Table of Contents | ||||||
---|---|---|---|---|---|---|
|
Introduction
Tags beginning with cdn.
cloudfarecloudflare
identify events generated by Cloudfare.
Valid tags and data tables
The full tag must have 4 levels. The first two are fixed ascdn.cloudfare
. The third level identifies the type of events sent, and the fourth level indicates the event subtype.
...
Technology
...
Brand
...
Type
...
...
cdn
...
cloudfare
...
audit
...
events
These are the valid tags and corresponding data tables that will receive the parsers' data:
Tag
Product / Service | Tags | Data tables |
---|---|---|
Cloudflare |
|
|
|
|
|
|
|
For more information, read more about Devo tags.
Table structure
This is These are the set fields displayed by in these tables:
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra Label fields | |
---|---|---|---|
eventdate |
| - | |
hostname |
| ||
ENTITY_ID |
| ||
id |
| ||
action__info |
| ||
action__type |
| - | |
action__result |
| - | |
actor__id |
| ||
actor__email |
| - | |
actor__type |
| ||
actor__ip |
| ||
newValue |
| ||
oldValue |
| ||
owner__id |
| - | |
resource__id |
| - | |
resource__type |
| - | |
interface |
| ||
metadata__zone_name |
| ||
metadata__zone_tag |
| - | |
metadata__type |
| ||
metadata__name |
| ||
metadata__value |
| ||
when |
| ||
hostchain |
| ✓ | |
tag |
| ✓ | |
rawMessage |
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
metadata__value
str
-
when
timestamp
-
hostchain
str
✓
tag
str
✓
rawMessage
str
Field | Type | Field transformation | Source field name |
---|
str
-
Extra fields | ||||||
---|---|---|---|---|---|---|
eventdate |
|
|
| |||
hostname |
|
|
| |||
zone_tag |
|
|
| |||
action |
|
|
| |||
clientASN |
|
|
| |||
clientASNDescription |
|
|
| |||
clientCountryName |
|
|
| |||
clientIP |
|
|
| |||
clientIP4 |
|
| clientIP | |||
clientIP_v6 |
|
| clientIP clientIP4 | |||
clientIPClass |
|
|
| |||
clientRefererHost |
|
|
| |||
clientRefererPath |
|
|
| |||
clientRefererQuery |
|
|
| |||
clientRefererScheme |
|
|
| |||
clientRequestHTTPHost |
|
|
| |||
clientRequestHTTPMethodName |
|
|
| |||
clientRequestHTTPProtocol |
|
|
| |||
clientRequestPath |
|
|
| |||
clientRequestQuery |
|
|
| |||
clientRequestScheme |
|
|
| |||
datetime |
|
|
| |||
edgeColoName |
|
|
| |||
edgeResponseStatus |
|
|
| |||
kind |
|
|
| |||
matchIndex |
|
|
| |||
originResponseStatus |
|
|
| |||
originatorRayName |
|
|
| |||
rayName |
|
|
| |||
ruleId |
|
|
| |||
source |
|
|
| |||
userAgent |
|
|
| |||
hostchain |
|
|
| ✓ | ||
tag |
|
|
| ✓ | ||
rawMessage |
|
|
| ✓ |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Field transformation | Source field name | Extra fields | ||
---|---|---|---|---|---|---|
eventdate |
|
|
| |||
hostname |
|
|
| |||
zone_tag |
|
|
| |||
ClientASN |
|
|
| |||
ClientCountry |
|
|
| |||
ClientDeviceType |
|
|
| |||
ClientIP |
|
|
| |||
ClientIPClass |
|
|
| |||
ClientRequestBytes |
|
|
| |||
ClientRequestHost |
|
|
| |||
ClientRequestMethod |
|
|
| |||
ClientRequestPath |
|
|
| |||
ClientRequestProtocol |
|
|
| |||
ClientRequestReferer |
|
|
| |||
ClientRequestURI |
|
|
| |||
ClientRequestUserAgent |
|
|
| |||
ClientSSLCipher |
|
|
| |||
ClientSSLProtocol |
|
|
| |||
ClientSrcPort |
|
|
| |||
ClientXRequestedWith |
|
|
| |||
Description |
|
|
| |||
EdgeColoCode |
|
|
| |||
EdgeColoID |
|
|
| |||
EdgeEndTimestamp |
|
|
| |||
EdgePathingOp |
|
|
| |||
EdgePathingSrc |
|
|
| |||
EdgePathingStatus |
|
|
| |||
EdgeRateLimitAction |
|
|
| |||
EdgeRateLimitID |
|
|
| |||
EdgeRequestHost |
|
|
| |||
EdgeResponseBytes |
|
|
| |||
EdgeResponseCompressionRatio |
|
|
| |||
EdgeResponseContentType |
|
|
| |||
EdgeResponseStatus |
|
|
| |||
EdgeServerIP |
|
|
| |||
FirewallMatchesActions_str |
|
| FirewallMatchesActions | |||
FirewallMatchesRuleIDs_str |
|
| FirewallMatchesRuleIDs | |||
FirewallMatchesSources_str |
|
| FirewallMatchesSources | |||
OriginIP |
|
|
| |||
OriginResponseBytes |
|
|
| |||
OriginResponseHTTPExpires |
|
|
| |||
OriginResponseHTTPLastModified |
|
|
| |||
OriginResponseStatus |
|
|
| |||
OriginResponseTime |
|
|
| |||
OriginSSLProtocol |
|
|
| |||
ParentRayID |
|
|
| |||
RayID |
|
|
| |||
Ref |
|
|
| |||
SecurityLevel |
|
|
| |||
WAFAction |
|
|
| |||
WAFFlags |
|
|
| |||
WAFMatchedVar |
|
|
| |||
WAFProfile |
|
|
| |||
WAFRuleID |
|
|
| |||
WAFRuleMessage |
|
|
| |||
ZoneID |
|
|
| |||
at_devo_collector_version |
|
|
| |||
at_devo_source_id |
|
|
| |||
at_devo_project_id |
|
|
| |||
at_devo_retrieving_timestamp |
|
|
| |||
hostchain |
|
|
| ✓ | ||
tag |
|
|
| ✓ | ||
rawMessage |
|
|
| ✓ |