All Products
Search
Document Center

Edge Security Acceleration:Standard log field reference

Last Updated:Aug 26, 2026

Alibaba Cloud DCDN records network-wide access logs and WAF blocking logs for your domain names at an hourly granularity. You can download the logs of a specific domain name for any single day within the last 30 days, save them to a local path, and analyze them.

Download

  • Go to the standard log download page. The navigation path is Data Center > Logs > standard log > Log Download. Select the date that you want and download the logs.

  • Log file latency: the latency is usually within 24 hours, but it can exceed 24 hours. If you need logs with a latency of less than 24 hours, use real-time log instead.

Usage

  • Log file naming convention: the file name starts with the accelerated domain name, followed by the year, month, day, start time, end time, and an optional extension field that starts with an underscore (_), joined by underscores. The file name ends with .gz. Example: aliyundoc.com_2018_10_30_000000_010000_xx.gz.

    Note

    The extension field may not exist. Example: aliyundoc.com_2018_10_30_000000_010000.gz.

  • You can view DCDN logs in common IDE tools such as Notepad++.

  • Traffic data from the DCDN console or API may differ from log-based data. Monitoring traffic is typically about 1.1 times the log-calculated amount. Why is the traffic amount found by using the monitoring and usage analytics feature or the usage statistics feature different from the traffic amount that is logged?

  • Resource monitoring collects data by client region and ISP. Billing is metered by traffic, bandwidth, and requests at DCDN POPs per billable region, so results may differ.

  • Some internet service providers (ISPs) in specific regions may assign private IP addresses to end-users. As a result, POPs may receive a user's private IP address.

    Note

    Private IP addresses fall into three ranges:

    • Class A private IP address: 10.0.0.0 to 10.255.255.255, subnet mask: 10.0.0.0/8

    • Class B private IP address: 172.16.0.0 to 172.31.255.255, subnet mask: 172.16.0.0/12

    • Class C private IP address: 192.168.0.0 to 192.168.255.255, subnet mask: 192.168.0.0/16

Fields in user access logs

  • Sample log entry

    // Sample log
    //         Request time             Client IP   Proxy IP   Response time    Referer   Request method and URL                 HTTP status code Request size   Response size    Cache status         "User-Agent"                                                           File type    Connection IP
    [9/Jun/2015:01:58:09 +0800]    10.10.10.10 -        1542       "-"        "GET http://www.aliyun.com/index.html"      200          191           2830           MISS                 "Mozilla/5.0 (compatible; AhrefsBot/5.0; +http://example.com/robot/)" "text/html"  1.1.X.X 
  • Fields

    Field

    Field meaning

    Description

    [9/Jun/2015:01:58:09 +0800]

    Request time

    The end time of the user access request.

    10.10.10.10

    Client IP address

    The first IP address from the left in the X-Forwarded-For request header, representing the client's IP address (client_ip). If no proxy sits between the client and the or DCDN edge node, this matches the IP address that established the TCP connection with the edge node.

    Note
    • The X-Forwarded-For header follows the format X-Forwarded-For: <client_ip>, <proxy_ip>.

    • If the client does not use a proxy to connect to the DCDN node (meaning the X-Forwarded-For header only contains <client_ip>), the value of <client_ip> in logs may be a private IP address. A common reason is that the Internet service provider (ISP) allocates a private IP address to the client to reduce the usage of public IP addresses and costs.

    • If the client uses a proxy to connect to the POP, the X-Forwarded-For request header contains <client_ip> and <proxy_ip>. In this case, the value of client_ip in logs may also be a private IP address. A common reason is that the ISP allocates a public IP address to the proxy and a private IP address to the client.

    • Because the X-Forwarded-For header can be forged, use the remote_ip field from Fields collected in real-time logsfor analysis and for configuring WAF rules to block malicious IP addresses. The remote_ip field contains the real IP address that established the connection with DCDN.

    -

    Proxy IP address

    The second IP address from the left in the X-Forwarded-For request header, representing the proxy's IP address (proxy_ip). If no proxy is used, this field contains a hyphen (-).

    1542

    Response time

    The response time. Unit: milliseconds.

    "-"

    Referer

    The Referer header in HTTP requests.

    GET

    Request method

    The request method. For example, GET, POST, PUT, or DELETE.

    http://www.aliyun.com/index.html

    Request URL

    The request URL.

    200

    HTTP status code

    The HTTP status code. Common examples include 200, 403, 404, and 500.

    191

    Request size

    The size of the request. Unit: bytes.

    2830

    Response size

    The size of the response. Unit: bytes.

    MISS

    Whether the request hits a point of presence

    The cache hit status.

    • HIT: The edge node served the content from its cache. No origin fetch was required.

    • MISS: The edge node did not have the requested content in cache. The content is fetched from an upstream server, which can be an L2 or DCDN node or the origin server.

    Alibaba Cloud DCDN currently only provides log information from DCDN edge nodes, not including origin-related information from DCDN L2 nodes. Therefore, when this field is MISS, you cannot obtain origin information, and cannot directly see from the logs whether the user request was forwarded to the origin.

    Mozilla/5.0 (compatible; AhrefsBot/5.0; +http://example.com/robot/)

    User-Agent

    The User-Agent header.

    text/html

    File type

    The webpage type.

    Logs of domain names for which you enable the global resource plan do not contain this field.

    1.1.1.1

    Access IP address

    The IP address that is used to establish the connection.

    Note

    Other fields:

    • DYNAMIC: Indicates a dynamic request.

    • CHARGE: Indicates that the request is billable.

    • NOTLAST: A reserved field with no practical meaning.

Fields in WAF logs

  • Sample log entry

    [16/May/2023:10:36:09 +0800] HEAD "http" api.aliyun.com "/block" "_dyc=89e7639543f17ddbe77361c56b9952b9" "-" api.aliyun.com 3d30530216842045692847280e 403 "-" "curl/7.29.0" "-" 1.XX.XX.1 1.XX.XX.1 false "-" deny "custom_acl" 20000014
  • Fields

    Field name

    Example value

    Description

    unixtime

    [16/May/2023:10:36:09 +0800]

    The time of the request.

    method

    HEAD

    The request method.

    scheme

    http

    The request protocol.

    domain

    api.aliyun.com

    The requested domain name.

    uri

    /block

    The requested resource.

    uri_param

    _dyc=89e7639543f17ddbe77361c56b9952b9

    The request parameters.

    content_type

    -

    The content type of the request.

    matched_host

    api.aliyun.com

    The domain name that the client request matches and that is already added and in service.

    request_id

    3d30530216842045692847280e

    The unique ID of the request.

    return_code

    403

    The response code for the request.

    referer

    -

    The HTTP Referer field.

    user_agent

    curl/7.29.0

    The user agent information.

    x_forwarded_for

    -

    The XFF header in the request. This header is used to identify the original IP address of a client that connects to a web server through an HTTP proxy or a load balancer.

    client_ip

    1.XX.XX.1

    The real IP address of the user.

    remote_addr

    1.XX.XX.1

    The IP address of the request.

    final_test

    FALSE

    The final matched rule is not in observation mode.

    cookie

    -

    The cookie information from the client that is included in the request header.

    final_action

    deny

    The final protection action taken.

    • block: Blocked by the basic web protection module.

    • deny: Blocked by a module other than the basic web protection module.

    • captcha: Challenged with a slider CAPTCHA.

    • js: Challenged with JavaScript verification.

    • Empty string: The request was allowed. This can occur if no protection rule was triggered, a whitelist rule or monitor rule was triggered, or the client passed a slider CAPTCHA or JavaScript verification.

    Note

    If a request triggers multiple protection modules, this field records only the final action taken. Actions are prioritized in the following order: block (block) > slider CAPTCHA (captcha) > dynamic token-based authentication (sigchl) > JavaScript verification (js).

    final_plugin

    custom_acl

    The protection module that was ultimately matched.

    • If the final_action field is not empty, this field indicates the single module that took the action.

    • If the final_action field is empty, this field lists all modules that were triggered by the request. A -T suffix on a module name indicates that the request matched a monitor rule within that module. The suffix does not apply to the whitelist or basic web protection modules.

    This field can contain multiple values separated by commas (,). The possible module values are:

    • whitelist: The request matched a rule in the whitelist module.

    • waf: The request matched a rule in the basic web protection module.

    • custom_acl: The request matched a rule in the custom rule module.

    • ip_blacklist: The request matched a rule in the IP blacklist module.

    • region_block: The request matched a rule in the region blacklist module.

    • bot: The request matched a rule in the bot management module.

    • anti_scan: The request matched a rule in the scan protection module.

    • intelligent_cc_global: The request matched a rule in the DDoS global protection strategy module.

    • intelligent_cc_acl: The request matched a rule in the DDoS intelligent CC protection module.

    final_rule_id

    20000014

    Information about the protection rule that was ultimately matched.

    • If the final_action field is not empty, this field indicates the ID of the single rule that took the action. The rule ID is a numeric value and does not include the module name.

    • If the final_action field is empty, this field lists all rules triggered by the request. The format for each rule is ModuleName-RuleID(-T). A -T suffix indicates that the rule is a monitor rule. The suffix does not apply to rules in the whitelist or basic web protection modules.

    This field can contain multiple values separated by commas (,).

Procedure

  1. Log on to the DCDN console.

  2. In the left-side navigation pane, choose Data Center > Logs > standard log.

  3. On the Log Download tab, select a domain name and a time range, and then click Search.

  4. In the search results, click Download in the Actions column to download the log file.