Standard log

Updated at:

Edge Security Acceleration (ESA) packages standard logs hourly. Download site access logs for any time period within the past 31 days and save them locally to optimize acceleration policies, diagnose issues, and analyze user behavior.

Notes

  • Standard logs are collected from all ESA POPs. Data latency is 6 to 8 hours. Each log record in the list is a complete package for that time period. Click Download to view it.

  • Standard logs support two types: Access Log and TCP/UDP Proxy Log, packaged hourly by default. If no requests occur within an hour, no log package is generated.

  • Log packages are gzip-compressed into .gz files. Naming convention: site_name_year_month_day_start_time_end_time.xx.gz. Example: aliyundoc.com_2024_01_01_000000_010000.xx.gz.

Download standard logs

  1. In the ESA console, select Websites, and in the Website column, click the target site.

  2. In the left navigation pane, choose Analytics and Logs > Standard Logs.

  3. On the Standard Logs page, select a time range and log type, and then click Search.

  4. Find the target log record and click Download in the Actions column. Decompress the downloaded file to view the logs.

    Note

    The console retains logs for the past 31 days, including the current day. To retrieve logs older than 31 days (up to 180 days), submit a ticket.

Standard log fields

Access Log

Field name

Data type

Description

ClientASN

string

The autonomous system number (ASN) parsed from the client IP address.

ClientIP

string

The client IP address connected to the ESA POP.

ClientRequestID

string

The unique identifier of the client request.

ClientRequestScheme

string

The Scheme of the client request.

ClientISP

string

The carrier parsed from the client IP address.

ClientCountryCode

string

The ISO-3166 Alpha-2 code parsed from the client IP address.

ClientRegionCode

string

The ISO-3166-2 code parsed from the client IP address.

ClientRequestBytes

int

The size of the client request, in bytes.

ClientRequestHeaderRange

string

The Range request header value. Example: bytes=0-100.

ClientRequestHost

string

The Host of the client request.

ClientRequestMethod

string

The HTTP Method of the client request.

ClientRequestProtocol

string

The protocol of the client request.

ClientRequestReferer

string

The Referer of the client request.

ClientRequestURI

string

The URI of the client request.

ClientRequestUserAgent

string

The User-Agent of the client request.

ClientSrcPort

int

The client port used to connect to the ESA POP.

EdgeCacheStatus

string

The cache status of the client request.

EdgeResponseBodyBytes

int

The response body size returned by the ESA POP, in bytes.

EdgeResponseBytes

int

The response size returned by the ESA POP, in bytes.

EdgeResponseStatusCode

int

The response status code from the ESA POP.

EdgeServerID

string

The unique ID of the ESA server the client accessed.

EdgeServerIP

string

The IP address of the ESA POP.

EdgeStartTimestamp

Timestamp ISO8601

The timestamp when the ESA POP received the client request. Example: 2024-01-01T00:00:00+08:00.

EdgeTimeToFirstByteMs

int

Time between the ESA POP receiving the request and the ESA POP returning the first response byte, in ms.

SiteName

string

The site name.

TCP/UDP Proxy Log

Field name

Data type

Description

BlockRuleID

string

The triggered interception and protection rule ID. Empty if the request was not intercepted.

ClientASN

string

The autonomous system number (ASN) parsed from the client IP address.

ClientBytes

int

The data bytes received from the client, in bytes.

ClientCountryCode

string

The ISO-3166 Alpha-2 code parsed from the client IP address.

ClientIP

string

The client IP address connected to the ESA POP.

ClientISP

string

The carrier parsed from the client IP address.

ClientMatchedIpFirewall

string

The type of the matched IP access rule.

ClientPort

int

The client port.

ClientProto

string

The data transmission protocol of the client.

ConnectTimeStamp

Timestamp ISO8601

The timestamp when the client connected to the ESA POP. Example: 2024-01-01T00:00:00+08:00.

DisconnetTimeStamp

Timestamp ISO8601

The timestamp when the client disconnected from the ESA POP. Example: 2024-01-02T00:00:00+08:00.

DomainName

string

The domain name of the application instance.

EdgeServerIP

string

The IP address of the ESA POP.

IpFirewall

bool

Indicates whether the IP access rule is enabled.

LogTimeStamp

Timestamp ISO8601

The timestamp when the log was generated. Example: 2024-01-01T00:00:00+08:00.

OriginBytes

int

The data bytes received from the origin server, in bytes.

OriginIP

string

The IP address of the origin server.

OriginPort

int

The port of the origin server.

OriginProto

string

The data transmission protocol of the origin server.

ProxyProtocol

string

The proxy protocol version. Valid values: off, v1, and v2.

SessionID

string

The globally unique stream identifier.

SiteName

string

The site name.

Status

int

The status code at the end of the session.