Edge Insights (BETA)

This feature is in BETA status. Please contact your account manager to preview this feature on your account.

Use Edge Insights to gain historical and near real-time insights into threat profiles, performance, and CDN usage. It allows you to:

The primary function of these reports is to identify threat profiles, assess performance, and gather data on CDN usage. This data should not be used for billing purposes.

Please contact your CDN account manager to activate Edge Insights.

Basic Usage

Generating a report consists of performing the following steps:

  1. Navigate to the Edge Insights page. ClosedHow?From the main menu, navigate to AnalyticsEdge Insights.
  2. Select one of the following data sources:

    • WAF Alerts: Use this data source to view access rule, bot rule, custom rule, and managed rule violations of your WAF security application manager configuration.
    • Rate Limiting Alerts: Use this data source to view rate rule violations of your WAF security application manager configuration that have been downsampled to 10%.
    • Sampled Access Logs: Use this data source to analyze CDN traffic that has been downsampled to 0.1%.
    • Analytics: Use this data source to analyze CDN traffic that has been downsampled to 0.1%.
    • Edge Control: Use this data source to analyze how a new CDN configuration affects content delivery and performance.
  3. Select the time period for which data will be returned.

    Define a time period that does not exceed the retention period defined for the selected data source.

  4. Optional. Define a filter for your report to gain deeper insights into security violations, key fields, or traffic patterns.
  5. Edge Control Only

    Define the configurations that will be compared and the type of data that will be analyzed.

    1. From the Customer config version section, select two or more configurations.
    2. Select the data that will be compared from the HTTP Status Code and Cache Status sections.

      For example, you may select TCP_MISS from the Cache Status section to compare whether cache misses increased as a result of your latest configuration update.

    3. Click Analyze.

Common Use Cases:

Sharing Data

You may share an entire report or specific data with other users.

You must establish a MCC session before attempting to load a MCC URL that points to a specific report or data. Attempting to load this type of URL without an active MCC session may load the MCC's home page instead.

Data Downsampling and Retention

Our policy on downsampling data and the amount of time that we store it varies according to data source.

Data Source

Downsampling

Retention Schedule

WAF Alerts

Not ApplicableWAF alerts are not downsampled.

30 days

Rate Limiting Alerts

10%

30 days

Sampled Access Logs

0.1%

7 days

Analytics

0.1%

7 days

Edge Control

Not ApplicableYour configuration changes are not downsampled.

7 days

Time Chart

The time chart (aka line graph) graphs the current report's data over time.

Key information:

Top Results Charts

The top results charts displays the top results for 2 key fields.

Key information:

Filtering

Filtering is critical for gaining deeper insights into your data. Perform the following steps to quickly filter your report:

  1. From Top Results section, select the field that contains the data that you would like to filter.

  2. From the pie chart, click on the value by which you would like to filter.

    The Filters section in the left-hand pane is immediately updated to display your filter query.

    Example:

    From the Top Results section, select the HTTP Status Code field and then click on 404 to create the following filter:

Perform the following common tasks from within the Filters section in the left-hand pane:

Log Data

Log data provides contextual information about a request that allows you to gain deeper behavioral insight into threat detection and CDN usage. View the log data associated with the current report from within the Logs section.

Key information:

WAF Alerts

Use the WAF Alerts data source for historical and near real-time analysis of recent threats to site traffic. For example, use this data to:

Edge Insights retains WAF data for 30 days.

Rate Limiting Alerts

Use the Rate Limiting Alerts data source for historical and near real-time analysis of recently rate limited requests. For example, use this data to:

Logging for rate limited requests is downsampled to 10% due to the volume of requests that may occur during a single incident (e.g., volumetric Distributed Denial-of-Service attack).

Calculate an approximation of your actual total events by multiplying your total events by 10.
For example, if your total events reports 325K, then the approximate number of requests for that time period is 3,250,000.

Edge Insights retains WAF data, including rate limited requests, for 30 days.

Sampled Access Logs

Use this data source to analyze CDN traffic that has been downsampled to 0.1%. This data provides historical and near real-time visibility into your CDN traffic at a high-level.

Calculate an approximation of your actual total events by multiplying your total events by 1,000.
For example, if your total events reports 235K, then the approximate number of requests for that time period is 235,000,000.

Analytics

Use this data source to analyze CDN traffic that has been downsampled to 0.1%. This data provides historical and near real-time visibility into your CDN traffic at a high-level.

Calculate an approximation of your actual total events by multiplying your total events by 1,000.
For example, if your total events reports 100K, then the approximate number of requests for that time period is 100,000,000.

Edge Control

Use this data source to analyze how a new CDN configuration affects content delivery and performance.