---
name: azion-find-the-top-sources-of-waf-threats
description: >-
  List the countries, attack families, and IP addresses that send the most WAF threats to your applications, in Azion Console or with the GraphQL API.
---

# Find the top sources of WAF threats

You can find the countries, attack families, and IP addresses that send the most [WAF](/en/documentation/platform/firewall/#waf) threats in Azion Console or with the GraphQL API. For what each chart on the WAF dashboards measures, refer to [Secure dashboards](/en/documentation/platform/real-time-metrics/secure-dashboards/). For the log of each request WAF flagged, refer to [Real-Time Events](/en/documentation/platform/real-time-events/).

[Real-Time Metrics](/en/documentation/platform/real-time-metrics/) reads these numbers from two datasets. The `httpMetrics` dataset groups the threats by country and by attack family. The `httpBreakdownMetrics` dataset groups them by the IP address that sent them. Every example on this page covers the last 7 days.

---

Select your interface once. The prerequisites and each task below show only that path.

## Prerequisites

- An Azion account. To create one, refer to [Create an account](/en/documentation/fundamentals/creating-account/).
- An [application](/en/documentation/platform/applications/) served by a [workload](/en/documentation/platform/workloads/), with requests in the last 7 days.
- A firewall that runs a WAF rule set on the requests to your application, in *Blocking* or *Logging* mode. To set one up, refer to [Create and apply a WAF rule set](/en/documentation/guides/application-security/firewall-and-waf/create-waf-rule-set/).

**Console**

- Access to Azion Console. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**API**

- A personal token. To create one, refer to [How to manage a personal token](/en/documentation/guides/platform/account-and-billing/personal-tokens/).
- `curl`.

---

## Find the countries

Real-Time Metrics counts the threats by the country each request came from. The WAF dashboard and the `httpMetrics` dataset both carry this count.

**Console**

To find the countries in Azion Console:

1. **Open Real-Time Metrics**

   Access [Azion Console](https://console.azion.com/) > **Real-Time Metrics**.

2. **Select Secure in the category dropdown**

   The **WAF** tab opens on its only dashboard, **Threats**.

3. **Set the range to the last 7 days**

   In the time-range picker, in the **Quick** tab, under **Commonly used**, select **Last 7 days**.

4. **Select Update**

   After the range changes, the **Refresh** button beside the picker reads **Update**.

5. **Read the country charts**

   Find the two **Top WAF Threat Requests by Country** charts.

The bar chart draws one bar per country, with the number of threats WAF blocked from it. The pie shows the share of each country. Both list the 20 countries with the most threats, and both leave out the threats WAF logged without blocking. When WAF blocked no threat in the range, each chart reads `No data available`.

**API**

To find the countries with the GraphQL API, send a `POST` request to `https://api.azion.com/v4/metrics/graphql`. The query groups the `httpMetrics` dataset by `geolocCountryName` and selects three WAF counts for each country.

Replace `[TOKEN VALUE]` with your personal token, and the `begin` and `end` values with the 7 days you want to read:

```bash
curl -X POST 'https://api.azion.com/v4/metrics/graphql' \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Token [TOKEN VALUE]' \
  -d '{"query":"query TopWafThreatSourcesByCountry($begin: DateTime!, $end: DateTime!) { httpMetrics(limit: 10, filter: { tsRange: { begin: $begin, end: $end } }, groupBy: [geolocCountryName], orderBy: [wafRequestsThreat_DESC]) { geolocCountryName wafRequestsThreat wafRequestsBlocked wafRequestsAllowed } }","variables":{"begin":"2026-01-01T12:00:00","end":"2026-01-08T12:00:00"}}'
```

The API answers `200` with one row per country, at most 10:

```json
{
  "data": {
    "httpMetrics": [
      {
        "geolocCountryName": "United States",
        "wafRequestsThreat": 0,
        "wafRequestsBlocked": 0,
        "wafRequestsAllowed": 0
      },
      {
        "geolocCountryName": "Brazil",
        "wafRequestsThreat": 0,
        "wafRequestsBlocked": 0,
        "wafRequestsAllowed": 0
      }
    ]
  }
}
```

Each row holds three counts for one country:

- `wafRequestsBlocked`: threats WAF blocked.
- `wafRequestsThreat`: threats WAF logged without blocking.
- `wafRequestsAllowed`: requests WAF allowed.

The rows run from the highest `wafRequestsThreat` down. To rank the countries by blocked threats, replace `wafRequestsThreat_DESC` with `wafRequestsBlocked_DESC`. A row whose three counts are `0` means WAF reported no request from that country in the range.

For every WAF field of the dataset, refer to [Real-Time Metrics GraphQL fields](/en/documentation/devtools/graphql/gql-real-time-metrics-fields/#workloadmetrics).

---

## Find the attack families

WAF assigns each threat to an attack family, such as SQL injection or cross-site scripting. Real-Time Metrics counts the threats in each family, on the WAF dashboard and in the `httpMetrics` dataset.

**Console**

To find the attack families in Azion Console:

1. **Open Real-Time Metrics**

   Access [Azion Console](https://console.azion.com/) > **Real-Time Metrics**.

2. **Select Secure in the category dropdown**

   The **WAF** tab opens on its only dashboard, **Threats**.

3. **Set the range to the last 7 days**

   In the time-range picker, in the **Quick** tab, under **Commonly used**, select **Last 7 days**.

4. **Select Update**

5. **Read the family chart**

   Find the **WAF Threat Requests by Family Attack** chart.

The chart draws one bar per attack family, with the number of threats WAF blocked in it, for the 10 families with the most. When WAF blocked no threat in the range, the chart reads `No data available`. For what each family name means, refer to [Secure dashboards](/en/documentation/platform/real-time-metrics/secure-dashboards/#waf).

To see which of your hosts received the blocked threats, read **WAF Threat Requests by Host** on the same dashboard. It draws one line per host, up to 16 hosts.

**API**

To find the attack families with the GraphQL API, send a `POST` request to `https://api.azion.com/v4/metrics/graphql`. The query groups the `httpMetrics` dataset by `wafAttackFamily`.

Replace `[TOKEN VALUE]` with your personal token, and the `begin` and `end` values with the 7 days you want to read:

```bash
curl -X POST 'https://api.azion.com/v4/metrics/graphql' \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Token [TOKEN VALUE]' \
  -d '{"query":"query ThreatsByAttackFamily($begin: DateTime!, $end: DateTime!) { httpMetrics(limit: 10, filter: { tsRange: { begin: $begin, end: $end } }, groupBy: [wafAttackFamily], orderBy: [wafRequestsThreat_DESC]) { wafAttackFamily wafRequestsThreat wafRequestsBlocked } }","variables":{"begin":"2026-01-01T12:00:00","end":"2026-01-08T12:00:00"}}'
```

The API answers `200` with one row per attack family, at most 10:

```json
{
  "data": {
    "httpMetrics": [
      {
        "wafAttackFamily": "-",
        "wafRequestsThreat": 0,
        "wafRequestsBlocked": 0
      }
    ]
  }
}
```

Each row counts, for one family, the threats WAF logged without blocking in `wafRequestsThreat` and the threats it blocked in `wafRequestsBlocked`. When WAF identifies no threat in the range, the response holds one row, `"wafAttackFamily": "-"`, with `0` in both counts.

---

## Find the IP addresses

The IP address of a threat is the remote address that sent the request. Only the Threats Breakdown dashboard and the `httpBreakdownMetrics` dataset carry it.

**Console**

To find the IP addresses in Azion Console:

1. **Open Real-Time Metrics**

   Access [Azion Console](https://console.azion.com/) > **Real-Time Metrics**.

2. **Select Secure in the category dropdown**

3. **Select the Threats Breakdown tab**

   The tab opens on its only dashboard, also named **Threats Breakdown**.

4. **Set the range to the last 7 days**

   In the time-range picker, in the **Quick** tab, under **Commonly used**, select **Last 7 days**.

5. **Select Update**

6. **Read the IP chart**

   Find the **Top WAF Threat Requests by IP** chart.

The chart draws one bar per IP address, with the number of requests from it that WAF identified as threats. It lists the 10 addresses with the most. When WAF identified no threat in the range, the chart reads `No data available`.

**API**

To find the IP addresses with the GraphQL API, send a `POST` request to `https://api.azion.com/v4/metrics/graphql`. The query sums `wafThreatRequests` from the `httpBreakdownMetrics` dataset, grouped by `remoteAddress`. The `wafThreatRequestsGt: 0` filter keeps only the addresses that sent threats.

Replace `[TOKEN VALUE]` with your personal token, and the `begin` and `end` values with the 7 days you want to read:

```bash
curl -X POST 'https://api.azion.com/v4/metrics/graphql' \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Token [TOKEN VALUE]' \
  -d '{"query":"query TopWafThreatSourcesByIp($begin: DateTime!, $end: DateTime!) { httpBreakdownMetrics(limit: 10, filter: { tsRange: { begin: $begin, end: $end }, wafThreatRequestsGt: 0 }, aggregate: { sum: wafThreatRequests }, groupBy: [remoteAddress], orderBy: [sum_DESC]) { remoteAddress sum } }","variables":{"begin":"2026-01-01T12:00:00","end":"2026-01-08T12:00:00"}}'
```

The API answers `200` with one row per address, at most 10:

```json
{
  "data": {
    "httpBreakdownMetrics": []
  }
}
```

Each row holds one address in `remoteAddress` and its threat requests in `sum`, from the highest down. An empty array means that no address sent a request WAF identified as a threat in the range. Keep the `wafThreatRequestsGt: 0` filter: without it, the query also returns the busiest addresses with a `sum` of `0`.

For every field of the dataset, refer to [Real-Time Metrics GraphQL fields](/en/documentation/devtools/graphql/gql-real-time-metrics-fields/#workloadbreakdownmetrics).

To act on the sources you found, block the addresses or countries with a [network list](/en/documentation/platform/firewall/network-shield/network-lists/), or adjust the [WAF rule set](/en/documentation/platform/firewall/waf/rules-set/) against the top attack families.

---

## Next steps

- [Secure dashboards](/en/documentation/platform/real-time-metrics/secure-dashboards.md): What each chart on the WAF and Threats Breakdown dashboards counts, and the field that returns it.
- [WAF](/en/documentation/platform/firewall.md#waf): How WAF scores each request against threat families, and where a firewall turns it on.
- [Network lists](/en/documentation/platform/firewall/network-shield/network-lists.md): Group the IP addresses or countries to block in one list that a firewall rule matches.
- [Real-Time Events](/en/documentation/platform/real-time-events.md): Read the log of each request WAF flagged, with its remote address and the WAF match.
