Document toolboxDocument toolbox

cdn.fastly

Introduction

The tags beginning with cdn.fastly identify events generated by Fastly.

Valid tags and data tables 

The full tag must have 4 levels. The first two are fixed as cdn.fastly. The third level identifies the type of events sent. The fourth level indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Fastly

cdn.fastly.waf.event

cdn.fastly.waf.event

cdn.fastly.web.event

cdn.fastly.web.event

For more information, read more About Devo tags.

Table structure

These are the fields displayed in these tables:

cdn.fastly.waf.event

Field

Type

Source field name

Extra fields

Field

Type

Source field name

Extra fields

eventdate

timestamp

 

 

host

str

vhost

 

type

str

 

 

request_id

str

 

 

rule_id

str

 

 

severity

str

 

 

anomaly_score

str

 

 

logdata

str

 

 

waf_message

str

 

 

hostchain

str

 

✓

tag

str

 

✓

rawMessage

str

 

✓

cdn.fastly.web.event

Field

Type

Source field name

Extra fields

Field

Type

Source field name

Extra fields

eventdate

timestamp

 

 

host

str

vhost

 

type

str

 

 

service_id

str

 

 

request_id

str

 

 

start_time

str

 

 

fastly_info

str

 

 

datacenter

str

 

 

client_ip

ip4

 

 

req_method

str

 

 

req_uri

str

 

 

req_h_host

str

 

 

tls_client_cipher

str

 

 

tls_client_ciphers_sha

str

 

 

req_h_user_agent

str

 

 

req_h_accept_encoding

str

 

 

req_header_bytes

str

 

 

req_body_bytes

str

 

 

waf_logged

str

 

 

waf_blocked

str

 

 

waf_failures

str

 

 

waf_executed

str

 

 

anomaly_score

str

 

 

sql_injection_score

str

 

 

rfi_score

str

 

 

lfi_score

str

 

 

rce_score

str

 

 

php_injection_score

str

 

 

session_fixation_score

str

 

 

http_violation_score

str

 

 

xss_score

str

 

 

resp_status

str

 

 

resp_bytes

str

 

 

resp_header_bytes

str

 

 

resp_body_bytes

str

 

 

fastly_info_state

str

 

 

hostchain

str

 

 

tag

str

 

 

rawMessage

str

 

Â