Standard log
Edge Security Acceleration (ESA) packages standard logs hourly. Download site access logs for any time period within the past 31 days and save them locally to optimize acceleration policies, diagnose issues, and analyze user behavior.
Notes
Standard logs are collected from all ESA POPs. Data latency is 6 to 8 hours. Each log record in the list is a complete package for that time period. Click Download to view it.
Standard logs support two types: Access Log and TCP/UDP Proxy Log, packaged hourly by default. If no requests occur within an hour, no log package is generated.
Log packages are gzip-compressed into
.gzfiles. Naming convention:site_name_year_month_day_start_time_end_time.xx.gz. Example:aliyundoc.com_2024_01_01_000000_010000.xx.gz.
Download standard logs
In the ESA console, select Websites, and in the Website column, click the target site.
In the left navigation pane, choose .
On the Standard Logs page, select a time range and log type, and then click Search.
Find the target log record and click Download in the Actions column. Decompress the downloaded file to view the logs.
NoteThe console retains logs for the past 31 days, including the current day. To retrieve logs older than 31 days (up to 180 days), submit a ticket.
Standard log fields
Access Log
Field name | Data type | Description |
ClientASN | string | The autonomous system number (ASN) parsed from the client IP address. |
ClientIP | string | The client IP address connected to the ESA POP. |
ClientRequestID | string | The unique identifier of the client request. |
ClientRequestScheme | string | The |
ClientISP | string | The carrier parsed from the client IP address. |
ClientCountryCode | string | The ISO-3166 Alpha-2 code parsed from the client IP address. |
ClientRegionCode | string | The ISO-3166-2 code parsed from the client IP address. |
ClientRequestBytes | int | The size of the client request, in bytes. |
ClientRequestHeaderRange | string | The |
ClientRequestHost | string | The |
ClientRequestMethod | string | The |
ClientRequestProtocol | string | The protocol of the client request. |
ClientRequestReferer | string | The |
ClientRequestURI | string | The |
ClientRequestUserAgent | string | The |
ClientSrcPort | int | The client port used to connect to the ESA POP. |
EdgeCacheStatus | string | The cache status of the client request. |
EdgeResponseBodyBytes | int | The response body size returned by the ESA POP, in bytes. |
EdgeResponseBytes | int | The response size returned by the ESA POP, in bytes. |
EdgeResponseStatusCode | int | The response status code from the ESA POP. |
EdgeServerID | string | The unique ID of the ESA server the client accessed. |
EdgeServerIP | string | The IP address of the ESA POP. |
EdgeStartTimestamp | Timestamp ISO8601 | The timestamp when the ESA POP received the client request. Example: 2024-01-01T00:00:00+08:00. |
EdgeTimeToFirstByteMs | int | Time between the ESA POP receiving the request and the ESA POP returning the first response byte, in ms. |
SiteName | string | The site name. |
TCP/UDP Proxy Log
Field name | Data type | Description |
BlockRuleID | string | The triggered interception and protection rule ID. Empty if the request was not intercepted. |
ClientASN | string | The autonomous system number (ASN) parsed from the client IP address. |
ClientBytes | int | The data bytes received from the client, in bytes. |
ClientCountryCode | string | The ISO-3166 Alpha-2 code parsed from the client IP address. |
ClientIP | string | The client IP address connected to the ESA POP. |
ClientISP | string | The carrier parsed from the client IP address. |
ClientMatchedIpFirewall | string | The type of the matched IP access rule. |
ClientPort | int | The client port. |
ClientProto | string | The data transmission protocol of the client. |
ConnectTimeStamp | Timestamp ISO8601 | The timestamp when the client connected to the ESA POP. Example: 2024-01-01T00:00:00+08:00. |
DisconnetTimeStamp | Timestamp ISO8601 | The timestamp when the client disconnected from the ESA POP. Example: 2024-01-02T00:00:00+08:00. |
DomainName | string | The domain name of the application instance. |
EdgeServerIP | string | The IP address of the ESA POP. |
IpFirewall | bool | Indicates whether the IP access rule is enabled. |
LogTimeStamp | Timestamp ISO8601 | The timestamp when the log was generated. Example: 2024-01-01T00:00:00+08:00. |
OriginBytes | int | The data bytes received from the origin server, in bytes. |
OriginIP | string | The IP address of the origin server. |
OriginPort | int | The port of the origin server. |
OriginProto | string | The data transmission protocol of the origin server. |
ProxyProtocol | string | The proxy protocol version. Valid values: off, v1, and v2. |
SessionID | string | The globally unique stream identifier. |
SiteName | string | The site name. |
Status | int | The status code at the end of the session. |