# Data sources and variables

A data source is where the logs of a [Data Stream](/en/documentation/platform/data-stream/) stream come from. Each stream reads one data source, and that choice decides which variables its template can place in a log line. A variable holds one piece of information about an event and belongs to a specific data source.

Azion Console names each data source differently from its API slug. The Console sets it in the **Data Source** field of the **Input** section, and the API in `inputs[0].attributes.data_source`:

| Console option     | API slug            | Carries                                                      | Needs on the account |
| ------------------ | ------------------- | ------------------------------------------------------------ | -------------------- |
| *Activity History* | `activity_history`  | The changes made on the account in Azion Console             | none                 |
| *Applications*     | `workloads`         | The requests made to your applications                       | none                 |
| *Functions*        | `functions_console` | The requests your functions handle and the messages they log | Functions            |
| *WAF Events*       | `waf`               | The requests WAF analyzed                                    | Firewall with WAF    |

In a template's **Data Set**, a variable is written with a leading `$`, such as `$request_id`. The **In preset** column of each table below names the preset templates whose **Data Set** carries the variable, or reads `none`. In the list of streams, the **Source** column shows the API slug rather than the Console option.

The API lists the data sources with a `GET` request:

```bash
curl https://api.azion.com/v4/workspace/stream/data_sources \
  -H "Authorization: Token [TOKEN VALUE]"
```

```json
{
  "count": 4,
  "total_pages": 1,
  "page": 1,
  "page_size": 10,
  "next": null,
  "previous": null,
  "results": [
    { "slug": "activity_history", "name": "Activity History", "active": true },
    { "slug": "workloads", "name": "Workloads", "active": true },
    { "slug": "functions_console", "name": "Functions Console", "active": true },
    { "slug": "waf", "name": "WAF Events", "active": true }
  ]
}
```

Each result carries the `slug` you send in a stream, the API `name`, and `active`. The API `name` reads `Workloads` and `Functions Console` where the Console shows *Applications* and *Functions*. A `data_source` outside the four slugs is refused with `10039`, as listed in [Stream settings](/en/documentation/platform/data-stream/stream-settings/#errors).

---

## Activity History

*Activity History* carries the account's [Activity History](/en/documentation/fundamentals/activity-history/): each change a user makes on the account in Azion Console. These events belong to the account rather than to a workload, so a stream on this data source uses sampling, as described in [Stream settings](/en/documentation/platform/data-stream/stream-settings/#transform).

| Variable                | Description                                                                                           | Example                                                                                                                 | In preset                    |
| ----------------------- | ----------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ---------------------------- |
| `$account_id`           | Identifier of the Azion account.                                                                      | `8437`                                                                                                                  | *Activity History Collector* |
| `$author_email`         | Email address of the Azion Console user who made the change.                                          | `user@example.com`                                                                                                      | *Activity History Collector* |
| `$author_name`          | Name of the Azion Console user who made the change.                                                   | `User name`                                                                                                             | *Activity History Collector* |
| `$client`               | Unique identifier of the Azion customer.                                                              | `4529r`                                                                                                                 | *Activity History Collector* |
| `$comment`              | Comment the user can add when making the change. Optional.                                            | `Changed Rule`                                                                                                          | *Activity History Collector* |
| `$created_at`           | Date and time the resource was created. Use it to filter and sort by creation time.                   | `2026-01-01T12:00:00Z`                                                                                                  | none                         |
| `$parent_resource_id`   | Unique identifier of the parent resource, when there is one.                                          | `1234567890`                                                                                                            | *Activity History Collector* |
| `$parent_resource_name` | Name of the parent resource, when there is one.                                                       | `APIv4`                                                                                                                 | *Activity History Collector* |
| `$parent_resource_type` | Type of the parent resource, when there is one.                                                       | `Application`                                                                                                           | *Activity History Collector* |
| `$referer_header`       | `Referer` header of the page that called the API. Present only when the call comes from an interface. | `https://console.azion.com/applications/edit/1234567890/rules-engine`                                                   | *Activity History Collector* |
| `$remote_port`          | Source port of the request.                                                                           | `80`                                                                                                                    | *Activity History Collector* |
| `$request_data`         | Payload of the request the user sent.                                                                 | `{"id": 123456, "name": "Debug rule", "active": true, …}`                                                               | *Activity History Collector* |
| `$resource_id`          | Unique identifier of the resource created or changed.                                                 | `123456`                                                                                                                | *Activity History Collector* |
| `$resource_name`        | Name of the resource created or changed.                                                              | `Debug rule`                                                                                                            | *Activity History Collector* |
| `$resource_type`        | Type of the resource created or changed.                                                              | `Application Response Rule`                                                                                             | *Activity History Collector* |
| `$time`                 | Date and time of the request.                                                                         | `2026-01-01T12:00:00Z`                                                                                                  | *Activity History Collector* |
| `$title`                | Title of the activity, made of the model name, the resource name, and the type of action.             | `Application Response Rule Debug rule was edited`                                                                       | *Activity History Collector* |
| `$type`                 | Type of action performed in Azion Console.                                                            | `edited`                                                                                                                | *Activity History Collector* |
| `$user_agent`           | `User-Agent` header of the request.                                                                   | `Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36` | *Activity History Collector* |
| `$user_id`              | Unique identifier of the user who made the change.                                                    | `1234`                                                                                                                  | *Activity History Collector* |
| `$user_ip`              | IP address of the user or source that sent the request.                                               | `203.0.113.10`                                                                                                          | *Activity History Collector* |

---

## Applications

*Applications* carries the requests made to your [Applications](/en/documentation/platform/applications/). Its API slug is `workloads`, and a stream on it collects from every [workload](/en/documentation/platform/workloads/) on the account or from a list of workloads, set in [Stream settings](/en/documentation/platform/data-stream/stream-settings/#transform).

Two presets read this data source. *Applications Event Collector* carries 36 variables. *Applications + WAF Event Collector* carries 51. It adds seven WAF variables and `$asn`, `$request_id`, `$server_addr`, `$server_port`, `$session_id`, `$ssl_server_name`, `$ssl_session_reused`, `$stream`, `$upstream_addr`, and `$upstream_bytes_sent`. It leaves out `$upstream_local_addr` and `$version`. To correlate a log line with other records of the same request, use `$request_id`, the unique identifier of the request, which the *Functions* data source also carries.

| Variable                           | Description                                                                                                                                                                                                  | Example                                                                | In preset                                                            |
| ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------- | -------------------------------------------------------------------- |
| `$asn`                             | Autonomous System Number (ASN): a network of IP addresses that one or more operators manage under one routing policy.                                                                                        | `AS52580`                                                              | *Applications + WAF Event Collector*                                 |
| `$bytes_sent`                      | Number of bytes sent to the client.                                                                                                                                                                          | `191`                                                                  | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$client`                          | Unique identifier of the Azion customer.                                                                                                                                                                     | `4529r`                                                                | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$configuration`                   | Unique identifier of the Azion configuration, set in the virtual host configuration file.                                                                                                                    | `1595368520`                                                           | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$country`                         | Country of the client, from IP address geolocation.                                                                                                                                                          | `United States`                                                        | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$host`                            | Host of the request: the host name in the request line, the host name in the `Host` request header, or the server name that matches the request.                                                             | none                                                                   | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$http_referrer`                   | Value of the `Referer` header: the address of the page the request came from.                                                                                                                                | `https://example.com`                                                  | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$http_user_agent`                 | Value of the `User-Agent` header: the application, operating system, vendor, or version of the client.                                                                                                       | `Mozilla/5.0 (Windows NT 10.0; Win64; x64)`                            | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$proxy_status`                    | HTTP error status code, or origin, when the upstream returns no response. `-` when the response comes from cache.                                                                                            | `520`                                                                  | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$remote_addr`                     | IP address that sent the request.                                                                                                                                                                            | none                                                                   | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$remote_port`                     | Remote port that sent the request.                                                                                                                                                                           | none                                                                   | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$request_id`                      | Unique identifier of the request.                                                                                                                                                                            | `5f222ae5938482c32a822dbf15e19f0f`                                     | *Applications + WAF Event Collector*                                 |
| `$request_length`                  | Length of the request, counting the request line, the headers, and the body.                                                                                                                                 | none                                                                   | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$request_method`                  | HTTP method of the request.                                                                                                                                                                                  | `GET`, `POST`                                                          | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$request_time`                    | Time spent processing the request, in seconds, counted from the first bytes read from the client.                                                                                                            | `0.234`                                                                | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$request_uri`                     | URI of the request with its arguments, without the host and the protocol.                                                                                                                                    | `/v1?v=bo%20dim`                                                       | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$requestPath`                     | URI of the request without the query string, the host, and the protocol. For `/jira/plans/48/scenarios/27?vid=320#plan/backlog`, it holds `/jira/plans/48/scenarios/27`.                                     | `/jira/plans/48/scenarios/27`                                          | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$requestQuery`                    | Parameters of the request URI.                                                                                                                                                                               | `vid=320#plan/backlog`                                                 | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$scheme`                          | Scheme of the request.                                                                                                                                                                                       | `HTTP`, `HTTPS`                                                        | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$sent_http_content_type`          | `Content-Type` header of the origin's response.                                                                                                                                                              | `text/html; charset=UTF-8`                                             | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$sent_http_x_original_image_size` | `X-Original-Image-Size` header of the origin's response, which reports the original size of an image.                                                                                                        | `987390`                                                               | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$server_addr`                     | IP address of the server that received the request.                                                                                                                                                          | none                                                                   | *Applications + WAF Event Collector*                                 |
| `$server_port`                     | Port of the server that received the request.                                                                                                                                                                | `443`                                                                  | *Applications + WAF Event Collector*                                 |
| `$server_protocol`                 | Protocol of the request.                                                                                                                                                                                     | `HTTP/1.1`, `HTTP/2.0`, `HTTP/3.0`                                     | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$session_id`                      | Identifier of the session.                                                                                                                                                                                   | none                                                                   | *Applications + WAF Event Collector*                                 |
| `$ssl_cipher`                      | Cipher string used to establish the TLS connection.                                                                                                                                                          | `TLS_AES_256_GCM_SHA384`                                               | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$ssl_protocol`                    | Protocol of the established TLS connection.                                                                                                                                                                  | `TLS v1.2`                                                             | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$ssl_server_name`                 | Server name the client sent when it connected.                                                                                                                                                               | `www.example.com`                                                      | *Applications + WAF Event Collector*                                 |
| `$ssl_session_reused`              | Whether the TLS session was reused: `r` when it was, `.` otherwise.                                                                                                                                          | `r`, `.`                                                               | *Applications + WAF Event Collector*                                 |
| `$state`                           | State of the client, from IP address geolocation.                                                                                                                                                            | `CA`                                                                   | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$status`                          | HTTP status code of the request.                                                                                                                                                                             | `200`                                                                  | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$stream`                          | ID set in the virtual host configuration file, based on the location directive.                                                                                                                              | none                                                                   | *Applications + WAF Event Collector*                                 |
| `$tcpinfo_rtt`                     | Round-trip time (RTT) to the client, in microseconds, measured by Azion. Available on systems that support the `TCP_INFO` socket option.                                                                     | `72052`                                                                | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$time`                            | Date and time of the request.                                                                                                                                                                                | `Oct. 31st, 2022 - 19:30:41`                                           | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$traceback`                       | Names of the Rules Engine rules of the application and of the firewall that ran on the request. Needs **Debug Rules** on the application.                                                                    | none                                                                   | none                                                                 |
| `$upstream_addr`                   | Address and port of the server, or servers, the request was sent to. Can hold several servers or server groups. `127.0.0.1:1666` means the upstream is [Azion Runtime](/en/documentation/devtools/runtime/). | `192.168.1.1:80`                                                       | *Applications + WAF Event Collector*                                 |
| `$upstream_bytes_received`         | Number of bytes received from the origin when the content is not cached.                                                                                                                                     | `8304`                                                                 | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$upstream_bytes_sent`             | Number of bytes sent to the origin.                                                                                                                                                                          | `2733`                                                                 | *Applications + WAF Event Collector*                                 |
| `$upstream_cache_status`           | Status of the local cache.                                                                                                                                                                                   | `MISS`, `BYPASS`, `EXPIRED`, `STALE`, `UPDATING`, `REVALIDATED`, `HIT` | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$upstream_connect_time`           | Time spent connecting to the origin, in seconds, including the TLS handshake. `0` for a KeepAlive connection, `-` when the response comes from cache.                                                        | `0.123`                                                                | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$upstream_header_time`            | Time spent receiving the response header from the origin, in seconds. `-` when the response comes from cache.                                                                                                | `0.345`                                                                | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$upstream_local_addr`             | Local IP address Azion uses to connect to the origin server: the outgoing (source) IP toward the upstream.                                                                                                   | `10.0.12.34`                                                           | *Applications Event Collector*                                       |
| `$upstream_response_time`          | Time spent receiving the full response from the origin, headers and body, in seconds. `-` when the response comes from cache.                                                                                | `0.876`                                                                | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$upstream_status`                 | HTTP status code of the origin. Keeps `502` (Bad Gateway) when no server can be selected. `-` when the response comes from cache.                                                                            | `200`                                                                  | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$version`                         | Azion Log version.                                                                                                                                                                                           | `v5`                                                                   | *Applications Event Collector*                                       |
| `$waf_attack_action`               | Action WAF took on the request.                                                                                                                                                                              | `$BLOCK`, `$PASS`, `$LEARNING_BLOCK`, `$LEARNING_PASS`                 | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$waf_attack_family`               | Class of the WAF infraction found in the request.                                                                                                                                                            | `SQL`, `XSS`, `TRAVERSAL`                                              | *Applications Event Collector*, *Applications + WAF Event Collector* |
| `$waf_block`                       | Whether WAF blocked the request: `1` when it did, `0` when it did not. While `$waf_learning` is `1`, no request is blocked, whatever this value.                                                             | `0`, `1`                                                               | *Applications + WAF Event Collector*                                 |
| `$waf_headers`                     | Base64 string of the request headers when WAF tags them as blocked, with `$waf_block` at `1`. `-` otherwise. Applies whatever the WAF mode.                                                                  | `-`                                                                    | *Applications + WAF Event Collector*                                 |
| `$waf_learning`                    | Learning flag of WAF. While it is `1`, WAF blocks no request.                                                                                                                                                | `0`, `1`                                                               | *Applications + WAF Event Collector*                                 |
| `$waf_match`                       | Infractions found in the request, as key-value pairs: the key is the type of violation, and the value is the string that caused it.                                                                          | none                                                                   | *Applications + WAF Event Collector*                                 |
| `$waf_score`                       | Score added when the request matches the rules set for WAF.                                                                                                                                                  | none                                                                   | *Applications + WAF Event Collector*                                 |
| `$waf_total_blocked`               | Total number of blocked requests.                                                                                                                                                                            | none                                                                   | *Applications + WAF Event Collector*                                 |
| `$waf_total_processed`             | Total number of processed requests.                                                                                                                                                                          | none                                                                   | *Applications + WAF Event Collector*                                 |

### Several values in one field

Six variables can hold more than one value, one per connection the request opened: `$upstream_bytes_received`, `$upstream_cache_status`, `$upstream_connect_time`, `$upstream_header_time`, `$upstream_response_time`, and `$upstream_status`. A request opens several connections when it is redirected internally, or when [Load Balancer](/en/documentation/platform/connectors/load-balancer/balancing-methods/) chooses another origin. `$upstream_addr` lists the servers the same way. Two separators split the values:

- A comma separates the servers contacted while processing the request, such as `192.168.1.1:80, 192.168.1.2:80`.
- A colon marks an internal redirect from one server group to another, started by *X-Accel-Redirect* or by *Error Responses*, such as `192.168.1.1:80, 192.168.1.2:80, unix:/tmp/sock : 192.168.10.1:80, 192.168.10.2:80`.

When no server can be selected, `$upstream_addr` keeps the name of the server group, and `$upstream_status` keeps `502`.

Read the values as transitions of the connection: the last value is usually the one that matters most. With *Error Responses* set for status `502` on an application, the upstream fields carry two values, typically `502 : 200`. The first try to fetch the content from the origin returned `502`, so Azion requested the URI set in *Error Responses* and delivered that page with `200`. Every upstream field keeps the values in the same positions.

### Values served from cache

When the response comes from cache, `$proxy_status`, `$upstream_connect_time`, `$upstream_header_time`, `$upstream_response_time`, and `$upstream_status` hold `-`. `$upstream_connect_time` holds `0` for a KeepAlive connection, and `$upstream_bytes_received` counts bytes only when the content is not cached.

### Rules a request ran

No preset carries `$traceback`. To receive it, use a custom template on the *Applications* data source with `$traceback` in its **Data Set**, and turn on [Debug Rules](/en/documentation/platform/applications/main-settings/#debug-rules) on the application.

The value groups the rule names by where they ran. `edge_application_request` holds the Request Phase rules of the application, `edge_application_response` holds its Response Phase rules, and `edge_firewall` holds the rules of the firewall. A request that passed through a firewall and an application can carry all three keys. A firewall rule that applies WAF lets the other rules of the firewall run alongside it, so the value can list more firewall rules for a request WAF blocked, and the block still applies.

---

## Functions

*Functions* carries the requests your [Functions](/en/documentation/platform/functions/) handle, with the messages each function writes to the log. Its API slug is `functions_console`, and the data source needs Functions on the account.

The *Functions Event Collector* preset carries all eight variables, but places six of them under keys with other names, such as `edgeFunctionID` for `$edge_function_id`. For each key, refer to [Templates and payload](/en/documentation/platform/data-stream/templates-and-payload/#preset-templates).

| Variable            | Description                                                                                                  | Example                                   | In preset                   |
| ------------------- | ------------------------------------------------------------------------------------------------------------ | ----------------------------------------- | --------------------------- |
| `$client`           | Unique identifier of the Azion customer.                                                                     | `4529r`                                   | *Functions Event Collector* |
| `$edge_function_id` | Identifier of the function.                                                                                  | `1321`                                    | *Functions Event Collector* |
| `$global_id`        | Identifier of the settings.                                                                                  | none                                      | *Functions Event Collector* |
| `$log_level`        | Level of the log.                                                                                            | `ERROR`, `WARN`, `INFO`, `DEBUG`, `TRACE` | *Functions Event Collector* |
| `$log_message`      | Message passed to the log function. You write it to identify and report a behavior.                          | none                                      | *Functions Event Collector* |
| `$message_source`   | Source of the message: `CONSOLE` for a message generated by the Console API, `RUNTIME` for an error message. | `CONSOLE`, `RUNTIME`                      | *Functions Event Collector* |
| `$request_id`       | Unique identifier of the request.                                                                            | `5f222ae5938482c32a822dbf15e19f0f`        | *Functions Event Collector* |
| `$time`             | Date and time of the request.                                                                                | `Oct. 31st, 2022 - 19:30:41`              | *Functions Event Collector* |

---

## WAF Events

*WAF Events* carries the requests WAF analyzed, so you can map the score each request received, the WAF rules it matched, and the reason it was blocked. Its API slug is `waf`, and the data source needs [Firewall](/en/documentation/platform/firewall/) with WAF on the account.

The *WAF Event Collector* preset does not carry `$headers`: it sends the literal `-` under its `headers` key.

| Variable             | Description                                                                                                                                                              | Example                                                | In preset             |
| -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------ | --------------------- |
| `$blocked`           | Whether WAF blocked the request: `1` when it did, `0` when it did not. While `$waf_learning` is `1`, no request is blocked, whatever this value.                         | `0`, `1`                                               | *WAF Event Collector* |
| `$client`            | Unique identifier of the Azion customer.                                                                                                                                 | `4529r`                                                | *WAF Event Collector* |
| `$configuration`     | Unique identifier of the Azion configuration, set in the virtual host configuration file.                                                                                | `1595368520`                                           | *WAF Event Collector* |
| `$country`           | Country of the client, from IP address geolocation.                                                                                                                      | `United States`                                        | *WAF Event Collector* |
| `$headers`           | Base64 string of the request headers when WAF blocked the request. `-` otherwise.                                                                                        | `-`                                                    | none                  |
| `$host`              | Host of the request: the host name in the request line, the host name in the `Host` request header, or the server name that matches the request.                         | none                                                   | *WAF Event Collector* |
| `$remote_addr`       | IP address that sent the request.                                                                                                                                        | none                                                   | *WAF Event Collector* |
| `$requestPath`       | URI of the request without the query string, the host, and the protocol. For `/jira/plans/48/scenarios/27?vid=320#plan/backlog`, it holds `/jira/plans/48/scenarios/27`. | `/jira/plans/48/scenarios/27`                          | *WAF Event Collector* |
| `$requestQuery`      | Parameters of the request URI.                                                                                                                                           | `vid=320#plan/backlog`                                 | *WAF Event Collector* |
| `$server_protocol`   | Protocol of the request.                                                                                                                                                 | `HTTP/1.1`, `HTTP/2.0`, `HTTP/3.0`                     | *WAF Event Collector* |
| `$time`              | Date and time of the request.                                                                                                                                            | `Oct. 31st, 2022 - 19:30:41`                           | *WAF Event Collector* |
| `$truncated_body`    | Deprecated. Holds `-` and no value.                                                                                                                                      | `-`                                                    | *WAF Event Collector* |
| `$version`           | Azion Log version.                                                                                                                                                       | `v5`                                                   | *WAF Event Collector* |
| `$waf_args`          | Arguments of the request.                                                                                                                                                | none                                                   | *WAF Event Collector* |
| `$waf_attack_action` | Action WAF took on the request.                                                                                                                                          | `$BLOCK`, `$PASS`, `$LEARNING_BLOCK`, `$LEARNING_PASS` | *WAF Event Collector* |
| `$waf_attack_family` | Class of the WAF infraction found in the request.                                                                                                                        | `SQL`, `XSS`, `TRAVERSAL`                              | *WAF Event Collector* |
| `$waf_learning`      | Learning flag of WAF. While it is `1`, WAF blocks no request.                                                                                                            | `0`, `1`                                               | *WAF Event Collector* |
| `$waf_match`         | Infractions found in the request, as key-value pairs: the key is the type of violation, and the value is the string that caused it.                                      | none                                                   | *WAF Event Collector* |
| `$waf_score`         | Score added when the request matches the rules set for WAF.                                                                                                              | none                                                   | *WAF Event Collector* |
| `$waf_server`        | Host name of the request WAF analyzed.                                                                                                                                   | `api-login.azion.com.br`                               | *WAF Event Collector* |
| `$waf_uri`           | URI of the request WAF analyzed.                                                                                                                                         | `/access/v2/after-login`                               | *WAF Event Collector* |

---

## Related resources

- [Stream settings](/en/documentation/platform/data-stream/stream-settings.md#input): The Input field that picks the data source, and the transforms that scope a stream to workloads or sample its events.
- [Templates and payload](/en/documentation/platform/data-stream/templates-and-payload.md): The keys each preset template sends, and how a custom template places these variables in a log line.
- [Debug rules created with Rules Engine](/en/documentation/guides/application-development/getting-started/debug-rules.md): The steps to turn on Debug Rules and receive the rules each request ran in `$traceback`.
- [How Data Stream works](/en/documentation/platform/data-stream/how-it-works.md): The path an event follows from its data source, through the template, to the endpoint.
