# Glossary

This glossary defines the terms that [Real-Time Metrics](/en/documentation/platform/real-time-metrics/) uses on its dashboards in Azion Console and in its GraphQL API.

| Term                   | Definition                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| aggregation tag        | The tag under a chart's description that names how the chart combines the values it plots: **Sum** adds them, and **Average** averages them. The legend total follows the same rule, so on an **Average** chart it is divided by the number of points. [Filters and time range](/en/documentation/platform/real-time-metrics/filters-and-time-range/) describes every part of a chart card.                                                                                                                                                                                                                                                                                                                  |
| at-most-once           | The counting approach of Real-Time Metrics, which favors performance: each event is counted once or not at all. Billing uses an exactly-once approach and counts each event precisely once, so the two can differ, and Billing is the figure to trust. [Real-Time Info and Precise Billing](/en/documentation/fundamentals/billing-and-subscriptions/#real-time-info-and-precise-billing) compares the two approaches.                                                                                                                                                                                                                                                                                       |
| Azion Query Language   | The syntax of the query input in the filter row, where you write a condition as a field, an operator, and a value separated by spaces, such as `status = 200`, and join conditions with `and`. A field name of two or more words goes in quotes, such as `"Upstream Status"`. [Filters and time range](/en/documentation/platform/real-time-metrics/filters-and-time-range/) lists the operators and the validation messages.                                                                                                                                                                                                                                                                                |
| bot                    | A request that shows the non-human characteristics of a [bot](https://www.azion.com/en/learning/bots/what-is-a-bot/): abnormal patterns, missing or unusual headers, a suspicious user-agent string, an IP address with a malicious history, a failed challenge such as a CAPTCHA, or signs of an automation tool. [Bot Manager](/en/documentation/platform/firewall/#bot-manager) classifies a bot as *Good Bot*, such as a search engine crawler, which is allowed, or *Bad Bot*, which scrapes data, launches attacks, or overloads systems. [Secure dashboards](/en/documentation/platform/real-time-metrics/secure-dashboards/) charts both classes, with *Legitimate* and *Under Evaluation* requests. |
| category               | The top-level grouping of Real-Time Metrics dashboards, selected in the category dropdown: **Build**, **Secure**, or **Observe**. A category holds product tabs, and a product tab holds one or more dashboards. [Build dashboards](/en/documentation/platform/real-time-metrics/build-dashboards/), [Secure dashboards](/en/documentation/platform/real-time-metrics/secure-dashboards/), and [Observe dashboards](/en/documentation/platform/real-time-metrics/observe-dashboards/) document one category each.                                                                                                                                                                                            |
| dashboard              | A set of charts that Real-Time Metrics shows together for one product, such as **Data Transferred** on the **Applications** tab. Every chart on a dashboard reads the same dataset, and a product with more than one dashboard shows a selector to switch between them. [Build dashboards](/en/documentation/platform/real-time-metrics/build-dashboards/) lists each Build dashboard and its charts.                                                                                                                                                                                                                                                                                                        |
| Data Transferred In    | The series that counts data traveling from the client toward the origin: from the client to the data center, then from the data center to the origin. With [Tiered Cache](/en/documentation/platform/applications/cache/tiered-cache/) on, that second leg ends at the Tiered Cache layer instead. The **Edge Cache** chart of the **Data Transferred** dashboard plots it from the `dataTransferredIn` field.                                                                                                                                                                                                                                                                                               |
| Data Transferred Out   | The series that counts data traveling from the origin toward the client: from the origin to the data center, then from the data center to the client. With [Tiered Cache](/en/documentation/platform/applications/cache/tiered-cache/) on, that first leg starts at the Tiered Cache layer instead. The **Edge Cache** chart of the **Data Transferred** dashboard plots it from the `dataTransferredOut` field.                                                                                                                                                                                                                                                                                             |
| Data Transferred Total | The sum of Data Transferred In and Data Transferred Out, in bytes, plotted from the `dataTransferredTotal` field. It measures volume over the range, while bandwidth, as in **Total Bandwidth Usage**, measures the content your application delivers every second, in bits per second. Saved data counts only the bytes delivered without a trip to the origin, and [Build dashboards](/en/documentation/platform/real-time-metrics/build-dashboards/) documents all three charts.                                                                                                                                                                                                                          |
| dataset                | A named collection of aggregated metrics that the GraphQL API exposes, such as `httpMetrics`, which holds the request events of Applications and Firewall. Each dashboard reads one dataset, and each chart on it queries fields of that dataset, as the query that **Copy query** copies to the clipboard shows. [Real-Time Metrics GraphQL fields](/en/documentation/devtools/graphql/gql-real-time-metrics-fields/) lists every dataset and its fields.                                                                                                                                                                                                                                                   |
| mean line              | A line that a time chart can overlay at the average of its points: the sum of the points divided by their number, for that chart and range. **Show Mean Line** draws one line for the chart, and **Show Mean Line per series** draws one line per series on a chart with two or more series. [Filters and time range](/en/documentation/platform/real-time-metrics/filters-and-time-range/) describes the chart menu.                                                                                                                                                                                                                                                                                        |
| metric                 | An aggregated value that Real-Time Metrics computes from the events a product generates, such as a count of requests or of bytes per time bucket, and plots on a chart. The raw events behind a metric are in Real-Time Events. The [Learning Center](https://www.azion.com/en/learning/observability/what-are-metrics/) covers metrics in general.                                                                                                                                                                                                                                                                                                                                                          |
| missed data            | Data that the data center delivered to the client after fetching the content from the origin, because the content was not in [cache](https://www.azion.com/en/learning/cdn/what-is-caching/): client → data center → origin → data center → client. The **Missed Data** chart sums it in bytes from the `missedData` field, and **Missed Requests** and **Missed Bandwidth** count the same case by requests and by bandwidth. [Build dashboards](/en/documentation/platform/real-time-metrics/build-dashboards/) documents the three charts.                                                                                                                                                                |
| offload                | The percentage of content that the data center delivered to the client without fetching it from the origin, charted on [Build dashboards](/en/documentation/platform/real-time-metrics/build-dashboards/). Real-Time Metrics reports it by data in **Edge Offload**, by requests in **Requests Offloaded**, and by bandwidth in **Bandwidth Offloaded**. **Tiered Cache Offload** reports the share of data that the Tiered Cache layer delivered without fetching it from the origin.                                                                                                                                                                                                                       |
| Real-Time Events       | The Observe product that holds the raw events products generate, such as the log of each request, while Real-Time Metrics shows those events aggregated into metrics over time. Use it to inspect the individual requests behind a change on a chart. [Real-Time Events](/en/documentation/platform/real-time-events/) documents the product.                                                                                                                                                                                                                                                                                                                                                                |
| request                | One access to your application's content: Real-Time Metrics counts each access as one request. The **Total Requests** chart splits requests into **Http Requests Total** and **Https Requests Total**, and **Edge Requests Total** is their sum. [Build dashboards](/en/documentation/platform/real-time-metrics/build-dashboards/) documents every request chart.                                                                                                                                                                                                                                                                                                                                           |
| Request Breakdown      | The fifth dashboard of the **Applications** tab, and the only one that reads the `httpBreakdownMetrics` dataset instead of `httpMetrics`. Its **IP Address Information** table distributes requests by remote address, ASN, country, and region. [Build dashboards](/en/documentation/platform/real-time-metrics/build-dashboards/) documents the table.                                                                                                                                                                                                                                                                                                                                                     |
| resolution             | The length of time that each point on a time chart covers: a minute, an hour, or a day. Real-Time Metrics picks it from the length of the selected range, not from the age of the data, so a longer range plots fewer and wider points. [How Real-Time Metrics works](/en/documentation/platform/real-time-metrics/how-it-works/) gives the range lengths that switch it.                                                                                                                                                                                                                                                                                                                                    |
| saved data             | Data that the data center delivered to the client from cache, without fetching the content from the origin: client → data center → client. The **Saved Data** chart sums it in bytes from the `savedData` field, and **Saved Requests** and **Saved Bandwidth** count the same case by requests and by bandwidth. Offload expresses the same case as a percentage, and [Build dashboards](/en/documentation/platform/real-time-metrics/build-dashboards/) documents each chart.                                                                                                                                                                                                                              |
| series                 | One line, bar, or slice of a chart, representing one category of data, such as one domain on a chart of requests over time. A chart can show several series, and the legend lists each one with its total over the range. [Filters and time range](/en/documentation/platform/real-time-metrics/filters-and-time-range/) describes the legend.                                                                                                                                                                                                                                                                                                                                                               |
| threat                 | A request that [WAF](/en/documentation/platform/firewall/#waf) identifies as an attack, which [Secure dashboards](/en/documentation/platform/real-time-metrics/secure-dashboards/) counts by type. Cross-Site Scripting (XSS) injects malicious client-side scripts into pages your visitors view, and Remote File Inclusion (RFI) includes remote files or scripts in your domain. SQL injection injects code that tries to read or attack data it has no permission to access, and **Other Threats** counts every other type.                                                                                                                                                                              |
| Tiered Cache layer     | The extra cache layer that [Tiered Cache](/en/documentation/platform/applications/cache/tiered-cache/) adds between the data center and the origin, described further in the [Learning Center](https://www.azion.com/en/learning/cdn/what-is-tiered-caching/). With Tiered Cache on, the **Edge Cache** chart counts data between the client, the data center, and the Tiered Cache layer. The **Tiered Cache** dashboard counts data between the data center, the Tiered Cache layer, and the origin.                                                                                                                                                                                                       |
| `tsRange`              | The filter argument of a [GraphQL query](/en/documentation/devtools/graphql/queries/) that sets its time interval with a `begin` and an `end` timestamp. A query needs a time interval, given by `tsRange` or by bounds such as `tsGte` and `tsLt`, or the API returns `400` with `To execute queries it is mandatory to provide the desired time interval.` Azion Console carries the selected range as `tsRange` in the `filters` parameter of a shared URL.                                                                                                                                                                                                                                               |
| upstream status        | The [status code](https://www.azion.com/en/learning/http-errors/http-status-codes-explained/) that the server behind Azion, such as your origin or an external service, returned for a request, recorded in the `upstreamStatus` field. The status is the code your application on Azion returned to the client, so the two can differ for one request. The **Requests by Status and Upstream Status** table counts requests by both, and [Build dashboards](/en/documentation/platform/real-time-metrics/build-dashboards/) documents it.                                                                                                                                                                   |
| variation tag          | The percentage tag beside the aggregation tag that compares the selected range with the window of equal length right before it. It appears on time charts with a single series and on big-number cards, and its color shows whether the change is good for that chart, so an increase in **Missed Data** shows in red. When there is nothing to compare, the tag reads **Can't compare**.                                                                                                                                                                                                                                                                                                                    |
