescription
count Snapshot Mount count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetrySnapshotMountsStagingAdaptiveGroupsDimensions

FieldDescription
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
fileSystem File system on disk (EXT4, NTFS, etc.)
kind Kind of disk (HDD, SSD, etc.)
mountPoint Path where disk is mounted
name Name of the disk mount

AccountMconnTelemetrySnapshotMountsStagingAdaptiveGroupsMax

FieldDescription
availableBytes Available disk size (bytes)
isReadOnly Determines whether the disk is read-only
isRemovable Determines whether the disk is removable
totalBytes Total disk size (bytes)

AccountMconnTelemetrySnapshotNetdevsAdaptiveGroups

Aggregated Magic WAN Connector netdev snapshots with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Snapshot Netdev count
dimensions List of dimensions to group by
sum

AccountMconnTelemetrySnapshotNetdevsAdaptiveGroupsConfidence

FieldDescription
count Snapshot Netdev count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetrySnapshotNetdevsAdaptiveGroupsDimensions

FieldDescription
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
name Name of the network device

AccountMconnTelemetrySnapshotNetdevsAdaptiveGroupsSum

FieldDescription
recvBytes Total bytes received (delta)
recvCompressed Compressed packets received (delta)
recvDrop Packets dropped (delta)
recvErrs Bad packets received (delta)
recvFifo FIFO overruns (delta)
recvFrame Frame alignment errors (delta)
recvMulticast Multicast packets received (delta)
recvPackets Total packets received (delta)
sentBytes Total bytes transmitted (delta)
sentCarrier Number of packets not sent due to carrier errors (delta)
sentColls Number of collisions (delta)
sentCompressed Number of compressed packets transmitted (delta)
sentDrop Number of packets dropped during transmission (delta)
sentErrs Number of transmission errors (delta)
sentFifo FIFO overruns (delta)
sentPackets Total packets transmitted (delta)

AccountMconnTelemetrySnapshotNetdevsStagingAdaptiveGroups

Aggregated Magic WAN Connector netdev snapshots with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Snapshot Netdev count
dimensions List of dimensions to group by
sum

AccountMconnTelemetrySnapshotNetdevsStagingAdaptiveGroupsConfidence

FieldDescription
count Snapshot Netdev count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetrySnapshotNetdevsStagingAdaptiveGroupsDimensions

FieldDescription
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
name Name of the network device

AccountMconnTelemetrySnapshotNetdevsStagingAdaptiveGroupsSum

FieldDescription
recvBytes Total bytes received (delta)
recvCompressed Compressed packets received (delta)
recvDrop Packets dropped (delta)
recvErrs Bad packets received (delta)
recvFifo FIFO overruns (delta)
recvFrame Frame alignment errors (delta)
recvMulticast Multicast packets received (delta)
recvPackets Total packets received (delta)
sentBytes Total bytes transmitted (delta)
sentCarrier Number of packets not sent due to carrier errors (delta)
sentColls Number of collisions (delta)
sentCompressed Number of compressed packets transmitted (delta)
sentDrop Number of packets dropped during transmission (delta)
sentErrs Number of transmission errors (delta)
sentFifo FIFO overruns (delta)
sentPackets Total packets transmitted (delta)

AccountMconnTelemetrySnapshotThermalsAdaptiveGroups

Aggregated Magic WAN Connector thermal snapshots with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Snapshot Thermal count
dimensions List of dimensions to group by
max

AccountMconnTelemetrySnapshotThermalsAdaptiveGroupsConfidence

FieldDescription
count Snapshot Thermal count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetrySnapshotThermalsAdaptiveGroupsDimensions

FieldDescription
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
label Sensor identifier for the component

AccountMconnTelemetrySnapshotThermalsAdaptiveGroupsMax

FieldDescription
criticalCelcius Critical failure temperature of the component (degrees Celsius)
currentCelcius Current temperature of the component (degrees Celsius)
maxCelcius Maximum temperature of the component (degrees Celsius)

AccountMconnTelemetrySnapshotThermalsStagingAdaptiveGroups

Aggregated Magic WAN Connector thermal snapshots with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Snapshot Thermal count
dimensions List of dimensions to group by
max

AccountMconnTelemetrySnapshotThermalsStagingAdaptiveGroupsConfidence

FieldDescription
count Snapshot Thermal count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetrySnapshotThermalsStagingAdaptiveGroupsDimensions

FieldDescription
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
label Sensor identifier for the component

AccountMconnTelemetrySnapshotThermalsStagingAdaptiveGroupsMax

FieldDescription
criticalCelcius Critical failure temperature of the component (degrees Celsius)
currentCelcius Current temperature of the component (degrees Celsius)
maxCelcius Maximum temperature of the component (degrees Celsius)

AccountMconnTelemetrySnapshotTunnelsAdaptiveGroups

Aggregated Magic WAN Connector tunnel snapshots with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Snapshot Tunnels count
dimensions List of dimensions to group by
max

AccountMconnTelemetrySnapshotTunnelsAdaptiveGroupsConfidence

FieldDescription
count Snapshot Tunnels count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetrySnapshotTunnelsAdaptiveGroupsDimensions

FieldDescription
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
interfaceName The tunnel interface name (i.e. xfrm1, xfrm3.99, etc.)
natdResult Public socket address returned by the NAT detector
natdTarget Target socket address probed by the NAT detector, using the detector source port
tunnelId Tunnel identifier

AccountMconnTelemetrySnapshotTunnelsAdaptiveGroupsMax

FieldDescription
healthValue Numeric value associated with tunnel state (0 = unknown, 1 = healthy, 2 = degraded, 3 = down)
natdState Numeric NAT detector state (0 = detected, 1 = missing result, 2 = stale result)

AccountMconnTelemetrySnapshotTunnelsStagingAdaptiveGroups

Aggregated Magic WAN Connector tunnel snapshots with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Snapshot Tunnels count
dimensions List of dimensions to group by
max

AccountMconnTelemetrySnapshotTunnelsStagingAdaptiveGroupsConfidence

FieldDescription
count Snapshot Tunnels count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetrySnapshotTunnelsStagingAdaptiveGroupsDimensions

FieldDescription
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
interfaceName The tunnel interface name (i.e. xfrm1, xfrm3.99, etc.)
natdResult Public socket address returned by the NAT detector
natdTarget Target socket address probed by the NAT detector, using the detector source port
tunnelId Tunnel identifier

AccountMconnTelemetrySnapshotTunnelsStagingAdaptiveGroupsMax

FieldDescription
healthValue Numeric value associated with tunnel state (0 = unknown, 1 = healthy, 2 = degraded, 3 = down)
natdState Numeric NAT detector state (0 = detected, 1 = missing result, 2 = stale result)

AccountMconnTelemetrySnapshotsAdaptiveGroups

Aggregated Magic WAN Connector system snapshots with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Snapshot count
dimensions List of dimensions to group by
max

AccountMconnTelemetrySnapshotsAdaptiveGroupsConfidence

FieldDescription
count Snapshot count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetrySnapshotsAdaptiveGroupsDimensions

FieldDescription
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
version Version

AccountMconnTelemetrySnapshotsAdaptiveGroupsMax

FieldDescription
cpuCount Count of processors/cores
haValue Numeric value associated with high availability state (0 = disabled, 1 = active, 2 = standby, 3 = stopped, 4 = fault)
kernelBtime Boot time (seconds since Unix epoch)
kernelProcessesRunning Number of processes in runnable state
loadAverage15m The fifteen-minute load average
loadAverage1m The one-minute load average
loadAverage5m The five-minute load average
memoryActiveBytes Memory that has been used more recently
memoryAvailableBytes Estimate of how much memory is available for starting new applications
memoryBuffersBytes Relatively temporary storage for raw disk blocks
memoryCachedBytes In-memory cache for files read from the disk
memoryFreeBytes The sum of LowFree and HighFree
memoryInactiveBytes Memory which has been less recently used
memoryTotalBytes Total usable RAM

AccountMconnTelemetrySnapshotsStagingAdaptiveGroups

Aggregated Magic WAN Connector system snapshots with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Snapshot count
dimensions List of dimensions to group by
max

AccountMconnTelemetrySnapshotsStagingAdaptiveGroupsConfidence

FieldDescription
count Snapshot count, with confidence intervals
level Confidence level that was requested

AccountMconnTelemetrySnapshotsStagingAdaptiveGroupsDimensions

FieldDescription
connectorId Connector identifier
date Timestamp truncated to the start of a day
datetime Timestamp
datetimeFifteenMinutes Timestamp bucketed by 15 minutes
datetimeFiveMinutes Timestamp bucketed by 5 minutes
datetimeHour Timestamp bucketed by hour
datetimeMinute Timestamp bucketed by minute
datetimeSixHours Timestamp bucketed by 6 hours
version Version

AccountMconnTelemetrySnapshotsStagingAdaptiveGroupsMax

FieldDescription
cpuCount Count of processors/cores
haValue Numeric value associated with high availability state (0 = disabled, 1 = active, 2 = standby, 3 = stopped, 4 = fault)
kernelBtime Boot time (seconds since Unix epoch)
kernelProcessesRunning Number of processes in runnable state
loadAverage15m The fifteen-minute load average
loadAverage1m The one-minute load average
loadAverage5m The five-minute load average
memoryActiveBytes Memory that has been used more recently
memoryAvailableBytes Estimate of how much memory is available for starting new applications
memoryBuffersBytes Relatively temporary storage for raw disk blocks
memoryCachedBytes In-memory cache for files read from the disk
memoryFreeBytes The sum of LowFree and HighFree
memoryInactiveBytes Memory which has been less recently used
memoryTotalBytes Total usable RAM

AccountMediaUniqueTransformations

Media unique transfromations per day

FieldDescription
date The date uniques are calculated for
transformations Number of unique media transformations per day in sliding window

AccountMediaUniqueTransformationsAccumulatedSinceStartOfMonth

Media unique transformations accumulated since start of month

FieldDescription
date The date uniques are calculated for
transformations Accumulated number of unique media transformations since start of month per day in sliding window

AccountMnmAWSVPCFlowDataAdaptiveGroups

AWS VPC Flow data collected through Magic Network Monitoring

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountMnmAWSVPCFlowDataAdaptiveGroupsAvg

FieldDescription
bitRate Sum of bits received, divided by 1 second, providing a per-second bit rate when grouped by datetime
bitRateDay Sum of bits received, divided by 86400 seconds, providing a per-second bit rate when grouped by date
bitRateFifteenMinutes Sum of bits received, divided by 900 seconds, providing a per-second bit rate when grouped by datetimeFifteenMinutes
bitRateFiveMinutes Sum of bits received, divided by 300 seconds, providing a per-second bit rate when grouped by datetimeFiveMinutes
bitRateHour Sum of bits received, divided by 3600 seconds, providing a per-second bit rate when grouped by datetimeHour
bitRateMinute Sum of bits received, divided by 60 seconds, providing a per-second bit rate when grouped by datetimeMinute
bitRateTenSeconds Sum of bits received, divided by 10 seconds, providing a per-second bit rate when grouped by datetimeTenSeconds
egressBitRate Sum of egress bits received, divided by 1 second, providing a per-second egress bit rate when grouped by datetime
egressBitRateDay Sum of egress bits received, divided by 86400 seconds, providing a per-second egress bit rate when grouped by date
egressBitRateFifteenMinutes Sum of egress bits received, divided by 900 seconds, providing a per-second egress bit rate when grouped by datetimeFifteenMinutes
egressBitRateFiveMinutes Sum of egress bits received, divided by 300 seconds, providing a per-second egress bit rate when grouped by datetimeFiveMinutes
egressBitRateHour Sum of egress bits received, divided by 3600 seconds, providing a per-second egress bit rate when grouped by datetimeHour
egressBitRateMinute Sum of egress bits received, divided by 60 seconds, providing a per-second egress bit rate when grouped by datetimeMinute
egressBitRateTenSeconds Sum of egress bits received, divided by 10 seconds, providing a per-second egress bit rate when grouped by datetimeTenSeconds
egressPacketRate Sum of egress packets received, divided by 1 second, providing a per-second egress packet rate when grouped by datetime
egressPacketRateDay Sum of egress packets received, divided by 86400 seconds, providing a per-second egress packet rate when grouped by date
egressPacketRateFifteenMinutes Sum of egress packets received, divided by 900 seconds, providing a per-second egress packet rate when grouped by datetimeFifteenMinutes
egressPacketRateFiveMinutes Sum of egress packets received, divided by 300 seconds, providing a per-second egress packet rate when grouped by datetimeFiveMinutes
egressPacketRateHour Sum of egress packets received, divided by 3600 seconds, providing a per-second egress packet rate when grouped by datetimeHour
egressPacketRateMinute Sum of egress packets received, divided by 60 seconds, providing a per-second egress packet rate when grouped by datetimeMinute
egressPacketRateTenSeconds Sum of egress packets received, divided by 10 seconds, providing a per-second egress packet rate when grouped by datetimeTenSeconds
packetRate Sum of packets received, divided by 1 second, providing a per-second packet rate when grouped by datetime
packetRateDay Sum of packets received, divided by 86400 seconds, providing a per-second packet rate when grouped by date
packetRateFifteenMinutes Sum of packets received, divided by 900 seconds, providing a per-second packet rate when grouped by datetimeFifteenMinutes
packetRateFiveMinutes Sum of packets received, divided by 300 seconds, providing a per-second packet rate when grouped by datetimeFiveMinutes
packetRateHour Sum of packets received, divided by 3600 seconds, providing a per-second packet rate when grouped by datetimeHour
packetRateMinute Sum of packets received, divided by 60 seconds, providing a per-second packet rate when grouped by datetimeMinute
packetRateTenSeconds Sum of packets received, divided by 10 seconds, providing a per-second packet rate when grouped by datetimeTenSeconds
sampleInterval Average sample interval applied to the data

AccountMnmAWSVPCFlowDataAdaptiveGroupsAvgConfidence

FieldDescription
bitRate Confidence interval for the corresponding point estimate
bitRateDay Confidence interval for the corresponding point estimate
bitRateFifteenMinutes Confidence interval for the corresponding point estimate
bitRateFiveMinutes Confidence interval for the corresponding point estimate
bitRateHour Confidence interval for the corresponding point estimate
bitRateMinute Confidence interval for the corresponding point estimate
bitRateTenSeconds Confidence interval for the corresponding point estimate
egressBitRate Confidence interval for the corresponding point estimate
egressBitRateDay Confidence interval for the corresponding point estimate
egressBitRateFifteenMinutes Confidence interval for the corresponding point estimate
egressBitRateFiveMinutes Confidence interval for the corresponding point estimate
egressBitRateHour Confidence interval for the corresponding point estimate
egressBitRateMinute Confidence interval for the corresponding point estimate
egressBitRateTenSeconds Confidence interval for the corresponding point estimate
egressPacketRate Confidence interval for the corresponding point estimate
egressPacketRateDay Confidence interval for the corresponding point estimate
egressPacketRateFifteenMinutes Confidence interval for the corresponding point estimate
egressPacketRateFiveMinutes Confidence interval for the corresponding point estimate
egressPacketRateHour Confidence interval for the corresponding point estimate
egressPacketRateMinute Confidence interval for the corresponding point estimate
egressPacketRateTenSeconds Confidence interval for the corresponding point estimate
packetRate Confidence interval for the corresponding point estimate
packetRateDay Confidence interval for the corresponding point estimate
packetRateFifteenMinutes Confidence interval for the corresponding point estimate
packetRateFiveMinutes Confidence interval for the corresponding point estimate
packetRateHour Confidence interval for the corresponding point estimate
packetRateMinute Confidence interval for the corresponding point estimate
packetRateTenSeconds Confidence interval for the corresponding point estimate

AccountMnmAWSVPCFlowDataAdaptiveGroupsConfidence

FieldDescription
avg The average of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountMnmAWSVPCFlowDataAdaptiveGroupsDimensions

FieldDescription
accountID The AWS account ID of the owner of the source network interface for which traffic is recorded.
action The action that is associated with the traffic: ACCEPT, REJECT.
azID The ID of the Availability Zone that contains the network interface for which traffic is recorded.
date Date that the packet was received
datetime Date and time that the packet was received
datetimeFifteenMinutes Date and time that the packet was received, rounded to the start of the nearest fifteen minutes
datetimeFiveMinutes Date and time that the packet was received, rounded to the start of the nearest five minutes
datetimeHour Date and time that the packet was received, rounded to the start of the nearest hour
datetimeMinute Date and time that the packet was received, rounded to the start of the nearest minute
datetimeTenSeconds Date and time that the packet was received, rounded to the start of the nearest ten seconds
destinationAddress IP to which the data was sent
destinationPort Value of the Destination Port header field in the packet
ecsClusterArn AWS Resource Name (ARN) of the ECS cluster if the traffic is from a running ECS task.
ecsClusterName Name of the ECS cluster if the traffic is from a running ECS task.
ecsContainerID Docker runtime ID of the container if the traffic is from a running ECS task.
ecsContainerInstanceArn ARN of the ECS container instance if the traffic is from a running ECS task on an EC2 instance.
ecsContainerInstanceID ID of the ECS container instance if the traffic is from a running ECS task on an EC2 instance.
ecsSecondContainerID Docker runtime ID of the second container if the traffic is from a running ECS task.
ecsServiceName Name of the ECS service if the traffic is from a running ECS task and the ECS task is started by an ECS service.
ecsTaskArn ARN of the ECS task if the traffic is from a running ECS task.
ecsTaskDefinitionArn ARN of the ECS task definition if the traffic is from a running ECS task.
ecsTaskID ID of the ECS task if the traffic is from a running ECS task.
end The time, in Unix seconds, when the last packet of the flow was received within the aggregation interval.
ethertype Value of the Ethertype header field in the Ethernet packet (2048 for IPv4; 34525 for IPv6)
firehoseStream Identification of the AWS firehose stream exporting flows
flowDirection The direction of the flow with respect to the interface where traffic is captured.
instanceID The ID of the instance that's associated with the network interface for which the traffic is recorded.
interfaceID The ID of the network interface for which the traffic is recorded.
logStatus The logging status of the flow log: OK, NODATA, SKIPDATA.
pktDestinationAddress The packet-level (original) destination IP address for the traffic.
pktDstAwsService The name of the subset of IP address ranges for the pktDstaddr field, if the destination IP address is for an AWS service.
pktSourceAddress The packet-level (original) source IP address of the traffic.
pktSrcAwsService The name of the subset of IP address ranges for the pktSrcaddr field, if the source IP address is for an AWS service.
protocol Layer 4 protocol
protocolString Human-readable string representation of the protocol
region The Region that contains the network interface for which traffic is recorded.
rejectReason Reason why traffic was rejected.
ruleIDs List of flow matching rules
sourceAddress IP from which the data was sent
sourcePort Value of the Source Port header field in the packet
start The time, in Unix seconds, when the first packet of the flow was received within the aggregation interval.
sublocationID The ID of the sublocation that contains the network interface for which traffic is recorded.
sublocationType The type of sublocation that's returned in the sublocationID field.
subnetID The ID of the subnet that contains the network interface for which the traffic is recorded.
tcpFlags Value of the Flags header field in the TCP packet
tcpFlagsString Human-readable string representation of the Flags header field in the TCP packet
trafficPath The path that egress traffic takes to the destination.
version Version of the record schema
vpcFlowVersion The VPC Flow Logs version.
vpcID The ID of the VPC that contains the network interface for which the traffic is recorded.

AccountMnmAWSVPCFlowDataAdaptiveGroupsSum

FieldDescription
bits Sum of bits
egressBits Sum of egress bits
egressPackets Sum of egress packets
packets Sum of packets

AccountMnmAWSVPCFlowDataAdaptiveGroupsSumConfidence

FieldDescription
bits Confidence interval for the corresponding point estimate
egressBits Confidence interval for the corresponding point estimate
egressPackets Confidence interval for the corresponding point estimate
packets Confidence interval for the corresponding point estimate

AccountMnmFlowDataAdaptiveGroups

Flow data collected through Magic Network Monitoring

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountMnmFlowDataAdaptiveGroupsAvg

FieldDescription
bitRate Sum of bits received, divided by 1 second, providing a per-second bit rate when grouped by datetime
bitRateDay Sum of bits received, divided by 86400 seconds, providing a per-second bit rate when grouped by date
bitRateFifteenMinutes Sum of bits received, divided by 900 seconds, providing a per-second bit rate when grouped by datetimeFifteenMinutes
bitRateFiveMinutes Sum of bits received, divided by 300 seconds, providing a per-second bit rate when grouped by datetimeFiveMinutes
bitRateHour Sum of bits received, divided by 3600 seconds, providing a per-second bit rate when grouped by datetimeHour
bitRateMinute Sum of bits received, divided by 60 seconds, providing a per-second bit rate when grouped by datetimeMinute
bitRateTenSeconds Sum of bits received, divided by 10 seconds, providing a per-second bit rate when grouped by datetimeTenSeconds
egressBitRate Sum of egress bits received, divided by 1 second, providing a per-second egress bit rate when grouped by datetime
egressBitRateDay Sum of egress bits received, divided by 86400 seconds, providing a per-second egress bit rate when grouped by date
egressBitRateFifteenMinutes Sum of egress bits received, divided by 900 seconds, providing a per-second egress bit rate when grouped by datetimeFifteenMinutes
egressBitRateFiveMinutes Sum of egress bits received, divided by 300 seconds, providing a per-second egress bit rate when grouped by datetimeFiveMinutes
egressBitRateHour Sum of egress bits received, divided by 3600 seconds, providing a per-second egress bit rate when grouped by datetimeHour
egressBitRateMinute Sum of egress bits received, divided by 60 seconds, providing a per-second egress bit rate when grouped by datetimeMinute
egressBitRateTenSeconds Sum of egress bits received, divided by 10 seconds, providing a per-second egress bit rate when grouped by datetimeTenSeconds
egressPacketRate Sum of egress packets received, divided by 1 second, providing a per-second egress packet rate when grouped by datetime
egressPacketRateDay Sum of egress packets received, divided by 86400 seconds, providing a per-second egress packet rate when grouped by date
egressPacketRateFifteenMinutes Sum of egress packets received, divided by 900 seconds, providing a per-second egress packet rate when grouped by datetimeFifteenMinutes
egressPacketRateFiveMinutes Sum of egress packets received, divided by 300 seconds, providing a per-second egress packet rate when grouped by datetimeFiveMinutes
egressPacketRateHour Sum of egress packets received, divided by 3600 seconds, providing a per-second egress packet rate when grouped by datetimeHour
egressPacketRateMinute Sum of egress packets received, divided by 60 seconds, providing a per-second egress packet rate when grouped by datetimeMinute
egressPacketRateTenSeconds Sum of egress packets received, divided by 10 seconds, providing a per-second egress packet rate when grouped by datetimeTenSeconds
packetRate Sum of packets received, divided by 1 second, providing a per-second packet rate when grouped by datetime
packetRateDay Sum of packets received, divided by 86400 seconds, providing a per-second packet rate when grouped by date
packetRateFifteenMinutes Sum of packets received, divided by 900 seconds, providing a per-second packet rate when grouped by datetimeFifteenMinutes
packetRateFiveMinutes Sum of packets received, divided by 300 seconds, providing a per-second packet rate when grouped by datetimeFiveMinutes
packetRateHour Sum of packets received, divided by 3600 seconds, providing a per-second packet rate when grouped by datetimeHour
packetRateMinute Sum of packets received, divided by 60 seconds, providing a per-second packet rate when grouped by datetimeMinute
packetRateTenSeconds Sum of packets received, divided by 10 seconds, providing a per-second packet rate when grouped by datetimeTenSeconds
sampleInterval Average sample interval applied to the data

AccountMnmFlowDataAdaptiveGroupsAvgConfidence

FieldDescription
bitRate Confidence interval for the corresponding point estimate
bitRateDay Confidence interval for the corresponding point estimate
bitRateFifteenMinutes Confidence interval for the corresponding point estimate
bitRateFiveMinutes Confidence interval for the corresponding point estimate
bitRateHour Confidence interval for the corresponding point estimate
bitRateMinute Confidence interval for the corresponding point estimate
bitRateTenSeconds Confidence interval for the corresponding point estimate
egressBitRate Confidence interval for the corresponding point estimate
egressBitRateDay Confidence interval for the corresponding point estimate
egressBitRateFifteenMinutes Confidence interval for the corresponding point estimate
egressBitRateFiveMinutes Confidence interval for the corresponding point estimate
egressBitRateHour Confidence interval for the corresponding point estimate
egressBitRateMinute Confidence interval for the corresponding point estimate
egressBitRateTenSeconds Confidence interval for the corresponding point estimate
egressPacketRate Confidence interval for the corresponding point estimate
egressPacketRateDay Confidence interval for the corresponding point estimate
egressPacketRateFifteenMinutes Confidence interval for the corresponding point estimate
egressPacketRateFiveMinutes Confidence interval for the corresponding point estimate
egressPacketRateHour Confidence interval for the corresponding point estimate
egressPacketRateMinute Confidence interval for the corresponding point estimate
egressPacketRateTenSeconds Confidence interval for the corresponding point estimate
packetRate Confidence interval for the corresponding point estimate
packetRateDay Confidence interval for the corresponding point estimate
packetRateFifteenMinutes Confidence interval for the corresponding point estimate
packetRateFiveMinutes Confidence interval for the corresponding point estimate
packetRateHour Confidence interval for the corresponding point estimate
packetRateMinute Confidence interval for the corresponding point estimate
packetRateTenSeconds Confidence interval for the corresponding point estimate

AccountMnmFlowDataAdaptiveGroupsConfidence

FieldDescription
avg The average of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountMnmFlowDataAdaptiveGroupsDimensions

FieldDescription
date Date that the packet was received
datetime Date and time that the packet was received
datetimeFifteenMinutes Date and time that the packet was received, rounded to the start of the nearest fifteen minutes
datetimeFiveMinutes Date and time that the packet was received, rounded to the start of the nearest five minutes
datetimeHour Date and time that the packet was received, rounded to the start of the nearest hour
datetimeMinute Date and time that the packet was received, rounded to the start of the nearest minute
datetimeTenSeconds Date and time that the packet was received, rounded to the start of the nearest ten seconds
destinationAS Autonomous System to which the data is directed. Corresponds to DstAS field in the packet
destinationAddress IP to which the data was sent
destinationPort Value of the Destination Port header field in the packet
deviceID Device ID of the warp client exporting MNM flows
ethertype Value of the Ethertype header field in the Ethernet packet (2048 for IPv4; 34525 for IPv6)
ipToS Defines the IP Type Of Service (TOS)
ipToSEncap Defines the IP Type Of Service (TOS) for encapsulated traffic
protocol Layer 4 protocol
protocolString Human-readable string representation of the protocol
routerAddress IP of the router that sampled the flows
ruleIDs List of flow matching rules
sourceAS Autonomous System from which the data was sent. Corresponds to SrcAS field in the packet
sourceAddress IP from which the data was sent
sourcePort Value of the Source Port header field in the packet
tcpFlags Value of the Flags header field in the TCP packet
tcpFlagsString Human-readable string representation of the Flags header field in the TCP packet
version Version of the record schema

AccountMnmFlowDataAdaptiveGroupsSum

FieldDescription
bits Sum of bits
egressBits Sum of egress bits
egressPackets Sum of egress packets
packets Sum of packets

AccountMnmFlowDataAdaptiveGroupsSumConfidence

FieldDescription
bits Confidence interval for the corresponding point estimate
egressBits Confidence interval for the corresponding point estimate
egressPackets Confidence interval for the corresponding point estimate
packets Confidence interval for the corresponding point estimate

AccountNelReportsAdaptiveGroups

Data to visualize network error logs

FieldDescription
avg
confidence ALPHA - DO NOT USE
count The number of NEL Reports
dimensions List of dimensions to group by

AccountNelReportsAdaptiveGroupsAvg

FieldDescription
sampleInterval Average sample interval

AccountNelReportsAdaptiveGroupsConfidence

FieldDescription
count The number of NEL Reports, with confidence intervals
level Confidence level that was requested

AccountNelReportsAdaptiveGroupsDimensions

FieldDescription
clientIPASN Client ASN
clientIPASNDescription Client ASN Description
clientIPCountry Client Country
clientIPCountryCode 2 letter client country code using ISO 3166-1 alpha-2 syntax
clientIPVersion IP Version the client used to connect
date Request date from browser
datetime Request datetime from browser
datetimeFifteenMinutes Request datetime from browser, truncated to multiple of 15 minutes
datetimeFiveMinutes Request datetime from browser, truncated to multiple of 5 minutes
datetimeHalfOfHour Request datetime from browser, truncated to multiple of 30 minutes
datetimeHour Request datetime from browser, truncated to the hour
datetimeMinute Request datetime from browser, truncated to the minute
lastKnownGoodColoCode IATA airport code of colo the client connected to
phase The phase of connection the error occurred in
protocol HTTP Protocol used when the error occured
type The type of error in the phase

AccountOhttpMetricsAdaptive

oHTTP request metrics with adaptive sampling

FieldDescription
bytesToClient Bytes returned to client
bytesToGateway Total bytes received from the client
colo The airport code of the Cloudflare datacenter that served this request
datetime The date and time the event was recorded
gatewayStatusCode The status code returned by the gateway
relayStatusCode The status code returned by the relay

AccountOhttpMetricsAdaptiveGroups

Aggregated oHTTP request metrics with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Number of HTTP requests
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountOhttpMetricsAdaptiveGroupsConfidence

FieldDescription
count Number of HTTP requests, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountOhttpMetricsAdaptiveGroupsDimensions

FieldDescription
colo The airport code of the Cloudflare datacenter that served this request
date Ohttp requests metrics date
datetime Ohttp requests metrics timestamp
datetimeFifteenMinutes Ohttp requests metrics timestamp, truncated to fifteen minutes
datetimeFiveMinutes Ohttp requests metrics timestamp, truncated to five minutes
datetimeHour Ohttp requests metrics timestamp, truncated to the hour
datetimeMinute Ohttp requests metrics timestamp, truncated to the minute
endpoint The appId that generated traffic
gatewayStatusCode Status code returned by the gateway
relayStatusCode Status code returned by the relay

AccountOhttpMetricsAdaptiveGroupsSum

FieldDescription
bytesToClient The total bytes sent from gateway to client, observed over the queried time period
bytesToGateway The total bytes from client to gateway, observed over the queried time period
clientRequestErrors The total number of client request errors, observed over the queried time period
gatewayResponseErrors The total number of gateway response errors, observed over the queried time period

AccountOhttpMetricsAdaptiveGroupsSumConfidence

FieldDescription
bytesToClient Confidence interval for the corresponding point estimate
bytesToGateway Confidence interval for the corresponding point estimate
clientRequestErrors Confidence interval for the corresponding point estimate
gatewayResponseErrors Confidence interval for the corresponding point estimate

AccountOhttpRelayEgressConnMetricsAdaptiveGroups

Aggregated OHTTP relay egress (relay-to-gateway) connection metrics with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count The number of egress connections
dimensions List of dimensions to group by
quantiles
sum Sum of values for a metric per dimension

AccountOhttpRelayEgressConnMetricsAdaptiveGroupsConfidence

FieldDescription
count The number of egress connections, with confidence intervals
level Confidence level that was requested
sum Sum of values for a metric per dimension, with confidence intervals

AccountOhttpRelayEgressConnMetricsAdaptiveGroupsDimensions

FieldDescription
coloCode IATA airport code of the Cloudflare data center that handled the connection
date Connection date
datetimeFifteenMinutes Connection timestamp truncated to fifteen minutes
datetimeFiveMinutes Connection timestamp truncated to five minutes
datetimeHour Connection timestamp truncated to the hour
datetimeMinute Connection timestamp truncated to the minute
endpoint The endpoint that generated traffic
transport Transport protocol on the relay-to-gateway connection (TCP, UDP, QUIC)

AccountOhttpRelayEgressConnMetricsAdaptiveGroupsQuantiles

FieldDescription
durationMsP25 Connection lifetime in milliseconds (25th percentile)
durationMsP50 Connection lifetime in milliseconds (50th percentile)
durationMsP75 Connection lifetime in milliseconds (75th percentile)
durationMsP90 Connection lifetime in milliseconds (90th percentile)
durationMsP95 Connection lifetime in milliseconds (95th percentile)
durationMsP99 Connection lifetime in milliseconds (99th percentile)
durationMsP999 Connection lifetime in milliseconds (99.9th percentile)
handshakeDurationUsP25 TCP/TLS or QUIC handshake time in microseconds (25th percentile)
handshakeDurationUsP50 TCP/TLS or QUIC handshake time in microseconds (50th percentile)
handshakeDurationUsP75 TCP/TLS or QUIC handshake time in microseconds (75th percentile)
handshakeDurationUsP90 TCP/TLS or QUIC handshake time in microseconds (90th percentile)
handshakeDurationUsP95 TCP/TLS or QUIC handshake time in microseconds (95th percentile)
handshakeDurationUsP99 TCP/TLS or QUIC handshake time in microseconds (99th percentile)
handshakeDurationUsP999 TCP/TLS or QUIC handshake time in microseconds (99.9th percentile)

AccountOhttpRelayEgressConnMetricsAdaptiveGroupsSum

FieldDescription
bytesRecvdFromGateway Total bytes received by the relay from the gateway
bytesSentToGateway Total bytes sent from the relay to the gateway
packetsRecvdFromGateway Total packets received by the relay from the gateway
packetsSentToGateway Total packets sent from the relay to the gateway

AccountOhttpRelayEgressConnMetricsAdaptiveGroupsSumConfidence

FieldDescription
bytesRecvdFromGateway Confidence interval for the corresponding point estimate
bytesSentToGateway Confidence interval for the corresponding point estimate
packetsRecvdFromGateway Confidence interval for the corresponding point estimate
packetsSentToGateway Confidence interval for the corresponding point estimate

AccountOhttpRelayIngressConnMetricsAdaptiveGroups

Aggregated OHTTP relay ingress (client-to-relay) connection metrics with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count The number of ingress connections
dimensions List of dimensions to group by
quantiles
sum Sum of values for a metric per dimension

AccountOhttpRelayIngressConnMetricsAdaptiveGroupsConfidence

FieldDescription
count The number of ingress connections, with confidence intervals
level Confidence level that was requested
sum Sum of values for a metric per dimension, with confidence intervals

AccountOhttpRelayIngressConnMetricsAdaptiveGroupsDimensions

FieldDescription
coloCode IATA airport code of the Cloudflare data center that handled the connection
date Connection date
datetimeFifteenMinutes Connection timestamp truncated to fifteen minutes
datetimeFiveMinutes Connection timestamp truncated to five minutes
datetimeHour Connection timestamp truncated to the hour
datetimeMinute Connection timestamp truncated to the minute
endpoint The endpoint that generated traffic
transport Transport protocol on the client-to-relay connection (TCP, UDP, QUIC)

AccountOhttpRelayIngressConnMetricsAdaptiveGroupsQuantiles

FieldDescription
durationMsP25 Connection lifetime in milliseconds (25th percentile)
durationMsP50 Connection lifetime in milliseconds (50th percentile)
durationMsP75 Connection lifetime in milliseconds (75th percentile)
durationMsP90 Connection lifetime in milliseconds (90th percentile)
durationMsP95 Connection lifetime in milliseconds (95th percentile)
durationMsP99 Connection lifetime in milliseconds (99th percentile)
durationMsP999 Connection lifetime in milliseconds (99.9th percentile)
handshakeDurationUsP25 TCP/TLS or QUIC handshake time in microseconds (25th percentile)
handshakeDurationUsP50 TCP/TLS or QUIC handshake time in microseconds (50th percentile)
handshakeDurationUsP75 TCP/TLS or QUIC handshake time in microseconds (75th percentile)
handshakeDurationUsP90 TCP/TLS or QUIC handshake time in microseconds (90th percentile)
handshakeDurationUsP95 TCP/TLS or QUIC handshake time in microseconds (95th percentile)
handshakeDurationUsP99 TCP/TLS or QUIC handshake time in microseconds (99th percentile)
handshakeDurationUsP999 TCP/TLS or QUIC handshake time in microseconds (99.9th percentile)

AccountOhttpRelayIngressConnMetricsAdaptiveGroupsSum

FieldDescription
bytesRecvdFromClient Total bytes received by the relay from the client
bytesSentToClient Total bytes sent from the relay to the client
packetsRecvdFromClient Total packets received by the relay from the client
packetsSentToClient Total packets sent from the relay to the client

AccountOhttpRelayIngressConnMetricsAdaptiveGroupsSumConfidence

FieldDescription
bytesRecvdFromClient Confidence interval for the corresponding point estimate
bytesSentToClient Confidence interval for the corresponding point estimate
packetsRecvdFromClient Confidence interval for the corresponding point estimate
packetsSentToClient Confidence interval for the corresponding point estimate

AccountOhttpRelayRequestMetricsAdaptiveGroups

Aggregated OHTTP relay request metrics with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count The number of OHTTP relay requests
dimensions List of dimensions to group by

AccountOhttpRelayRequestMetricsAdaptiveGroupsConfidence

FieldDescription
count The number of OHTTP relay requests, with confidence intervals
level Confidence level that was requested

AccountOhttpRelayRequestMetricsAdaptiveGroupsDimensions

FieldDescription
coloCode IATA airport code of the Cloudflare data center that handled the request
date Request date
datetimeFifteenMinutes Request timestamp truncated to fifteen minutes
datetimeFiveMinutes Request timestamp truncated to five minutes
datetimeHour Request timestamp truncated to the hour
datetimeMinute Request timestamp truncated to the minute
endpoint The endpoint that generated traffic
proxyStatus Proxy-level error classification, empty when no proxy-level error occurred
relayStatusCode HTTP status code returned by the relay

AccountPageShieldReportsAdaptiveGroups

Page Shield CSP reports

FieldDescription
avg
confidence ALPHA - DO NOT USE
count Number of Page Shield CSP reports
dimensions List of dimensions to group by

AccountPageShieldReportsAdaptiveGroupsAvg

FieldDescription
sampleInterval Average sample interval

AccountPageShieldReportsAdaptiveGroupsConfidence

FieldDescription
count Number of Page Shield CSP reports, with confidence intervals
level Confidence level that was requested

AccountPageShieldReportsAdaptiveGroupsDimensions

FieldDescription
action policy action, log | allow
cspDirective csp directive e.g 'script-src'
date
datetime The date and time the event occurred at the edge
datetimeFifteenMinutes Report datetime from edge, truncated to multiple of 15 minutes
datetimeFiveMinutes Report datetime from edge, truncated to multiple of 5 minutes
datetimeHalfOfHour Report datetime from edge, truncated to multiple of 30 minutes
datetimeHour Report datetime from edge, truncated to the hour
datetimeMinute Report datetime from edge, truncated to the minute
host hostname of the zone
pageURL page on which the resource was found
policyID The ID of the Policy
resourceType resource type e.g script
url URL of the CSP reported resource
urlHost hostname of the resource URL
zoneTag Associated zone

AccountPagesFunctionsInvocationsAdaptiveGroups

Pages Functions invocations with adaptive sampling

FieldDescription
avg
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension

AccountPagesFunctionsInvocationsAdaptiveGroupsAvg

FieldDescription
sampleInterval Average sample interval

AccountPagesFunctionsInvocationsAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountPagesFunctionsInvocationsAdaptiveGroupsDimensions

FieldDescription
date Request datetime, truncated to start of a day
datetime Request datetime
datetimeFifteenMinutes Request datetime, truncated to start of fifteen minutes
datetimeFiveMinutes Request datetime, truncated to start of five minutes
datetimeHour Request datetime, truncated to start of an hour
datetimeMinute Request datetime, truncated to start of an minute
datetimeSixHours Request datetime, truncated to start of six hour window
scriptName The name of the script
status Status of the worker invocation
usageModel Usage model of the worker invocation

AccountPagesFunctionsInvocationsAdaptiveGroupsQuantiles

FieldDescription
cpuTimeP25 CPU time 25th percentile - microseconds
cpuTimeP50 CPU time 50th percentile - microseconds
cpuTimeP75 CPU time 75th percentile - microseconds
cpuTimeP90 CPU time 90th percentile - microseconds
cpuTimeP95 CPU time 95th percentile - microseconds
cpuTimeP99 CPU time 99th percentile - microseconds
cpuTimeP999 CPU time 99.9th percentile - microseconds
durationP25 Duration 25th percentile - GB*s
durationP50 Duration 50th percentile - GB*s
durationP75 Duration 75th percentile - GB*s
durationP90 Duration 90th percentile - GB*s
durationP95 Duration 95th percentile - GB*s
durationP99 Duration 99th percentile - GB*s
durationP999 Duration 99.9th percentile - GB*s

AccountPagesFunctionsInvocationsAdaptiveGroupsSum

FieldDescription
clientDisconnects Sum of client disconnects
duration Sum of Duration - GB*s
errors Sum of Errors
requests Sum of Requests
responseBodySize Sum of Response Body Sizes
subrequests Sum of Subrequests
wallTime Sum of Wall Time

AccountPagesFunctionsInvocationsAdaptiveGroupsSumConfidence

FieldDescription
clientDisconnects Confidence interval for the corresponding point estimate
duration Confidence interval for the corresponding point estimate
errors Confidence interval for the corresponding point estimate
requests Confidence interval for the corresponding point estimate
responseBodySize Confidence interval for the corresponding point estimate
subrequests Confidence interval for the corresponding point estimate
wallTime Confidence interval for the corresponding point estimate

AccountPipelinesDeliveryAdaptiveGroups

Beta. Data delivered via Workers Pipelines

FieldDescription
confidence ALPHA - DO NOT USE
count Number of delivery events
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountPipelinesDeliveryAdaptiveGroupsConfidence

FieldDescription
count Number of delivery events, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountPipelinesDeliveryAdaptiveGroupsDimensions

FieldDescription
date Delivery operation timestamp, truncated to start of a day
datetime Delivery operation timestamp
datetimeFifteenMinutes Delivery operation timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Delivery operation timestamp, truncated to start of five minutes
datetimeHour Delivery operation timestamp, truncated to start of an hour
datetimeMinute Delivery operation timestamp, truncated to start of an minute
pipelineId The pipeline ID

AccountPipelinesDeliveryAdaptiveGroupsSum

FieldDescription
deliveredBytes Total amount of bytes delivered

AccountPipelinesDeliveryAdaptiveGroupsSumConfidence

FieldDescription
deliveredBytes Confidence interval for the corresponding point estimate

AccountPipelinesIngestionAdaptiveGroups

Beta. Data ingested via Workers Pipelines

FieldDescription
confidence ALPHA - DO NOT USE
count Number of ingestion events
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountPipelinesIngestionAdaptiveGroupsConfidence

FieldDescription
count Number of ingestion events, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountPipelinesIngestionAdaptiveGroupsDimensions

FieldDescription
date Ingestion operation timestamp, truncated to start of a day
datetime Ingestion operation timestamp
datetimeFifteenMinutes Ingestion operation timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Ingestion operation timestamp, truncated to start of five minutes
datetimeHour Ingestion operation timestamp, truncated to start of an hour
datetimeMinute Ingestion operation timestamp, truncated to start of an minute
pipelineId The pipeline ID

AccountPipelinesIngestionAdaptiveGroupsSum

FieldDescription
ingestedBytes Total amount of bytes ingested
ingestedRecords Total number of records ingested

AccountPipelinesIngestionAdaptiveGroupsSumConfidence

FieldDescription
ingestedBytes Confidence interval for the corresponding point estimate
ingestedRecords Confidence interval for the corresponding point estimate

AccountPipelinesOperatorAdaptiveGroups

Aggregated Pipelines source metrics with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountPipelinesOperatorAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountPipelinesOperatorAdaptiveGroupsDimensions

FieldDescription
date Delivery operation timestamp, truncated to start of a day
datetime Delivery operation timestamp
datetimeFifteenMinutes Delivery operation timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Delivery operation timestamp, truncated to start of five minutes
datetimeHour Delivery operation timestamp, truncated to start of an hour
datetimeMinute Delivery operation timestamp, truncated to start of a minute
pipelineId The pipeline ID
streamId The Stream ID

AccountPipelinesOperatorAdaptiveGroupsSum

FieldDescription
bytesIn Total number of bytes ingested
decodeErrors Number of messages that could not be deserialized in the stream schema
recordsIn Total number of records ingestesd

AccountPipelinesOperatorAdaptiveGroupsSumConfidence

FieldDescription
bytesIn Confidence interval for the corresponding point estimate
decodeErrors Confidence interval for the corresponding point estimate
recordsIn Confidence interval for the corresponding point estimate

AccountPipelinesOperatorStagingAdaptiveGroups

Aggregated Pipelines source metrics with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountPipelinesOperatorStagingAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountPipelinesOperatorStagingAdaptiveGroupsDimensions

FieldDescription
date Delivery operation timestamp, truncated to start of a day
datetime Delivery operation timestamp
datetimeFifteenMinutes Delivery operation timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Delivery operation timestamp, truncated to start of five minutes
datetimeHour Delivery operation timestamp, truncated to start of an hour
datetimeMinute Delivery operation timestamp, truncated to start of a minute
pipelineId The pipeline ID
streamId The Stream ID

AccountPipelinesOperatorStagingAdaptiveGroupsSum

FieldDescription
bytesIn Total number of bytes ingested
decodeErrors Number of messages that could not be deserialized in the stream schema
messagesIn Total number of messages ingested

AccountPipelinesOperatorStagingAdaptiveGroupsSumConfidence

FieldDescription
bytesIn Confidence interval for the corresponding point estimate
decodeErrors Confidence interval for the corresponding point estimate
messagesIn Confidence interval for the corresponding point estimate

AccountPipelinesSinkAdaptiveGroups

Aggregated Pipelines sink metrics with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountPipelinesSinkAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountPipelinesSinkAdaptiveGroupsDimensions

FieldDescription
date Delivery operation timestamp, truncated to start of a day
datetime Delivery operation timestamp
datetimeFifteenMinutes Delivery operation timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Delivery operation timestamp, truncated to start of five minutes
datetimeHour Delivery operation timestamp, truncated to start of an hour
datetimeMinute Delivery operation timestamp, truncated to start of a minute
pipelineId The pipeline ID
sinkId The Sink ID

AccountPipelinesSinkAdaptiveGroupsSum

FieldDescription
bytesWritten Total number of bytes written to the sink, after compression
filesWritten Number of files written
recordsWritten Total number of records written to the sink
rowGroupsWritten Number of Parquet Row Groups written
uncompressedBytesWritten Total number of bytes written before compression

AccountPipelinesSinkAdaptiveGroupsSumConfidence

FieldDescription
bytesWritten Confidence interval for the corresponding point estimate
filesWritten Confidence interval for the corresponding point estimate
recordsWritten Confidence interval for the corresponding point estimate
rowGroupsWritten Confidence interval for the corresponding point estimate
uncompressedBytesWritten Confidence interval for the corresponding point estimate

AccountPipelinesSinkStagingAdaptiveGroups

Aggregated Pipelines sink metrics with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountPipelinesSinkStagingAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountPipelinesSinkStagingAdaptiveGroupsDimensions

FieldDescription
date Delivery operation timestamp, truncated to start of a day
datetime Delivery operation timestamp
datetimeFifteenMinutes Delivery operation timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Delivery operation timestamp, truncated to start of five minutes
datetimeHour Delivery operation timestamp, truncated to start of an hour
datetimeMinute Delivery operation timestamp, truncated to start of a minute
pipelineId The pipeline ID
streamId The Stream ID

AccountPipelinesSinkStagingAdaptiveGroupsSum

FieldDescription
bytesWritten Total number of bytes written to the sink, after compression
filesWritten Number of files written
recordsWritten Total number of records written to the sink
rowGroupsWritten Number of Parquet Row Groups written
uncompressedBytesWritten Total number of bytes written before compression

AccountPipelinesSinkStagingAdaptiveGroupsSumConfidence

FieldDescription
bytesWritten Confidence interval for the corresponding point estimate
filesWritten Confidence interval for the corresponding point estimate
recordsWritten Confidence interval for the corresponding point estimate
rowGroupsWritten Confidence interval for the corresponding point estimate
uncompressedBytesWritten Confidence interval for the corresponding point estimate

AccountPipelinesUserErrorsAdaptive

Raw user errors from Workers Pipelines

FieldDescription
datetime Error timestamp
errorDetails Error details
errorFamily Error category
errorType Specific error type
pipelineId The pipeline identifier
sampleInterval ABR sample interval

AccountPipelinesUserErrorsAdaptiveGroups

User errors from Workers Pipelines

FieldDescription
confidence ALPHA - DO NOT USE
count Number of user errors
dimensions List of dimensions to group by

AccountPipelinesUserErrorsAdaptiveGroupsConfidence

FieldDescription
count Number of user errors, with confidence intervals
level Confidence level that was requested

AccountPipelinesUserErrorsAdaptiveGroupsDimensions

FieldDescription
date Error timestamp, truncated to start of a day
datetime Error timestamp
datetimeFifteenMinutes Error timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Error timestamp, truncated to start of five minutes
datetimeHour Error timestamp, truncated to start of hour
datetimeMinute Error timestamp, truncated to start of minute
errorFamily Error category
errorType Specific error type
pipelineId The pipeline identifier

AccountPipelinesUserErrorsStagingAdaptive

Raw user errors from Workers Pipelines (staging)

FieldDescription
datetime Error timestamp
errorDetails Error details
errorFamily Error category
errorType Specific error type
pipelineId The pipeline identifier
sampleInterval ABR sample interval

AccountPipelinesUserErrorsStagingAdaptiveGroups

User errors from Workers Pipelines (staging)

FieldDescription
confidence ALPHA - DO NOT USE
count Number of user errors
dimensions List of dimensions to group by

AccountPipelinesUserErrorsStagingAdaptiveGroupsConfidence

FieldDescription
count Number of user errors, with confidence intervals
level Confidence level that was requested

AccountPipelinesUserErrorsStagingAdaptiveGroupsDimensions

FieldDescription
date Error timestamp, truncated to start of a day
datetime Error timestamp
datetimeFifteenMinutes Error timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Error timestamp, truncated to start of five minutes
datetimeHour Error timestamp, truncated to start of hour
datetimeMinute Error timestamp, truncated to start of minute
errorFamily Error category
errorType Specific error type
pipelineId The pipeline identifier

AccountPrecursorEventsAdaptiveGroups

Beta. Cloudflare Precursor aggregated validation events with adaptive sampling

FieldDescription
avg
confidence ALPHA - DO NOT USE
count Number of Cloudflare Precursor validation events processed
dimensions List of dimensions to group by
sum

AccountPrecursorEventsAdaptiveGroupsAvg

FieldDescription
sampleInterval Average sample interval

AccountPrecursorEventsAdaptiveGroupsConfidence

FieldDescription
count Number of Cloudflare Precursor validation events processed, with confidence intervals
level Confidence level that was requested
sum

AccountPrecursorEventsAdaptiveGroupsDimensions

FieldDescription
asn ASN tied to that Precursor validation event
browserMajor Major version of the browser tied to that Precursor validation event
browserName Browser name tied to that Precursor validation event
countryCode 2 character country code tied to that Precursor validation event
date The date the Precursor validation event was emitted
datetime The date and time the Precursor validation event was emitted
datetimeDay The date and time the Precursor validation event was emitted truncated to the day
datetimeFifteenMinutes The date and time the Precursor validation event was emitted truncated to a multiple of 15 minutes
datetimeFiveMinutes The date and time the Precursor validation event was emitted truncated to a multiple of 5 minutes
datetimeHalfOfHour The date and time the Precursor validation event was emitted truncated to a multiple of 30 minutes
datetimeHour The date and time the Precursor validation event was emitted truncated to the hour
datetimeMinute The date and time the Precursor validation event was emitted truncated to the minute
eventType The type of the Cloudflare Precursor event
hostname Hostname tied to that Precursor validation event
ipv4 IPv4 tied to that Precursor validation event
ipv6 IPv6 tied to that Precursor validation event
osMajor Major version of the OS tied to that Precursor validation event
osName OS name tied to that Precursor validation event
userAgent User agent tied to that Precursor validation event
zoneId Zone ID tied to that Precursor validation event

AccountPrecursorEventsAdaptiveGroupsSum

FieldDescription
sessionsStarted Estimated number of Cloudflare Precursor sessions whose first validation was observed

AccountPrecursorEventsAdaptiveGroupsSumConfidence

FieldDescription
sessionsStarted Confidence interval for the corresponding point estimate

AccountPrivacyProxyAuthMetricsAdaptiveGroups

Aggregated Privacy Proxy authentication metrics with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count The number of authentication attempts
dimensions List of dimensions to group by

AccountPrivacyProxyAuthMetricsAdaptiveGroupsConfidence

FieldDescription
count The number of authentication attempts, with confidence intervals
level Confidence level that was requested

AccountPrivacyProxyAuthMetricsAdaptiveGroupsDimensions

FieldDescription
authMethod Authentication method used (None, Psk, Token, SessionAuth)
authResult Authentication outcome (success or failure)
coloCode IATA airport code of the Cloudflare data center that handled the authentication
date Authentication event date
datetimeFifteenMinutes Authentication event timestamp truncated to fifteen minutes
datetimeFiveMinutes Authentication event timestamp truncated to five minutes
datetimeHour Authentication event timestamp truncated to the hour
datetimeMinute Authentication event timestamp truncated to the minute
endpoint The proxy endpoint that generated traffic

AccountPrivacyProxyEgressConnMetricsAdaptiveGroups

Aggregated Privacy Proxy egress (proxy-to-origin) connection metrics with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count The number of egress connections
dimensions List of dimensions to group by
quantiles
sum Sum of values for a metric per dimension

AccountPrivacyProxyEgressConnMetricsAdaptiveGroupsConfidence

FieldDescription
count The number of egress connections, with confidence intervals
level Confidence level that was requested
sum Sum of values for a metric per dimension, with confidence intervals

AccountPrivacyProxyEgressConnMetricsAdaptiveGroupsDimensions

FieldDescription
coloCode IATA airport code of the Cloudflare data center that handled the connection
date Connection date
datetimeFifteenMinutes Connection timestamp truncated to fifteen minutes
datetimeFiveMinutes Connection timestamp truncated to five minutes
datetimeHour Connection timestamp truncated to the hour
datetimeMinute Connection timestamp truncated to the minute
endpoint The proxy endpoint that generated traffic
transport Transport protocol on the connection (TCP, UDP, QUIC)

AccountPrivacyProxyEgressConnMetricsAdaptiveGroupsQuantiles

FieldDescription
durationMsP25 Connection lifetime in milliseconds (25th percentile)
durationMsP50 Connection lifetime in milliseconds (50th percentile)
durationMsP75 Connection lifetime in milliseconds (75th percentile)
durationMsP90 Connection lifetime in milliseconds (90th percentile)
durationMsP95 Connection lifetime in milliseconds (95th percentile)
durationMsP99 Connection lifetime in milliseconds (99th percentile)
durationMsP999 Connection lifetime in milliseconds (99.9th percentile)
handshakeDurationUsP25 Time taken for TCP/TLS or QUIC handshake in microseconds (25th percentile)
handshakeDurationUsP50 Time taken for TCP/TLS or QUIC handshake in microseconds (50th percentile)
handshakeDurationUsP75 Time taken for TCP/TLS or QUIC handshake in microseconds (75th percentile)
handshakeDurationUsP90 Time taken for TCP/TLS or QUIC handshake in microseconds (90th percentile)
handshakeDurationUsP95 Time taken for TCP/TLS or QUIC handshake in microseconds (95th percentile)
handshakeDurationUsP99 Time taken for TCP/TLS or QUIC handshake in microseconds (99th percentile)
handshakeDurationUsP999 Time taken for TCP/TLS or QUIC handshake in microseconds (99.9th percentile)

AccountPrivacyProxyEgressConnMetricsAdaptiveGroupsSum

FieldDescription
bytesRecvdFromOrigin Total bytes received by the proxy from the upstream origin
bytesSentToOrigin Total bytes sent from the proxy to the upstream origin
packetsRecvdFromOrigin Total number of packets received from the upstream origin
packetsSentToOrigin Total number of packets sent to the upstream origin

AccountPrivacyProxyEgressConnMetricsAdaptiveGroupsSumConfidence

FieldDescription
bytesRecvdFromOrigin Confidence interval for the corresponding point estimate
bytesSentToOrigin Confidence interval for the corresponding point estimate
packetsRecvdFromOrigin Confidence interval for the corresponding point estimate
packetsSentToOrigin Confidence interval for the corresponding point estimate

AccountPrivacyProxyIngressConnMetricsAdaptiveGroups

Aggregated Privacy Proxy ingress (client-to-proxy) connection metrics with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count The number of ingress connections
dimensions List of dimensions to group by
quantiles
sum Sum of values for a metric per dimension

AccountPrivacyProxyIngressConnMetricsAdaptiveGroupsConfidence

FieldDescription
count The number of ingress connections, with confidence intervals
level Confidence level that was requested
sum Sum of values for a metric per dimension, with confidence intervals

AccountPrivacyProxyIngressConnMetricsAdaptiveGroupsDimensions

FieldDescription
coloCode IATA airport code of the Cloudflare data center that handled the connection
date Connection date
datetimeFifteenMinutes Connection timestamp truncated to fifteen minutes
datetimeFiveMinutes Connection timestamp truncated to five minutes
datetimeHour Connection timestamp truncated to the hour
datetimeMinute Connection timestamp truncated to the minute
endpoint The proxy endpoint that generated traffic
transport Transport protocol on the connection (TCP, UDP, QUIC)

AccountPrivacyProxyIngressConnMetricsAdaptiveGroupsQuantiles

FieldDescription
durationMsP25 Connection lifetime in milliseconds (25th percentile)
durationMsP50 Connection lifetime in milliseconds (50th percentile)
durationMsP75 Connection lifetime in milliseconds (75th percentile)
durationMsP90 Connection lifetime in milliseconds (90th percentile)
durationMsP95 Connection lifetime in milliseconds (95th percentile)
durationMsP99 Connection lifetime in milliseconds (99th percentile)
durationMsP999 Connection lifetime in milliseconds (99.9th percentile)
handshakeDurationUsP25 Time taken for TCP/TLS or QUIC handshake in microseconds (25th percentile)
handshakeDurationUsP50 Time taken for TCP/TLS or QUIC handshake in microseconds (50th percentile)
handshakeDurationUsP75 Time taken for TCP/TLS or QUIC handshake in microseconds (75th percentile)
handshakeDurationUsP90 Time taken for TCP/TLS or QUIC handshake in microseconds (90th percentile)
handshakeDurationUsP95 Time taken for TCP/TLS or QUIC handshake in microseconds (95th percentile)
handshakeDurationUsP99 Time taken for TCP/TLS or QUIC handshake in microseconds (99th percentile)
handshakeDurationUsP999 Time taken for TCP/TLS or QUIC handshake in microseconds (99.9th percentile)

AccountPrivacyProxyIngressConnMetricsAdaptiveGroupsSum

FieldDescription
bytesRecvdFromClient Total bytes received by the proxy from the client
bytesSentToClient Total bytes sent from the proxy to the client
packetsRecvdFromClient Total number of packets received from the client
packetsSentToClient Total number of packets sent to the client

AccountPrivacyProxyIngressConnMetricsAdaptiveGroupsSumConfidence

FieldDescription
bytesRecvdFromClient Confidence interval for the corresponding point estimate
bytesSentToClient Confidence interval for the corresponding point estimate
packetsRecvdFromClient Confidence interval for the corresponding point estimate
packetsSentToClient Confidence interval for the corresponding point estimate

AccountPrivacyProxyRequestMetricsAdaptiveGroups

Aggregated Privacy Proxy request metrics with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count The number of proxy requests
dimensions List of dimensions to group by

AccountPrivacyProxyRequestMetricsAdaptiveGroupsConfidence

FieldDescription
count The number of proxy requests, with confidence intervals
level Confidence level that was requested

AccountPrivacyProxyRequestMetricsAdaptiveGroupsDimensions

FieldDescription
coloCode IATA airport code of the Cloudflare data center that handled the request
date Request date
datetimeFifteenMinutes Request timestamp truncated to fifteen minutes
datetimeFiveMinutes Request timestamp truncated to five minutes
datetimeHour Request timestamp truncated to the hour
datetimeMinute Request timestamp truncated to the minute
endpoint The proxy endpoint that generated traffic
proxyStatus Proxy-level error classification, empty when no proxy-level error occurred
statusCode HTTP status code returned by the proxy to the client

AccountProgrammableFlowProtectionNetworkAnalyticsAdaptiveGroups

Network analytics data for Programmable Flow Protection

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountProgrammableFlowProtectionNetworkAnalyticsAdaptiveGroupsAvg

FieldDescription
bitRate Sum of bits received, divided by 1 second, providing a per-second bit rate when grouped by datetime
bitRateDay Sum of bits received, divided by 86400 seconds, providing a per-second bit rate when grouped by date
bitRateFifteenMinutes Sum of bits received, divided by 900 seconds, providing a per-second bit rate when grouped by datetimeFifteenMinutes
bitRateFiveMinutes Sum of bits received, divided by 300 seconds, providing a per-second bit rate when grouped by datetimeFiveMinutes
bitRateHour Sum of bits received, divided by 3600 seconds, providing a per-second bit rate when grouped by datetimeHour
bitRateMinute Sum of bits received, divided by 60 seconds, providing a per-second bit rate when grouped by datetimeMinute
bitRateTenSeconds Sum of bits received, divided by 10 seconds, providing a per-second bit rate when grouped by datetimeTenSeconds
packetRate Sum of packets received, divided by 1 second, providing a per-second packet rate when grouped by datetime
packetRateDay Sum of packets received, divided by 86400 seconds, providing a per-second packet rate when grouped by date
packetRateFifteenMinutes Sum of packets received, divided by 900 seconds, providing a per-second packet rate when grouped by datetimeFifteenMinutes
packetRateFiveMinutes Sum of packets received, divided by 300 seconds, providing a per-second packet rate when grouped by datetimeFiveMinutes
packetRateHour Sum of packets received, divided by 3600 seconds, providing a per-second packet rate when grouped by datetimeHour
packetRateMinute Sum of packets received, divided by 60 seconds, providing a per-second packet rate when grouped by datetimeMinute
packetRateTenSeconds Sum of packets received, divided by 10 seconds, providing a per-second packet rate when grouped by datetimeTenSeconds

AccountProgrammableFlowProtectionNetworkAnalyticsAdaptiveGroupsAvgConfidence

FieldDescription
bitRate Confidence interval for the corresponding point estimate
bitRateDay Confidence interval for the corresponding point estimate
bitRateFifteenMinutes Confidence interval for the corresponding point estimate
bitRateFiveMinutes Confidence interval for the corresponding point estimate
bitRateHour Confidence interval for the corresponding point estimate
bitRateMinute Confidence interval for the corresponding point estimate
bitRateTenSeconds Confidence interval for the corresponding point estimate
packetRate Confidence interval for the corresponding point estimate
packetRateDay Confidence interval for the corresponding point estimate
packetRateFifteenMinutes Confidence interval for the corresponding point estimate
packetRateFiveMinutes Confidence interval for the corresponding point estimate
packetRateHour Confidence interval for the corresponding point estimate
packetRateMinute Confidence interval for the corresponding point estimate
packetRateTenSeconds Confidence interval for the corresponding point estimate

AccountProgrammableFlowProtectionNetworkAnalyticsAdaptiveGroupsConfidence

FieldDescription
avg The average of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountProgrammableFlowProtectionNetworkAnalyticsAdaptiveGroupsDimensions

FieldDescription
applicationTag Application tag associated with the packet
coloCity City where the Cloudflare datacenter that received the packet is located
coloCode Cloudflare datacenter that received the packet (nearest IATA airport code)
coloCountry Country where the Cloudflare datacenter that received the packet is located (ISO 3166-1 alpha-2)
coloGeohash Latitude and longitude where the Cloudflare datacenter that received the packet is located (Geohash encoding)
coloName Cloudflare datacenter that received the packet (unique site identifier)
date Date that the packet was received
datetime Date and time that the packet was received
datetimeFifteenMinutes Date and time that the packet was received, rounded to the start of the nearest fifteen minutes
datetimeFiveMinutes Date and time that the packet was received, rounded to the start of the nearest five minutes
datetimeHour Date and time that the packet was received, rounded to the start of the nearest hour
datetimeMinute Date and time that the packet was received, rounded to the start of the nearest minute
datetimeTenSeconds Date and time that the packet was received, rounded to the start of the nearest ten seconds
destinationAsn ASN associated with the destination IP of the packet, or 0 if there was no mapping available
destinationAsnName Name of ASN associated with the destination IP of the packet, if available
destinationCountry Country where the destination IP of the packet is located (ISO 3166-1 alpha-2)
destinationGeohash Latitude and longitude where the destination IP of the packet is located (Geohash encoding)
destinationPort Value of the Destination Port header field in the TCP or UDP packet
direction Direction of the packet relative to the customer network (possible values: inbound, outbound, lateral)
ethertype Value of the Ethertype header field in the Ethernet packet (2048 for IPv4; 34525 for IPv6)
greChecksum Value of the Checkusm header field in the GRE packet
greEthertype Value of the Ethertype header field in the GRE packet
greHeaderLength Length of the GRE packet header, in bytes
greKey Value of the Key header field in the GRE packet
greSequenceNumber Value of the Sequence Number header field in the GRE packet
greVersion Value of the Version header field in the GRE packet
icmpChecksum Value of the Checkusm header field in the ICMP packet
icmpCode Value of the Code header field in the ICMP packet
icmpType Value of the Type header field in the ICMP packet
ipDestinationAddress Value of the Destination Address header field in the IPv4 or IPv6 packet
ipDestinationSubnet Computed subnet of the Destination Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipFragmentOffset Value of the Fragment Offset header field in the IPv4 or IPv6 packet
ipHeaderLength Length of the IPv4 or IPv6 packet header, in bytes
ipMoreFragments Value of the More Fragments header field in the IPv4 or IPv6 packet
ipProtocol Value of the Protocol header field in the IPv4 or IPv6 packet
ipProtocolName Name of the protocol specified by the Protocol header field in the IPv4 or IPv6 packet
ipSourceAddress Value of the Source Address header field in the IPv4 or IPv6 packet
ipSourceSubnet Computed subnet of the Source Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipTotalLength Total length of the IPv4 or IPv6 packet, in bytes
ipTotalLengthBuckets Total length of the IPv4 or IPv6 packet, in bytes, with the last two digits truncated
ipTtl Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet
ipTtlBuckets Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet, with the last digit truncated
ipv4Checksum Value of the Checksum header field in the IPv4 packet
ipv4DontFragment Value of the Don't Fragment header field in the IPv4 packet
ipv4Dscp Value of the Differentiated Services Code Point header field in the IPv4 packet
ipv4Ecn Value of the Explicit Congestion Notification header field in the IPv4 packet
ipv4Identification Value of the Identification header field in the IPv4 packet
ipv4Options List of Options numbers included in the IPv4 packet header
ipv6Dscp Value of the Differentiated Services Code Point header field in the IPv6 packet
ipv6Ecn Value of the Explicit Congestion Notification header field in the IPv6 packet
ipv6ExtensionHeaders List of Extension Header numbers included in the IPv6 packet header
ipv6FlowLabel Value of the Flow Label header field in the IPv6 packet
ipv6Identification Value of the Identification extension header field in the IPv6 packet
leaseTag IP lease tag associated with the packet
mitigationReason Reason for applying a mitigation to the packet, if any
mitigationScope Whether the packet matched a local or global mitigation, if any (possible values: local, global)
outcome The action that was taken on the packet (possible values: pass, drop)
pfpCustomTag The custom network analytics tag set by Programmable Flow Protection program
prefixTag IP prefix tag associated with the packet
programId Unique identifier of the program that executed on the packet, if any
programName Human readable name of program that executed on the packet, if any
ruleId Unique identifier of the rule that matched the packet, if any
sampleInterval ABR sample interval
sourceAsn ASN associated with the source IP of the packet, or 0 if there was no mapping available
sourceAsnName Name of ASN associated with the source IP of the packet, if available
sourceCountry Country where the source IP of the packet is located (ISO 3166-1 alpha-2)
sourceGeohash Latitude and longitude where the source IP of the packet is located (Geohash encoding)
sourcePort Value of the Source Port header field in the TCP or UDP packet
tcpAcknowledgementNumber Value of the Acknowledgement Number header field in the TCP packet
tcpChecksum Value of the Checkusm header field in the TCP packet
tcpDataOffset Value of the Data Offset header field in the TCP packet
tcpFlags Value of the Flags header field in the TCP packet
tcpFlagsString Human-readable string representation of the Flags header field in the TCP packet
tcpMss Value of the MSS option header field in the TCP packet
tcpOptions List of Options numbers included in the TCP packet header
tcpSackBlocks Value of the SACK Blocks option header field in the TCP packet
tcpSackPermitted Value of the SACK Permitted option header field in the TCP packet
tcpSequenceNumber Value of the Sequence Number header field in the TCP packet
tcpTimestampEcr Value of the Timestamp Echo Reply option header field in the TCP packet
tcpTimestampValue Value of the Timestamp option header field in the TCP packet
tcpUrgentPointer Value of the Urgent Pointer header field in the TCP packet
tcpWindowScale Value of the Window Scale option header field in the TCP packet
tcpWindowSize Value of the Window Size header field in the TCP packet
udpChecksum Value of the Checkusm header field in the UDP packet
udpPayloadLength Value of the Payload Length header field in the UDP packet
verdict The action that Cloudflare thinks should be taken on the packet (possible values: pass, drop)

AccountProgrammableFlowProtectionNetworkAnalyticsAdaptiveGroupsSum

FieldDescription
bits Sum of bits received
packets Sum of packets received

AccountProgrammableFlowProtectionNetworkAnalyticsAdaptiveGroupsSumConfidence

FieldDescription
bits Confidence interval for the corresponding point estimate
packets Confidence interval for the corresponding point estimate

AccountQueueBacklogAdaptiveGroups

Beta. Queue backlog data with adaptive sampling. Queues that are not being written to, or read from, will not return data, even if they have a backlog.

FieldDescription
avg The average value for a metric per dimension
dimensions List of dimensions to group by

AccountQueueBacklogAdaptiveGroupsAvg

FieldDescription
bytes The average size of the backlog in bytes for sample interval
messages The average number of messages in the backlog for sample interval
sampleInterval The average value used for sample interval

AccountQueueBacklogAdaptiveGroupsDimensions

FieldDescription
date Message operation timestamp, truncated to start of a day
datetime Message operation timestamp
datetimeFifteenMinutes Message operation timestamp, truncated to fifteen minutes
datetimeFiveMinutes Message operation timestamp, truncated to five minutes
datetimeHour Message operation timestamp, truncated to start of an hour
datetimeMinute Message operation timestamp, truncated to start of an minute
datetimeSixHours Message operation timestamp, truncated to start of six hour window
queueId The ID of the Queue

AccountQueueConsumerMetricsAdaptiveGroups

Beta. Queue consumer metrics with adaptive sampling. Inactive queues will not return data.

FieldDescription
avg The average value for a metric per dimension
dimensions List of dimensions to group by

AccountQueueConsumerMetricsAdaptiveGroupsAvg

FieldDescription
concurrency The average concurrency of the queue
sampleInterval The average value used for sample interval

AccountQueueConsumerMetricsAdaptiveGroupsDimensions

FieldDescription
date Message operation timestamp, truncated to start of a day
datetime Message operation timestamp
datetimeFifteenMinutes Message operation timestamp, truncated to fifteen minutes
datetimeFiveMinutes Message operation timestamp, truncated to five minutes
datetimeHour Message operation timestamp, truncated to start of an hour
datetimeMinute Message operation timestamp, truncated to start of an minute
datetimeSixHours Message operation timestamp, truncated to start of six hour window
queueId The ID of the Queue

AccountQueueDelayedBacklogAdaptiveGroups

Beta. Queue delayed backlog data with adaptive sampling. Queues that are not being written to, or read from, will not return data, even if they have a backlog.

FieldDescription
avg The average value for a metric per dimension
dimensions List of dimensions to group by

AccountQueueDelayedBacklogAdaptiveGroupsAvg

FieldDescription
messages The average number of messages in the delayed backlog for sample interval
sampleInterval The average value used for sample interval

AccountQueueDelayedBacklogAdaptiveGroupsDimensions

FieldDescription
date Message operation timestamp, truncated to start of a day
datetime Message operation timestamp
datetimeFifteenMinutes Message operation timestamp, truncated to fifteen minutes
datetimeFiveMinutes Message operation timestamp, truncated to five minutes
datetimeHour Message operation timestamp, truncated to start of an hour
datetimeMinute Message operation timestamp, truncated to start of an minute
datetimeSixHours Message operation timestamp, truncated to start of six hour window
queueId The ID of the Queue

AccountQueueMessageOperationsAdaptiveGroups

Beta. Queue message operation data with adaptive sampling

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count Number of Message Operations
dimensions List of dimensions to group by
max The max of values for a metric per dimension
sum The sum of values for a metric per dimension

AccountQueueMessageOperationsAdaptiveGroupsAvg

FieldDescription
lagTime The average time in milliseconds between when the message was written to the queue and the current operation over the sample interval. Will always be 0 for WriteMessage operations.
retryCount The average number of retries per message operation. A retry occurs after an unsucessful delivery, if the queue is configured to retry failed attempts. Only applicable to ReadMessage and DeleteMessage operations. Will always be 0 for WriteMessage operations.
sampleInterval The average value used for sample interval

AccountQueueMessageOperationsAdaptiveGroupsConfidence

FieldDescription
count Number of Message Operations, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountQueueMessageOperationsAdaptiveGroupsDimensions

FieldDescription
actionType The type of the Queue message operation
consumerType The queue consumer type for the operation. Only applicable for ReadMessage and DeleteMessge action types.
date Message operation timestamp, truncated to start of a day
datetime Message operation timestamp
datetimeFifteenMinutes Message operation timestamp, truncated to fifteen minutes
datetimeFiveMinutes Message operation timestamp, truncated to five minutes
datetimeHour Message operation timestamp, truncated to start of an hour
datetimeMinute Message operation timestamp, truncated to start of an minute
datetimeSixHours Message operation timestamp, truncated to start of six hour window
outcome The outcome of the operation. Only applicable to DeleteMessage action types. Can be 'success', 'dlq', or 'fail'. Always 'none' for other operations.
queueId The ID of the Queue

AccountQueueMessageOperationsAdaptiveGroupsMax

FieldDescription
messageSize Max Message Size

AccountQueueMessageOperationsAdaptiveGroupsSum

FieldDescription
billableOperations Number of Billable Operations (some message operations count as multiple billable operations)
bytes Total size (in bytes) of message operations

AccountQueueMessageOperationsAdaptiveGroupsSumConfidence

FieldDescription
billableOperations Confidence interval for the corresponding point estimate
bytes Confidence interval for the corresponding point estimate

AccountR2CatalogDataOperationsAdaptiveGroups

R2 Data Catalog data plane operations (Iceberg REST API requests) with adaptive sampling

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
count Total number of catalog data plane requests
dimensions List of dimensions to group by
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension

AccountR2CatalogDataOperationsAdaptiveGroupsAvg

FieldDescription
requestDurationMs Average request duration in milliseconds
sampleInterval Average sample interval

AccountR2CatalogDataOperationsAdaptiveGroupsConfidence

FieldDescription
count Total number of catalog data plane requests, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountR2CatalogDataOperationsAdaptiveGroupsDimensions

FieldDescription
date Request timestamp, truncated to start of a day
datetime Request timestamp
datetimeFifteenMinutes Request timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Request timestamp, truncated to start of five minutes
datetimeHour Request timestamp, truncated to start of an hour
datetimeMinute Request timestamp, truncated to start of a minute
httpStatus HTTP response status code
namespaceName The Iceberg namespace targeted by the request, if applicable
operation The Iceberg REST API operation name (e.g. load-table, list-namespaces)
tableName The Iceberg table targeted by the request, if applicable
warehouseName The name of the R2 Data Catalog warehouse

AccountR2CatalogDataOperationsAdaptiveGroupsQuantiles

FieldDescription
requestDurationMsP25 25th percentile request duration (milliseconds)
requestDurationMsP50 50th percentile request duration (milliseconds)
requestDurationMsP75 75th percentile request duration (milliseconds)
requestDurationMsP90 90th percentile request duration (milliseconds)
requestDurationMsP95 95th percentile request duration (milliseconds)
requestDurationMsP99 99th percentile request duration (milliseconds)
requestDurationMsP999 99.9th percentile request duration (milliseconds)

AccountR2CatalogDataOperationsAdaptiveGroupsSum

FieldDescription
requestBodyBytes Sum of request body bytes
requestDurationMs Total request duration in milliseconds

AccountR2CatalogDataOperationsAdaptiveGroupsSumConfidence

FieldDescription
requestBodyBytes Confidence interval for the corresponding point estimate
requestDurationMs Confidence interval for the corresponding point estimate

AccountR2CatalogTableMaintenanceAdaptiveGroups

R2 Data Catalog table maintenance job metrics (compaction, snapshot expiration) with adaptive sampling

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
count Total number of table maintenance jobs
dimensions List of dimensions to group by
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension

AccountR2CatalogTableMaintenanceAdaptiveGroupsAvg

FieldDescription
jobDurationMs Average job duration in milliseconds
sampleInterval Average sample interval

AccountR2CatalogTableMaintenanceAdaptiveGroupsConfidence

FieldDescription
count Total number of table maintenance jobs, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountR2CatalogTableMaintenanceAdaptiveGroupsDimensions

FieldDescription
date Job timestamp, truncated to start of a day
datetime Job timestamp
datetimeFifteenMinutes Job timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Job timestamp, truncated to start of five minutes
datetimeHour Job timestamp, truncated to start of an hour
datetimeMinute Job timestamp, truncated to start of a minute
jobType The type of maintenance job (compaction, snapshot-expiration)
namespaceName The Iceberg namespace containing the table
success Whether the job succeeded (1) or failed (0)
tableName The Iceberg table that was maintained
warehouseName The name of the R2 Data Catalog warehouse

AccountR2CatalogTableMaintenanceAdaptiveGroupsQuantiles

FieldDescription
jobDurationMsP25 25th percentile job duration (milliseconds)
jobDurationMsP50 50th percentile job duration (milliseconds)
jobDurationMsP75 75th percentile job duration (milliseconds)
jobDurationMsP90 90th percentile job duration (milliseconds)
jobDurationMsP95 95th percentile job duration (milliseconds)
jobDurationMsP99 99th percentile job duration (milliseconds)
jobDurationMsP999 99.9th percentile job duration (milliseconds)

AccountR2CatalogTableMaintenanceAdaptiveGroupsSum

FieldDescription
filesOutput Sum of output files created by maintenance jobs
filesProcessed Sum of input files processed by maintenance jobs
inputBytes Sum of bytes read/scanned by maintenance jobs
jobDurationMs Total job duration in milliseconds
outputBytes Sum of bytes written by maintenance jobs

AccountR2CatalogTableMaintenanceAdaptiveGroupsSumConfidence

FieldDescription
filesOutput Confidence interval for the corresponding point estimate
filesProcessed Confidence interval for the corresponding point estimate
inputBytes Confidence interval for the corresponding point estimate
jobDurationMs Confidence interval for the corresponding point estimate
outputBytes Confidence interval for the corresponding point estimate

AccountR2OperationsAdaptiveGroups

Beta. R2 operations with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountR2OperationsAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountR2OperationsAdaptiveGroupsDimensions

FieldDescription
actionStatus Status of the R2 operation
actionType The name of the R2 operation
bucketName The name of the R2 bucket, if applicable to this request
date Request timestamp, truncated to start of a day
datetime Request timestamp
datetimeFifteenMinutes Request timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Request timestamp, truncated to start of five minutes
datetimeHour Request timestamp, truncated to start of an hour
datetimeMinute Request timestamp, truncated to start of an minute
eyeballRegion The region from which the request originated (WNAM, ENAM, WEUR, EEUR, APAC, SAM, OC, AFR, ME)
objectName The name of the R2 object, if applicable to this request
responseStatusCode HTTP status code returned by R2
storageClass The storage class that applies to this request

AccountR2OperationsAdaptiveGroupsSum

FieldDescription
requests Sum of Requests
responseBytes Sum of retrieved bytes
responseObjectSize Sum of Response Object Sizes

AccountR2OperationsAdaptiveGroupsSumConfidence

FieldDescription
requests Confidence interval for the corresponding point estimate
responseBytes Confidence interval for the corresponding point estimate
responseObjectSize Confidence interval for the corresponding point estimate

AccountR2StorageAdaptiveGroups

Beta. R2 storage with adaptive sampling

FieldDescription
dimensions List of dimensions to group by
max The max of values for a metric per dimension

AccountR2StorageAdaptiveGroupsDimensions

FieldDescription
bucketName The name of the R2 bucket, if applicable to this request
date Storage sample timestamp, truncated to start of a day
datetime Storage sample timestamp
datetimeFifteenMinutes Storage sample timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Storage sample timestamp, truncated to start of five minutes
datetimeHour Storage sample timestamp, truncated to start of an hour
datetimeMinute Storage sample timestamp, truncated to start of an minute
storageClass The storage class that applies to this request

AccountR2StorageAdaptiveGroupsMax

FieldDescription
metadataSize Max of metadata size
objectCount Max of object count
payloadSize Max of payload size
uploadCount Max of upload count

AccountR2sqlOperationsAdaptiveGroups

R2 SQL requests with adaptive sampling

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count Total number of R2 SQL requests
dimensions List of dimensions to group by
max The max of values for a metric per dimension
min The min of values for a metric per dimension
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension

AccountR2sqlOperationsAdaptiveGroupsAvg

FieldDescription
latencyMs Average query latency in milliseconds
sampleInterval Average sample interval

AccountR2sqlOperationsAdaptiveGroupsConfidence

FieldDescription
count Total number of R2 SQL requests, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountR2sqlOperationsAdaptiveGroupsDimensions

FieldDescription
bucket The R2 bucket name
date Request timestamp, truncated to start of a day
datetime Request timestamp
datetimeFifteenMinutes Request timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Request timestamp, truncated to start of five minutes
datetimeHour Request timestamp, truncated to start of an hour
datetimeMinute Request timestamp, truncated to start of a minute
errorCode R2 SQL error code
httpStatus HTTP response status code
namespace The Iceberg namespace targeted by the request
table The Iceberg table targeted by the request

AccountR2sqlOperationsAdaptiveGroupsMax

FieldDescription
latencyMs Maximum query latency in milliseconds

AccountR2sqlOperationsAdaptiveGroupsMin

FieldDescription
latencyMs Minimum query latency in milliseconds

AccountR2sqlOperationsAdaptiveGroupsQuantiles

FieldDescription
latencyMsP25 25th percentile query latency (milliseconds)
latencyMsP50 50th percentile query latency (milliseconds)
latencyMsP75 75th percentile query latency (milliseconds)
latencyMsP90 90th percentile query latency (milliseconds)
latencyMsP95 95th percentile query latency (milliseconds)
latencyMsP99 99th percentile query latency (milliseconds)
latencyMsP999 99.9th percentile query latency (milliseconds)

AccountR2sqlOperationsAdaptiveGroupsSum

FieldDescription
latencyMs Total query latency in milliseconds
r2BytesRead Total compressed bytes read from R2
r2ColdReads Total R2 requests that did not hit cache
r2HotReads Total cache hits
r2Reads Total number of R2 requests
r2ScannedFiles Total files scanned

AccountR2sqlOperationsAdaptiveGroupsSumConfidence

FieldDescription
latencyMs Confidence interval for the corresponding point estimate
r2BytesRead Confidence interval for the corresponding point estimate
r2ColdReads Confidence interval for the corresponding point estimate
r2HotReads Confidence interval for the corresponding point estimate
r2Reads Confidence interval for the corresponding point estimate
r2ScannedFiles Confidence interval for the corresponding point estimate

AccountRealtimeKitUsageAdaptiveGroups

RealtimeKit usage metrics

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
count Total number of RealtimeKit usage events
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountRealtimeKitUsageAdaptiveGroupsAvg

FieldDescription
audioMinutes Average audio-only participant minutes per event
exportAudioMinutes Average export minutes per event (recording, RTMP or HLS streaming, audio only)
exportMinutes Average export minutes per event (recording, RTMP or HLS streaming)
mediaMinutes Average audio and video participant minutes per event

AccountRealtimeKitUsageAdaptiveGroupsConfidence

FieldDescription
count Total number of RealtimeKit usage events, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountRealtimeKitUsageAdaptiveGroupsDimensions

FieldDescription
appId The RealtimeKit application identifier
date The date of the usage event
datetime The exact timestamp of the usage event
datetimeFifteenMinutes The date and time truncated to fifteen minutes
datetimeFiveMinutes The date and time truncated to five minutes
datetimeHour The date and time truncated to the hour
datetimeMinute The date and time truncated to the minute

AccountRealtimeKitUsageAdaptiveGroupsSum

FieldDescription
audioMinutes Total audio only participant minutes
exportAudioMinutes Total export minutes (recording, RTMP or HLS streaming, audio only)
exportMinutes Total export minutes (recording, RTMP or HLS streaming)
mediaMinutes Total audio and video participant minutes

AccountRealtimeKitUsageAdaptiveGroupsSumConfidence

FieldDescription
audioMinutes Confidence interval for the corresponding point estimate
exportAudioMinutes Confidence interval for the corresponding point estimate
exportMinutes Confidence interval for the corresponding point estimate
mediaMinutes Confidence interval for the corresponding point estimate

AccountRumPageloadEventsAdaptiveGroups

Beta. Aggregated RUM pageload event metrics with adaptive sampling

FieldDescription
avg
confidence ALPHA - DO NOT USE
count The number of pages viewed by end-users
dimensions List of dimensions to group by
sum

AccountRumPageloadEventsAdaptiveGroupsAvg

FieldDescription
sampleInterval Average sample interval

AccountRumPageloadEventsAdaptiveGroupsConfidence

FieldDescription
count The number of pages viewed by end-users, with confidence intervals
level Confidence level that was requested
sum

AccountRumPageloadEventsAdaptiveGroupsDimensions

FieldDescription
bot Indicates if the request is likely from a bot (non-human traffic). Returns 1 if from a bot, 0 otherwise.
countryName Client country ISO 3166 alpha2 code
customTagInternalSxg Signed Exchange enabled status
date Request date from browser
datetimeFifteenMinutes Request datetime from browser, truncated to multiple of 15 minutes
datetimeFiveMinutes Request datetime from browser, truncated to multiple of 5 minutes
datetimeHalfOfHour Request datetime from browser, truncated to multiple of 30 minutes
datetimeHour Request datetime from browser, truncated to the hour
datetimeMinute Request datetime from browser, truncated to the minute
deliveryType Delivery type of the request
deviceType Device type used for view the page
navigationType Navigation type of the request
refererHost Host of the HTTP request referer
refererPath Path of the HTTP request referer
refererScheme Scheme of the HTTP request referer (http or https)
requestHost HTTP Host of the web page URL
requestPath Path of the web page URL
requestScheme Scheme of the web page URL (http or https)
siteTag The key value to identify a site
userAgentBrowser Browser parsed from the user agent
userAgentOS OS parsed from the user agent

AccountRumPageloadEventsAdaptiveGroupsSum

FieldDescription
visits The number of pages viewed by end-users that were initiated from a different website (i.e. where the Document.referrer does not match the hostname)

AccountRumPageloadEventsAdaptiveGroupsSumConfidence

FieldDescription
visits Confidence interval for the corresponding point estimate

AccountRumPerformanceEventsAdaptiveGroups

Beta. Aggregated RUM performance event metrics with adaptive sampling

FieldDescription
avg
confidence ALPHA - DO NOT USE
count The number of pages viewed by end-users
dimensions List of dimensions to group by
quantiles
sum

AccountRumPerformanceEventsAdaptiveGroupsAvg

FieldDescription
connectionTime Connection time
dnsTime Domain lookup time
firstContentfulPaint The time when the first content piece from the DOM is painted (i.e. some text or an image)
firstPaint The time when the first pixel is painted onto the screen (i.e. background of the page)
loadEventTime The time taken for the load event
pageLoadTime The time to download and display the entire content of a web page in the browser window
pageRenderTime The time to download and display the entire content of a web page in the browser window
requestTime The time between initiating the request and receiving the first byte of the response
responseTime The time between receiving the first byte and the last byte of the response
sampleInterval Average sample interval

AccountRumPerformanceEventsAdaptiveGroupsConfidence

FieldDescription
count The number of pages viewed by end-users, with confidence intervals
level Confidence level that was requested
sum

AccountRumPerformanceEventsAdaptiveGroupsDimensions

FieldDescription
bot Indicates if the request is likely from a bot (non-human traffic). Returns 1 if from a bot, 0 otherwise.
countryName Client country ISO 3166 alpha2 code
customTagInternalSxg Signed Exchange enabled status
date Request date from browser
datetimeFifteenMinutes Request datetime from browser, truncated to multiple of 15 minutes
datetimeFiveMinutes Request datetime from browser, truncated to multiple of 5 minutes
datetimeHalfOfHour Request datetime from browser, truncated to multiple of 30 minutes
datetimeHour Request datetime from browser, truncated to the hour
datetimeMinute Request datetime from browser, truncated to the minute
deliveryType Delivery type of the request
deviceType Device type used for view the page
navigationType Navigation type of the request
refererHost Host of the HTTP request referer
refererPath Path of the HTTP request referer
refererScheme Scheme of the HTTP request referer (http or https)
requestHost HTTP Host of the web page URL
requestPath Path of the web page URL
requestScheme Scheme of the web page URL (http or https)
siteTag The key value to identify a site
userAgentBrowser Browser parsed from the user agent
userAgentOS OS parsed from the user agent

AccountRumPerformanceEventsAdaptiveGroupsQuantiles

FieldDescription
connectionTimeP25 Connection time
connectionTimeP50 Connection time
connectionTimeP75 Connection time
connectionTimeP90 Connection time
connectionTimeP95 Connection time
connectionTimeP99 Connection time
connectionTimeP999 Connection time
dnsTimeP25 Domain lookup time
dnsTimeP50 Domain lookup time
dnsTimeP75 Domain lookup time
dnsTimeP90 Domain lookup time
dnsTimeP95 Domain lookup time
dnsTimeP99 Domain lookup time
dnsTimeP999 Domain lookup time
firstContentfulPaintP25 The time when the first content piece from the DOM is painted (i.e. some text or an image)
firstContentfulPaintP50 The time when the first content piece from the DOM is painted (i.e. some text or an image)
firstContentfulPaintP75 The time when the first content piece from the DOM is painted (i.e. some text or an image)
firstContentfulPaintP90 The time when the first content piece from the DOM is painted (i.e. some text or an image)
firstContentfulPaintP95 The time when the first content piece from the DOM is painted (i.e. some text or an image)
firstContentfulPaintP99 The time when the first content piece from the DOM is painted (i.e. some text or an image)
firstContentfulPaintP999 The time when the first content piece from the DOM is painted (i.e. some text or an image)
firstPaintP25 The time when the first pixel is painted onto the screen (i.e. background of the page)
firstPaintP50 The time when the first pixel is painted onto the screen (i.e. background of the page)
firstPaintP75 The time when the first pixel is painted onto the screen (i.e. background of the page)
firstPaintP90 The time when the first pixel is painted onto the screen (i.e. background of the page)
firstPaintP95 The time when the first pixel is painted onto the screen (i.e. background of the page)
firstPaintP99 The time when the first pixel is painted onto the screen (i.e. background of the page)
firstPaintP999 The time when the first pixel is painted onto the screen (i.e. background of the page)
loadEventTimeP25 The time taken for the load event
loadEventTimeP50 The time taken for the load event
loadEventTimeP75 The time taken for the load event
loadEventTimeP90 The time taken for the load event
loadEventTimeP95 The time taken for the load event
loadEventTimeP99 The time taken for the load event
loadEventTimeP999 The time taken for the load event
pageLoadTimeP25 The time to download and display the entire content of a web page in the browser window
pageLoadTimeP50 The time to download and display the entire content of a web page in the browser window
pageLoadTimeP75 The time to download and display the entire content of a web page in the browser window
pageLoadTimeP90 The time to download and display the entire content of a web page in the browser window
pageLoadTimeP95 The time to download and display the entire content of a web page in the browser window
pageLoadTimeP99 The time to download and display the entire content of a web page in the browser window
pageLoadTimeP999 The time to download and display the entire content of a web page in the browser window
pageRenderTimeP25 The time to download and display the entire content of a web page in the browser window
pageRenderTimeP50 The time to download and display the entire content of a web page in the browser window
pageRenderTimeP75 The time to download and display the entire content of a web page in the browser window
pageRenderTimeP90 The time to download and display the entire content of a web page in the browser window
pageRenderTimeP95 The time to download and display the entire content of a web page in the browser window
pageRenderTimeP99 The time to download and display the entire content of a web page in the browser window
pageRenderTimeP999 The time to download and display the entire content of a web page in the browser window
requestTimeP25 The time between initiating the request and receiving the first byte of the response
requestTimeP50 The time between initiating the request and receiving the first byte of the response
requestTimeP75 The time between initiating the request and receiving the first byte of the response
requestTimeP90 The time between initiating the request and receiving the first byte of the response
requestTimeP95 The time between initiating the request and receiving the first byte of the response
requestTimeP99 The time between initiating the request and receiving the first byte of the response
requestTimeP999 The time between initiating the request and receiving the first byte of the response
responseTimeP25 The time between receiving the first byte and the last byte of the response
responseTimeP50 The time between receiving the first byte and the last byte of the response
responseTimeP75 The time between receiving the first byte and the last byte of the response
responseTimeP90 The time between receiving the first byte and the last byte of the response
responseTimeP95 The time between receiving the first byte and the last byte of the response
responseTimeP99 The time between receiving the first byte and the last byte of the response
responseTimeP999 The time between receiving the first byte and the last byte of the response

AccountRumPerformanceEventsAdaptiveGroupsSum

FieldDescription
visits The number of pages viewed by end-users that were initiated from a different website (i.e. where the Document.referrer does not match the hostname)

AccountRumPerformanceEventsAdaptiveGroupsSumConfidence

FieldDescription
visits Confidence interval for the corresponding point estimate

AccountRumWebVitalsEventsAdaptive

Beta. RUM Web Vitals event metrics with adaptive sampling

FieldDescription
bot Indicates if the request is likely from a bot (non-human traffic). Returns 1 if from a bot, 0 otherwise.
countryName Client country ISO 3166 alpha2 code
cumulativeLayoutShift Cumulative Layout Shift (Core Web Vitals) (-1 indicates N/A)
cumulativeLayoutShiftCurrentRect Layout values of the rectangular area after the changes
cumulativeLayoutShiftElement DOM selector name of the largest layout shift
cumulativeLayoutShiftPath Observed path of the Cumulative Layout Shift (Core Web Vitals)
cumulativeLayoutShiftPreviousRect Layout values of the rectangular area before the changes
customTagInternalSxg Signed Exchange enabled status
date Request date from browser
datetime Request datetime from browser
datetimeFifteenMinutes Request datetime from browser, truncated to multiple of 15 minutes
datetimeFiveMinutes Request datetime from browser, truncated to multiple of 5 minutes
datetimeHalfOfHour Request datetime from browser, truncated to multiple of 30 minutes
datetimeHour Request datetime from browser, truncated to the hour
datetimeMinute Request datetime from browser, truncated to the minute
deliveryType Delivery type of the request
deviceType Device type used for view the page
navigationType Navigation type of the request
refererHost Host of the HTTP request referer
refererPath Path of the HTTP request referer
refererScheme Scheme of the HTTP request referer (http or https)
requestHost HTTP Host of the web page URL
requestPath Path of the web page URL
requestScheme Scheme of the web page URL (http or https)
sampleInterval ABR sample interval
siteTag The key value to identify a site
userAgentBrowser Browser parsed from the user agent
userAgentOS OS parsed from the user agent

AccountRumWebVitalsEventsAdaptiveGroups

Beta. Aggregated RUM Web Vitals event metrics with adaptive sampling

FieldDescription
avg
confidence ALPHA - DO NOT USE
count The number of pages viewed by end-users
dimensions List of dimensions to group by
quantiles
sum

AccountRumWebVitalsEventsAdaptiveGroupsAvg

FieldDescription
cumulativeLayoutShift Cumulative Layout Shift (Core Web Vitals) (negative value indicates N/A)
firstContentfulPaint First Contentful Paint in microseconds (negative value indicates N/A)
firstInputDelay DEPRECATED (FirstInputDelay is replaced by InteractionToNextPaint. Please use INP instead.): First Input Delay (Core Web Vitals) in microseconds (negative value indicates N/A)
interactionToNextPaint Interaction to Next Paint in microseconds (negative value indicates N/A)
largestContentfulPaint Largest Contentful Paint (Core Web Vitals) in microseconds (negative value indicates N/A)
lcpElementRenderDelay Largest Contentful Paint Attributions Element Render Delay in microseconds (negative value indicates N/A)
lcpResourceLoadDelay Largest Contentful Paint Attributions Resource Load Delay in microseconds (negative value indicates N/A)
lcpResourceLoadTime Largest Contentful Paint Attributions Resource Load Time in microseconds (negative value indicates N/A)
sampleInterval Average sample interval
timeToFirstByte Time to First Byte in microseconds (negative value indicates N/A)

AccountRumWebVitalsEventsAdaptiveGroupsConfidence

FieldDescription
count The number of pages viewed by end-users, with confidence intervals
level Confidence level that was requested
sum

AccountRumWebVitalsEventsAdaptiveGroupsDimensions

FieldDescription
bot Indicates if the request is likely from a bot (non-human traffic). Returns 1 if from a bot, 0 otherwise.
countryName Client country ISO 3166 alpha2 code
cumulativeLayoutShiftElement DOM selector name of the largest layout shift
cumulativeLayoutShiftPath Observed path of the Cumulative Layout Shift (Core Web Vitals)
customTagInternalSxg Signed Exchange enabled status
date Request date from browser
datetimeFifteenMinutes Request datetime from browser, truncated to multiple of 15 minutes
datetimeFiveMinutes Request datetime from browser, truncated to multiple of 5 minutes
datetimeHalfOfHour Request datetime from browser, truncated to multiple of 30 minutes
datetimeHour Request datetime from browser, truncated to the hour
datetimeMinute Request datetime from browser, truncated to the minute
deliveryType Delivery type of the request
deviceType Device type used for view the page
firstInputDelayElement DEPRECATED (FirstInputDelay is replaced by InteractionToNextPaint. Please use INP instead.): DOM selector name of the input delay
firstInputDelayName DEPRECATED (FirstInputDelay is replaced by InteractionToNextPaint. Please use INP instead.): Action name of the input delay
firstInputDelayPath DEPRECATED (FirstInputDelay is replaced by InteractionToNextPaint. Please use INP instead.): Observed path of the First Input Delay (Core Web Vitals)
interactionToNextPaintElement DOM selector name of the interaction
interactionToNextPaintName Action name of the interaction
interactionToNextPaintPath Observed path of the Cumulative Layout Shift (Core Web Vitals)
largestContentfulPaintElement DOM selector name of the largest object
largestContentfulPaintObjectHost Host of the largest object
largestContentfulPaintObjectPath Path of the largest object
largestContentfulPaintObjectScheme Scheme of the largest object (http or https)
largestContentfulPaintPath Observed path of the Largest Contentful Paint (Core Web Vitals)
lcpFetchPriority Fetch priority of the LCP element.
lcpInitiatorType Initiator type of the LCP element.
navigationType Navigation type of the request
refererHost Host of the HTTP request referer
refererPath Path of the HTTP request referer
refererScheme Scheme of the HTTP request referer (http or https)
requestHost HTTP Host of the web page URL
requestPath Path of the web page URL
requestScheme Scheme of the web page URL (http or https)
siteTag The key value to identify a site
userAgentBrowser Browser parsed from the user agent
userAgentOS OS parsed from the user agent

AccountRumWebVitalsEventsAdaptiveGroupsQuantiles

FieldDescription
cumulativeLayoutShiftP25 Cumulative Layout Shift (Core Web Vitals) (negative value indicates N/A)
cumulativeLayoutShiftP50 Cumulative Layout Shift (Core Web Vitals) (negative value indicates N/A)
cumulativeLayoutShiftP75 Cumulative Layout Shift (Core Web Vitals) (negative value indicates N/A)
cumulativeLayoutShiftP90 Cumulative Layout Shift (Core Web Vitals) (negative value indicates N/A)
cumulativeLayoutShiftP95 Cumulative Layout Shift (Core Web Vitals) (negative value indicates N/A)
cumulativeLayoutShiftP99 Cumulative Layout Shift (Core Web Vitals) (negative value indicates N/A)
cumulativeLayoutShiftP999 Cumulative Layout Shift (Core Web Vitals) (negative value indicates N/A)
firstContentfulPaintP25 First Contentful Paint in microseconds (negative value indicates N/A)
firstContentfulPaintP50 First Contentful Paint in microseconds (negative value indicates N/A)
firstContentfulPaintP75 First Contentful Paint in microseconds (negative value indicates N/A)
firstContentfulPaintP90 First Contentful Paint in microseconds (negative value indicates N/A)
firstContentfulPaintP95 First Contentful Paint in microseconds (negative value indicates N/A)
firstContentfulPaintP99 First Contentful Paint in microseconds (negative value indicates N/A)
firstContentfulPaintP999 First Contentful Paint in microseconds (negative value indicates N/A)
firstInputDelayP25 DEPRECATED (FirstInputDelay is replaced by InteractionToNextPaint. Please use INP instead.): First Input Delay (Core Web Vitals) in microseconds (negative value indicates N/A)
firstInputDelayP50 DEPRECATED (FirstInputDelay is replaced by InteractionToNextPaint. Please use INP instead.): First Input Delay (Core Web Vitals) in microseconds (negative value indicates N/A)
firstInputDelayP75 DEPRECATED (FirstInputDelay is replaced by InteractionToNextPaint. Please use INP instead.): First Input Delay (Core Web Vitals) in microseconds (negative value indicates N/A)
firstInputDelayP90 DEPRECATED (FirstInputDelay is replaced by InteractionToNextPaint. Please use INP instead.): First Input Delay (Core Web Vitals) in microseconds (negative value indicates N/A)
firstInputDelayP95 DEPRECATED (FirstInputDelay is replaced by InteractionToNextPaint. Please use INP instead.): First Input Delay (Core Web Vitals) in microseconds (negative value indicates N/A)
firstInputDelayP99 DEPRECATED (FirstInputDelay is replaced by InteractionToNextPaint. Please use INP instead.): First Input Delay (Core Web Vitals) in microseconds (negative value indicates N/A)
firstInputDelayP999 DEPRECATED (FirstInputDelay is replaced by InteractionToNextPaint. Please use INP instead.): First Input Delay (Core Web Vitals) in microseconds (negative value indicates N/A)
interactionToNextPaintP25 Interaction to Next Paint in microseconds (negative value indicates N/A)
interactionToNextPaintP50 Interaction to Next Paint in microseconds (negative value indicates N/A)
interactionToNextPaintP75 Interaction to Next Paint in microseconds (negative value indicates N/A)
interactionToNextPaintP90 Interaction to Next Paint in microseconds (negative value indicates N/A)
interactionToNextPaintP95 Interaction to Next Paint in microseconds (negative value indicates N/A)
interactionToNextPaintP99 Interaction to Next Paint in microseconds (negative value indicates N/A)
interactionToNextPaintP999 Interaction to Next Paint in microseconds (negative value indicates N/A)
largestContentfulPaintP25 Largest Contentful Paint (Core Web Vitals) in microseconds (negative value indicates N/A)
largestContentfulPaintP50 Largest Contentful Paint (Core Web Vitals) in microseconds (negative value indicates N/A)
largestContentfulPaintP75 Largest Contentful Paint (Core Web Vitals) in microseconds (negative value indicates N/A)
largestContentfulPaintP90 Largest Contentful Paint (Core Web Vitals) in microseconds (negative value indicates N/A)
largestContentfulPaintP95 Largest Contentful Paint (Core Web Vitals) in microseconds (negative value indicates N/A)
largestContentfulPaintP99 Largest Contentful Paint (Core Web Vitals) in microseconds (negative value indicates N/A)
largestContentfulPaintP999 Largest Contentful Paint (Core Web Vitals) in microseconds (negative value indicates N/A)
lcpElementRenderDelayP25 Largest Contentful Paint Attributions Element Render Delay in microseconds (negative value indicates N/A)
lcpElementRenderDelayP50 Largest Contentful Paint Attributions Element Render Delay in microseconds (negative value indicates N/A)
lcpElementRenderDelayP75 Largest Contentful Paint Attributions Element Render Delay in microseconds (negative value indicates N/A)
lcpElementRenderDelayP90 Largest Contentful Paint Attributions Element Render Delay in microseconds (negative value indicates N/A)
lcpElementRenderDelayP95 Largest Contentful Paint Attributions Element Render Delay in microseconds (negative value indicates N/A)
lcpElementRenderDelayP99 Largest Contentful Paint Attributions Element Render Delay in microseconds (negative value indicates N/A)
lcpElementRenderDelayP999 Largest Contentful Paint Attributions Element Render Delay in microseconds (negative value indicates N/A)
lcpResourceLoadDelayP25 Largest Contentful Paint Attributions Resource Load Delay in microseconds (negative value indicates N/A)
lcpResourceLoadDelayP50 Largest Contentful Paint Attributions Resource Load Delay in microseconds (negative value indicates N/A)
lcpResourceLoadDelayP75 Largest Contentful Paint Attributions Resource Load Delay in microseconds (negative value indicates N/A)
lcpResourceLoadDelayP90 Largest Contentful Paint Attributions Resource Load Delay in microseconds (negative value indicates N/A)
lcpResourceLoadDelayP95 Largest Contentful Paint Attributions Resource Load Delay in microseconds (negative value indicates N/A)
lcpResourceLoadDelayP99 Largest Contentful Paint Attributions Resource Load Delay in microseconds (negative value indicates N/A)
lcpResourceLoadDelayP999 Largest Contentful Paint Attributions Resource Load Delay in microseconds (negative value indicates N/A)
lcpResourceLoadTimeP25 Largest Contentful Paint Attributions Resource Load Time in microseconds (negative value indicates N/A)
lcpResourceLoadTimeP50 Largest Contentful Paint Attributions Resource Load Time in microseconds (negative value indicates N/A)
lcpResourceLoadTimeP75 Largest Contentful Paint Attributions Resource Load Time in microseconds (negative value indicates N/A)
lcpResourceLoadTimeP90 Largest Contentful Paint Attributions Resource Load Time in microseconds (negative value indicates N/A)
lcpResourceLoadTimeP95 Largest Contentful Paint Attributions Resource Load Time in microseconds (negative value indicates N/A)
lcpResourceLoadTimeP99 Largest Contentful Paint Attributions Resource Load Time in microseconds (negative value indicates N/A)
lcpResourceLoadTimeP999 Largest Contentful Paint Attributions Resource Load Time in microseconds (negative value indicates N/A)
timeToFirstByteP25 Time to First Byte in microseconds (negative value indicates N/A)
timeToFirstByteP50 Time to First Byte in microseconds (negative value indicates N/A)
timeToFirstByteP75 Time to First Byte in microseconds (negative value indicates N/A)
timeToFirstByteP90 Time to First Byte in microseconds (negative value indicates N/A)
timeToFirstByteP95 Time to First Byte in microseconds (negative value indicates N/A)
timeToFirstByteP99 Time to First Byte in microseconds (negative value indicates N/A)
timeToFirstByteP999 Time to First Byte in microseconds (negative value indicates N/A)

AccountRumWebVitalsEventsAdaptiveGroupsSum

FieldDescription
clsGood Cumulative Layout Shift (Core Web Vitals), count of Good occurrences (under 0.1)
clsNeedsImprovement Cumulative Layout Shift (Core Web Vitals), count of Needs Improvement occurrences (between 0.1 and 0.25)
clsPoor Cumulative Layout Shift (Core Web Vitals), count of Poor occurrences (over 0.25)
clsTotal Cumulative Layout Shift (Core Web Vitals), total count
fcpGood First Contentful Paint, count of Good occurrences (under 1.8 s)
fcpNeedsImprovement First Contentful Paint, count of Needs Improvement occurrences (between 1.8 s and 3 s)
fcpPoor First Contentful Paint, count of Poor occurrences (over 3 s)
fcpTotal First Contentful Paint, total count
fidGood DEPRECATED (FirstInputDelay is replaced by InteractionToNextPaint. Please use INP instead.): First Input Delay (Core Web Vitals), count of Good occurrences (under 100 ms)
fidNeedsImprovement DEPRECATED (FirstInputDelay is replaced by InteractionToNextPaint. Please use INP instead.): First Input Delay (Core Web Vitals), count of Needs Improvement occurrences (between 100 ms and 300ms)
fidPoor DEPRECATED (FirstInputDelay is replaced by InteractionToNextPaint. Please use INP instead.): First Input Delay (Core Web Vitals), count of Poor occurrences (over 300 ms)
fidTotal DEPRECATED (FirstInputDelay is replaced by InteractionToNextPaint. Please use INP instead.): First Input Delay (Core Web Vitals), total count
inpGood Interaction to Next Paint, count of Good occurrences (under 200 ms)
inpNeedsImprovement Interaction to Next Paint, count of Needs Improvement occurrences (between 200 ms and 500ms)
inpPoor Interaction to Next Paint, count of Poor occurrences (over 500 ms)
inpTotal Interaction to Next Paint, total count
lcpGood Largest Contentful Paint (Core Web Vitals), count of Good occurrences (under 2.5 sec)
lcpNeedsImprovement Largest Contentful Paint (Core Web Vitals), count of Needs Improvement occurrences (between 2.5 sec and 4.0 sec)
lcpPoor Largest Contentful Paint (Core Web Vitals), count of Poor occurrences (over 4.0 sec)
lcpTotal Largest Contentful Paint (Core Web Vitals), total count
ttfbGood Time to First Byte, count of Good occurrences (under 800 ms)
ttfbNeedsImprovement Time to First Byte, count of Needs Improvement occurrences (between 800 ms and 1800ms)
ttfbPoor Time to First Byte, count of Poor occurrences (over 500 ms)
ttfbTotal Time to First Byte, total count
visits The number of pages viewed by end-users that were initiated from a different website (i.e. where the Document.referrer does not match the hostname)

AccountRumWebVitalsEventsAdaptiveGroupsSumConfidence

FieldDescription
clsGood Confidence interval for the corresponding point estimate
clsNeedsImprovement Confidence interval for the corresponding point estimate
clsPoor Confidence interval for the corresponding point estimate
clsTotal Confidence interval for the corresponding point estimate
fcpGood Confidence interval for the corresponding point estimate
fcpNeedsImprovement Confidence interval for the corresponding point estimate
fcpPoor Confidence interval for the corresponding point estimate
fcpTotal Confidence interval for the corresponding point estimate
inpGood Confidence interval for the corresponding point estimate
inpNeedsImprovement Confidence interval for the corresponding point estimate
inpPoor Confidence interval for the corresponding point estimate
inpTotal Confidence interval for the corresponding point estimate
lcpGood Confidence interval for the corresponding point estimate
lcpNeedsImprovement Confidence interval for the corresponding point estimate
lcpPoor Confidence interval for the corresponding point estimate
lcpTotal Confidence interval for the corresponding point estimate
ttfbGood Confidence interval for the corresponding point estimate
ttfbNeedsImprovement Confidence interval for the corresponding point estimate
ttfbPoor Confidence interval for the corresponding point estimate
ttfbTotal Confidence interval for the corresponding point estimate
visits Confidence interval for the corresponding point estimate

AccountSettings

Access and limitations for an account

FieldDescription
MagicWANConnectorMetricsAdaptiveGroups
accessLoginRequestsAdaptiveGroups
advancedDnsProtectionNetworkAnalyticsAdaptiveGroups
advancedTcpProtectionNetworkAnalyticsAdaptiveGroups
aegisIpUtilizationAdaptiveGroups
aiGatewayCacheAdaptiveGroups
aiGatewayErrorsAdaptiveGroups
aiGatewayRequestsAdaptiveGroups
aiGatewaySizeAdaptiveGroups
aiInferenceAdaptive
aiInferenceAdaptiveGroups
aiSearchAPIAdaptiveGroups
aiSearchIngestedItemsAdaptiveGroups
artifactsEventsAdaptiveGroups
autoRAGConfigAPIAdaptiveGroups
autoRAGEngineAdaptiveGroups
browserIsolationSessionsAdaptiveGroups
browserIsolationUserActionsAdaptiveGroups
browserRenderingApiAdaptive
browserRenderingApiAdaptiveGroups
browserRenderingBindingSessionsAdaptiveGroups
browserRenderingBrowserTimeUsageAdaptiveGroups
browserRenderingEventsAdaptive
browserRenderingEventsAdaptiveGroups
callsStatusAdaptive
callsTurnUsageAdaptiveGroups
callsUsageAdaptiveGroups
cdnNetworkAnalyticsAdaptiveGroups
cf1AccessLogins1dGroups
cf1AccessLogins1hGroups
cf1AccessLoginsRawGroups
cf1GatewayDns1dGroups
cf1GatewayDns1hGroups
cf1GatewayDnsLuga1dGroups
cf1GatewayDnsLuga1hGroups
cf1GatewayDnsLugaRawGroups
cf1GatewayDnsRawGroups
cf1GatewayHttp1dGroups
cf1GatewayHttp1hGroups
cf1GatewayHttpRawGroups
cf1GatewayNetwork1dGroups
cf1GatewayNetwork1hGroups
cf1GatewayNetworkRawGroups
cf1GatewayNetworkSession1dGroups
cf1GatewayNetworkSession1hGroups
cf1GatewayNetworkSessionRawGroups
cf1McpHost1dGroups
cloudchamberMetricsAdaptiveGroups
cloudflareTunnelsAnalyticsAdaptiveGroups
cloudforceOneDetectionsAdaptiveGroups
cloudforceOneDetectionsStagingAdaptiveGroups
containersMetricsAdaptiveGroups
containersUsageAdaptiveGroups
d1AnalyticsAdaptiveGroups
d1QueriesAdaptiveGroups
d1StorageAdaptiveGroups
dnsAnalyticsAdaptive
dnsAnalyticsAdaptiveGroups
dnsFirewallAnalyticsAdaptive
dnsFirewallAnalyticsAdaptiveGroups
dosdAttackAnalyticsGroups
dosdNetworkAnalyticsAdaptiveGroups
durableObjectsInvocationsAdaptiveGroups
durableObjectsPeriodicGroups
durableObjectsSqlStorageGroups
durableObjectsStorageGroups
durableObjectsSubrequestsAdaptiveGroups
fbmAttackAnalyticsGroups
firewallEventsAdaptive
firewallEventsAdaptiveGroups
flagshipFlagEvaluationsAdaptive
flagshipFlagEvaluationsAdaptiveGroups
flowtrackdNetworkAnalyticsAdaptiveGroups
gatewayL4DownstreamSessionsAdaptiveGroups
gatewayL4SessionsAdaptiveGroups
gatewayL4UpstreamSessionsAdaptiveGroups
gatewayL7RequestsAdaptiveGroups
gatewayResolverByCategoryAdaptiveGroups
gatewayResolverByCustomResolverGroups
gatewayResolverByRuleExecutionPerformanceAdaptiveGroups
gatewayResolverQueriesAdaptiveGroups
httpRequests1dGroups
httpRequests1hGroups
httpRequests1mGroups
httpRequestsAdaptive
httpRequestsAdaptiveGroups
httpRequestsOverviewAdaptiveGroups
hyperdrivePoolSizesAdaptiveGroups
hyperdriveQueriesAdaptiveGroups
imagesRequestsAdaptiveGroups
imagesUniqueTransformations
imagesUniqueTransformationsAccumulatedSinceStartOfMonth
kvOperationsAdaptiveGroups
kvStorageAdaptiveGroups
liveInputEventsAdaptive
liveInputEventsAdaptiveGroups
logExplorerIngestionAdaptiveGroups
logpushHealthAdaptiveGroups
logpushTransformersAdaptiveGroups
magicEndpointHealthCheckAdaptiveGroups
magicFirewallNetworkAnalyticsAdaptiveGroups
magicFirewallRateLimitNetworkAnalyticsAdaptiveGroups
magicFirewallSamplesAdaptiveGroups
magicIDPSNetworkAnalyticsAdaptiveGroups
magicTransitNetworkAnalyticsAdaptiveGroups
magicTransitTunnelHealthCheckSLOsAdaptiveGroups
magicTransitTunnelHealthChecksAdaptiveGroups
magicTransitTunnelTrafficAdaptiveGroups
mconnTelemetryEventsAdaptiveGroups
mconnTelemetryEventsStagingAdaptiveGroups
mconnTelemetrySnapshotDhcpLeasesAdaptiveGroups
mconnTelemetrySnapshotDhcpLeasesStagingAdaptiveGroups
mconnTelemetrySnapshotDisksAdaptiveGroups
mconnTelemetrySnapshotDisksStagingAdaptiveGroups
mconnTelemetrySnapshotInterfaceAddressesAdaptiveGroups
mconnTelemetrySnapshotInterfaceAddressesStagingAdaptiveGroups
mconnTelemetrySnapshotInterfacesAdaptiveGroups
mconnTelemetrySnapshotInterfacesStagingAdaptiveGroups
mconnTelemetrySnapshotMountsAdaptiveGroups
mconnTelemetrySnapshotMountsStagingAdaptiveGroups
mconnTelemetrySnapshotNetdevsAdaptiveGroups
mconnTelemetrySnapshotNetdevsStagingAdaptiveGroups
mconnTelemetrySnapshotThermalsAdaptiveGroups
mconnTelemetrySnapshotThermalsStagingAdaptiveGroups
mconnTelemetrySnapshotTunnelsAdaptiveGroups
mconnTelemetrySnapshotTunnelsStagingAdaptiveGroups
mconnTelemetrySnapshotsAdaptiveGroups
mconnTelemetrySnapshotsStagingAdaptiveGroups
mediaUniqueTransformations
mediaUniqueTransformationsAccumulatedSinceStartOfMonth
mnmAWSVPCFlowDataAdaptiveGroups
mnmFlowDataAdaptiveGroups
nelReportsAdaptiveGroups
ohttpMetricsAdaptive
ohttpMetricsAdaptiveGroups
ohttpRelayEgressConnMetricsAdaptiveGroups
ohttpRelayIngressConnMetricsAdaptiveGroups
ohttpRelayRequestMetricsAdaptiveGroups
pageShieldReportsAdaptiveGroups
pagesFunctionsInvocationsAdaptiveGroups
pipelinesDeliveryAdaptiveGroups
pipelinesIngestionAdaptiveGroups
pipelinesOperatorAdaptiveGroups
pipelinesOperatorStagingAdaptiveGroups
pipelinesSinkAdaptiveGroups
pipelinesSinkStagingAdaptiveGroups
pipelinesUserErrorsAdaptive
pipelinesUserErrorsAdaptiveGroups
pipelinesUserErrorsStagingAdaptive
pipelinesUserErrorsStagingAdaptiveGroups
precursorEventsAdaptiveGroups
privacyProxyAuthMetricsAdaptiveGroups
privacyProxyEgressConnMetricsAdaptiveGroups
privacyProxyIngressConnMetricsAdaptiveGroups
privacyProxyRequestMetricsAdaptiveGroups
programmableFlowProtectionNetworkAnalyticsAdaptiveGroups
queueBacklogAdaptiveGroups
queueConsumerMetricsAdaptiveGroups
queueDelayedBacklogAdaptiveGroups
queueMessageOperationsAdaptiveGroups
r2CatalogDataOperationsAdaptiveGroups
r2CatalogTableMaintenanceAdaptiveGroups
r2OperationsAdaptiveGroups
r2StorageAdaptiveGroups
r2sqlOperationsAdaptiveGroups
realtimeKitUsageAdaptiveGroups
rumPageloadEventsAdaptiveGroups
rumPerformanceEventsAdaptiveGroups
rumWebVitalsEventsAdaptive
rumWebVitalsEventsAdaptiveGroups
shadowIt1hGroups
sinkholeRequestLogsAdaptive
sinkholeRequestLogsAdaptiveGroups
sippyOperationsAdaptiveGroups
spectrumNetworkAnalyticsAdaptiveGroups
storageTraces
streamCMCDAdaptiveGroups
streamMinutesViewedAdaptiveGroups
toMarkdownConversionAdaptive
toMarkdownConversionAdaptiveGroups
turnstileAdaptiveGroups
vectorizeQueriesAdaptiveGroups
vectorizeStorageAdaptiveGroups
vectorizeV2OperationsAdaptiveGroups
vectorizeV2QueriesAdaptiveGroups
vectorizeV2StorageAdaptiveGroups
vectorizeV2WritesAdaptiveGroups
videoBufferEventsAdaptiveGroups
videoPlaybackEventsAdaptiveGroups
videoQualityEventsAdaptiveGroups
warpDeviceAdaptiveGroups
webSearchRequestsAdaptiveGroups
workerPlacementAdaptiveGroups
workersAnalyticsEngineAdaptiveGroups
workersAssetsRequestsAdaptiveGroups
workersBuildsBuildMinutesAdaptiveGroups
workersCacheRequestsAdaptiveGroups
workersInvocationsAdaptive
workersInvocationsByOwnerAndScriptGroups
workersInvocationsScheduled
workersOverviewDataAdaptiveGroups
workersOverviewRequestsAdaptiveGroups
workersSubrequestsAdaptiveGroups
workersVpcConnectionAdaptiveGroups
workflowsAdaptive
workflowsAdaptiveGroups
zarazTrackAdaptiveGroups
zarazTriggersAdaptiveGroups
zeroTrustPrivateNetworkDiscoveryGroups

AccountShadowIt1hGroups

Shadow IT analytics - applications seen in Gateway HTTP traffic, 1 hour rollup (up to 90d window, 365d back)

FieldDescription
dimensions List of dimensions to group by
sum
uniq

AccountShadowIt1hGroupsDimensions

FieldDescription
applicationId Application ID
applicationStatus Application approval status
applicationTypeId Application type ID
country Source country code
datetime Hour start timestamp (hourly granularity)
deviceId Device ID. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
email User email address. Requires the #teams:pii (legacy) or com.cloudflare.team.gateway.pii.read (Bach) permission; otherwise returned as the literal "REDACTED"
httpHost HTTP hostname

AccountShadowIt1hGroupsSum

FieldDescription
bodyBytesRcvd Total body bytes received
bodyBytesSent Total body bytes sent
httpHostBytesRcvd Total bytes received per host
httpHostBytesSent Total bytes sent per host
requests Total HTTP requests

AccountShadowIt1hGroupsUniq

FieldDescription
applications Unique applications
users Unique users

AccountSinkholeRequestLogsAdaptive

Sinkhole Request Logs

FieldDescription
body The request body
datetime The date and time the event was recorded
destinationAddress The destination IP address of the request
headers The request headers. If a header has multiple values, the values are comma separated. Each header is newline separated.
host The host the request was sent to
method The request method
r2Path The path to the object within the R2 bucket linked to this sinkhole that stores overflow body and header data. Blank if neither headers nor body was larger than 256 bytes.
referrer The referrer of the request
sampleInterval ABR sample interval
sinkholeId The ID of the sinkhole that logged the request
sourceAddress The sender's IP address
uri The request uri
url The request url
userAgent The request user agent

AccountSinkholeRequestLogsAdaptiveGroups

Sinkhole Request Logs

FieldDescription
confidence ALPHA - DO NOT USE
count Number of requests logged
dimensions List of dimensions to group by

AccountSinkholeRequestLogsAdaptiveGroupsConfidence

FieldDescription
count Number of requests logged, with confidence intervals
level Confidence level that was requested

AccountSinkholeRequestLogsAdaptiveGroupsDimensions

FieldDescription
body The request body
date The date the event was recorded, truncated to the start of a day
datetime The date and time the event was recorded
datetimeFifteenMinutes The date and time the event was recorded truncated to fifteen minutes
datetimeFiveMinutes The date and time the event was recorded truncated to five minutes
datetimeHour The date and time the event was recorded truncated to the hour
datetimeMinute The date and time the event was recorded truncated to the minute
destinationAddress The destination IP address of the request
headers The request headers. If a header has multiple values, the values are comma separated. Each header is newline separated.
host The host the request was sent to
method The request method
r2Path The path to the object within the R2 bucket linked to this sinkhole that stores overflow body and header data. Blank if neither headers nor body was larger than 256 bytes.
referrer The referrer of the request
sinkholeId The ID of the sinkhole that logged the request
sourceAddress The sender's IP address
uri The request uri
url The request url
userAgent The request user agent

AccountSippyOperationsAdaptiveGroups

Sippy operations with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Total number of Sippy operations
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountSippyOperationsAdaptiveGroupsConfidence

FieldDescription
count Total number of Sippy operations, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountSippyOperationsAdaptiveGroupsDimensions

FieldDescription
action Operation's name
bucket Name of the R2 bucket
date Operation timestamp, truncated to start of a day
datetime Operation timestamp
datetimeFifteenMinutes Operation timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Operation timestamp, truncated to start of five minutes
datetimeHour Operation timestamp, truncated to start of an hour
datetimeMinute Operation timestamp, truncated to start of an minute
initiator Operation's initiator (eyeball / Sippy)
object Object key the operation was made for
size Number of bytes transferred as part of the operation
status Operation's response HTTP code
target Operation's target (upstream / R2)

AccountSippyOperationsAdaptiveGroupsSum

FieldDescription
size Total bytes transferred

AccountSippyOperationsAdaptiveGroupsSumConfidence

FieldDescription
size Confidence interval for the corresponding point estimate

AccountSpectrumNetworkAnalyticsAdaptiveGroups

Network analytics data for Spectrum traffic

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountSpectrumNetworkAnalyticsAdaptiveGroupsAvg

FieldDescription
bitRate Sum of bits received, divided by 1 second, providing a per-second bit rate when grouped by datetime
bitRateDay Sum of bits received, divided by 86400 seconds, providing a per-second bit rate when grouped by date
bitRateFifteenMinutes Sum of bits received, divided by 900 seconds, providing a per-second bit rate when grouped by datetimeFifteenMinutes
bitRateFiveMinutes Sum of bits received, divided by 300 seconds, providing a per-second bit rate when grouped by datetimeFiveMinutes
bitRateHour Sum of bits received, divided by 3600 seconds, providing a per-second bit rate when grouped by datetimeHour
bitRateMinute Sum of bits received, divided by 60 seconds, providing a per-second bit rate when grouped by datetimeMinute
bitRateTenSeconds Sum of bits received, divided by 10 seconds, providing a per-second bit rate when grouped by datetimeTenSeconds
packetRate Sum of packets received, divided by 1 second, providing a per-second packet rate when grouped by datetime
packetRateDay Sum of packets received, divided by 86400 seconds, providing a per-second packet rate when grouped by date
packetRateFifteenMinutes Sum of packets received, divided by 900 seconds, providing a per-second packet rate when grouped by datetimeFifteenMinutes
packetRateFiveMinutes Sum of packets received, divided by 300 seconds, providing a per-second packet rate when grouped by datetimeFiveMinutes
packetRateHour Sum of packets received, divided by 3600 seconds, providing a per-second packet rate when grouped by datetimeHour
packetRateMinute Sum of packets received, divided by 60 seconds, providing a per-second packet rate when grouped by datetimeMinute
packetRateTenSeconds Sum of packets received, divided by 10 seconds, providing a per-second packet rate when grouped by datetimeTenSeconds

AccountSpectrumNetworkAnalyticsAdaptiveGroupsAvgConfidence

FieldDescription
bitRate Confidence interval for the corresponding point estimate
bitRateDay Confidence interval for the corresponding point estimate
bitRateFifteenMinutes Confidence interval for the corresponding point estimate
bitRateFiveMinutes Confidence interval for the corresponding point estimate
bitRateHour Confidence interval for the corresponding point estimate
bitRateMinute Confidence interval for the corresponding point estimate
bitRateTenSeconds Confidence interval for the corresponding point estimate
packetRate Confidence interval for the corresponding point estimate
packetRateDay Confidence interval for the corresponding point estimate
packetRateFifteenMinutes Confidence interval for the corresponding point estimate
packetRateFiveMinutes Confidence interval for the corresponding point estimate
packetRateHour Confidence interval for the corresponding point estimate
packetRateMinute Confidence interval for the corresponding point estimate
packetRateTenSeconds Confidence interval for the corresponding point estimate

AccountSpectrumNetworkAnalyticsAdaptiveGroupsConfidence

FieldDescription
avg The average of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountSpectrumNetworkAnalyticsAdaptiveGroupsDimensions

FieldDescription
applicationTag Application tag associated with the packet
coloCity City where the Cloudflare datacenter that received the packet is located
coloCode Cloudflare datacenter that received the packet (nearest IATA airport code)
coloCountry Country where the Cloudflare datacenter that received the packet is located (ISO 3166-1 alpha-2)
coloGeohash Latitude and longitude where the Cloudflare datacenter that received the packet is located (Geohash encoding)
coloName Cloudflare datacenter that received the packet (unique site identifier)
date Date that the packet was received
datetime Date and time that the packet was received
datetimeFifteenMinutes Date and time that the packet was received, rounded to the start of the nearest fifteen minutes
datetimeFiveMinutes Date and time that the packet was received, rounded to the start of the nearest five minutes
datetimeHour Date and time that the packet was received, rounded to the start of the nearest hour
datetimeMinute Date and time that the packet was received, rounded to the start of the nearest minute
datetimeTenSeconds Date and time that the packet was received, rounded to the start of the nearest ten seconds
destinationAsn ASN associated with the destination IP of the packet, or 0 if there was no mapping available
destinationAsnName Name of ASN associated with the destination IP of the packet, if available
destinationCountry Country where the destination IP of the packet is located (ISO 3166-1 alpha-2)
destinationGeohash Latitude and longitude where the destination IP of the packet is located (Geohash encoding)
destinationPort Value of the Destination Port header field in the TCP or UDP packet
direction Direction of the packet relative to the customer network (possible values: inbound, outbound, lateral)
ethertype Value of the Ethertype header field in the Ethernet packet (2048 for IPv4; 34525 for IPv6)
greChecksum Value of the Checkusm header field in the GRE packet
greEthertype Value of the Ethertype header field in the GRE packet
greHeaderLength Length of the GRE packet header, in bytes
greKey Value of the Key header field in the GRE packet
greSequenceNumber Value of the Sequence Number header field in the GRE packet
greVersion Value of the Version header field in the GRE packet
icmpChecksum Value of the Checkusm header field in the ICMP packet
icmpCode Value of the Code header field in the ICMP packet
icmpType Value of the Type header field in the ICMP packet
ipDestinationAddress Value of the Destination Address header field in the IPv4 or IPv6 packet
ipDestinationSubnet Computed subnet of the Destination Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipFragmentOffset Value of the Fragment Offset header field in the IPv4 or IPv6 packet
ipHeaderLength Length of the IPv4 or IPv6 packet header, in bytes
ipMoreFragments Value of the More Fragments header field in the IPv4 or IPv6 packet
ipProtocol Value of the Protocol header field in the IPv4 or IPv6 packet
ipProtocolName Name of the protocol specified by the Protocol header field in the IPv4 or IPv6 packet
ipSourceAddress Value of the Source Address header field in the IPv4 or IPv6 packet
ipSourceSubnet Computed subnet of the Source Address header field in the IPv4 or IPv6 packet (/24 for IPv4; /48 for IPv6)
ipTotalLength Total length of the IPv4 or IPv6 packet, in bytes
ipTotalLengthBuckets Total length of the IPv4 or IPv6 packet, in bytes, with the last two digits truncated
ipTtl Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet
ipTtlBuckets Value of the TTL header field in the IPv4 packet or the Hop Limit header field in the IPv6 packet, with the last digit truncated
ipv4Checksum Value of the Checksum header field in the IPv4 packet
ipv4DontFragment Value of the Don't Fragment header field in the IPv4 packet
ipv4Dscp Value of the Differentiated Services Code Point header field in the IPv4 packet
ipv4Ecn Value of the Explicit Congestion Notification header field in the IPv4 packet
ipv4Identification Value of the Identification header field in the IPv4 packet
ipv4Options List of Options numbers included in the IPv4 packet header
ipv6Dscp Value of the Differentiated Services Code Point header field in the IPv6 packet
ipv6Ecn Value of the Explicit Congestion Notification header field in the IPv6 packet
ipv6ExtensionHeaders List of Extension Header numbers included in the IPv6 packet header
ipv6FlowLabel Value of the Flow Label header field in the IPv6 packet
ipv6Identification Value of the Identification extension header field in the IPv6 packet
leaseTag IP lease tag associated with the packet
mitigationSystem Which system dropped the packet (possible values: dosd, flowtrackd, magic-firewall)
outcome The action that was taken on the packet (possible values: pass, drop)
prefixTag IP prefix tag associated with the packet
sampleInterval ABR sample interval
sourceAsn ASN associated with the source IP of the packet, or 0 if there was no mapping available
sourceAsnName Name of ASN associated with the source IP of the packet, if available
sourceCountry Country where the source IP of the packet is located (ISO 3166-1 alpha-2)
sourceGeohash Latitude and longitude where the source IP of the packet is located (Geohash encoding)
sourcePort Value of the Source Port header field in the TCP or UDP packet
tcpAcknowledgementNumber Value of the Acknowledgement Number header field in the TCP packet
tcpChecksum Value of the Checkusm header field in the TCP packet
tcpDataOffset Value of the Data Offset header field in the TCP packet
tcpFlags Value of the Flags header field in the TCP packet
tcpFlagsString Human-readable string representation of the Flags header field in the TCP packet
tcpMss Value of the MSS option header field in the TCP packet
tcpOptions List of Options numbers included in the TCP packet header
tcpSackBlocks Value of the SACK Blocks option header field in the TCP packet
tcpSackPermitted Value of the SACK Permitted option header field in the TCP packet
tcpSequenceNumber Value of the Sequence Number header field in the TCP packet
tcpTimestampEcr Value of the Timestamp Echo Reply option header field in the TCP packet
tcpTimestampValue Value of the Timestamp option header field in the TCP packet
tcpUrgentPointer Value of the Urgent Pointer header field in the TCP packet
tcpWindowScale Value of the Window Scale option header field in the TCP packet
tcpWindowSize Value of the Window Size header field in the TCP packet
udpChecksum Value of the Checkusm header field in the UDP packet
udpPayloadLength Value of the Payload Length header field in the UDP packet

AccountSpectrumNetworkAnalyticsAdaptiveGroupsSum

FieldDescription
bits Sum of bits received
packets Sum of packets received

AccountSpectrumNetworkAnalyticsAdaptiveGroupsSumConfidence

FieldDescription
bits Confidence interval for the corresponding point estimate
packets Confidence interval for the corresponding point estimate

AccountStorageTraces

Storage Tracing Information

FieldDescription
containerId The container that this resource is stored under.
datetime Storage trace timestamp
resourceId The identifier to access this resource in the container.
serviceId The identifier of the storage service that houses the resourse.
traceId The ID that this trace entry is under.
userAccountId The AccountID of the user who owns the resource.

AccountStorageTracesOrderBy

FieldDescription

AccountStreamCMCDAdaptiveGroups

Stream CMCD data

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count The number of values for a metric per dimension
dimensions List of dimensions to group by
max The maximum value for a metric per dimension
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension
uniq The number of unique values for a metric per dimension

AccountStreamCMCDAdaptiveGroupsAvg

FieldDescription
bufferLength Average buffer length
bufferStarvationDuration Average buffer starvation duration in milliseconds
encodedBitrate Average encoded bitrate
initialBufferStarvationDuration Average buffer starvation duration at the start of viewing in milliseconds
measuredThroughput Average throughput

AccountStreamCMCDAdaptiveGroupsConfidence

FieldDescription
count The number of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountStreamCMCDAdaptiveGroupsDimensions

FieldDescription
bufferLength Buffer length of the requested object
bufferStarvation 1 if the buffer was starved between the last request and this request, 0 if not
bufferStarvationDuration Buffer starvation duration in milliseconds
contentId Content ID
country Viewer country
creatorId Creator ID
date Ingest event date, truncated to the start of a day
datetime Ingest event timestamp
datetimeFifteenMinutes The date and time of the ingest event truncated to fifteen minutes
datetimeFiveMinutes The date and time of the ingest event truncated to five minutes
datetimeHour The date and time of the ingest event truncated to the hour
datetimeMinute The date and time of the ingest event truncated to the minute
datetimeSixHours The date and time of the ingest event truncated to the start of the six hour window
encodedBitrate Encoded bitrate of the requested object
hlsType HLS type, hls if HLS, ll-hls if LL-HLS, otherwise blank
initialBufferStarvationDuration Initial buffer starvation duration in milliseconds
inputId Input ID
measuredThroughput Throughput between client and server
objectDuration Playback duration in ms of the requested object
playbackRate 1 if real-time, 2 if 2x speed, 0 if not playing
resolution Resolution
sessionId Session ID
startup 1 if request object is needed for startup, 0 if not
streamType l for live, v for video on demand (VOD)
streamingFormat h if HLS or LL-HLS, d if DASH
topBitrate Highest available bitrate rendition
videoId Video ID

AccountStreamCMCDAdaptiveGroupsMax

FieldDescription
latestDatetime Last time this dimension combination was seen

AccountStreamCMCDAdaptiveGroupsQuantiles

FieldDescription
bufferStarvationDurationP25 25th percentile buffer starvation duration in milliseconds
bufferStarvationDurationP50 50th percentile buffer starvation duration in milliseconds
bufferStarvationDurationP75 75th percentile buffer starvation duration in milliseconds
bufferStarvationDurationP90 90th percentile buffer starvation duration in milliseconds
bufferStarvationDurationP95 95th percentile buffer starvation duration in milliseconds
bufferStarvationDurationP99 99th percentile buffer starvation duration in milliseconds
bufferStarvationDurationP999 99.9th percentile buffer starvation duration in milliseconds
initialBufferStarvationDurationP25 25th percentile initial buffer starvation duration in milliseconds
initialBufferStarvationDurationP50 50th percentile initial buffer starvation duration in milliseconds
initialBufferStarvationDurationP75 75th percentile initial buffer starvation duration in milliseconds
initialBufferStarvationDurationP90 90th percentile initial buffer starvation duration in milliseconds
initialBufferStarvationDurationP95 95th percentile initial buffer starvation duration in milliseconds
initialBufferStarvationDurationP99 99th percentile initial buffer starvation duration in milliseconds
initialBufferStarvationDurationP999 99.9th percentile initial buffer starvation duration in milliseconds

AccountStreamCMCDAdaptiveGroupsSum

FieldDescription
millisecondsViewed Estimated time viewed in milliseconds

AccountStreamCMCDAdaptiveGroupsSumConfidence

FieldDescription
millisecondsViewed Confidence interval for the corresponding point estimate

AccountStreamCMCDAdaptiveGroupsUniq

FieldDescription
viewers The number of unique viewers

AccountStreamMinutesViewedAdaptiveGroups

A high-level summary of Cloudflare Stream minutes viewed.

FieldDescription
confidence ALPHA - DO NOT USE
count The number of values for a metric per dimension
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountStreamMinutesViewedAdaptiveGroupsConfidence

FieldDescription
count The number of values for a metric per dimension, with confidence intervals
level Confidence level that was requested

AccountStreamMinutesViewedAdaptiveGroupsDimensions

FieldDescription
clientCountryName ISO 3166 alpha2 country code from the client
creator Customer-provided creator ID of a video
date The date the event occurred at the edge
datetime The date and time the event occurred at the edge
datetimeFifteenMinutes The date and time the event occurred at the edge truncated to a multiple of 15 minutes
datetimeFiveMinutes The date and time the event occurred at the edge truncated to a multiple of 5 minutes
datetimeHour The date and time the event occurred at the edge truncated to hours
datetimeMinute The date and time the event occurred at the edge truncated to the minute
mediaType The source of the minutes viewed
uid Unique ID of a video

AccountStreamMinutesViewedAdaptiveGroupsSum

FieldDescription
minutesViewed

AccountToMarkdownConversionAdaptive

Markdown Conversion Metrics

FieldDescription
conversionId The ID of this conversion, as a ULID
date The date when trigger was triggered
datetimeFifteenMinutes The date and time truncated to fifteen minutes
datetimeFiveMinutes The date and time truncated to five minutes
datetimeHour The date and time truncated to the hour
datetimeMinute The date and time truncated to the minute
durationMs The duration in milliseconds it took to convert this file
errorReason The reason this conversion might have errored. Empty if the conversion is successful
fileName The name of the file under conversion
fileSize The size of the file being converted in bytes
mimeType The MIME Type of the file under conversion
options Conversion options used on the request that originated this conversion
outputSize The size of the markdown content after conversion, in bytes
parentConversion The original file conversion that originated this one. Empty if this is a 'root' conversion
requestId The ID of this request that originated this conversion, as a ULID
result Whether this conversion was successful or not. Values can be 'markdown' for success or 'error' for errors
service The service that originated this conversion request
source Whether this conversion request was done via the binding method or via an API request

AccountToMarkdownConversionAdaptiveGroups

Markdown Conversion Metrics

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
count Total number of conversions for an account
dimensions List of dimensions to group by
max The max of values for a metric per dimension
min The min of values for a metric per dimension

AccountToMarkdownConversionAdaptiveGroupsAvg

FieldDescription
completed Average of output size
durationMs Average of conversion duration
fileSize Average of file sizes

AccountToMarkdownConversionAdaptiveGroupsConfidence

FieldDescription
count Total number of conversions for an account, with confidence intervals
level Confidence level that was requested

AccountToMarkdownConversionAdaptiveGroupsDimensions

FieldDescription
conversionId The ID of this conversion, as a ULID
date The date when trigger was triggered
datetime The date and time the conversion event occurred
datetimeFifteenMinutes The date and time truncated to fifteen minutes
datetimeFiveMinutes The date and time truncated to five minutes
datetimeHour The date and time truncated to the hour
datetimeMinute The date and time truncated to the minute
durationMs The duration in milliseconds it took to convert this file
errorReason The reason this conversion might have errored. Empty if the conversion is successful
fileName The name of the file under conversion
fileSize The size of the file being converted in bytes
mimeType The MIME Type of the file under conversion
options Conversion options used on the request that originated this conversion
outputSize The size of the markdown content after conversion, in bytes
parentConversion The original file conversion that originated this one. Empty if this is a 'root' conversion
requestId The ID of this request that originated this conversion, as a ULID
result Whether this conversion was successful or not. Values can be 'markdown' for success or 'error' for errors
service The service that originated this conversion request
source Whether this conversion request was done via the binding method or via an API request

AccountToMarkdownConversionAdaptiveGroupsMax

FieldDescription
completed Max of output size
durationMs Max of conversion duration
fileSize Max of file sizes

AccountToMarkdownConversionAdaptiveGroupsMin

FieldDescription
completed Min of output size
durationMs Min of conversion duration
fileSize Min of file sizes

AccountTurnstileAdaptiveGroups

Beta. Cloudflare Turnstile aggregated events with adaptive sampling

FieldDescription
avg
confidence ALPHA - DO NOT USE
count Number of Cloudflare Turnstile events processed
dimensions List of dimensions to group by

AccountTurnstileAdaptiveGroupsAvg

FieldDescription
sampleInterval Average sample interval

AccountTurnstileAdaptiveGroupsConfidence

FieldDescription
count Number of Cloudflare Turnstile events processed, with confidence intervals
level Confidence level that was requested

AccountTurnstileAdaptiveGroupsDimensions

FieldDescription
action The action tag tied to that challenge event
asn ASN tied to that Turnstile event
browserMajor Major version of the browser tied to that Turnstile event
browserName Browser name tied to that Turnstile event
countryCode 2 character country code tied to that Turnstile event
date The date the challenge event was emitted
datetime The date and time the challenge event was emitted
datetimeDay The date and time the challenge event was emitted truncated to the day
datetimeFifteenMinutes The date and time the challenge event was emitted truncated to a multiple of 15 minutes
datetimeFiveMinutes The date and time the challenge event was emitted truncated to a multiple of 5 minutes
datetimeHalfOfHour The date and time the challenge event was emitted truncated to a multiple of 30 minutes
datetimeHour The date and time the challenge event was emitted truncated to the hour
datetimeMinute The date and time the challenge event was emitted truncated to the minute
eventType The type of the Cloudflare Turnstile event
hostname Hostname tied to that Turnstile event
ipv4 IPv4 tied to that Turnstile event
ipv6 IPv6 tied to that Turnstile event
osMajor Major version of the OS tied to that Turnstile event
osName OS name tied to that Turnstile event
siteKey The sitekey of the widget associated with the event
userAgent User agent tied to that Turnstile event

AccountVectorizeQueriesAdaptiveGroups

Beta. Vectorize usage with adaptive sampling

FieldDescription
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountVectorizeQueriesAdaptiveGroupsDimensions

FieldDescription
date Vectorize storage sample timestamp
datetime Vectorize storage sample timestamp
datetimeFifteenMinutes Vectorize storage sample timestamp, truncated to fifteen minutes
datetimeFiveMinutes Vectorize storage sample timestamp, truncated to five minutes
datetimeHour Vectorize storage sample timestamp, truncated to the hour
datetimeMinute Vectorize storage sample timestamp, truncated to the minute
vectorizeIndexId Identifier for a Vectorize index

AccountVectorizeQueriesAdaptiveGroupsSum

FieldDescription
queriedVectorDimensions The number of queried vector dimensions in Vectorize over the queried time period.

AccountVectorizeStorageAdaptiveGroups

Beta. Vectorize storage with adaptive sampling

FieldDescription
dimensions List of dimensions to group by
max The max of values for a metric per dimension

AccountVectorizeStorageAdaptiveGroupsDimensions

FieldDescription
date Vectorize storage sample timestamp
datetime Vectorize storage sample timestamp
datetimeFifteenMinutes Vectorize storage sample timestamp, truncated to fifteen minutes
datetimeFiveMinutes Vectorize storage sample timestamp, truncated to five minutes
datetimeHour Vectorize storage sample timestamp, truncated to the hour
datetimeMinute Vectorize storage sample timestamp, truncated to the minute
vectorizeIndexId Identifier for a Vectorize index

AccountVectorizeStorageAdaptiveGroupsMax

FieldDescription
storedVectorDimensions The maximum number of stored vector dimensions in Vectorize over the queried time period.

AccountVectorizeV2OperationsAdaptiveGroups

Vectorize operations with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Total number of Vectorize operations
dimensions List of dimensions to group by

AccountVectorizeV2OperationsAdaptiveGroupsConfidence

FieldDescription
count Total number of Vectorize operations, with confidence intervals
level Confidence level that was requested

AccountVectorizeV2OperationsAdaptiveGroupsDimensions

FieldDescription
date Vectorize operation event timestamp, truncated to start of a day
datetime Vectorize operation event timestamp
datetimeFifteenMinutes Vectorize operation event timestamp, truncated to fifteen minutes
datetimeFiveMinutes Vectorize operation event timestamp, truncated to five minutes
datetimeHour Vectorize operation event timestamp, truncated to start of hour
datetimeMinute Vectorize operation event timestamp, truncated to start of minute
indexName Name of a Vectorize index
operation The type of Vectorize operation
requestStatus Request status. One of [2xx, 4xx, 5xx, unknown]

AccountVectorizeV2QueriesAdaptiveGroups

Vectorize queries with adaptive sampling

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count Total number of Vectorize queries
dimensions List of dimensions to group by
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension

AccountVectorizeV2QueriesAdaptiveGroupsAvg

FieldDescription
requestDurationMs Average latency (in milliseconds) of serving a Vectorize query

AccountVectorizeV2QueriesAdaptiveGroupsConfidence

FieldDescription
count Total number of Vectorize queries, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountVectorizeV2QueriesAdaptiveGroupsDimensions

FieldDescription
date Vectorize queries event timestamp, truncated to start of a day
datetime Vectorize queries event timestamp
datetimeHour Vectorize queries event timestamp, truncated to start of hour
datetimeMinute Vectorize queries event timestamp, truncated to start of minute
indexName Name of a Vectorize index
operation The type of Vectorize operation
requestStatus Request status. One of [2xx, 4xx, 5xx, unknown]

AccountVectorizeV2QueriesAdaptiveGroupsQuantiles

FieldDescription
requestDurationMsP25 25th percentile latency (milliseconds)
requestDurationMsP50 50th percentile latency (milliseconds)
requestDurationMsP75 75th percentile latency (milliseconds)
requestDurationMsP90 90th percentile latency (milliseconds)
requestDurationMsP95 95th percentile latency (milliseconds)
requestDurationMsP99 99th percentile latency (milliseconds)
requestDurationMsP999 99.9th percentile latency (milliseconds)

AccountVectorizeV2QueriesAdaptiveGroupsSum

FieldDescription
queriedVectorDimensions The number of queried vector dimensions in Vectorize over the queried time period. This metric must always be fetched along with the 'indexName' and 'datetime' dimensions, as well as a 'requestStatus:2xx' filter to estimate billable usage.
requestDurationMs Total latency (in milliseconds) of serving Vectorize queries over the queried time period
servedVectorCount The number of vectors served in Vectorize queries over the queried time period.

AccountVectorizeV2QueriesAdaptiveGroupsSumConfidence

FieldDescription
requestDurationMs Confidence interval for the corresponding point estimate
servedVectorCount Confidence interval for the corresponding point estimate

AccountVectorizeV2StorageAdaptiveGroups

Vectorize storage with adaptive sampling

FieldDescription
dimensions List of dimensions to group by
max The max of values for a metric per dimension

AccountVectorizeV2StorageAdaptiveGroupsDimensions

FieldDescription
date Vectorize storage event timestamp, truncated to start of a day
datetime Vectorize storage event timestamp
datetimeHour Vectorize storage event timestamp, truncated to start of hour
datetimeMinute Vectorize storage event timestamp, truncated to start of minute
indexName Name of a Vectorize index

AccountVectorizeV2StorageAdaptiveGroupsMax

FieldDescription
storedVectorDimensions The maximum number of stored vector dimensions in Vectorize over the queried time period.
vectorCount The maximum number of stored vectors in Vectorize over the queried time period.

AccountVectorizeV2WritesAdaptiveGroups

Vectorize writes with adaptive sampling

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count Total number of Vectorize writes
dimensions List of dimensions to group by
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension

AccountVectorizeV2WritesAdaptiveGroupsAvg

FieldDescription
requestDurationMs Average latency (in milliseconds) of serving a Vectorize write

AccountVectorizeV2WritesAdaptiveGroupsConfidence

FieldDescription
count Total number of Vectorize writes, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountVectorizeV2WritesAdaptiveGroupsDimensions

FieldDescription
date Vectorize write event timestamp, truncated to start of a day
datetime Vectorize write event timestamp
datetimeHour Vectorize write event timestamp, truncated to start of hour
datetimeMinute Vectorize write event timestamp, truncated to start of minute
indexName Name of a Vectorize index
operation The type of Vectorize operation
requestStatus Request status. One of [2xx, 4xx, 5xx, unknown]

AccountVectorizeV2WritesAdaptiveGroupsQuantiles

FieldDescription
requestDurationMsP25 25th percentile latency (milliseconds)
requestDurationMsP50 50th percentile latency (milliseconds)
requestDurationMsP75 75th percentile latency (milliseconds)
requestDurationMsP90 90th percentile latency (milliseconds)
requestDurationMsP95 95th percentile latency (milliseconds)
requestDurationMsP99 99th percentile latency (milliseconds)
requestDurationMsP999 99.9th percentile latency (milliseconds)

AccountVectorizeV2WritesAdaptiveGroupsSum

FieldDescription
addedVectorCount The number of vectors added in Vectorize writes over the queried time period.
deletedVectorCount The number of vectors deleted in Vectorize writes over the queried time period.
requestDurationMs Total latency (in milliseconds) of serving Vectorize writes over the queried time period

AccountVectorizeV2WritesAdaptiveGroupsSumConfidence

FieldDescription
addedVectorCount Confidence interval for the corresponding point estimate
deletedVectorCount Confidence interval for the corresponding point estimate
requestDurationMs Confidence interval for the corresponding point estimate

AccountVideoBufferEventsAdaptiveGroups

Beta. Aggregated video streaming buffer event metrics with adaptive sampling

FieldDescription
avg
confidence ALPHA - DO NOT USE
count Total number of buffer events
dimensions List of dimensions to group by

AccountVideoBufferEventsAdaptiveGroupsAvg

FieldDescription
sampleInterval Average sample interval

AccountVideoBufferEventsAdaptiveGroupsConfidence

FieldDescription
count Total number of buffer events, with confidence intervals
level Confidence level that was requested

AccountVideoBufferEventsAdaptiveGroupsDimensions

FieldDescription
clientCountryName ISO 3166 alpha2 country code from the client
date Request date of the event
datetime Request datetime of the event
datetimeFifteenMinutes Request datetime of the event, truncated to multiple of 15 minutes
datetimeFiveMinutes Request datetime of the event, truncated to multiple of 5 minutes
datetimeHalfOfHour Request datetime of the event, truncated to multiple of 30 minutes
datetimeHour Request datetime of the event, truncated to the hour
datetimeMinute Request datetime of the event, truncated to the minute
deviceBrowser Browser of the device used in playback
deviceOs OS of the device used in playback
deviceType Device type used in playback
uid unique id for a video

AccountVideoPlaybackEventsAdaptiveGroups

Beta. Aggregated video streaming playback event metrics with adaptive sampling

FieldDescription
avg
confidence ALPHA - DO NOT USE
count Total number of playback starts
dimensions List of dimensions to group by
sum

AccountVideoPlaybackEventsAdaptiveGroupsAvg

FieldDescription
sampleInterval Average sample interval

AccountVideoPlaybackEventsAdaptiveGroupsConfidence

FieldDescription
count Total number of playback starts, with confidence intervals
level Confidence level that was requested
sum

AccountVideoPlaybackEventsAdaptiveGroupsDimensions

FieldDescription
clientCountryName ISO 3166 alpha2 country code from the client
date Request date of the event
datetime Request datetime of the event
datetimeFifteenMinutes Request datetime of the event, truncated to multiple of 15 minutes
datetimeFiveMinutes Request datetime of the event, truncated to multiple of 5 minutes
datetimeHalfOfHour Request datetime of the event, truncated to multiple of 30 minutes
datetimeHour Request datetime of the event, truncated to the hour
datetimeMinute Request datetime of the event, truncated to the minute
deviceBrowser Browser of the device used in playback
deviceOs OS of the device used in playback
deviceType Device type used in playback
uid unique id for a video

AccountVideoPlaybackEventsAdaptiveGroupsSum

FieldDescription
timeViewedMinutes Total time viewed in minutes

AccountVideoPlaybackEventsAdaptiveGroupsSumConfidence

FieldDescription
timeViewedMinutes Confidence interval for the corresponding point estimate

AccountVideoQualityEventsAdaptiveGroups

Beta. Aggregated video streaming quality change event metrics with adaptive sampling

FieldDescription
avg
confidence ALPHA - DO NOT USE
count Total number of quality change events
dimensions List of dimensions to group by

AccountVideoQualityEventsAdaptiveGroupsAvg

FieldDescription
sampleInterval Average sample interval

AccountVideoQualityEventsAdaptiveGroupsConfidence

FieldDescription
count Total number of quality change events, with confidence intervals
level Confidence level that was requested

AccountVideoQualityEventsAdaptiveGroupsDimensions

FieldDescription
clientCountryName ISO 3166 alpha2 country code from the client
date Request date of the event
datetime Request datetime of the event
datetimeFifteenMinutes Request datetime of the event, truncated to multiple of 15 minutes
datetimeFiveMinutes Request datetime of the event, truncated to multiple of 5 minutes
datetimeHalfOfHour Request datetime of the event, truncated to multiple of 30 minutes
datetimeHour Request datetime of the event, truncated to the hour
datetimeMinute Request datetime of the event, truncated to the minute
deviceBrowser Browser of the device used in playback
deviceOs OS of the device used in playback
deviceType Device type used in playback
qualityResolution Video playback vertical resolution
uid unique id for a video

AccountWarpDeviceAdaptiveGroups

Beta. Warp device health events with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count Number of device health events, which usually occur at 2m intervals per device
dimensions List of dimensions to group by
uniq

AccountWarpDeviceAdaptiveGroupsConfidence

FieldDescription
count Number of device health events, which usually occur at 2m intervals per device, with confidence intervals
level Confidence level that was requested

AccountWarpDeviceAdaptiveGroupsDimensions

FieldDescription
clientPlatform Device's OS
clientVersion Device's Warp version
colo Device's connected colo
date The date of the device log
datetime The date and time of the device log
datetimeFifteenMinutes The date and time of the device log truncated to fifteen minutes
datetimeFiveMinute The date and time of the device log truncated to every five minutes
datetimeFiveMinutes The date and time of the device log truncated to five minutes
datetimeHour The date and time of the device log truncated to the hour
datetimeMinute The date and time of the device log truncated to the minute
datetimeTenMinute The date and time of the device log truncated to every ten minutes
deviceId Device ID
mode Device's Warp mode
status Device connection status

AccountWarpDeviceAdaptiveGroupsUniq

FieldDescription
deviceIds Approximate count of unique deviceIds

AccountWebSearchRequestsAdaptiveGroups

Web Search Requests Analytics

FieldDescription
avg The average of values for a metric per dimension
confidence ALPHA - DO NOT USE
count Total number of web search request events
dimensions List of dimensions to group by
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension

AccountWebSearchRequestsAdaptiveGroupsAvg

FieldDescription
requestedCount Average number of results requested
sampleInterval Average sample interval
totalDurationMs Average request duration in milliseconds

AccountWebSearchRequestsAdaptiveGroupsConfidence

FieldDescription
count Total number of web search request events, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountWebSearchRequestsAdaptiveGroupsDimensions

FieldDescription
billable Whether the request is billable (0 = false, 1 = true)
clientCountry The country of the client that made the request
date The date of the web search request
datetime The date and time the event occurred
datetimeFifteenMinutes The date and time truncated to fifteen minutes
datetimeFiveMinutes The date and time truncated to five minutes
datetimeHour The date and time truncated to the hour
datetimeMinute The date and time truncated to the minute
errorCode The error code returned, if any
errorStage The stage at which an error occurred, if any
query The verbatim search query (truncated to 1024 characters)
queryHash The SHA-256 hex hash of the search query
queryLength The length of the search query in characters
region The region the request was served from
requestId The unique identifier for the web search request
requestedCount The number of results requested
result The high-level outcome of the request
source The source of the request
totalDurationMs The total duration of the request in milliseconds
userAgent The user agent string of the inbound request

AccountWebSearchRequestsAdaptiveGroupsQuantiles

FieldDescription
totalDurationMsP25 Request duration in milliseconds (25th percentile)
totalDurationMsP50 Request duration in milliseconds (50th percentile)
totalDurationMsP75 Request duration in milliseconds (75th percentile)
totalDurationMsP90 Request duration in milliseconds (90th percentile)
totalDurationMsP95 Request duration in milliseconds (95th percentile)
totalDurationMsP99 Request duration in milliseconds (99th percentile)
totalDurationMsP999 Request duration in milliseconds (99.9th percentile)

AccountWebSearchRequestsAdaptiveGroupsSum

FieldDescription
billableCount Total number of billable requests
queryLength Total query length in characters
requestedCount Total number of results requested
totalDurationMs Total request duration in milliseconds

AccountWebSearchRequestsAdaptiveGroupsSumConfidence

FieldDescription
billableCount Confidence interval for the corresponding point estimate
queryLength Confidence interval for the corresponding point estimate
requestedCount Confidence interval for the corresponding point estimate
totalDurationMs Confidence interval for the corresponding point estimate

AccountWorkerPlacementAdaptiveGroups

Worker placement metrics

FieldDescription
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension

AccountWorkerPlacementAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountWorkerPlacementAdaptiveGroupsDimensions

FieldDescription
clientColoCode IATA airport code for the Cloudflare datacenter where the request entered Cloudflare's network.
coloCode IATA airport code for the Cloudflare datacenter where the script ran.
date Request timestamp, truncated to start of a day
datetime Request timestamp
datetimeFifteenMinutes Request timestamp, truncated to fifteen minutes
datetimeFiveMinutes Request timestamp, truncated to five minutes
datetimeHour Request timestamp, truncated to start of an hour
datetimeMinute Request timestamp, truncated to start of an minute
datetimeSixHours Request timestamp, truncated to start of six hour window
httpStatus Response status of worker
isSample 1 if the request was sampled to bypass Smart Placement, 0 if it was processed using Smart Placement
placementUsed 1 if the request was processed using Smart Placement, 0 if it was processed in default mode
requestDurationBucketMin Bucket of request duration rounded down to nearest 10*2^n
requestDurationBucketMin100ms Bucket of request duration rounded down to nearest 100ms
scriptName The script name
scriptTag The unique tag of the script
scriptVersion The script version

AccountWorkerPlacementAdaptiveGroupsQuantiles

FieldDescription
requestDurationP25 Request duration 25th percentile - milliseconds
requestDurationP50 Request duration 50th percentile - milliseconds
requestDurationP75 Request duration 75th percentile - milliseconds
requestDurationP90 Request duration 90th percentile - milliseconds
requestDurationP95 Request duration 95th percentile - milliseconds
requestDurationP99 Request duration 99th percentile - milliseconds
requestDurationP999 Request duration 99.9th percentile - milliseconds

AccountWorkerPlacementAdaptiveGroupsSum

FieldDescription
requestDuration Sum of duration ms of requests measured at the data centers that receive the requests
requests Total number of requests

AccountWorkerPlacementAdaptiveGroupsSumConfidence

FieldDescription
requestDuration Confidence interval for the corresponding point estimate
requests Confidence interval for the corresponding point estimate

AccountWorkersAnalyticsEngineAdaptiveGroups

Beta. Custom Events with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count The number of values for a metric per dimension
dimensions List of dimensions to group by

AccountWorkersAnalyticsEngineAdaptiveGroupsConfidence

FieldDescription
count The number of values for a metric per dimension, with confidence intervals
level Confidence level that was requested

AccountWorkersAnalyticsEngineAdaptiveGroupsDimensions

FieldDescription
dataset The dataset name
date The date the event occurred
datetime The date and time the event occurred
datetimeFifteenMinutes The date and time the event occurred truncated to a multiple of 15 minutes
datetimeFiveMinutes The date and time the event occurred truncated to a multiple of 5 minutes
datetimeHour The date and time the event occurred truncated to the start of an hour
datetimeMinute The date and time the event occurred truncated to the start of a minute

AccountWorkersAssetsRequestsAdaptiveGroups

Workers Assets requests with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountWorkersAssetsRequestsAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountWorkersAssetsRequestsAdaptiveGroupsDimensions

FieldDescription
cacheStatus The cache status for the asset request
coloCode IATA airport code for the Cloudflare datacenter that served the asset request
date Asset request timestamp, truncated to start of a day
datetime Asset request timestamp
datetimeFifteenMinutes Asset request timestamp, truncated to fifteen minutes
datetimeFiveMinutes Asset request timestamp, truncated to five minutes
datetimeHour Asset request timestamp, truncated to start of an hour
datetimeMinute Asset request timestamp, truncated to start of a minute
datetimeSixHours Asset request timestamp, truncated to start of six hour window
hostname The request hostname
statusCode HTTP response status code

AccountWorkersAssetsRequestsAdaptiveGroupsSum

FieldDescription
requests Total number of asset requests

AccountWorkersAssetsRequestsAdaptiveGroupsSumConfidence

FieldDescription
requests Confidence interval for the corresponding point estimate

AccountWorkersBuildsBuildMinutesAdaptiveGroups

Workers Builds build minute overview data with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountWorkersBuildsBuildMinutesAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountWorkersBuildsBuildMinutesAdaptiveGroupsDimensions

FieldDescription
date Build minutes recorded date, truncated to start of a day
datetime Build minutes recorded timestamp
datetimeFifteenMinutes Build minutes recorded timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Build minutes recorded timestamp, truncated to start of five minutes
datetimeHour Build minutes recorded timestamp, truncated to start of an hour
datetimeMinute Build minutes recorded timestamp, truncated to start of a minute

AccountWorkersBuildsBuildMinutesAdaptiveGroupsSum

FieldDescription
buildMinutes The sum of build minutes

AccountWorkersBuildsBuildMinutesAdaptiveGroupsSumConfidence

FieldDescription
buildMinutes Confidence interval for the corresponding point estimate

AccountWorkersCacheRequestsAdaptiveGroups

Beta. Cache-enabled Workers request events with adaptive sampling

FieldDescription
avg The average value used for sample interval
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountWorkersCacheRequestsAdaptiveGroupsAvg

FieldDescription
sampleInterval

AccountWorkersCacheRequestsAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountWorkersCacheRequestsAdaptiveGroupsDimensions

FieldDescription
cacheStatus Cache status for the cache-side Worker request event
coloCode IATA airport code for the Cloudflare datacenter where the request was handled.
date Request datetime, truncated to start of a day
datetime Request datetime
datetimeFifteenMinutes The date and time of the event truncated to fifteen minutes
datetimeFiveMinutes The date and time of the event truncated to five minutes
datetimeHour Request datetime, truncated to start of an hour
datetimeMinute Request datetime, truncated to start of a minute
datetimeSixHours Request datetime, truncated to start of six hour window
dispatchNamespaceName The name of the script's dispatch namespace
environmentName The name of the script environment
isDispatcher Whether the request is from a Dispatch Worker. Non-zero if true
isPreview Whether this request is for a preview. 1 if preview, 0 if not.
previewSlug The name (slug) of the preview script
scriptName The name of the script
scriptTag The unique tag of the script
scriptVersion The version of the Worker
status Status of the worker request event
usageModel Usage model of the worker request

AccountWorkersCacheRequestsAdaptiveGroupsSum

FieldDescription
requests Sum of cache-side requests

AccountWorkersCacheRequestsAdaptiveGroupsSumConfidence

FieldDescription
requests Confidence interval for the corresponding point estimate

AccountWorkersInvocationsAdaptive

Beta. Workers invocations with adaptive sampling

FieldDescription
avg The average value used for sample interval
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
max The max value for a metric
min The min value for a metric
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension

AccountWorkersInvocationsAdaptiveAvg

FieldDescription
sampleInterval

AccountWorkersInvocationsAdaptiveConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountWorkersInvocationsAdaptiveDimensions

FieldDescription
cacheStatus Cache status for cache-enabled Worker invocation, if applicable
coloCode IATA airport code for the Cloudflare datacenter where the script ran.
date Request datetime, truncated to start of a day
datetime Request datetime
datetimeFifteenMinutes The date and time of the event truncated to fifteen minutes
datetimeFiveMinutes The date and time of the event truncated to five minutes
datetimeHour Request datetime, truncated to start of an hour
datetimeMinute Request datetime, truncated to start of an minute
datetimeSixHours Request datetime, truncated to start of six hour window
dispatchNamespaceName The name of the script's dispatch namespace
environmentName The name of the script environment
isDispatcher Whether the request is from a Dispatch Worker. Non-zero if true
isPreview Whether this invocation is for a preview. 1 if preview, 0 if not.
previewSlug The name (slug) of the preview script
scriptName The name of the script
scriptTag The unique tag of the script
scriptVersion The version of the Worker
status Status of the worker invocation
usageModel Usage model of the worker invocation

AccountWorkersInvocationsAdaptiveMax

FieldDescription
cpuTime Maximum CPU time for one request - microseconds
duration Maximum duration of one request - GB*s
memoryUsageBytes Maximum V8 isolate memory usage across Worker invocations - bytes
requestDuration Maximum Request Duration in microseconds
responseBodySize Maximum response body size for one request - bytes
wallTime Maximum wall time for one request - microseconds
wasmMemoryBytes Maximum WebAssembly linear memory usage across Worker invocations - bytes

AccountWorkersInvocationsAdaptiveMin

FieldDescription
cpuTime Minimum CPU time for one request - microseconds
duration Minimum duration of one request - GB*s
requestDuration Minimum Request Duration in microseconds
responseBodySize Minimum response body size for one request - bytes
wallTime Minimum wall time for one request - microseconds

AccountWorkersInvocationsAdaptiveQuantiles

FieldDescription
cpuTimeP25 CPU time 25th percentile - microseconds
cpuTimeP50 CPU time 50th percentile - microseconds
cpuTimeP75 CPU time 75th percentile - microseconds
cpuTimeP90 CPU time 90th percentile - microseconds
cpuTimeP95 CPU time 95th percentile - microseconds
cpuTimeP99 CPU time 99th percentile - microseconds
cpuTimeP999 CPU time 99.9th percentile - microseconds
durationP25 Duration 25th percentile - GB*s
durationP50 Duration 50th percentile - GB*s
durationP75 Duration 75th percentile - GB*s
durationP90 Duration 90th percentile - GB*s
durationP95 Duration 95th percentile - GB*s
durationP99 Duration 99th percentile - GB*s
durationP999 Duration 99.9th percentile - GB*s
memoryUsageBytesP25 V8 isolate memory usage 25th percentile across Worker invocations - bytes
memoryUsageBytesP50 V8 isolate memory usage 50th percentile across Worker invocations - bytes
memoryUsageBytesP75 V8 isolate memory usage 75th percentile across Worker invocations - bytes
memoryUsageBytesP90 V8 isolate memory usage 90th percentile across Worker invocations - bytes
memoryUsageBytesP95 V8 isolate memory usage 95th percentile across Worker invocations - bytes
memoryUsageBytesP99 V8 isolate memory usage 99th percentile across Worker invocations - bytes
memoryUsageBytesP999 V8 isolate memory usage 99.9th percentile across Worker invocations - bytes
requestDurationP25 Request duration 25th percentile - microseconds
requestDurationP50 Request duration 50th percentile - microseconds
requestDurationP75 Request duration 75th percentile - microseconds
requestDurationP90 Request duration 90th percentile - microseconds
requestDurationP95 Request duration 95th percentile - microseconds
requestDurationP99 Request duration 99th percentile - microseconds
requestDurationP999 Request duration 99.9th percentile - microseconds
responseBodySizeP25 Response body size 25th percentile - bytes
responseBodySizeP50 Response body size 50th percentile - bytes
responseBodySizeP75 Response body size 75th percentile - bytes
responseBodySizeP90 Response body size 90th percentile - bytes
responseBodySizeP95 Response body size 95th percentile - bytes
responseBodySizeP99 Response body size 99th percentile - bytes
responseBodySizeP999 Response body size 99.9th percentile - bytes
wallTimeP25 Wall time 25th percentile - microseconds
wallTimeP50 Wall time 50th percentile - microseconds
wallTimeP75 Wall time 75th percentile - microseconds
wallTimeP90 Wall time 90th percentile - microseconds
wallTimeP95 Wall time 95th percentile - microseconds
wallTimeP99 Wall time 99th percentile - microseconds
wallTimeP999 Wall time 99.9th percentile - microseconds
wasmMemoryBytesP25 WebAssembly linear memory usage 25th percentile across Worker invocations - bytes
wasmMemoryBytesP50 WebAssembly linear memory usage 50th percentile across Worker invocations - bytes
wasmMemoryBytesP75 WebAssembly linear memory usage 75th percentile across Worker invocations - bytes
wasmMemoryBytesP90 WebAssembly linear memory usage 90th percentile across Worker invocations - bytes
wasmMemoryBytesP95 WebAssembly linear memory usage 95th percentile across Worker invocations - bytes
wasmMemoryBytesP99 WebAssembly linear memory usage 99th percentile across Worker invocations - bytes
wasmMemoryBytesP999 WebAssembly linear memory usage 99.9th percentile across Worker invocations - bytes

AccountWorkersInvocationsAdaptiveSum

FieldDescription
clientDisconnects Sum of client disconnects
cpuTimeUs Sum of cpu time in us
duration Sum of Duration - GB*s
errors Sum of Errors
requestDuration Sum of Request Duration in microseconds
requests Sum of Requests
responseBodySize Sum of Response Body Sizes
subrequests Sum of Subrequests
wallTime Sum of Wall Time

AccountWorkersInvocationsAdaptiveSumConfidence

FieldDescription
clientDisconnects Confidence interval for the corresponding point estimate
cpuTimeUs Confidence interval for the corresponding point estimate
duration Confidence interval for the corresponding point estimate
errors Confidence interval for the corresponding point estimate
requestDuration Confidence interval for the corresponding point estimate
requests Confidence interval for the corresponding point estimate
responseBodySize Confidence interval for the corresponding point estimate
subrequests Confidence interval for the corresponding point estimate
wallTime Confidence interval for the corresponding point estimate

AccountWorkersInvocationsByOwnerAndScriptGroups

Workers dynamic worker invocations. Used for exact distinct dynamic worker counts.

FieldDescription
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension
uniq Unique count metrics

AccountWorkersInvocationsByOwnerAndScriptGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountWorkersInvocationsByOwnerAndScriptGroupsDimensions

FieldDescription
date Request datetime, truncated to start of a day
datetime Request datetime
datetimeFifteenMinutes Request datetime, truncated to fifteen minutes
datetimeFiveMinutes Request datetime, truncated to five minutes
datetimeHour Request datetime, truncated to start of an hour
datetimeMinute Request datetime, truncated to start of a minute

AccountWorkersInvocationsByOwnerAndScriptGroupsSum

FieldDescription
cpuTimeUs Sum of cpu time in us
requests Sum of Requests

AccountWorkersInvocationsByOwnerAndScriptGroupsSumConfidence

FieldDescription
cpuTimeUs Confidence interval for the corresponding point estimate
requests Confidence interval for the corresponding point estimate

AccountWorkersInvocationsByOwnerAndScriptGroupsUniq

FieldDescription
distinctDynamicWorkerCount Count of distinct dynamic workers in given timeframe

AccountWorkersInvocationsScheduled

Workers scheduled invocations

FieldDescription
cpuTimeUs CPU time - microseconds
cron The cron string of the schedule
datetime Request datetime
environmentName The name of the script environment
scheduledDatetime Scheduled datetime
scriptName The name of the script
status Status of the worker invocation

AccountWorkersOverviewDataAdaptiveGroups

Beta. Workers account overview invocation data with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountWorkersOverviewDataAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountWorkersOverviewDataAdaptiveGroupsDimensions

FieldDescription
date Request datetime, truncated to start of a day
datetime Request datetime
datetimeFifteenMinutes Request datetime, truncated to start of fifteen minutes
datetimeFiveMinutes Request datetime, truncated to start of five minutes
datetimeHour Request datetime, truncated to start of an hour
datetimeMinute Request datetime, truncated to start of a minute
usageModel Usage model of the worker invocation

AccountWorkersOverviewDataAdaptiveGroupsSum

FieldDescription
standardCpuTimeUs Standard usage model cpu time in us
unboundDurationUs Unbound usage model duration in us

AccountWorkersOverviewDataAdaptiveGroupsSumConfidence

FieldDescription
standardCpuTimeUs Confidence interval for the corresponding point estimate
unboundDurationUs Confidence interval for the corresponding point estimate

AccountWorkersOverviewRequestsAdaptiveGroups

Beta. Workers account overview invocation count with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
count The number of values for a metric per dimension
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountWorkersOverviewRequestsAdaptiveGroupsConfidence

FieldDescription
count The number of values for a metric per dimension, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountWorkersOverviewRequestsAdaptiveGroupsDimensions

FieldDescription
date Request datetime, truncated to start of a day
datetime Request datetime
datetimeFifteenMinutes Request datetime, truncated to start of fifteen minutes
datetimeFiveMinutes Request datetime, truncated to start of five minutes
datetimeHour Request datetime, truncated to start of an hour
datetimeMinute Request datetime, truncated to start of a minute
scriptName The name of the script
status Status of the worker invocation
usageModel Usage model of the worker invocation

AccountWorkersOverviewRequestsAdaptiveGroupsSum

FieldDescription
cpuTimeUs Cpu time in us

AccountWorkersOverviewRequestsAdaptiveGroupsSumConfidence

FieldDescription
cpuTimeUs Confidence interval for the corresponding point estimate

AccountWorkersSubrequestsAdaptiveGroups

Beta. Workers subrequests with adaptive sampling

FieldDescription
confidence ALPHA - DO NOT USE
dimensions List of dimensions to group by
quantiles Quantiles of a metric per dimension
sum The sum of values for a metric per dimension

AccountWorkersSubrequestsAdaptiveGroupsConfidence

FieldDescription
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountWorkersSubrequestsAdaptiveGroupsDimensions

FieldDescription
cacheStatus Cache status
date Request datetime, truncated to start of a day
datetime Request datetime
datetimeFifteenMinutes The date and time of the event truncated to fifteen minutes
datetimeFiveMinutes The date and time of the event truncated to five minutes
datetimeHour Request datetime, truncated to start of an hour
datetimeMinute Request datetime, truncated to start of an minute
datetimeSixHours Request datetime, truncated to start of six hour window
environmentName The name of the script environment
hostname The hostname of the subrequest
httpResponseStatus Origin HTTP response code
isPreview Whether this invocation is for a preview. 1 if preview, 0 if not.
previewSlug The name (slug) of the preview script
requestOutcome The outcome of the subrequest
scriptName The name of the script
scriptVersion The version of the Worker
usageModel Usage model of the worker invocation

AccountWorkersSubrequestsAdaptiveGroupsQuantiles

FieldDescription
timeToResponseDrainedUsP25 Response drained time 25th percentile - microseconds
timeToResponseDrainedUsP50 Response drained time 50th percentile - microseconds
timeToResponseDrainedUsP75 Response drained time 75th percentile - microseconds
timeToResponseDrainedUsP90 Response drained time 90th percentile - microseconds
timeToResponseDrainedUsP95 Response drained time 95th percentile - microseconds
timeToResponseDrainedUsP99 Response drained time 99th percentile - microseconds
timeToResponseDrainedUsP999 Response drained time 999th percentile - microseconds
timeToResponseUsP25 Response time 25th percentile - microseconds
timeToResponseUsP50 Response time 50th percentile - microseconds
timeToResponseUsP75 Response time 75th percentile - microseconds
timeToResponseUsP90 Response time 90th percentile - microseconds
timeToResponseUsP95 Response time 95th percentile - microseconds
timeToResponseUsP99 Response time 99th percentile - microseconds
timeToResponseUsP999 Response time 999th percentile - microseconds

AccountWorkersSubrequestsAdaptiveGroupsSum

FieldDescription
requestBodySize Workers fetch request body size in bytes
requestBodySizeUncached Workers fetch request body size in bytes where the request was not cached
responseBodySize Workers fetch response body size in bytes
subrequests Number of subrequests
timeToResponseDrainedUs Sum of time to response in us
timeToResponseUs Sum of time to response in us

AccountWorkersSubrequestsAdaptiveGroupsSumConfidence

FieldDescription
requestBodySize Confidence interval for the corresponding point estimate
requestBodySizeUncached Confidence interval for the corresponding point estimate
responseBodySize Confidence interval for the corresponding point estimate
subrequests Confidence interval for the corresponding point estimate
timeToResponseDrainedUs Confidence interval for the corresponding point estimate
timeToResponseUs Confidence interval for the corresponding point estimate

AccountWorkersVpcConnectionAdaptiveGroups

Workers VPC connections with adaptive sampling.

FieldDescription
avg The average value for a metric per dimension
confidence ALPHA - DO NOT USE
count Total number of Workers VPC Connections
dimensions List of dimensions to group by
sum The sum of values for a metric per dimension

AccountWorkersVpcConnectionAdaptiveGroupsAvg

FieldDescription
connectionLatency Average latency (in milliseconds) of retrieving a connection to the origin database
dnsLatency Average latency (in milliseconds) of resolving the hostname of the origin
sampleInterval The average value used for sample interval

AccountWorkersVpcConnectionAdaptiveGroupsConfidence

FieldDescription
count Total number of Workers VPC Connections, with confidence intervals
level Confidence level that was requested
sum The sum of values for a metric per dimension, with confidence intervals

AccountWorkersVpcConnectionAdaptiveGroupsDimensions

FieldDescription
coloCode IATA airport code for the Cloudflare datacenter where the connection originated.
date Workers VPC Connection timestamp, truncated to start of a day
datetime Workers VPC Connection timestamp
datetimeFifteenMinutes Workers VPC Connection timestamp, truncated to start of fifteen minutes
datetimeFiveMinutes Workers VPC Connection timestamp, truncated to start of five minutes
datetimeHour Workers VPC Connection timestamp, truncated to start of hour
datetimeMinute Workers VPC Connection timestamp, truncated to start of minute
errorCode Set for error statuses, contains a user-facing error message.
status The result status of the connection: 'success' or 'error'. Error events may not have complete data.
targetId The ID of the Workers VPC Resource

AccountWorkersVpcConnectionAdaptiveGroupsSum

FieldDescription
connectionLatency Total latency (in milliseconds) of establishing a connection to the origin, including DNS resolution and TLS session establishment.
dnsLatency Total Latency (in milliseconds) of resolving the hostname of the origin

AccountWorkersVpcConnectionAdaptiveGroupsSumConfidence

FieldDescription
connectionLatency Confidence interval for the corresponding point estimate
dnsLatency Confidence interval for the corresponding point estimate

AccountWorkflowsAdaptive

Workflows analytics

FieldDescription
allStepCount Number of operations across all step types during the timestamp interval
cpuTime CPU time in timestamp (ms)
datetime The date when trigger was triggered
endTimestamp Instance end timestamp(seconds)
eventType Event type
executionDuration Execution duration in timestamp (GB*s)
instanceId Instance Id
retryCount Number of retries in timestamp
sampleInterval ABR sample interval
startTimestamp Instance start timestamp(seconds)
stepCount Number of step.do operations during the timestamp interval
storageRate Instance storage size growth in timestamp (bytes)
wallTime Wall time in seconds
workflowName Workflow name

AccountWorkflowsAdaptiveGroups

Workflows analytics

FieldDescription
avg
confidence ALPHA - DO NOT USE
count Number of events(workflow invocations) per dimension
dimensions List of dimensions to group by
sum

AccountWorkflowsAdaptiveGroupsAvg

FieldDescription
cpuTime Average CPU time per dimension
wallTime