Last update:2026-09-22 10:26:14
This article introduces the WAAP Attack Log in the platform’s native data and provides descriptions of its fields.
| No. | Field Name | Field Code | Data Type | Field Description |
|---|---|---|---|---|
| 1 | Log Version | log_version |
LONG |
Identifies the version of the log format. |
| 2 | Log Sampling Rate | log_sampling_rate |
INT |
A value of N indicates that one real-time log is generated for every N requests. |
| 3 | Hostname | host |
string |
The client hostname configured on the platform. |
| 4 | Status Code | status_code |
int |
The status code returned to the client in response to the request. |
| 5 | Detailed Hostname | detail_host |
string |
The specific hostname requested by the client. |
| 6 | URL | url_detail |
string |
The host, request path, and query parameters. |
| 7 | UUID | uuid |
string |
The unique identifier for the log entry. |
| 8 | Referer | referer |
string |
The value of the Referer header in the client request. |
| 9 | Path | path |
string |
The request path. |
| 10 | HTTP Protocol Version | version |
string |
The HTTP version used in the client request. |
| 11 | HTTP Method | mode |
string |
The HTTP method used in the client request. |
| 12 | User-Agent | user_agent |
string |
The value of the User-Agent header from the client. |
| 13 | Request ID | ws_request_id |
string |
The unique identifier for the client request. |
| 14 | Query | query |
string |
The query parameters in the client’s URI. To monitor this field, configure the Hostname property to include all parameters. The value is escaped according to W3C HTML and RFC 1866. |
| 15 | Response Bytes | bytes |
long |
The number of bytes returned by the server in response to the client request. |
| 16 | HTTP Port | port |
int |
The port number used by the client to initiate the request. |
| No. | Field Name | Field Code | Data Type | Field Description |
|---|---|---|---|---|
| 1 | Client IP | client_ip |
string |
The IPv4 or IPv6 address of the requesting client. |
| 2 | JA4 Fingerprint | ssl_fingerprint_ja4 |
string |
An improved JA3 method for identifying the client’s TLS handshake fingerprint. |
| 3 | JA3 Fingerprint | ssl_fingerprint_ja3 |
string |
A method for identifying the client’s TLS handshake fingerprint. |
| 4 | Client City | client_city |
string |
The city from which the client request originated. |
| 5 | Client Country/Region | client_country_region |
string |
The country or region from which the client request originated. |
| 6 | Client Province | client_province |
string |
The province from which the client request originated. |
| 7 | Client ASN | client_asn |
string |
The Autonomous System Number to which the client IP address belongs. |
| No. | Field Name | Field Code | Data Type | Field Description |
|---|---|---|---|---|
| 1 | Final Rule ID | final_rule_id |
long |
The unique identifier of the last matched security policy rule. |
| 2 | Custom Rule Name | rule_name |
string |
The name of the security rule that was triggered. |
| 3 | Action | act |
int |
The mitigation action executed by the security policy for the request. |
| 4 | Policy Type | attack_type |
string |
The type of security policy triggered by the request. |
| 5 | Bot Tag | bot_type |
string |
The subclass details for each bot type. |
| 6 | Attack Time | attack_time |
long |
The timestamp when the attack occurred. |
| 7 | Security Policy Name | custom_msg |
string |
The specific name of the security policy that was triggered. |
| 8 | Matched Policy Content | content |
string |
The content in the request that matches the policy. |
| 9 | Bot Category | bot_category |
string |
The publicly declared bot type, including AI bots and public bots. |
| 10 | Bot Name | bot_name |
string |
The identified bot name, including AI bots, public bots, and definite bots. |
| 11 | Bot Tags | bot_tags |
string |
Detailed bot characteristics used to assign a bot score to the request. |
| 12 | Bot Score | bot_score |
string |
The bot score assigned to the request, indicating the likelihood that the request originated from a bot. A higher score indicates a higher probability. |
Note:
- The availability of log fields may vary depending on the actual configuration. Please select fields reasonably according to your business scenario.