Cloudflare_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Custom Log V1 Yes 🔶 — uses type-suffixed column names
Ingestion API Supported ✓ Yes

Contents

Schema (104 columns)

Source: KQL validation test schema

Column Name Type
Action_s string
Application_s string
BotScore_d real
BotScoreSrc_s string
CacheCacheStatus_s string
CacheResponseBytes_d real
CacheResponseStatus_d real
CacheTieredFill_b bool
ClientASN_d real
ClientASNDescription_s string
ClientBytes_d real
ClientCountry_s string
ClientDeviceType_s string
ClientIP_s string
ClientIPClass_s string
ClientMatchedIpFirewall_s string
ClientPort_d real
ClientProto_s string
ClientRefererHost_s string
ClientRefererPath_s string
ClientRefererQuery_s string
ClientRefererScheme_s string
ClientRequestBytes_d real
ClientRequestHost_s string
ClientRequestMethod_s string
ClientRequestPath_s string
ClientRequestProtocol_s string
ClientRequestQuery_s string
ClientRequestReferer_s string
ClientRequestScheme_s string
ClientRequestURI_s string
ClientRequestUserAgent_s string
ClientSrcPort_d real
ClientSSLCipher_s string
ClientSSLProtocol_s string
ClientTcpRtt_d real
ClientTlsCipher_s string
ClientTlsClientHelloServerName_s string
ClientTlsProtocol_s string
ClientTlsStatus_s string
ClientXRequestedWith_s string
ColoCode_s string
ConnectTimestamp_t datetime
Datetime_t datetime
DisconnectTimestamp_t datetime
EdgeColoCode_s string
EdgeColoID_d real
EdgeEndTimestamp_t datetime
EdgePathingOp_s string
EdgePathingSrc_s string
EdgePathingStatus_s string
EdgeRateLimitAction_s string
EdgeRateLimitID_d real
EdgeRequestHost_s string
EdgeResponseBytes_d real
EdgeResponseCompressionRatio_d real
EdgeResponseContentType_s string
EdgeResponseStatus_d real
EdgeServerIP_s string
EdgeStartTimestamp_t datetime
Event_s string
FirewallMatchesActions_s string
FirewallMatchesRuleIDs_s string
FirewallMatchesSources_s string
IpFirewall_b bool
Kind_s string
MatchIndex_d real
OriginatorRayID_s string
OriginBytes_d real
OriginIP_s string
OriginPort_d real
OriginProto_s string
OriginResponseBytes_d real
OriginResponseHTTPExpires_s string
OriginResponseHTTPLastModified_s string
OriginResponseStatus_d real
OriginResponseTime_d real
OriginSSLProtocol_s string
OriginTcpRtt_d real
OriginTlsCipher_s string
OriginTlsFingerprint_s string
OriginTlsMode_s string
OriginTlsProtocol_s string
OriginTlsStatus_s string
ParentRayID_s string
ProxyProtocol_s string
RayID_s string
RuleID_s string
SecurityLevel_s string
Source_s string
Status_d real
TimeGenerated datetime
Timestamp_t datetime
WAFAction_s string
WAFFlags_s string
WAFMatchedVar_s string
WAFProfile_s string
WAFRuleID_s string
WAFRuleMessage_s string
WorkerCPUTime_d real
WorkerStatus_s string
WorkerSubrequest_b bool
WorkerSubrequestCount_d real
ZoneID_d real

Solutions (2)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
[DEPRECATED] Cloudflare

Content Items Using This Table (42)

Analytic Rules (20)

In solution Cloudflare:

Analytic Rule Selection Criteria
Cloudflare - Bad client IP
Cloudflare - Client request from country in blocklist
Cloudflare - Empty user agent
Cloudflare - Multiple error requests from single source
Cloudflare - Multiple user agents for single source
Cloudflare - Unexpected POST requests
Cloudflare - Unexpected URI
Cloudflare - Unexpected client request
Cloudflare - WAF Allowed threat
Cloudflare - XSS probing pattern in request

In solution Cloudflare CCF:

Analytic Rule Selection Criteria
Cloudflare - Bad client IP
Cloudflare - Client request from country in blocklist
Cloudflare - Empty user agent
Cloudflare - Multiple error requests from single source
Cloudflare - Multiple user agents for single source
Cloudflare - Unexpected POST requests
Cloudflare - Unexpected URI
Cloudflare - Unexpected client request
Cloudflare - WAF Allowed threat
Cloudflare - XSS probing pattern in request

Hunting Queries (20)

In solution Cloudflare:

Hunting Query Selection Criteria
Cloudflare - Client TLS errors
Cloudflare - Client errors
Cloudflare - Files requested
Cloudflare - Rare user agents
Cloudflare - Server TLS errors
Cloudflare - Server errors
Cloudflare - Top Network rules
Cloudflare - Top WAF rules
Cloudflare - Unexpected countries
Cloudflare - Unexpected edge response

In solution Cloudflare CCF:

Hunting Query Selection Criteria
Cloudflare - Client TLS errors
Cloudflare - Client errors
Cloudflare - Files requested
Cloudflare - Rare user agents
Cloudflare - Server TLS errors
Cloudflare - Server errors
Cloudflare - Top Network rules
Cloudflare - Top WAF rules
Cloudflare - Unexpected countries
Cloudflare - Unexpected edge response

Workbooks (2)

In solution Cloudflare:

Workbook Selection Criteria
Cloudflare

In solution Cloudflare CCF:

Workbook Selection Criteria
Cloudflare

Parsers Using This Table (2)

Other Parsers (2)

Parser Solution Selection Criteria
Cloudflare Cloudflare
Cloudflare Cloudflare CCF

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index