Find the top attacks with GraphQL
Rank the attack families WAF detects on your applications by threat requests, with one GraphQL API query to the metrics endpoint.
You can rank the attack types that WAF detects on your applications, from the most frequent down, with one GraphQL API query. The query reads the workloadMetrics dataset, which helps you follow traffic patterns, spot anomalies, and analyze threats. The deprecated httpMetrics dataset takes the same query and returns the same rows; use workloadMetrics.
To send a GraphQL query for the first time, refer to First steps with the GraphQL API.
Prerequisites
- A personal token. To create one, refer to How to manage a personal token.
- An application whose requests a firewall inspects with a WAF rule set. To set one up, refer to Create and apply a WAF rule set.
Rank the attack families
The metrics endpoint counts the requests WAF flags as threats and groups them by attack family. To get the five most frequent attack families:
Group the workloadMetrics dataset by wafAttackFamily and sort it by wafRequestsThreat, from the highest count down. Set begin and end to the period you want to read:
Each argument shapes the ranking:
| Argument | What it does |
|---|---|
limit | The maximum number of rows the API returns. 5 keeps the five families with the most threat requests. |
filter | The criteria that select the data the query reads. |
tsRange | Inside filter, the period to read, from begin to end. Each value takes the format "YYYY-MM-DDTHH:mm:ss", such as "2024-04-11T00:00:00". |
groupBy | The fields that group the rows. [wafAttackFamily] returns one row per attack family. |
orderBy | The sort order of the rows. [wafRequestsThreat_DESC] puts the highest count first; [wafRequestsThreat_ASC] puts the lowest first. |
Send the query in a POST request to https://api.azion.com/v4/metrics/graphql, with the header Authorization: Token [TOKEN VALUE]. You can also paste it into the GraphiQL Playground at the same URL. For how to open it, refer to GraphiQL Playground.
The API answers with one object per attack family, in the workloadMetrics array:
A row whose wafRequestsThreat is 0 means WAF flagged no request as a threat in the period.
Each object carries the two fields the query selected:
| Field | Value |
|---|---|
wafAttackFamily | The category of attack WAF detected, based on the characteristics of the request, such as $SQL, $XSS, $RFI, or $OTHERS. A group can name several families, such as $SQL, $XSS. |
wafRequestsThreat | The number of requests WAF flagged as threats in that family during the period, such as 216747. |
The rows run from the family with the most threat requests to the one with the fewest, up to the limit you set. For every WAF field of the dataset, refer to Real-Time Metrics fields.