# Secure dashboards

The **Secure** category of [Real-Time Metrics](/en/documentation/platform/real-time-metrics/) groups the dashboards of four product tabs: **WAF**, **Edge DNS**, **Bot Manager**, and **Threats Breakdown**. Select **Secure** in the category dropdown to open them, and Real-Time Metrics shows the first tab, **WAF**. **Bot Manager** is the only tab with two dashboards, so it is the only one that shows the dashboard selector.

Each dashboard below has a table with one row per chart, in the order the Console draws them. A big-number card, which shows one total instead of a chart, moves to a first row above the other charts. The **Aggregation** column holds the tag shown under each chart's description, and every Secure chart reads **Sum**: a legend entry or a card shows the total over the selected range. The prose under each table names the series a chart draws, what each one counts, and its variation tag. That tag compares the selected range with the window of equal length immediately before it. It appears on a big-number card and on a time chart that draws one series, never on a pie, a bar chart, or a map. Each dashboard closes with the dataset and fields that return the same numbers through the GraphQL API. For the time range and the filters that apply to every chart, refer to [Filters and time range](/en/documentation/platform/real-time-metrics/filters-and-time-range/).

---

## WAF

The **WAF** tab shows how [WAF](/en/documentation/platform/firewall/#waf) handled the requests to the domains of your applications. WAF, the Web Application Firewall, analyzes each request for attacks such as SQL injection or cross-site scripting, and blocks or logs the requests it identifies as threats. The tab holds one dashboard, **Threats**, so the Console shows no dashboard selector. Every chart on it reads the `httpMetrics` dataset.

| Chart                                | What it measures                                                                                                   | Unit     | Aggregation |
| ------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | -------- | ----------- |
| Threats vs Requests                  | Requests WAF analyzed, split into threats it blocked, threats it logged without blocking, and requests it allowed. | Requests | Sum         |
| Cross-Site scripting (XSS) Threats   | Requests WAF identified as cross-site scripting attacks against your domains.                                      | Requests | Sum         |
| Remote File Inclusion (RFI) Threats  | Requests WAF identified as remote file inclusion attacks against your domains.                                     | Requests | Sum         |
| SQL Injection Threats                | Requests WAF identified as SQL injection attacks against your domains.                                             | Requests | Sum         |
| Other Threats                        | Requests WAF identified as attacks of any type other than XSS, RFI, or SQL injection.                              | Requests | Sum         |
| Top WAF Threat Requests by Country   | Share of the threats WAF blocked that came from each country, as a pie, for the 20 countries with the most.        | Percent  | Sum         |
| Top WAF Threat Requests by Country   | Threats WAF blocked from each country, as bars, for the 20 countries with the most.                                | Requests | Sum         |
| WAF Threat Requests by Family Attack | Threats WAF blocked in each attack family, for the 10 families with the most.                                      | Requests | Sum         |
| WAF Threat Requests by Host          | Threats WAF blocked on each host over time, one line per host.                                                     | Requests | Sum         |

**Threats vs Requests** draws three series, which compare the threats WAF stopped with the traffic it let through:

- **Waf Requests Blocked**: requests WAF identified as threats and blocked, because the firewall rule runs WAF in *Blocking* mode.
- **Waf Requests Threat**: requests WAF identified as threats and did not block, because the firewall rule runs WAF in *Logging* mode. These requests reach your application.
- **Waf Requests Allowed**: requests WAF did not identify as threats.

A firewall rule sets the mode when it runs a rule set. For the two modes and how WAF scores a threat, refer to [Rule sets](/en/documentation/platform/firewall/waf/rules-set/).

**Cross-Site scripting (XSS) Threats**, **Remote File Inclusion (RFI) Threats**, and **SQL Injection Threats** each draw one series with every request of the selected range that carries that attack. A cross-site scripting attack injects malicious scripts that run in the browser of the visitors to your pages. A remote file inclusion attack makes your domain load a remote file or script. An SQL injection attack inserts code into a database query to read or attack data it must not reach. **Other Threats** draws the threats of every other type. The four series read **Waf Requests Xss Attacks**, **Waf Requests Rfi Attacks**, **Waf Requests Sql Attacks**, and **Waf Requests Others Attacks**. For the log of each request WAF flagged, refer to [Real-Time Events](/en/documentation/platform/real-time-events/).

The two **Top WAF Threat Requests by Country** charts break down the same count by the country each threat came from. The pie shows the share of each country as a percentage, and the bar chart shows the number of threats behind each share, so read them together. Both list the 20 countries with the most threats. To block the requests of one country, create a network list by geolocation; refer to [Block requests by IP, ASN, or country](/en/documentation/guides/application-security/bots-and-network/blocklists-ip-addresses-edge/).

**WAF Threat Requests by Family Attack** draws one bar per attack family, for the 10 families with the most threats. The `wafAttackFamily` value carries a `$` prefix, such as `$SQL`, which the Console removes from each bar label. Some families combine more than one attack type:

| Family         | Attack                                                                                |
| -------------- | ------------------------------------------------------------------------------------- |
| SQL            | SQL injection, which manipulates database queries.                                    |
| SQL, XSS       | SQL injection combined with cross-site scripting.                                     |
| SQL, TRAVERSAL | SQL injection combined with path traversal, to reach restricted files or directories. |
| OTHERS, SQL    | Less common patterns related to SQL, grouped together.                                |
| RFI            | Remote file inclusion, which loads external malicious scripts.                        |
| TRAVERSAL      | Directory traversal, which reaches files or directories without authorization.        |
| SQL, RFI       | SQL injection combined with remote file inclusion.                                    |
| SQL, XSS, RFI  | SQL injection, cross-site scripting, and remote file inclusion in one attack.         |
| OTHERS         | Patterns that fit none of the predefined families.                                    |

Use the chart to find which families cause most of the threats, then set the protection against them. For more information, refer to [Create and apply a WAF rule set](/en/documentation/guides/application-security/firewall-and-waf/create-waf-rule-set/).

**WAF Threat Requests by Host** draws one line per host that received threats, up to 16 lines. Use it to find the hosts with the most threats and take measures on them: block the source addresses with a [network list](/en/documentation/platform/firewall/network-shield/network-lists/), adjust the [rule set](/en/documentation/platform/firewall/waf/rules-set/), or limit the request rate with the [Set Rate Limit](/en/documentation/platform/firewall/rules-engine/#set-rate-limit) behavior.

The two country charts, the family chart, and the host chart filter on `wafBlock` and `wafLearning`, so they count only the threats WAF blocked. Threats WAF logged without blocking appear on **Threats vs Requests** and are left out of these four charts.

An increase shows as bad on **Cross-Site scripting (XSS) Threats**, **Remote File Inclusion (RFI) Threats**, **SQL Injection Threats**, and **Other Threats**. **WAF Threat Requests by Host** shows the tag only when one host has data, and an increase there also shows as bad. **Threats vs Requests** draws three series and shows no variation tag, and neither do the country and family charts.

To query the same numbers, use the `httpMetrics` dataset. **Threats vs Requests** reads `wafRequestsBlocked`, `wafRequestsThreat`, and `wafRequestsAllowed`. The four attack charts, in table order, read `wafRequestsXssAttacks`, `wafRequestsRfiAttacks`, `wafRequestsSqlAttacks`, and `wafRequestsOthersAttacks`. The country, family, and host charts sum `requests` grouped by `geolocCountryName`, `wafAttackFamily`, and `host`, filtered to `wafBlock` equal to `1` and `wafLearning` equal to `0`. To list the countries and addresses that send the most threats through the GraphQL API, refer to [Find the top sources of WAF threats](/en/documentation/guides/platform/observability/find-top-waf-threat-sources/). For each field, refer to [Real-Time Metrics GraphQL fields](/en/documentation/devtools/graphql/gql-real-time-metrics-fields/#workloadmetrics).

---

## Edge DNS

The **Edge DNS** tab counts the queries that [Edge DNS](/en/documentation/platform/edge-dns/) receives for the domains hosted and managed on Azion in your account. Edge DNS must be active in your account for the tab to report data. The tab holds one dashboard, **Standard Queries**, so the Console shows no dashboard selector.

| Chart         | What it measures                         | Unit    | Aggregation |
| ------------- | ---------------------------------------- | ------- | ----------- |
| Total Queries | Queries your zones on Edge DNS received. | Queries | Sum         |

**Total Queries** draws one series, **Requests**, with every query made to your zones in the selected range. An increase shows as good. To count the queries of one zone, add a filter on **Zone Id**, which lists your zones by name. To count one record type, such as `A` or `AAAA`, add a filter on **Qtype**. For the filters, refer to [Filters and time range](/en/documentation/platform/real-time-metrics/filters-and-time-range/).

To query the same number, sum `requests` from the `edgeDnsQueriesMetrics` dataset. The dataset also carries `zoneId` and `qtype`, to filter or group the count by zone or by record type. For each field, refer to [Real-Time Metrics GraphQL fields](/en/documentation/devtools/graphql/gql-real-time-metrics-fields/#dnsqueriesmetrics).

---

## Bot Manager

The **Bot Manager** tab shows how [Bot Manager](/en/documentation/platform/firewall/#bot-manager) classified the requests it evaluated, and which action it took on the bots. Bot Manager scores each request. A request whose score is equal to or greater than the threshold set in Bot Manager is a bad bot, and Bot Manager runs the action defined for it; any other request is processed as usual. The tab shows data only when your account is subscribed to Bot Manager; for the subscription, contact [Technical Support](/en/documentation/support/). The tab holds two dashboards, in this order in the dashboard selector: **Overview**, which reads the `botManagerMetrics` dataset, and **Breakdown**, which reads `botManagerBreakdownMetrics`.

### Overview

The **Overview** dashboard counts the requests Bot Manager evaluated by class, by action, by CAPTCHA result, by bot category, and by country. Its four big-number cards show in a first row above the charts.

| Chart                   | What it measures                                                                                                     | Unit     | Aggregation |
| ----------------------- | -------------------------------------------------------------------------------------------------------------------- | -------- | ----------- |
| Bad Bot Hits            | Requests classified as bad bots.                                                                                     | Requests | Sum         |
| Good Bot Hits           | Requests classified as good bots.                                                                                    | Requests | Sum         |
| Bot Hits                | Requests classified as bots, bad or good.                                                                            | Requests | Sum         |
| Transactions            | Requests Bot Manager evaluated, in every class.                                                                      | Requests | Sum         |
| Bot Traffic             | Evaluated requests over time, one line per class.                                                                    | Requests | Sum         |
| Top Bot Traffic         | Share of evaluated requests in each class, as a pie.                                                                 | Percent  | Sum         |
| Top Bot Action          | Requests from bots for each action Bot Manager took, as a pie in totals and percentages.                             | Requests | Sum         |
| Bot CAPTCHA             | CAPTCHA challenge results for requests classified as bots, over time, split into solved and not solved.              | Requests | Sum         |
| Top Bot CAPTCHA         | Share of solved and not solved CAPTCHA challenges, as a pie.                                                         | Percent  | Sum         |
| Top Bot Classifications | Requests from bots for each bot category, by the tactic and purpose of the bot, for the 10 categories with the most. | Requests | Sum         |
| Bot Activity Map        | Requests from bots by their country of origin, on a world map.                                                       | Requests | Sum         |

**Bad Bot Hits**, **Good Bot Hits**, **Bot Hits**, and **Transactions** each show one number, the total over the selected range, followed by the word `requests`. **Bot Hits** is the sum of **Bad Bot Hits** and **Good Bot Hits**. **Transactions** counts every request Bot Manager evaluated, including the legitimate requests and those under evaluation.

**Bot Traffic** and **Top Bot Traffic** split the evaluated requests into four classes:

- **Legitimate**: not identified as an attack, with enough data to confirm it is not one. These are legitimate human users.
- **Bad Bot**: reached the score threshold, or identified as an attack.
- **Good Bot**: not identified as an attack, and matched a commonly used good bot, such as a search engine crawler. Good bots are allowed traffic, and their requests proceed as usual.
- **Under Evaluation**: not identified as a bot, without enough data to confirm it is not an attack. This class marks suspicious access.

Use **Bot Traffic** to find periods of suspicious activity, patterns, and anomalies; hovering a line shows the date, the time, and the requests in each class. Use **Top Bot Traffic** to weigh the share of bot traffic and spot anomalies and trends; hovering a slice shows the total requests of that class.

**Top Bot Action** shows the action Bot Manager took on the requests it identified as bots:

| Action          | What Bot Manager did                                                                                                  |
| --------------- | --------------------------------------------------------------------------------------------------------------------- |
| Allow           | Let the request continue. A request with a score below the threshold is processed, and `allow` is the default action. |
| Custom HTML     | Delivered custom HTML content when the request reached the threshold.                                                 |
| Deny            | Answered with a standard `403` status code.                                                                           |
| Drop            | Ended the request without a response.                                                                                 |
| Hold Connection | Kept the connection open for 1 minute, then dropped it.                                                               |
| Random Delay    | Waited a random time between 1 and 10 seconds, then let the request continue.                                         |
| Redirect        | Redirected the request to another URL when it reached the threshold, including to a CAPTCHA challenge.                |

The Console shows the actions with these labels in the filter's value list. The GraphQL API returns them in the `action` field as `allow`, `custom_html`, `deny`, `drop`, `hold_connection`, `random_delay`, and `redirect`.

**Bot CAPTCHA** and **Top Bot CAPTCHA** show the result of the CAPTCHA challenge returned to requests classified as bots. **Solved** counts the bots that completed the challenge with the correct answer and proceeded. **Not Solved** counts the bots that failed the challenge, answered it incorrectly, or did not attempt it, and the action defined for blocked or suspicious bots runs on them. **Bot CAPTCHA** draws the two results over time, and hovering a line shows the date, the time, and the number of bots that passed or failed. **Top Bot CAPTCHA** shows the percentage of each result. Use the two charts to adjust the difficulty or the frequency of the challenges, so that they stop bots without slowing down your visitors.

**Top Bot Classifications** draws one bar per bot category, which names the tactic and the purpose Bot Manager identified, such as Crawling, Brute Force, Scraping, Bad Bot Signatures, Malicious Browser Behavior, Scripted Bots, Enterprise Bots, Reputation Intelligence, Monitoring Bots, and Malicious Intent Detected. **Top Bot Classifications** and **Top Bot Action** leave out the requests with no bot category and those in the category `Non-Bot Like`.

**Bot Activity Map** colors each country by the number of requests from bad and good bots that came from it:

| Color        | Requests from the country |
| ------------ | ------------------------- |
| Red          | More than 1,000,000       |
| Light red    | 100,000 to 1,000,000      |
| Orange       | 10,000 to 99,999          |
| Light orange | 1,000 to 9,999            |
| Yellow       | 1 to 999                  |

Hovering a country shows its total after `Requests:`. Use the map to find regional patterns of bot attacks, then apply geo-blocking or a mitigation for one region. For more information, refer to [Block requests by IP, ASN, or country](/en/documentation/guides/application-security/bots-and-network/blocklists-ip-addresses-edge/).

An increase shows as bad on **Bad Bot Hits**, **Bot Hits**, and **Bot CAPTCHA**, and as good on **Bot Traffic**. **Good Bot Hits** and **Transactions** show the change in blue in both directions, as neither direction is good or bad. **Bot Traffic** and **Bot CAPTCHA** show the tag only when one class or one result has data. The pies, the bar chart, and the map show no variation tag.

To query the same numbers, sum `requests` from the `botManagerMetrics` dataset. **Bad Bot Hits** filters on `classified` equal to `bad bot`, **Good Bot Hits** on `good bot`, and **Bot Hits** and **Bot Activity Map** on both values. **Bot Traffic** and **Top Bot Traffic** group by `classified`, **Top Bot Action** by `action`, **Bot CAPTCHA** and **Top Bot CAPTCHA** by `challengeSolved`, **Top Bot Classifications** by `botCategory`, and **Bot Activity Map** by `geolocCountryName`. For worked queries, refer to [Query Bot Manager data with GraphQL](/en/documentation/guides/platform/observability/query-bot-manager-data-with-graphql/). For each field, refer to [Real-Time Metrics GraphQL fields](/en/documentation/devtools/graphql/gql-real-time-metrics-fields/#botmanagermetrics).

### Breakdown

The **Breakdown** dashboard of the **Bot Manager** tab shows which URLs bots request and which IP addresses the bad bots come from. Its **Impacted URLs** card shows in a first row above the two bar charts.

| Chart             | What it measures                                                                | Unit     | Aggregation |
| ----------------- | ------------------------------------------------------------------------------- | -------- | ----------- |
| Impacted URLs     | Distinct URLs that bots requested.                                              | URLs     | Sum         |
| Top Bad Bot IPs   | Requests from bad bots for each IP address, for the 10 addresses with the most. | Requests | Sum         |
| Top Impacted URLs | Requests from bots for each URL, for the 10 URLs with the most.                 | Requests | Sum         |

**Impacted URLs** shows one number followed by the word `URLs`, and an increase shows as bad. **Top Bad Bot IPs** draws one bar per IP address. Use it to find the addresses bad bots use most, to follow trends in their activity, and to respond to an attack by blocking or limiting the traffic of those addresses. To block them, add them to a [network list](/en/documentation/platform/firewall/network-shield/network-lists/); to limit them, use the [Set Rate Limit](/en/documentation/platform/firewall/rules-engine/#set-rate-limit) behavior. **Top Impacted URLs** draws one bar per URL, labeled with the URL as requested: the host and the path, without arguments. Use it to find the URLs bots target most. The two bar charts show no variation tag.

Bot Manager keeps the data of the two datasets for different periods. For each period, refer to [Logs](/en/documentation/platform/firewall/bot-manager/logs/#retention).

To query the same numbers, use the `botManagerBreakdownMetrics` dataset. **Impacted URLs** reads `uniqRequestUrl`. **Top Bad Bot IPs** sums `badBotRequests` grouped by `remoteAddr`, and **Top Impacted URLs** sums `botRequests` grouped by `requestUrl`. For each field, refer to [Real-Time Metrics GraphQL fields](/en/documentation/devtools/graphql/gql-real-time-metrics-fields/#botmanagerbreakdownmetrics).

---

## Threats Breakdown

The **Threats Breakdown** tab shows which IP addresses send the threats that [WAF](/en/documentation/platform/firewall/#waf) identifies in the requests to your applications. It holds one dashboard, also named **Threats Breakdown**, which reads the `httpBreakdownMetrics` dataset.

| Chart                         | What it measures                                                                            | Unit     | Aggregation |
| ----------------------------- | ------------------------------------------------------------------------------------------- | -------- | ----------- |
| Top WAF Threat Requests by IP | Requests WAF identified as threats for each IP address, for the 10 addresses with the most. | Requests | Sum         |

**Top WAF Threat Requests by IP** draws one bar per remote IP address, with the total of threat requests from it. Use it to focus your protection on the largest sources of threats. To block an address, create a network list by IP; refer to [Block requests by IP, ASN, or country](/en/documentation/guides/application-security/bots-and-network/blocklists-ip-addresses-edge/). For the log of each threat request, refer to [Real-Time Events](/en/documentation/platform/real-time-events/). The chart shows no variation tag.

To query the same numbers, sum `wafThreatRequests` from the `httpBreakdownMetrics` dataset grouped by `remoteAddress`. Add the filter `wafThreatRequestsGt: 0` so that the result lists only the addresses that sent threats; without it, the query also returns addresses with a total of `0`. For the complete query, refer to [Find the top sources of WAF threats](/en/documentation/guides/platform/observability/find-top-waf-threat-sources/). For each field, refer to [Real-Time Metrics GraphQL fields](/en/documentation/devtools/graphql/gql-real-time-metrics-fields/#workloadbreakdownmetrics).

---

## Related resources

- [Filters and time range](/en/documentation/platform/real-time-metrics/filters-and-time-range.md): The time range, the filters, and the chart menu that apply to every chart on these dashboards.
- [How Real-Time Metrics works](/en/documentation/platform/real-time-metrics/how-it-works.md): How a metric reaches a chart, and which bucket size each time range returns.
- [Real-Time Metrics fields](/en/documentation/devtools/graphql/gql-real-time-metrics-fields.md): Every field of the WAF, Edge DNS, and Bot Manager datasets named on this page.
- [Find the top sources of WAF threats](/en/documentation/guides/platform/observability/find-top-waf-threat-sources.md): Query the countries and IP addresses that send the most WAF threats through the GraphQL API.
