---
name: azion-find-the-top-attacks-with-graphql
description: >-
  Rank the attack families WAF detects on your applications by threat requests, with one GraphQL API query to the metrics endpoint.
---

# Find the top attacks with GraphQL

You can rank the attack types that [WAF](/en/documentation/platform/firewall/#waf) detects on your applications, from the most frequent down, with one GraphQL API query. The query reads the `workloadMetrics` dataset, which helps you follow traffic patterns, spot anomalies, and analyze threats. The deprecated `httpMetrics` dataset takes the same query and returns the same rows; use `workloadMetrics`.

To send a GraphQL query for the first time, refer to [First steps with the GraphQL API](/en/documentation/devtools/graphql/first-steps/).

---

## Prerequisites

- A personal token. To create one, refer to [How to manage a personal token](/en/documentation/guides/platform/account-and-billing/personal-tokens/).
- An application whose requests a firewall inspects with a WAF rule set. To set one up, refer to [Create and apply a WAF rule set](/en/documentation/guides/application-security/firewall-and-waf/create-waf-rule-set/).

---

## Rank the attack families

The metrics endpoint counts the requests WAF flags as threats and groups them by attack family. To get the five most frequent attack families:

1. **Write the query**

   Group the `workloadMetrics` dataset by `wafAttackFamily` and sort it by `wafRequestsThreat`, from the highest count down. Set `begin` and `end` to the period you want to read:

   ```graphql
   query Top5Attacks {
     workloadMetrics(
       limit: 5
       filter: {
         tsRange: {
           begin:"2026-09-26T14:00:00"
           end:"2026-10-03T14:00:00"
         }
       }
       groupBy:[wafAttackFamily]
       orderBy:[wafRequestsThreat_DESC]
     )
     {
       wafAttackFamily
       wafRequestsThreat
     }
   }
   ```

   Each argument shapes the ranking:

   | Argument  | What it does                                                                                                                                      |
   | --------- | ------------------------------------------------------------------------------------------------------------------------------------------------- |
   | `limit`   | The maximum number of rows the API returns. `5` keeps the five families with the most threat requests.                                            |
   | `filter`  | The criteria that select the data the query reads.                                                                                                |
   | `tsRange` | Inside `filter`, the period to read, from `begin` to `end`. Each value takes the format `"YYYY-MM-DDTHH:mm:ss"`, such as `"2024-04-11T00:00:00"`. |
   | `groupBy` | The fields that group the rows. `[wafAttackFamily]` returns one row per attack family.                                                            |
   | `orderBy` | The sort order of the rows. `[wafRequestsThreat_DESC]` puts the highest count first; `[wafRequestsThreat_ASC]` puts the lowest first.             |

2. **Send the query to the metrics endpoint**

   Send the query in a `POST` request to `https://api.azion.com/v4/metrics/graphql`, with the header `Authorization: Token [TOKEN VALUE]`. You can also paste it into the GraphiQL Playground at the same URL. For how to open it, refer to [GraphiQL Playground](/en/documentation/devtools/graphql/graphql-playground/).

3. **Read the ranking**

   The API answers with one object per attack family, in the `workloadMetrics` array:

   ```json
   {
     "data": {
       "workloadMetrics": [
         {
           "wafAttackFamily": "-",
           "wafRequestsThreat": 0
         }
       ]
     }
   }
   ```

   A row whose `wafRequestsThreat` is `0` means WAF flagged no request as a threat in the period.

   Each object carries the two fields the query selected:

   | Field               | Value                                                                                                                                                                                    |
   | ------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | `wafAttackFamily`   | The category of attack WAF detected, based on the characteristics of the request, such as `$SQL`, `$XSS`, `$RFI`, or `$OTHERS`. A group can name several families, such as `$SQL, $XSS`. |
   | `wafRequestsThreat` | The number of requests WAF flagged as threats in that family during the period, such as `216747`.                                                                                        |

The rows run from the family with the most threat requests to the one with the fewest, up to the `limit` you set. For every WAF field of the dataset, refer to [Real-Time Metrics fields](/en/documentation/devtools/graphql/gql-real-time-metrics-fields/).

---

## Next steps

- [Find the IPs behind attack traffic](/en/documentation/guides/platform/observability/query-top-ips-attack-traffic-with-graphql.md): List the client addresses that send the requests WAF flags.
- [Find the top sources of WAF threats](/en/documentation/guides/platform/observability/find-top-waf-threat-sources.md): Rank threats by country, family, and IP address in Console or the API.
- [Real-Time Metrics fields](/en/documentation/devtools/graphql/gql-real-time-metrics-fields.md): Look up every field of the workloadMetrics dataset.
- [Datasets and query arguments](/en/documentation/devtools/graphql/features.md): Filter, group, sort, and page through any dataset.
