# Real-Time Metrics fields

The Real-Time Metrics datasets of the GraphQL API hold request data that Azion aggregates into time buckets, served by the metrics endpoint, `https://api.azion.com/v4/metrics/graphql`. Each section of this page lists the fields of one dataset: the name a query selects, the type the schema declares, what the field holds, and an example value. The same fields feed [Real-Time Metrics](/en/documentation/platform/real-time-metrics/) in Azion Console, where some dashboards also offer a `domains` field that lists every domain configured in the account.

A field that is the result of a calculation, such as a sum, is a *calculated field*, and each dataset lists its calculated fields in a table of their own. A deprecated field stays in the schema, and its row names the field that replaces it. To filter, group, and sort on these fields, refer to [Datasets and query arguments](/en/documentation/devtools/graphql/features/).

---

## workloadMetrics

`workloadMetrics` holds the request data of [Applications](/en/documentation/platform/applications/) and of the Web Application Firewall (WAF) of a [firewall](/en/documentation/platform/firewall/), in minute, hour, and day buckets. `httpMetrics` is deprecated; use `workloadMetrics`. The two serve the same fields and return the same rows.

| Field                        | Type           | Description                                                                                                                                                                                                                                   |
| ---------------------------- | -------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `bytesSent`                  | Int            | Number of bytes sent to a client. The value is a sum. Example: `191`                                                                                                                                                                          |
| `configurationId`            | String         | Unique Azion configuration identifier set on the virtual host configuration file. Example: `1595368520`                                                                                                                                       |
| `geolocCountryName`          | String         | Country name resolved from the client IP address. Example: `Canada`                                                                                                                                                                           |
| `geolocRegionName`           | String         | Region or state name resolved from the client IP address. Example: `Parana`                                                                                                                                                                   |
| `host`                       | String         | Host information sent on the request line: the host name from the request line, the host name from the `Host` request header, or the server name that matches the request. Example: `www.example.com`                                         |
| `proxyStatus`                | Int            | HTTP error status code, or the origin, when no response is obtained from the upstream. Example: `500`                                                                                                                                         |
| `remoteAddressClass`         | String         | Class of the IP address of the origin that generated the request. Example: `192.0.2.0/24`                                                                                                                                                     |
| `requestLength`              | Int            | Request length in bytes, including the request line, headers, and body. The value is a sum. Example: `167`                                                                                                                                    |
| `requestMethod`              | String         | HTTP request method. Example: `GET` or `POST`                                                                                                                                                                                                 |
| `requestTime`                | Decimal        | Request processing time, in seconds, since the first bytes were read from the client. The value is a sum. Example: `0.234`                                                                                                                    |
| `requests`                   | Int            | Total amount of requests in the aggregation in use. The value is a sum. Example: `11`                                                                                                                                                         |
| `scheme`                     | String         | Request scheme. Example: `HTTP` or `HTTPS`                                                                                                                                                                                                    |
| `sentHttpXOriginalImageSize` | Int            | The `X-Original-Image-Size` header sent in the origin response, which Image Processor uses to report the original image size. The value is a sum. Example: `987390`                                                                           |
| `serverProtocol`             | String         | Version of the request protocol. Example: `HTTP/1.1`, `HTTP/2.0`, or `HTTP/3.0`                                                                                                                                                               |
| `sourceLocPop`               | String         | Location of the Azion server that received the request. Example: `lax-bso`                                                                                                                                                                    |
| `sslProtocol`                | String         | Protocol of an established TLS connection. Example: `TLS v1.2`                                                                                                                                                                                |
| `status`                     | Int            | HTTP status code of the request. Example: `200`                                                                                                                                                                                               |
| `ts`                         | CustomDateTime | Timestamp of when the event was created. Example: `2026-10-03T13:00:00Z`                                                                                                                                                                      |
| `upstreamBytesReceived`      | Int            | Number of bytes received from the origin when the content is not cached. The value is a sum. Example: `8304`                                                                                                                                  |
| `upstreamCacheStatus`        | String         | Status of the local cache: `MISS`, `BYPASS`, `EXPIRED`, `STALE`, `UPDATING`, `REVALIDATED`, `HIT`, or `-`                                                                                                                                     |
| `upstreamResponseTime`       | Decimal        | Time Azion takes to receive the response from the origin, in seconds, including headers and body. The value is a sum. Example: `0.876`                                                                                                        |
| `upstreamStatus`             | Int            | HTTP status code of the origin. When no server can be selected, the value is `502` (Bad Gateway). Example: `200`                                                                                                                              |
| `wafAttackFamily`            | String         | Category of the attack WAF detected, based on its characteristics. Example: `$SQL`, `$RFI`, `$XSS`, or `$OTHERS`                                                                                                                              |
| `wafBlock`                   | String         | Whether WAF blocked the request: `0` when it did not, and `1` when it did. In the [*Logging* mode](/en/documentation/platform/firewall/waf/scoring-and-modes/), which this dataset calls learning, WAF blocks no request, whatever the value. |
| `wafLearning`                | String         | Whether WAF runs in the *Logging* mode, which the field name calls learning. Returns `0` when it does not, and `1` when it does.                                                                                                              |

### Calculated fields

The calculated fields of `workloadMetrics` are the result of a calculation, such as a sum, over the requests of each bucket:

| Field                               | Type   | Description                                                                                                                                             |
| ----------------------------------- | ------ | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `bandwidthImagesProcessedSavedData` | BigInt | Saved data bandwidth, in bytes, that Image Processor achieved through Azion services. Example: `1026730813`                                             |
| `bandwidthMissedData`               | Float  | Missed data bandwidth rate, in bytes, through Azion services. Example: `3.76`                                                                           |
| `bandwidthOffload`                  | Float  | Percentage of the bandwidth offloaded through Azion services. Example: `85.23`                                                                          |
| `bandwidthSavedData`                | Float  | Saved data bandwidth rate, in bytes, through Azion services. Example: `0.21`                                                                            |
| `bandwidthTotal`                    | Float  | Bandwidth rate, in bytes, through Azion services. Example: `4.21`                                                                                       |
| `dataTransferredIn`                 | Float  | Sum of the request length, in bytes. When the request is not a cache hit, the request length is added once more. Example: `1202`                        |
| `dataTransferredOut`                | Float  | Sum of the bytes sent. When the request is not a cache hit, the upstream bytes sent are added. Example: `6460`                                          |
| `dataTransferredTotal`              | Float  | `dataTransferredIn` plus `dataTransferredOut`, in bytes. Example: `766`                                                                                 |
| `edgeRequestsTotal`                 | BigInt | Deprecated; use `requestsTotal`.                                                                                                                        |
| `edgeRequestsTotalPerSecond`        | Float  | Deprecated; use `requestsTotalPerSecond`.                                                                                                               |
| `httpRequestsTotal`                 | BigInt | Total amount of requests that used the HTTP protocol. Example: `10`                                                                                     |
| `httpsRequestsTotal`                | BigInt | Total amount of requests that used the HTTPS protocol. Example: `120`                                                                                   |
| `missedData`                        | Float  | Total amount of data that was missing and fetched from the origin. Example: `384`                                                                       |
| `missedRequests`                    | Float  | Total amount of requests missed by Azion services. Example: `5`                                                                                         |
| `missedRequestsPerSecond`           | Float  | Total amount of requests missed per second by Azion services. Example: `0.00034`                                                                        |
| `offload`                           | Float  | Percentage of client data delivered by Azion, which saves data. Example: `9.71`                                                                         |
| `requestsHttpMethodGet`             | BigInt | Total amount of requests with the HTTP method `GET`. Example: `18`                                                                                      |
| `requestsHttpMethodHead`            | BigInt | Total amount of requests with the HTTP method `HEAD`. Example: `2`                                                                                      |
| `requestsHttpMethodOthers`          | BigInt | Total amount of requests with other HTTP methods. Example: `3`                                                                                          |
| `requestsHttpMethodPost`            | BigInt | Total amount of requests with the HTTP method `POST`. Example: `6`                                                                                      |
| `requestsOffloaded`                 | Float  | Percentage of client requests delivered by Azion. Example: `50`                                                                                         |
| `requestsPerSecondOffloaded`        | Float  | Percentage of the requests per second offloaded through Azion services. Example: `10`                                                                   |
| `requestsStatusCode200`             | BigInt | Total amount of requests with the HTTP `200` status code. Example: `45`                                                                                 |
| `requestsStatusCode204`             | BigInt | Total amount of requests with the HTTP `204` status code. Example: `20`                                                                                 |
| `requestsStatusCode206`             | BigInt | Total amount of requests with the HTTP `206` status code. Example: `30`                                                                                 |
| `requestsStatusCode2xx`             | BigInt | Total amount of requests with other `2xx` HTTP status codes. Example: `60`                                                                              |
| `requestsStatusCode301`             | BigInt | Total amount of requests with the HTTP `301` status code. Example: `10`                                                                                 |
| `requestsStatusCode302`             | BigInt | Total amount of requests with the HTTP `302` status code. Example: `12`                                                                                 |
| `requestsStatusCode304`             | BigInt | Total amount of requests with the HTTP `304` status code. Example: `5`                                                                                  |
| `requestsStatusCode3xx`             | BigInt | Total amount of requests with other `3xx` HTTP status codes. Example: `30`                                                                              |
| `requestsStatusCode400`             | BigInt | Total amount of requests with the HTTP `400` status code. Example: `24`                                                                                 |
| `requestsStatusCode403`             | BigInt | Total amount of requests with the HTTP `403` status code. Example: `14`                                                                                 |
| `requestsStatusCode404`             | BigInt | Total amount of requests with the HTTP `404` status code. Example: `35`                                                                                 |
| `requestsStatusCode4xx`             | BigInt | Total amount of requests with other `4xx` HTTP status codes. Example: `50`                                                                              |
| `requestsStatusCode500`             | BigInt | Total amount of requests with the HTTP `500` status code. Example: `6`                                                                                  |
| `requestsStatusCode502`             | BigInt | Total amount of requests with the HTTP `502` status code. Example: `18`                                                                                 |
| `requestsStatusCode503`             | BigInt | Total amount of requests with the HTTP `503` status code. Example: `40`                                                                                 |
| `requestsStatusCode5xx`             | BigInt | Total amount of requests with other `5xx` HTTP status codes. Example: `100`                                                                             |
| `requestsTotal`                     | BigInt | Total amount of requests in the application. Example: `23`                                                                                              |
| `requestsTotalPerSecond`            | Float  | Total amount of requests per second in the application. Example: `0.00026`                                                                              |
| `savedData`                         | Float  | Total amount of data saved by Azion services. Example: `8300`                                                                                           |
| `savedRequests`                     | Float  | Total amount of requests saved by Azion services. Example: `18`                                                                                         |
| `savedRequestsPerSecond`            | Float  | Total amount of requests saved per second by Azion services. Example: `11`                                                                              |
| `wafRequestsAllowed`                | BigInt | Total amount of requests WAF allowed. Example: `10`                                                                                                     |
| `wafRequestsBlocked`                | BigInt | Total amount of requests WAF blocked. Example: `4`                                                                                                      |
| `wafRequestsOthersAttacks`          | BigInt | Total amount of requests with other attacks, excluding Cross-site scripting (XSS), Remote File Inclusion (RFI), and SQL Injection threats. Example: `2` |
| `wafRequestsRfiAttacks`             | BigInt | Total amount of requests with a Remote File Inclusion (RFI) attack. Example: `5`                                                                        |
| `wafRequestsSqlAttacks`             | BigInt | Total amount of requests with an SQL Injection attack. Example: `3`                                                                                     |
| `wafRequestsThreat`                 | BigInt | In the *Logging* mode, total amount of requests WAF identified as threats and processed without blocking. Example: `10`                                 |
| `wafRequestsXssAttacks`             | BigInt | Total amount of requests with a Cross-site scripting (XSS) attack. Example: `1`                                                                         |

---

## workloadBreakdownMetrics

`workloadBreakdownMetrics` breaks the request data of Applications down by request attributes, such as path, user agent, and client network, in hour buckets. `httpBreakdownMetrics` is deprecated; use `workloadBreakdownMetrics`. The two serve the same fields and return the same rows.

| Field                 | Type           | Description                                                                                                                                                                                           |
| --------------------- | -------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `geolocAsn`           | String         | Autonomous System Number (ASN) allocation, queried from the MaxMind table. Example: `AS52580 Azion Technologies Ltda.`                                                                                |
| `geolocCountryName`   | String         | Country of the remote client, detected from IP address geolocation. Example: `United States` or `Russian Federation`                                                                                  |
| `geolocRegionName`    | String         | — Example: `Parana`                                                                                                                                                                                   |
| `host`                | String         | Host information sent on the request line: the host name from the request line, the host name from the `Host` request header, or the server name that matches the request. Example: `www.example.com` |
| `httpReferer`         | String         | Address of the page the request was made from. Example: `https://example.com`                                                                                                                         |
| `httpUserAgent`       | String         | Value of the `User-Agent` header: the application, operating system, vendor, or version of the end user. Example: `Mozilla/5.0 (Windows NT 10.0; Win64; x64)`                                         |
| `remoteAddress`       | String         | IP address of the origin that generated the request. Example: `192.0.2.10`                                                                                                                            |
| `requestPath`         | String         | Path of the request made by the end user, without the host, protocol, and arguments. Example: `/v1/application`                                                                                       |
| `sentHttpContentType` | String         | The `Content-Type` header sent in the origin response. Example: `text/html; charset=UTF-8`                                                                                                            |
| `ts`                  | CustomDateTime | Timestamp of when the event was created. Example: `2026-10-03T13:00:00Z`                                                                                                                              |
| `upstreamAddr`        | String         | IP address and port of the upstream. It can also hold several servers or server groups. Example: `192.0.2.1:80`. The value `127.0.0.1:1666` means the upstream is Azion Runtime.                      |

### Calculated fields

The calculated fields of `workloadBreakdownMetrics` are the result of a calculation, such as a sum, over the requests of each bucket:

| Field               | Type | Description                                                                                               |
| ------------------- | ---- | --------------------------------------------------------------------------------------------------------- |
| `blockedRequests`   | Int  | Total amount of blocked requests in the aggregation in use. The value is a sum. Example: `17`             |
| `requests`          | Int  | Total amount of requests in the aggregation in use. The value is a sum. Example: `11`                     |
| `wafThreatRequests` | Int  | Total amount of requests WAF detected and blocked because of identified security threats. Example: `1523` |

---

## tieredCacheMetrics

`tieredCacheMetrics` holds the request data of [Tiered Cache](/en/documentation/platform/applications/cache/tiered-cache/), in minute, hour, and day buckets.

| Field                   | Type           | Description                                                                                                                                                                                           |
| ----------------------- | -------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `bytesSent`             | Int            | Number of bytes sent to a client. The value is a sum. Example: `191`                                                                                                                                  |
| `configurationId`       | String         | Unique Azion configuration identifier set on the virtual host configuration file. Example: `1595368520`                                                                                               |
| `host`                  | String         | Host information sent on the request line: the host name from the request line, the host name from the `Host` request header, or the server name that matches the request. Example: `www.example.com` |
| `proxyStatus`           | Int            | HTTP error status code, or the origin, when no response is obtained from the upstream. Example: `520`                                                                                                 |
| `remoteAddressClass`    | String         | Class of the IP address of the origin that generated the request. Example: `192.0.2.0/24`                                                                                                             |
| `requestLength`         | Int            | Request length in bytes, including the request line, headers, and body. The value is a sum. Example: `167`                                                                                            |
| `requestMethod`         | String         | HTTP request method. Example: `GET` or `POST`                                                                                                                                                         |
| `requestTime`           | Decimal        | Request processing time, in seconds, since the first bytes were read from the client. The value is a sum. Example: `0.234`                                                                            |
| `requests`              | Int            | Total amount of requests in the aggregation in use. The value is a sum. Example: `11`                                                                                                                 |
| `scheme`                | String         | Request scheme. Example: `HTTP` or `HTTPS`                                                                                                                                                            |
| `sourceLocPop`          | String         | Location of the Azion server that received the request. Example: `lax-bso`                                                                                                                            |
| `status`                | Int            | HTTP status code of the request. Example: `200`                                                                                                                                                       |
| `ts`                    | CustomDateTime | Timestamp of when the event was created. Example: `2026-10-03T13:00:00Z`                                                                                                                              |
| `upstreamBytesReceived` | Int            | Number of bytes received from the origin when the content is not cached. The value is a sum. Example: `8304`                                                                                          |
| `upstreamCacheStatus`   | String         | Status of the local cache: `MISS`, `BYPASS`, `EXPIRED`, `STALE`, `UPDATING`, `REVALIDATED`, `HIT`, or `-`                                                                                             |
| `upstreamResponseTime`  | Decimal        | Time Azion takes to receive the response from the origin, in seconds, including headers and body. The value is a sum. Example: `0.876`                                                                |
| `upstreamStatus`        | Int            | HTTP status code of the origin. When no server can be selected, the value is `502` (Bad Gateway). Example: `200`                                                                                      |

### Calculated fields

The calculated fields of `tieredCacheMetrics` are the result of a calculation, such as a sum, over the requests of each bucket:

| Field                  | Type  | Description                                                                                                                      |
| ---------------------- | ----- | -------------------------------------------------------------------------------------------------------------------------------- |
| `dataTransferredIn`    | Float | Sum of the request length, in bytes. When the request is not a cache hit, the request length is added once more. Example: `1202` |
| `dataTransferredOut`   | Float | Sum of the bytes sent. When the request is not a cache hit, the upstream bytes sent are added. Example: `6460`                   |
| `dataTransferredTotal` | Float | `dataTransferredIn` plus `dataTransferredOut`, in bytes. Example: `766`                                                          |
| `offload`              | Float | Percentage of client data delivered by Azion, which saves data. Example: `9.71`                                                  |

---

## functionsMetrics

`functionsMetrics` holds the invocation data of [Functions](/en/documentation/platform/functions/), in minute, hour, and day buckets. `edgeFunctionsMetrics` is deprecated; use `functionsMetrics`. The two serve the same fields.

| Field                         | Type           | Description                                                                                             |
| ----------------------------- | -------------- | ------------------------------------------------------------------------------------------------------- |
| `computeTime`                 | Decimal        | Total execution time of the function, in milliseconds. The value is a sum. Example: `120`               |
| `configurationId`             | String         | Unique Azion configuration identifier set on the virtual host configuration file. Example: `1595368520` |
| `edgeFunctionId`              | String         | Deprecated; use `functionId`.                                                                           |
| `edgeFunctionInstanceId`      | String         | Deprecated; use `functionInstanceId`.                                                                   |
| `edgeFunctionsInstanceIdList` | String         | Deprecated; use `functionsInstanceIdList`.                                                              |
| `functionId`                  | String         | Identifier of your function. Example: `1321`                                                            |
| `functionInstanceId`          | String         | Identifier of your function instance. Example: `10590`                                                  |
| `functionLanguage`            | String         | Language of the function. Example: `javascript`                                                         |
| `functionsInstanceIdList`     | String         | List of the function instances invoked during the request. Example: `10728`                             |
| `initiatorType`               | String         | What started the function: `1` for an application or `2` for a firewall.                                |
| `invocations`                 | Int            | Total amount of invocations. The value is a sum. Example: `8`                                           |
| `sourceLocPop`                | String         | Location of the Azion server that received the request. Example: `lax-bso`                              |
| `ts`                          | CustomDateTime | Timestamp of when the event was created. Example: `2026-10-03T13:00:00Z`                                |

### Calculated fields

The calculated fields of `functionsMetrics` are the result of a calculation, such as a sum, over the invocations of each bucket:

| Field                        | Type   | Description                                                                  |
| ---------------------------- | ------ | ---------------------------------------------------------------------------- |
| `applicationInvocations`     | BigInt | Total amount of invocations of a function from an application. Example: `50` |
| `edgeApplicationInvocations` | BigInt | Deprecated; use `applicationInvocations`.                                    |
| `edgeFirewallInvocations`    | BigInt | Deprecated; use `firewallInvocations`.                                       |
| `firewallInvocations`        | BigInt | Total amount of invocations of a function from a firewall. Example: `30`     |

---

## imagesProcessedMetrics

`imagesProcessedMetrics` holds the request data of [Image Processor](/en/documentation/platform/applications/image-processor/settings/), in minute, hour, and day buckets.

| Field                  | Type           | Description                                                                                                                                                                                           |
| ---------------------- | -------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `bytesSent`            | Int            | Number of bytes sent to a client. The value is a sum. Example: `191`                                                                                                                                  |
| `configurationId`      | String         | Unique Azion configuration identifier set on the virtual host configuration file. Example: `1595368520`                                                                                               |
| `host`                 | String         | Host information sent on the request line: the host name from the request line, the host name from the `Host` request header, or the server name that matches the request. Example: `www.example.com` |
| `remoteAddressClass`   | String         | Class of the IP address of the origin that generated the request. Example: `192.0.2.0/24`                                                                                                             |
| `requestMethod`        | String         | HTTP request method. Example: `GET` or `POST`                                                                                                                                                         |
| `requestTime`          | Decimal        | Request processing time, in seconds, since the first bytes were read from the client. The value is a sum. Example: `0.234`                                                                            |
| `requests`             | Int            | Total amount of requests in the aggregation in use. The value is a sum. Example: `11`                                                                                                                 |
| `scheme`               | String         | Request scheme. Example: `HTTP` or `HTTPS`                                                                                                                                                            |
| `sourceLocPop`         | String         | Location of the Azion server that received the request. Example: `lax-bso`                                                                                                                            |
| `status`               | Int            | HTTP status code of the request. Example: `200`                                                                                                                                                       |
| `ts`                   | CustomDateTime | Timestamp of when the event was created. Example: `2026-10-03T13:00:00Z`                                                                                                                              |
| `upstreamCacheStatus`  | String         | Status of the local cache: `MISS`, `BYPASS`, `EXPIRED`, `STALE`, `UPDATING`, `REVALIDATED`, `HIT`, or `-`                                                                                             |
| `upstreamResponseTime` | Decimal        | Time Azion takes to receive the response from the origin, in seconds, including headers and body. The value is a sum. Example: `0.876`                                                                |
| `upstreamStatus`       | Int            | HTTP status code of the origin. When no server can be selected, the value is `502` (Bad Gateway). Example: `200`                                                                                      |

---

## dnsQueriesMetrics

`dnsQueriesMetrics` holds the query data of [Edge DNS](/en/documentation/platform/edge-dns/), in minute, hour, and day buckets. `edgeDnsQueriesMetrics` is deprecated; use `dnsQueriesMetrics`. The two serve the same fields and return the same rows.

| Field          | Type           | Description                                                                                 |
| -------------- | -------------- | ------------------------------------------------------------------------------------------- |
| `qtype`        | String         | Type of the record the query asks for. Example: `PTR`, `A`, `AAAA`, `HTTPS`, `NS`, or `SRV` |
| `requests`     | Int            | Total amount of requests in the aggregation in use. The value is a sum. Example: `11`       |
| `sourceLocPop` | String         | Location of the Azion server that received the request. Example: `lax-bso`                  |
| `ts`           | CustomDateTime | Timestamp of when the event was created. Example: `2026-10-03T12:00:00Z`                    |
| `zoneId`       | String         | Unique identifier of the Edge DNS zone. Example: `1340`                                     |

---

## dataStreamedMetrics

`dataStreamedMetrics` holds the delivery data of [Data Stream](/en/documentation/platform/data-stream/), in minute, hour, and day buckets.

| Field             | Type           | Description                                                                                                                   |
| ----------------- | -------------- | ----------------------------------------------------------------------------------------------------------------------------- |
| `configurationId` | String         | Unique Azion configuration identifier set on the virtual host configuration file. Example: `1595368520`                       |
| `dataStreamed`    | Int            | Total amount of data streamed to the configured endpoint, in bytes. The value is a sum. Example: `1270`                       |
| `endpointType`    | String         | Type of the endpoint the data stream uses. Example: `S3`                                                                      |
| `requests`        | Int            | Total amount of requests in the aggregation in use. The value is a sum. Example: `11`                                         |
| `sourceLocPop`    | String         | Location of the Azion server that received the request. Example: `lax-bso`                                                    |
| `streamedLines`   | Int            | Total amount of lines streamed to the configured endpoint, with a maximum value of `2000`. The value is a sum. Example: `837` |
| `ts`              | CustomDateTime | Timestamp of when the event was created. Example: `2026-10-02T19:00:00Z`                                                      |

---

## connectedUsersMetrics

`connectedUsersMetrics` holds the session data of [Live Ingest](/en/documentation/platform/connectors/live-ingest/ingestion-and-delivery/), in minute buckets.

| Field  | Type           | Description                                                  |
| ------ | -------------- | ------------------------------------------------------------ |
| `host` | String         | Host the data was collected from.                            |
| `ts`   | CustomDateTime | Timestamp of the data point. Example: `2026-10-03T13:00:00Z` |

### Calculated fields

The calculated fields of `connectedUsersMetrics` count the unique sessions of each bucket:

| Field                 | Type | Description                                        |
| --------------------- | ---- | -------------------------------------------------- |
| `uniqueSessions`      | Int  | Number of unique sessions recorded for the host.   |
| `uniqueSessionsTotal` | Int  | Total unique sessions calculated across all hosts. |

---

## botManagerMetrics

`botManagerMetrics` holds the request data of [Bot Manager](/en/documentation/platform/firewall/bot-manager/bot-scoring/), in minute buckets. The dataset returns data only on an account subscribed to Bot Manager.

| Field               | Type           | Description                                                                                                                                                                                           |
| ------------------- | -------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `action`            | String         | Action Bot Manager ran on a request identified as a bot: `allow`, `deny`, `redirect`, `custom_html`, `drop`, `random_delay`, or `hold_connection`. Example: `deny`                                    |
| `botCategory`       | String         | Bot category identified in the request. Example: `scraping`, `crawling`, or `brute-force`                                                                                                             |
| `botMode`           | String         | Bot protection mode of the request. Example: `Web`                                                                                                                                                    |
| `challengeSolved`   | String         | Whether the bot passed the CAPTCHA challenge: `1` for solved and `0` for not solved.                                                                                                                  |
| `classified`        | String         | Traffic identification: `bad bot`, `good bot`, `legitimate`, or `under evaluation`.                                                                                                                   |
| `geolocCountryName` | String         | Country the bot attack came from. Example: `Brazil`                                                                                                                                                   |
| `geolocRegionName`  | String         | State or region the bot attack came from. Example: `Parana`                                                                                                                                           |
| `host`              | String         | Host information sent on the request line: the host name from the request line, the host name from the `Host` request header, or the server name that matches the request. Example: `www.example.com` |
| `requestMethod`     | String         | HTTP method of the request. Example: `GET`                                                                                                                                                            |
| `sourceLocPop`      | String         | Location of the Azion server that received the request. Example: `lax-bso`                                                                                                                            |
| `ts`                | CustomDateTime | Timestamp of when the event was created. Example: `2026-10-03T13:00:00Z`                                                                                                                              |

The seven values of `action` are the actions Bot Manager can run. For what each one does, such as the `403` response of `deny`, refer to [Arguments](/en/documentation/platform/firewall/bot-manager/arguments/#action).

### Calculated fields

The calculated field of `botManagerMetrics` is a sum over the requests of each bucket:

| Field      | Type | Description                                                                      |
| ---------- | ---- | -------------------------------------------------------------------------------- |
| `requests` | Int  | Total amount of requests Bot Manager analyzed. The value is a sum. Example: `11` |

---

## botManagerBreakdownMetrics

`botManagerBreakdownMetrics` breaks the request data of Bot Manager down by client address and URL, in minute buckets. The dataset returns data only on an account subscribed to Bot Manager.

| Field        | Type           | Description                                                                                                                                                                                           |
| ------------ | -------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `host`       | String         | Host information sent on the request line: the host name from the request line, the host name from the `Host` request header, or the server name that matches the request. Example: `www.example.com` |
| `remoteAddr` | String         | IP address of the origin that generated the request. Example: `192.0.2.10`                                                                                                                            |
| `requestUrl` | String         | URL of the request made by the end user, with the host and the path and without arguments. Example: `www.example.com/v1`                                                                              |
| `ts`         | CustomDateTime | Timestamp of when the event was created. Example: `2026-10-03T13:00:00Z`                                                                                                                              |

### Calculated fields

The calculated fields of `botManagerBreakdownMetrics` count the bot requests of each bucket:

| Field            | Type | Description                                                                        |
| ---------------- | ---- | ---------------------------------------------------------------------------------- |
| `badBotRequests` | Int  | Total amount of requests classified as bad bots. The value is a sum. Example: `12` |
| `botRequests`    | Int  | Total amount of requests classified as bots. The value is a sum. Example: `11`     |
| `uniqRequestUrl` | Int  | Number of distinct URLs that bots requested. Example: `5`                          |

---

## l2CacheMetrics

`l2CacheMetrics` holds the request data of Tiered Cache, in minute, hour, and day buckets, and the schema gives it the same fields as `tieredCacheMetrics`.

| Field                   | Type           | Description                                                                                                                                                                                           |
| ----------------------- | -------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `bytesSent`             | Int            | Number of bytes sent to a client. The value is a sum. Example: `191`                                                                                                                                  |
| `configurationId`       | String         | Unique Azion configuration identifier set on the virtual host configuration file. Example: `1595368520`                                                                                               |
| `host`                  | String         | Host information sent on the request line: the host name from the request line, the host name from the `Host` request header, or the server name that matches the request. Example: `www.example.com` |
| `proxyStatus`           | Int            | HTTP error status code, or the origin, when no response is obtained from the upstream. Example: `520`                                                                                                 |
| `remoteAddressClass`    | String         | Class of the IP address of the origin that generated the request. Example: `192.0.2.0/24`                                                                                                             |
| `requestLength`         | Int            | Request length in bytes, including the request line, headers, and body. The value is a sum. Example: `167`                                                                                            |
| `requestMethod`         | String         | HTTP request method. Example: `GET` or `POST`                                                                                                                                                         |
| `requestTime`           | Decimal        | Request processing time, in seconds, since the first bytes were read from the client. The value is a sum. Example: `0.234`                                                                            |
| `requests`              | Int            | Total amount of requests in the aggregation in use. The value is a sum. Example: `11`                                                                                                                 |
| `scheme`                | String         | Request scheme. Example: `HTTP` or `HTTPS`                                                                                                                                                            |
| `sourceLocPop`          | String         | Location of the Azion server that received the request. Example: `lax-bso`                                                                                                                            |
| `status`                | Int            | HTTP status code of the request. Example: `200`                                                                                                                                                       |
| `ts`                    | CustomDateTime | Timestamp of when the event was created. Example: `2026-10-03T13:00:00Z`                                                                                                                              |
| `upstreamBytesReceived` | Int            | Number of bytes received from the origin when the content is not cached. The value is a sum. Example: `8304`                                                                                          |
| `upstreamCacheStatus`   | String         | Status of the local cache: `MISS`, `BYPASS`, `EXPIRED`, `STALE`, `UPDATING`, `REVALIDATED`, `HIT`, or `-`                                                                                             |
| `upstreamResponseTime`  | Decimal        | Time Azion takes to receive the response from the origin, in seconds, including headers and body. The value is a sum. Example: `0.876`                                                                |
| `upstreamStatus`        | Int            | HTTP status code of the origin. When no server can be selected, the value is `502` (Bad Gateway). Example: `200`                                                                                      |

### Calculated fields

The calculated fields of `l2CacheMetrics` are the result of a calculation, such as a sum, over the requests of each bucket:

| Field                  | Type  | Description                                                                                                                      |
| ---------------------- | ----- | -------------------------------------------------------------------------------------------------------------------------------- |
| `dataTransferredIn`    | Float | Sum of the request length, in bytes. When the request is not a cache hit, the request length is added once more. Example: `1202` |
| `dataTransferredOut`   | Float | Sum of the bytes sent. When the request is not a cache hit, the upstream bytes sent are added. Example: `6460`                   |
| `dataTransferredTotal` | Float | `dataTransferredIn` plus `dataTransferredOut`, in bytes. Example: `766`                                                          |
| `offload`              | Float | Percentage of client data delivered by Azion, which saves data. Example: `9.71`                                                  |

---

## idnsQueriesMetrics

`idnsQueriesMetrics` holds the query data of Edge DNS, in minute, hour, and day buckets. It serves the same fields as `dnsQueriesMetrics` and returns the same rows.

| Field          | Type           | Description                                                                                 |
| -------------- | -------------- | ------------------------------------------------------------------------------------------- |
| `qtype`        | String         | Type of the record the query asks for. Example: `PTR`, `A`, `AAAA`, `HTTPS`, `NS`, or `SRV` |
| `requests`     | Int            | Total amount of requests in the aggregation in use. The value is a sum. Example: `11`       |
| `sourceLocPop` | String         | Location of the Azion server that received the request. Example: `lax-bso`                  |
| `ts`           | CustomDateTime | Timestamp of when the event was created. Example: `2026-10-03T12:00:00Z`                    |
| `zoneId`       | String         | Unique identifier of the Edge DNS zone. Example: `1340`                                     |

The zone field is `zoneId`, with a lowercase `d`. A query that groups by `zoneID` returns `400`, with a `detail` that ends in `Expected type "IdnsQueriesMetricsGroupByFields", found zoneID.`

---

## Related resources

- [Datasets and query arguments](/en/documentation/devtools/graphql/features.md): The datasets of each endpoint and the filter, sort, and pagination arguments a query accepts.
- [Queries](/en/documentation/devtools/graphql/queries.md): The query shape for each kind of data, with the aggregate functions that read the calculated fields.
- [Real-Time Events fields](/en/documentation/devtools/graphql/gql-real-time-events-fields.md): The fields of the raw datasets, one record per request, on the events endpoint.
- [Real-Time Metrics](/en/documentation/platform/real-time-metrics.md): The Azion Console dashboards that read the same datasets.
