# Real-Time Events fields

The [Real-Time Events](/en/documentation/platform/real-time-events/) datasets of the GraphQL API hold raw data: one record per request or event, with no processing. A query reads them from the events endpoint, `https://api.azion.com/v4/events/graphql`, with the header `Authorization: Token [TOKEN VALUE]`. Each table on this page lists the fields a query can select on one dataset, with the type the schema declares. The datasets, and the arguments every query accepts, are on [Datasets and query arguments](/en/documentation/devtools/graphql/features/).

The API matches field names by exact case. A field with other casing returns `400`, and the message suggests the correct name: `Cannot query field "zoneID" on type "IdnsQueriesEventsAggregatedFieldsLog". Did you mean "zoneId"?`

---

## activityHistoryEvents (Activity History)

`activityHistoryEvents` holds the [Activity History](/en/documentation/fundamentals/activity-history/) of the account: one record per action a user performs in Azion Console.

| Field                | Type           | Description                                                                                                                                            |
| -------------------- | -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `accountId`          | String         | Account's identifier on Azion. Example: `8437`                                                                                                         |
| `authorEmail`        | String         | Email address of the Azion Console user who performed the action. Example: `you@example.com`                                                           |
| `authorName`         | String         | Name of the Azion Console user who performed the action. Example: `Hannah`                                                                             |
| `comment`            | String         | Editable space where users add a comment when they make a change. Example: `Action performed during investigation`                                     |
| `parentResourceId`   | String         | Unique identifier of the parent resource, when one exists. Example: `8190`                                                                             |
| `parentResourceName` | String         | Name of the parent resource, when one exists. Example: `Application for domain xxx`                                                                    |
| `parentResourceType` | String         | Type of the parent resource, when one exists. Example: `Application`                                                                                   |
| `refererHeader`      | String         | `Referer` header of the page that called the API. Returned when the call comes from a user interface. Example: `Test 123`                              |
| `remotePort`         | String         | Port of the origin that generated the request. Example: `80`                                                                                           |
| `requestData`        | String         | Data received in the payload of the request the user generated. Example: `{"test": 123}`                                                               |
| `resourceId`         | String         | Unique identifier of the resource that was created or modified. Example: `1234`                                                                        |
| `resourceName`       | String         | Name of the resource that was created or modified. Example: `Rule abc`                                                                                 |
| `resourceType`       | String         | Type of the resource that was created or modified. Example: `Application Request Rule`                                                                 |
| `title`              | String         | Title of the activity, made of the model name, the name, and the type of activity. Example: `Pathorigin Default Origin was changed`                    |
| `ts`                 | CustomDateTime | Timestamp of when the event was created. Example: `2022-10-20T10:10:10`                                                                                |
| `type`               | String         | Type of action performed in Azion Console: created, changed, deleted, or signed up. The value comes back in lowercase, such as `created` or `deleted`. |
| `userAgent`          | String         | `User-Agent` header sent in the request. Example: `curl 1.2.6`                                                                                         |
| `userId`             | String         | Unique identifier of the user who performed the action. Example: `999`                                                                                 |
| `userIp`             | String         | IP address of the user or origin that generated the request. Example: `127.0.0.1`                                                                      |
| `uuid`               | String         | Unique request identifier. Example: `c09k4385-o8f4-9fb9-8088-238555dd`                                                                                 |

This query returns the time, type, title, and resource type of the latest actions in a seven-day window:

```graphql
query {
  activityHistoryEvents(
    limit: 5
    filter: { tsRange: {begin: "2026-09-26T14:00:00", end: "2026-10-03T14:00:00"} }
    orderBy: [ts_DESC]
  ) {
    ts
    type
    title
    resourceType
  }
}
```

The response holds five records, cut here after the third:

```json
{
  "data": {
    "activityHistoryEvents": [
      {
        "ts": "2026-10-03T12:53:20Z",
        "type": "deleted",
        "title": "Dns Zone example.net was deleted",
        "resourceType": "Dns Zone"
      },
      {
        "ts": "2026-10-03T12:53:17Z",
        "type": "deleted",
        "title": "Dns Zone example.org was deleted",
        "resourceType": "Dns Zone"
      },
      {
        "ts": "2026-10-03T11:52:57Z",
        "type": "created",
        "title": "Dns Zone Record my-record TXT was created",
        "resourceType": "Dns Zone Record"
      },
      …
    ]
  }
}
```

---

## functionConsoleEvents (previous cellsConsoleEvents) (Azion Runtime)

`functionConsoleEvents` holds the log messages that functions running on [Azion Runtime](/en/documentation/devtools/runtime/) generate. The dataset `cellsConsoleEvents` is deprecated; use `functionConsoleEvents`.

| Field             | Type           | Description                                                                                                                  |
| ----------------- | -------------- | ---------------------------------------------------------------------------------------------------------------------------- |
| `configurationId` | String         | Unique Azion configuration identifier, set in the virtual host configuration file. Example: `1595368520`                     |
| `functionId`      | String         | Unique Azion function identifier. It appears in the function URL path in Azion Console and in API responses. Example: `1111` |
| `id`              | String         | Request identifier. It groups the messages of a single request. Example: `240g95f04832f2872dd6e8ae308e8a73`                  |
| `level`           | String         | Level of the message: `MDN`, `DEBUG`, `INFO`, `ERROR`, `LOG`, or `WARN`                                                      |
| `line`            | String         | Log message generated by Azion Runtime. Example: `at async mainFetch (ext:deno_fetch/26_fetch.js:266:12)`                    |
| `lineSource`      | String         | Category of the log message. Example: `CONSOLE`, `RUNTIME`                                                                   |
| `solutionId`      | String         | Unique Azion ID of the solution, set in the virtual host configuration file. Example: `1441740010`                           |
| `ts`              | CustomDateTime | Timestamp of when the event was created. Example: `2022-10-20T10:10:10`                                                      |

---

## dataStreamedEvents (Data Stream)

`dataStreamedEvents` holds one record per send that [Data Stream](/en/documentation/platform/data-stream/) makes to the endpoint of a stream.

| Field              | Type           | Description                                                                                                                                                                                     |
| ------------------ | -------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `bootstrapServers` | String         | —                                                                                                                                                                                               |
| `configurationId`  | String         | Unique Azion configuration identifier, set in the virtual host configuration file. Example: `1595368520`                                                                                        |
| `dataStreamed`     | Int            | Total amount of data streamed to the configured endpoint, in bytes. This field is the result of a sum. Example: `1270`                                                                          |
| `endpointType`     | String         | Type of the endpoint the stream uses: `HTTP_POST`, `S3`, `ELASTICSEARCH`, `QRADAR`, `AWS_KINESIS_FIREHOSE`, `KAFKA`, `DATADOG`, `BIG_QUERY`, `SPLUNK`, `AZURE_MONITOR`, or `AZURE_BLOB_STORAGE` |
| `jobName`          | String         | Unique Azion identifier for the type of stream. Example: `Data Stream HTTP`, `Data Stream WAF`                                                                                                  |
| `statusCode`       | Int            | HTTP status code of the request. Example: `200`                                                                                                                                                 |
| `streamedLines`    | Int            | Total number of lines streamed to the configured endpoint, up to `2000`. This field is the result of a sum. Example: `837`                                                                      |
| `topic`            | String         | —                                                                                                                                                                                               |
| `ts`               | CustomDateTime | Timestamp of when the event was created. Example: `2022-10-20T10:10:10`                                                                                                                         |
| `url`              | String         | URL the data was sent to. Example for an *HTTP POST* endpoint: `https://log-receiver.com:3000`                                                                                                  |

---

## functionEvents (previous edgeFunctionsEvents) (Functions)

`functionEvents` holds one record per request that invokes [Functions](/en/documentation/platform/functions/). The dataset `edgeFunctionsEvents` is deprecated; use `functionEvents`. The five fields whose names start with `edgeFunctions` are deprecated too, each replaced by the field that starts with `functions`.

| Field                            | Type           | Description                                                                                                                    |
| -------------------------------- | -------------- | ------------------------------------------------------------------------------------------------------------------------------ |
| `configurationId`                | String         | Unique Azion configuration identifier, set in the virtual host configuration file. Example: `1595368520`                       |
| `edgeFunctionsInitiatorTypeList` | String         | Deprecated; use `functionsInitiatorTypeList`.                                                                                  |
| `edgeFunctionsInstanceIdList`    | String         | Deprecated; use `functionsInstanceIdList`.                                                                                     |
| `edgeFunctionsList`              | String         | Deprecated; use `functionsList`.                                                                                               |
| `edgeFunctionsSolutionId`        | Int            | Deprecated; use `functionsSolutionId`.                                                                                         |
| `edgeFunctionsTime`              | String         | Deprecated; use `functionsTime`.                                                                                               |
| `functionLanguage`               | String         | Language of the function. Example: `javascript`                                                                                |
| `functionsInitiatorTypeList`     | String         | List of the initiators of the function, separated by `;`: `1` (Applications) or `2` (Firewall).                                |
| `functionsInstanceIdList`        | String         | List of the function instances invoked during the request. Example: `10728`                                                    |
| `functionsList`                  | String         | List of the functions invoked during the request, in invocation order: the first function listed ran first. Example: `3324;43` |
| `functionsSolutionId`            | Int            | Identifier of your function. Example: `1321`                                                                                   |
| `functionsTime`                  | String         | Total execution time of the function, in seconds. This field is the result of a sum. Example: `0.021`                          |
| `ts`                             | CustomDateTime | Timestamp of when the event was created. Example: `2022-10-20T10:10:10`                                                        |
| `virtualhostid`                  | String         | Unique ID available in Azion Console, set in the virtual host configuration file. Example: `2410001a`                          |

---

## workloadEvents (previous httpEvents) (Applications, WAF)

`workloadEvents` holds one record per request to an application on [Applications](/en/documentation/platform/applications/), with the WAF result for that request. The dataset `httpEvents` is deprecated; use `workloadEvents`, which returns the same records.

| Field                        | Type           | Description                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ---------------------------- | -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `bytesSent`                  | BigInt         | Number of bytes sent to the client. This field is the result of a sum. Example: `191`                                                                                                                                                                                                                                                                                                                                                                   |
| `configurationId`            | String         | Unique Azion configuration identifier, set in the virtual host configuration file. Example: `1595368520`                                                                                                                                                                                                                                                                                                                                                |
| `debugLog`                   | String         | Value of any variable from the request, set through a Rules Engine behavior. Example: `{\\\"idHash\\\":\\\"pQ04xXYD4JSYyOERu3mcwA==\\\",\\\"type\\\":\\\"product_screen_element_element_action\\\",\\\"message\\\":{\\\"event\\\":\\\"product_screen_element_element_action\\\",\\\"action\\\":\\\"value\\\",\\\"product\\\":\\\"value\\\",\\\"screen\\\":\\\"value\\\",\\\"element\\\":\\\"value\\\"},\\\"date\\\":\\\"2023-10-27T19:44:57.251Z\\\"}"` |
| `geolocAsn`                  | String         | Autonomous System Number (ASN) allocation, queried from the MaxMind table. Example: `AS52580 Azion Technologies Ltda.`                                                                                                                                                                                                                                                                                                                                  |
| `geolocCountryName`          | String         | Country of the client, detected through IP address geolocation. Example: `United States`, `Russian Federation`                                                                                                                                                                                                                                                                                                                                          |
| `geolocRegionName`           | String         | Region of the client, detected through IP address geolocation. Example: `California`, `Rio Grande do Sul`                                                                                                                                                                                                                                                                                                                                               |
| `host`                       | String         | Host of the request: the host name from the request line, the `Host` request header, or the server name that matched the request. Example: `hello.myhost.net`                                                                                                                                                                                                                                                                                           |
| `httpReferer`                | String         | Address of the page the user made the request from. Example: `https://example.com`                                                                                                                                                                                                                                                                                                                                                                      |
| `httpUserAgent`              | String         | Application, operating system, vendor, or version of the client, from the `User-Agent` header. Example: `Mozilla/5.0 (Windows NT 10.0; Win64; x64)`                                                                                                                                                                                                                                                                                                     |
| `proxyStatus`                | Int            | HTTP error status code, or the origin, when the upstream returns no response. Example: `520`. For a cached response, the value is `-`.                                                                                                                                                                                                                                                                                                                  |
| `remoteAddress`              | String         | IP address of the origin that generated the request. Example: `127.0.0.1`                                                                                                                                                                                                                                                                                                                                                                               |
| `remotePort`                 | Int            | Port of the origin that generated the request. Example: `8080`                                                                                                                                                                                                                                                                                                                                                                                          |
| `requestId`                  | String         | Unique request identifier. Example: `5f222ae5938482c32a822dbf15e19f0f`                                                                                                                                                                                                                                                                                                                                                                                  |
| `requestLength`              | BigInt         | Length of the request in bytes, including the request line, headers, and body. This field is the result of a sum. Example: `167`                                                                                                                                                                                                                                                                                                                        |
| `requestMethod`              | String         | HTTP request method. Example: `GET` or `POST`                                                                                                                                                                                                                                                                                                                                                                                                           |
| `requestTime`                | Decimal        | Request processing time, in seconds, counted from the first bytes read from the client. This field is the result of a sum. Example: `0.234`                                                                                                                                                                                                                                                                                                             |
| `requestUri`                 | String         | URI of the request, with its arguments and without the host and protocol. Example: `/v1?v=bo%20dim`                                                                                                                                                                                                                                                                                                                                                     |
| `scheme`                     | String         | Request scheme. Example: `HTTP` or `HTTPS`                                                                                                                                                                                                                                                                                                                                                                                                              |
| `sentHttpContentType`        | String         | `Content-Type` header sent in the origin's response. Example: `text/html; charset=UTF-8`                                                                                                                                                                                                                                                                                                                                                                |
| `sentHttpXOriginalImageSize` | Int            | `X-Original-Image-Size` header sent in the origin's response. Image Processor uses it to report the original image size, in bytes. Example: `987390`                                                                                                                                                                                                                                                                                                    |
| `serverAddr`                 | String         | IP address of the server that received the request. Example: `192.0.2.10`                                                                                                                                                                                                                                                                                                                                                                               |
| `serverPort`                 | String         | Remote port of the server that received the request. Example: `443`                                                                                                                                                                                                                                                                                                                                                                                     |
| `serverProtocol`             | String         | Version of the request protocol. Example: `HTTP/1.1`, `HTTP/2.0`, `HTTP/3.0`                                                                                                                                                                                                                                                                                                                                                                            |
| `sessionid`                  | String         | ID of the session, set in the virtual host configuration file from the location directive. Example: `f41eabd4-c172-43e4-ac21-d9f5fc427128`                                                                                                                                                                                                                                                                                                              |
| `solutionId`                 | Int            | Unique Azion ID of the solution, set in the virtual host configuration file. Example: `1441740010`                                                                                                                                                                                                                                                                                                                                                      |
| `sslCipher`                  | String         | Cipher string used to establish the TLS connection. Example: `TLS_AES_256_GCM_SHA384`                                                                                                                                                                                                                                                                                                                                                                   |
| `sslProtocol`                | String         | Protocol of an established TLS connection. Example: `TLS v1.2`                                                                                                                                                                                                                                                                                                                                                                                          |
| `sslServerName`              | String         | Session identifier of an established SSL connection. Example: `mywebsite.com`                                                                                                                                                                                                                                                                                                                                                                           |
| `sslSessionReused`           | String         | `r` if an SSL session was reused, `.` if it was not.                                                                                                                                                                                                                                                                                                                                                                                                    |
| `stacktrace`                 | String         | Names of the Rules Engine rules, from your application or your firewall, that the request runs. Example: `{}`                                                                                                                                                                                                                                                                                                                                           |
| `status`                     | Int            | HTTP status code of the request. Example: `200`                                                                                                                                                                                                                                                                                                                                                                                                         |
| `streamname`                 | String         | ID set in the virtual host configuration file from the location directive. Example: `company_sector.sdp`                                                                                                                                                                                                                                                                                                                                                |
| `tcpinfoRtt`                 | Int            | Round-trip time (RTT) to the client, in microseconds, as Azion measures it. Available on systems that support the `TCP_INFO` socket option. Example: `72052`                                                                                                                                                                                                                                                                                            |
| `ts`                         | CustomDateTime | Timestamp of when the event was created. Example: `2022-10-20T10:10:10`                                                                                                                                                                                                                                                                                                                                                                                 |
| `upstreamAddr`               | String         | IP address and port of the client. It can also hold several servers or server groups. Example: `192.0.2.20:80`. The value `127.0.0.1:1666` means the upstream is [Azion Runtime](/en/documentation/devtools/runtime/).                                                                                                                                                                                                                                  |
| `upstreamAddrStr`            | String         | List of every `upstreamAddr` value.                                                                                                                                                                                                                                                                                                                                                                                                                     |
| `upstreamBytesReceived`      | Int            | Number of bytes Azion received from the origin when the content is not cached. Example: `8304`                                                                                                                                                                                                                                                                                                                                                          |
| `upstreamBytesReceivedStr`   | String         | List of every `upstreamBytesReceived` value.                                                                                                                                                                                                                                                                                                                                                                                                            |
| `upstreamBytesSent`          | BigInt         | Number of bytes sent to the origin. Example: `2733`                                                                                                                                                                                                                                                                                                                                                                                                     |
| `upstreamBytesSentStr`       | String         | List of every `upstreamBytesSent` value.                                                                                                                                                                                                                                                                                                                                                                                                                |
| `upstreamCacheStatus`        | String         | Status of the local cache: `MISS`, `BYPASS`, `EXPIRED`, `STALE`, `UPDATING`, `REVALIDATED`, `HIT`, or `-`                                                                                                                                                                                                                                                                                                                                               |
| `upstreamConnectTime`        | Decimal        | Time Azion takes to establish a connection with the origin, in seconds, including the TLS handshake. Example: `0.123`. The value is `0` for KeepAlive and `-` for cache.                                                                                                                                                                                                                                                                                |
| `upstreamConnectTimeStr`     | String         | List of every `upstreamConnectTime` value.                                                                                                                                                                                                                                                                                                                                                                                                              |
| `upstreamHeaderTime`         | Decimal        | Time Azion takes to receive the response header from the origin, in seconds. Example: `0.345`. For a cached response, the value is `-`.                                                                                                                                                                                                                                                                                                                 |
| `upstreamHeaderTimeStr`      | String         | List of every `upstreamHeaderTime` value.                                                                                                                                                                                                                                                                                                                                                                                                               |
| `upstreamLocalAddr`          | String         | Local IP address Azion uses to connect to the origin server: the outgoing, or source, address toward the upstream. Example: `10.0.12.34`                                                                                                                                                                                                                                                                                                                |
| `upstreamResponseTime`       | Decimal        | Time Azion takes to receive the full response from the origin, headers and body, in seconds. Example: `0.876`. For a cached response, the value is `-`.                                                                                                                                                                                                                                                                                                 |
| `upstreamResponseTimeStr`    | String         | List of every `upstreamResponseTime` value.                                                                                                                                                                                                                                                                                                                                                                                                             |
| `upstreamStatus`             | Int            | HTTP status code of the origin. When no server can be selected, the value is `502` (Bad Gateway). Example: `200`. For a cached response, the value is `-`.                                                                                                                                                                                                                                                                                              |
| `upstreamStatusStr`          | String         | List of every `upstreamStatus` value.                                                                                                                                                                                                                                                                                                                                                                                                                   |
| `virtualhostId`              | String         | Unique ID available in Azion Console, set in the virtual host configuration file. Example: `2410001a`                                                                                                                                                                                                                                                                                                                                                   |
| `wafAttackAction`            | String         | —                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| `wafAttackFamily`            | String         | Category of the attack WAF detected, based on its characteristics. Example: `$SQL`, `$RFI`, `$XSS`, `$OTHERS`                                                                                                                                                                                                                                                                                                                                           |
| `wafBlock`                   | String         | Whether WAF blocked the request: `1` when it did, `0` when it did not. In *Logging* mode, the request is not blocked whatever the value.                                                                                                                                                                                                                                                                                                                |
| `wafEvheaders`               | String         | A base64-encoded string when WAF analyzed the request headers and tagged them as blocked with `$waf_block = 1`, otherwise `-`. Applies in *Logging* and *Blocking* modes.                                                                                                                                                                                                                                                                               |
| `wafLearning`                | String         | Whether WAF runs in *Logging* mode: `1` when it does, `0` when it does not.                                                                                                                                                                                                                                                                                                                                                                             |
| `wafMatch`                   | String         | List of infractions found in the request, as key-value elements: the key is the type of violation, and the value is the string that caused it. Example: `0:1402:HEADERS:cookie`                                                                                                                                                                                                                                                                         |
| `wafScore`                   | String         | Score that increases when the request matches the rules set for WAF: `SQL`, `XSS`, `TRAVERSAL`, `RFI`, or `-`                                                                                                                                                                                                                                                                                                                                           |
| `wafTotalBlocked`            | Int            | Total number of blocked requests. Example: `2`                                                                                                                                                                                                                                                                                                                                                                                                          |
| `wafTotalProcessed`          | Int            | Total number of processed requests. Example: `5`                                                                                                                                                                                                                                                                                                                                                                                                        |

This query returns `sessionid`, `streamname`, and `wafAttackAction` for the three latest requests in a seven-day window:

```graphql
query {
  workloadEvents(limit: 3, filter: { tsRange: {begin: "2026-09-26T14:00:00", end: "2026-10-03T14:00:00"} }, orderBy: [ts_DESC]) {
    ts
    sessionid
    streamname
    wafAttackAction
  }
}
```

A field that does not apply to a request holds `-`:

```json
{
  "data": {
    "workloadEvents": [
      {
        "ts": "2026-10-03T13:34:44Z",
        "sessionid": "-",
        "streamname": "-",
        "wafAttackAction": "-"
      },
      {
        "ts": "2026-10-03T13:16:33Z",
        "sessionid": "-",
        "streamname": "-",
        "wafAttackAction": "-"
      },
      {
        "ts": "2026-10-03T12:53:40Z",
        "sessionid": "-",
        "streamname": "-",
        "wafAttackAction": "-"
      }
    ]
  }
}
```

---

## dnsQueriesEvents (Edge DNS)

`dnsQueriesEvents` holds the DNS query records of [Edge DNS](/en/documentation/platform/edge-dns/). The dataset `edgeDnsQueriesEvents` is deprecated; use `dnsQueriesEvents`, which returns the same records. `idnsQueriesEvents` returns the same records too, and it is listed in its own section on this page.

| Field            | Type           | Description                                                                                                                      |
| ---------------- | -------------- | -------------------------------------------------------------------------------------------------------------------------------- |
| `level`          | String         | Level of the log generator: `ERROR`, `WARN`, `INFO`, `DEBUG`, or `TRACE`                                                         |
| `qtype`          | String         | [Record type](/en/documentation/platform/edge-dns/record-types/) of the query. Example: `PTR`, `A`, `AAAA`, `HTTPS`, `NS`, `SRV` |
| `resolutionType` | String         | Method used to resolve the host. Example: `standard`                                                                             |
| `solutionId`     | String         | Identifier of your Edge DNS instance. Example: `1321`                                                                            |
| `statusCode`     | String         | DNS response code of the query. Example: `NOERROR`                                                                               |
| `ts`             | CustomDateTime | Timestamp of when the event was created. Example: `2022-10-20T10:10:10`                                                          |
| `uuid`           | String         | Unique request identifier. Example: `b204b8c3-e463-4c3d-af3d-025703a4`                                                           |
| `version`        | String         | Example: `v1`                                                                                                                    |
| `zoneId`         | String         | Unique identifier of the Edge DNS zone. Example: `1340`                                                                          |

This query returns the record type, response code, and resolution type of the latest queries in a seven-day window:

```graphql
query {
  dnsQueriesEvents(
    limit: 5
    filter: { tsRange: {begin: "2026-09-26T14:00:00", end: "2026-10-03T14:00:00"} }
    orderBy: [ts_DESC]
  ) {
    ts
    qtype
    statusCode
    resolutionType
  }
}
```

The response holds five records, cut here after the third:

```json
{
  "data": {
    "dnsQueriesEvents": [
      {
        "ts": "2026-10-03T12:53:01Z",
        "qtype": "TXT",
        "statusCode": "NOERROR",
        "resolutionType": "standard"
      },
      {
        "ts": "2026-10-03T11:57:59Z",
        "qtype": "TXT",
        "statusCode": "NOERROR",
        "resolutionType": "standard"
      },
      {
        "ts": "2026-10-03T11:52:57Z",
        "qtype": "TXT",
        "statusCode": "NOERROR",
        "resolutionType": "standard"
      },
      …
    ]
  }
}
```

---

## imagesProcessedEvents (Image Processor)

`imagesProcessedEvents` holds the request records of Image Processor.

| Field                     | Type           | Description                                                                                                                                                                                |
| ------------------------- | -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `bytesSent`               | Int            | Number of bytes sent to the client. This field is the result of a sum. Example: `191`                                                                                                      |
| `configurationId`         | String         | Unique Azion configuration identifier, set in the virtual host configuration file. Example: `1595368520`                                                                                   |
| `host`                    | String         | Host of the request: the host name from the request line, the `Host` request header, or the server name that matched the request. Example: `hello.myhost.net`                              |
| `httpReferer`             | String         | Address of the page the user made the request from. Example: `https://example.com`                                                                                                         |
| `httpUserAgent`           | String         | Application, operating system, vendor, or version of the client, from the `User-Agent` header. Example: `Mozilla/5.0 (Windows NT 10.0; Win64; x64)`                                        |
| `referenceError`          | String         | Reference ID of the request, generated when the status code is higher than 400. Example: `#AECFE66100000000C947B9B3B3BFBE46FFFFFFFF9401`. Can also be `-`                                  |
| `remoteAddr`              | String         | IP address of the origin that generated the request. Example: `127.0.0.1`                                                                                                                  |
| `remotePort`              | Int            | Port of the origin that generated the request. Example: `8080`                                                                                                                             |
| `requestMethod`           | String         | HTTP request method. Example: `GET` or `POST`                                                                                                                                              |
| `requestTime`             | Decimal        | Request processing time, in seconds, counted from the first bytes read from the client. This field is the result of a sum. Example: `0.234`                                                |
| `requestUri`              | String         | URI of the request, with its arguments and without the host and protocol. Example: `/v1?v=bo%20dim`                                                                                        |
| `scheme`                  | String         | Request scheme. Example: `HTTP` or `HTTPS`                                                                                                                                                 |
| `sentHttpContentType`     | String         | `Content-Type` header sent in the origin's response. Example: `text/html; charset=UTF-8`                                                                                                   |
| `serverProtocol`          | String         | Version of the request protocol. Example: `HTTP/1.1`, `HTTP/2.0`, `HTTP/3.0`                                                                                                               |
| `solution`                | Int            | Identifier of your application. Example: `1321`                                                                                                                                            |
| `sslCipher`               | String         | Cipher string used to establish the TLS connection. Example: `TLS_AES_256_GCM_SHA384`                                                                                                      |
| `sslProtocol`             | String         | Protocol of an established TLS connection. Example: `TLS v1.2`                                                                                                                             |
| `sslSessionReused`        | String         | `r` if an SSL session was reused, `.` if it was not.                                                                                                                                       |
| `status`                  | Int            | HTTP status code of the request. Example: `200`                                                                                                                                            |
| `tcpinfoRtt`              | Int            | Round-trip time (RTT) to the client, in microseconds, as Azion measures it. Available on systems that support the `TCP_INFO` socket option. Example: `72052`                               |
| `ts`                      | CustomDateTime | Timestamp of when the event was created. Example: `2022-10-20T10:10:10`                                                                                                                    |
| `upstreamCacheStatus`     | String         | Status of the local cache: `MISS`, `BYPASS`, `EXPIRED`, `STALE`, `UPDATING`, `REVALIDATED`, `HIT`, or `-`                                                                                  |
| `upstreamResponseTime`    | Decimal        | Time Azion takes to receive the full response from the origin, headers and body, in seconds. This field is the result of a sum. Example: `0.876`. For a cached response, the value is `-`. |
| `upstreamResponseTimeStr` | String         | List of every `upstreamResponseTime` value.                                                                                                                                                |
| `upstreamStatus`          | Int            | HTTP status code of the origin. When no server can be selected, the value is `502` (Bad Gateway). Example: `200`. For a cached response, the value is `-`.                                 |
| `upstreamStatusStr`       | String         | List of every `upstreamStatus` value.                                                                                                                                                      |

---

## tieredCacheEvents (Tiered Cache)

`tieredCacheEvents` holds the request records of [Tiered Cache](/en/documentation/platform/applications/cache/tiered-cache/). `l2CacheEvents` serves the same fields, and it is listed in its own section on this page.

| Field                      | Type           | Description                                                                                                                                                              |
| -------------------------- | -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `bytesSent`                | Int            | Number of bytes sent to the client. This field is the result of a sum. Example: `191`                                                                                    |
| `cacheKey`                 | String         | Cache key of the stored object for the content the client requested. Example: `/index.html`                                                                              |
| `cacheTtl`                 | String         | Time, in seconds, the cached object stays valid. After it expires, the next request makes Tiered Cache query the origin (upstream). Example: `31536000`                  |
| `clientId`                 | String         | Unique Azion client identifier. Example: `8437r`                                                                                                                         |
| `configurationId`          | String         | Unique Azion configuration identifier, set in the virtual host configuration file. Example: `1595368520`                                                                 |
| `host`                     | String         | Host of the request: the host name from the request line, the `Host` request header, or the server name that matched the request. Example: `hello.myhost.net`            |
| `proxyHost`                | String         | Host name being proxied. Example: `storage.googleapis.com:443`                                                                                                           |
| `proxyStatus`              | Int            | HTTP error status code, or the origin, when the upstream returns no response. Example: `520`. For a cached response, the value is `-`.                                   |
| `proxyUpstream`            | String         | Address of the origin (upstream). The second origin can be Image Processor, which processes the image before it is cached. Example: `ims_http`                           |
| `referenceError`           | String         | Reference ID of the request, generated when the status code is `4xx` or `5xx`. Example: `#AECFE66100000000C947B9B3B3BFBE46FFFFFFFF9401`. Can also be `-`                 |
| `remoteAddr`               | String         | IP address of the origin that generated the request. Example: `127.0.0.1`                                                                                                |
| `remotePort`               | Int            | Port of the origin that generated the request. Example: `8080`                                                                                                           |
| `requestLength`            | Int            | Length of the request, including the request line, headers, and body. This field is the result of a sum. Example: `167`                                                  |
| `requestMethod`            | String         | HTTP request method. Example: `GET` or `POST`                                                                                                                            |
| `requestTime`              | Decimal        | Request processing time, in seconds, counted from the first bytes read from the client. This field is the result of a sum. Example: `0.234`                              |
| `requestUri`               | String         | URI of the request, with its arguments and without the host and protocol. Example: `/v1?v=bo%20dim`                                                                      |
| `scheme`                   | String         | Request scheme. Example: `HTTP` or `HTTPS`                                                                                                                               |
| `sentHttpContentType`      | String         | `Content-Type` header sent in the origin's response. Example: `text/html; charset=UTF-8`                                                                                 |
| `serverProtocol`           | String         | Version of the request protocol. Example: `HTTP/1.1`, `HTTP/2.0`, `HTTP/3.0`                                                                                             |
| `solution`                 | Int            | Identifier of your application. Example: `1321`                                                                                                                          |
| `status`                   | Int            | HTTP status code of the request. Example: `200`                                                                                                                          |
| `tcpinfoRtt`               | Int            | Round-trip time (RTT) to the client, in microseconds, as Azion measures it. Available on systems that support the `TCP_INFO` socket option. Example: `72052`             |
| `ts`                       | CustomDateTime | Timestamp of when the event was created. Example: `2022-10-20T10:10:10`                                                                                                  |
| `upstreamBytesReceived`    | Int            | Number of bytes Azion received from the origin when the content is not cached. Example: `8304`                                                                           |
| `upstreamBytesReceivedStr` | String         | List of every `upstreamBytesReceived` value.                                                                                                                             |
| `upstreamCacheStatus`      | String         | Status of the local cache: `MISS`, `BYPASS`, `EXPIRED`, `STALE`, `UPDATING`, `REVALIDATED`, `HIT`, or `-`                                                                |
| `upstreamConnectTime`      | Decimal        | Time Azion takes to establish a connection with the origin, in seconds, including the TLS handshake. Example: `0.123`. The value is `0` for KeepAlive and `-` for cache. |
| `upstreamHeaderTime`       | Decimal        | Time Azion takes to receive the response header from the origin, in seconds. Example: `0.345`. For a cached response, the value is `-`.                                  |
| `upstreamResponseTime`     | Decimal        | Time Azion takes to receive the full response from the origin, headers and body, in seconds. Example: `0.876`. For a cached response, the value is `-`.                  |
| `upstreamStatus`           | Int            | HTTP status code of the origin. When no server can be selected, the value is `502` (Bad Gateway). Example: `200`. For a cached response, the value is `-`.               |
| `version`                  | String         | —                                                                                                                                                                        |

---

## telemetryDeviceInfoEvents (Azion Mobile SDK)

`telemetryDeviceInfoEvents` holds the device information that the Azion Mobile SDK collects.

| Field               | Type           | Description                                                                                                                                                                          |
| ------------------- | -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `agent`             | String         | Identifier of the Azion SDK version. Example: `AzionSDK-Android-v0.0.1`                                                                                                              |
| `azionFingerprint`  | String         | Fingerprint generated by the SDK. Example: `1cc48e375c84610c1d90d93f80c03`                                                                                                           |
| `board`             | String         | Name of the development board. Example: `goldfish_arm64`                                                                                                                             |
| `bootloader`        | String         | Version of the system bootloader. Example: `unknown`                                                                                                                                 |
| `clientId`          | String         | Unique Azion client identifier. Example: `8437r`                                                                                                                                     |
| `device`            | String         | Name of the device, such as its codename or model name. Example: `emu64a`                                                                                                            |
| `deviceId`          | String         | Device ID that identifies an Android device. Example: `c2e38e0eb35a62f1`                                                                                                             |
| `displayResolution` | String         | Screen size of an iOS device, in the `[H]x[W]` format. Example: `1179.0x2556.0`                                                                                                      |
| `fingerprint`       | String         | Unique identifier of the build, which usually includes the device and the system version. Example: `google/sdk_gphone64_arm64/emu64a:14/UE1A.230829.030/10921827:userdebug/dev-keys` |
| `hardware`          | String         | Information about the device hardware. Example: `ranch`                                                                                                                              |
| `kernelVersion`     | String         | Kernel version. Example: `6.1.23-android14-4-00257-g7e35917775b8-ab9964412`                                                                                                          |
| `manufacturer`      | String         | Name of the device manufacturer. Example: `Google`                                                                                                                                   |
| `model`             | String         | Device model name. Example: `sdk_gphone64_arm64`                                                                                                                                     |
| `osRelease`         | String         | Operating system release version. Example: `15`                                                                                                                                      |
| `osType`            | String         | Operating system type. Example: `16`                                                                                                                                                 |
| `osVersion`         | String         | Operating system version. Example: `18`                                                                                                                                              |
| `sdkVersion`        | String         | Android SDK version number used to compile the application. Example: `34`                                                                                                            |
| `tags`              | String         | Tags of the Android system build. Example: `dev-keys`                                                                                                                                |
| `ts`                | CustomDateTime | Date and time of the request. Example: `2022-10-20T10:10:10`                                                                                                                         |
| `user`              | String         | Name of the user who made the build. Example: `android-build`                                                                                                                        |
| `version`           | String         | Version of the log. Example: `v2`                                                                                                                                                    |

---

## telemetrySensorsEvents (Azion Mobile SDK)

`telemetrySensorsEvents` holds the sensor readings that the Azion Mobile SDK collects.

| Field              | Type           | Description                                                                       |
| ------------------ | -------------- | --------------------------------------------------------------------------------- |
| `accelTs`          | String         | List of timestamps of the accelerometer readings. Example: `2023-12-14-T00:00:00` |
| `accelX`           | Float          | List of X-axis readings of the accelerometer. Example: `0.1`                      |
| `accelY`           | Float          | List of Y-axis readings of the accelerometer. Example: `0.343`                    |
| `accelZ`           | Float          | List of Z-axis readings of the accelerometer. Example: `0.243`                    |
| `azionFingerprint` | String         | Fingerprint generated by the SDK. Example: `1cc48e375c84610c1d90d93f80c03`        |
| `clientId`         | String         | Unique Azion client identifier. Example: `8437r`                                  |
| `geoLatitude`      | Float          | —                                                                                 |
| `geoLongitude`     | Float          | —                                                                                 |
| `geoTs`            | String         | —                                                                                 |
| `gyroTs`           | String         | List of timestamps of the gyroscope readings. Example: `2023-12-14-T00:00:00`     |
| `gyroX`            | Float          | List of X-axis readings of the gyroscope. Example: `0.1`                          |
| `gyroY`            | Float          | List of Y-axis readings of the gyroscope. Example: `0.343`                        |
| `gyroZ`            | Float          | List of Z-axis readings of the gyroscope. Example: `0.243`                        |
| `touchAction`      | String         | —                                                                                 |
| `touchTs`          | String         | List of timestamps of the touch screen events. Example: `2023-12-14-T00:00:00`    |
| `touchX`           | Float          | List of X-axis readings of the touch screen. Example: `0.343`                     |
| `touchY`           | Float          | List of Y-axis readings of the touch screen. Example: `0.243`                     |
| `ts`               | CustomDateTime | Date and time of the request. Example: `2022-10-20T10:10:10`                      |
| `version`          | String         | Version of the log. Example: `v2`                                                 |

---

## pulseEvents (Edge Pulse)

`pulseEvents` holds the measurements that [Edge Pulse](/en/documentation/platform/edge-pulse/) collects from the browsers of real visitors. The raw table carries the widest set of fields, listed below, and an aggregated table exposes a subset of them. For the catalog as the API serves it, open the Documentation Explorer of the GraphiQL Playground and select the dataset.

| Field             | Type           | Description                                                                  |
| ----------------- | -------------- | ---------------------------------------------------------------------------- |
| `ts`              | CustomDateTime | Date and time of the measurement.                                            |
| `clientId`        | String         | Unique Azion client identifier.                                              |
| `scriptid`        | String         | Identifier of the Edge Pulse script that produced the measurement.           |
| `platform`        | String         | Platform the visitor's browser reports.                                      |
| `browser`         | String         | Browser that performed the measurement.                                      |
| `useragent`       | String         | `User-Agent` the visitor's browser sent.                                     |
| `locationhref`    | String         | Address of the page the measurement was taken on.                            |
| `referrer`        | String         | Address the visitor arrived from.                                            |
| `type`            | String         | Type of the measurement.                                                     |
| `navtype`         | Int            | Navigation type the browser reported for the visit.                          |
| `typenavigate`    | Int            | Navigations the visitor reached by entering the address or following a link. |
| `typereload`      | Int            | Navigations the visitor reached by reloading the page.                       |
| `typebackforward` | Int            | Navigations the visitor reached through browser history.                     |
| `typereserved`    | Int            | Navigations the browser reported under no other type.                        |
| `redirectcount`   | Int            | Redirects the browser followed before the page was served.                   |
| `dns`             | Int            | Time spent resolving the name.                                               |
| `tcp`             | Int            | Time spent opening the connection.                                           |
| `ssl`             | Int            | Time spent on the TLS handshake.                                             |
| `ttfb`            | Int            | Time until the first byte of the response arrived.                           |
| `contentdownload` | Int            | Time spent downloading the content.                                          |
| `networkduration` | Int            | Total time the network part of the visit took.                               |
| `rendertime`      | Int            | Time the browser spent rendering.                                            |
| `pageloadtime`    | Int            | Time until the page finished loading.                                        |
| `rtt`             | Int            | Round-trip time the browser estimated for the connection.                    |
| `downlink`        | Int            | Downlink speed the browser estimated for the connection.                     |
| `effectivetype`   | String         | Connection class the browser reported, such as `4g`.                         |
| `count`           | BigInt         | Number of records an aggregated query matched.                               |
| `sum`             | AggregateType  | Sum of a field, used with the `aggregate` argument.                          |
| `max`             | AggregateType  | Highest value of a field, used with the `aggregate` argument.                |
| `min`             | AggregateType  | Lowest value of a field, used with the `aggregate` argument.                 |
| `avg`             | AggregateType  | Average of a field, used with the `aggregate` argument.                      |

A query takes `filter`, `aggregate`, `groupBy`, `orderBy`, `offset` and `limit`. `offset` defaults to `0` and `limit` defaults to `10`.

---

## l2CacheEvents (Tiered Cache)

`l2CacheEvents` also holds the request records of [Tiered Cache](/en/documentation/platform/applications/cache/tiered-cache/). It serves the same 31 fields as `tieredCacheEvents`, with the same types and descriptions, so the `tieredCacheEvents` table on this page covers it.

---

## idnsQueriesEvents (Edge DNS)

`idnsQueriesEvents` also holds the DNS query records of [Edge DNS](/en/documentation/platform/edge-dns/), and it returns the same records as `dnsQueriesEvents`. It serves the same nine fields, with the same types and descriptions, so the `dnsQueriesEvents` table on this page covers it.

---

## edgePulseEvents (Edge Pulse)

`edgePulseEvents` is deprecated and the schema says so, returning `[DEPRECATED] Use pulseEvents instead. Query Edge Pulse with aggregate options.` It holds the same measurements as `pulseEvents`, so the `pulseEvents` table on this page covers it.

---

## Related resources

- [Datasets and query arguments](/en/documentation/devtools/graphql/features.md): The datasets of each endpoint and the filter, sort, and pagination arguments a query accepts.
- [Queries](/en/documentation/devtools/graphql/queries.md): The query shapes for raw, aggregated, financial, and usage data, each with a sample response.
- [Real-Time Metrics fields](/en/documentation/devtools/graphql/gql-real-time-metrics-fields.md): The fields of the aggregated datasets the metrics endpoint serves.
- [GraphQL API limits](/en/documentation/devtools/graphql/limits.md): The row, field, and retention bounds a query on raw data runs within.
