$remote_addr | 203.0.113.45 | User’s IP address |
$masked_remote_addr | 4.d18b5cafa3d1c016d8194583f593a87e89271e6dc8e2ba44f851fdd5a8be1ccb | Privacy-preserving alternative to $remote_addr. Replaces the client IP address with a deterministic SHA-256 hash. Output format: <version>.<hash> |
$remote_user (internal system variable) | - | Username used in Basic authentication |
[$time_local] | [26/Apr/2019:09:47:40 +0000] | Local time in Common Log Format |
$timestamp_request_start | 1772707791454 | Request start time as Unix epoch in milliseconds |
$request | GET /ContentCommon/images/image.png HTTP/1.1 | HTTP method, requested file path, and HTTP version |
$status | 200 | Response status code from a CDN server |
$body_bytes_sent | 1514283 | Number of bytes sent to a user, excluding the response header size |
$http_referer | https://video.invalid/10 | Value of the Referer request header, which usually identifies the page that initiated the request |
$http_user_agent | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.116 YaBrowser/16.10.0.2309 Safari/537.36 | User agent that was used to send a request (browser or other application) |
$bytes_sent | 1514848 | Number of bytes sent to a user |
$edgename | [dh-up-gc18] | CDN server that forwarded the requested file |
$scheme | https | Protocol (HTTP or HTTPS) of a request |
$host | cdn.invalid | Requested hostname of a CDN resource |
$cname (internal system variable) | cdn.invalid | Similar to the $host field, but derived from internal systems rather than the incoming HTTP request |
$gcdn_vhost (internal system variable) | cdn.invalid[_cache_sharded] | The vhost value as used internally in CDN |
$request_time | 1.500 | Request processing time in seconds (accurate to milliseconds); time elapsed between the first bytes of a request being processed and logging after the last bytes were sent to a user |
$first_byte_sent_mcs | 0.170103 | Time from request start until the first byte of the response was sent to the user (time to first byte), in seconds with microsecond accuracy |
$request_time_mcs | 0.170660 | Total request processing time from receiving the first bytes from the client until the last byte was sent, in seconds with microsecond accuracy |
$upstream_response_time | 0.445 | Number of seconds (accurate to milliseconds) it took to receive a response from the upstream server. When Origin Shielding is active, the upstream server may be an intermediate CDN cache rather than the origin. In case of multiple responses, commas and colons are used |
$request_length | 157 | Request length (including request line, header, and request body) |
$http_range | bytes=0-1901653 | File fragment size in a Range request |
[$responding_node] | dh | Responding data center |
$upstream_cache_status | MISS | Status of a requested file in CDN cache:
HIT: response served from the CDN cache.
STALE: outdated response that failed to update (origin not responding or responding incorrectly).
UPDATING: outdated response still updating from a previous request.
REVALIDATED: response matching one on an origin (based on the proxy_cache_revalidate directive).
EXPIRED: response that has expired in cache but still matches one on an origin; a request was sent to re-cache it.
MISS: response served directly from an origin rather than from cache.
BYPASS: response served from the upstream server because configured cache bypass conditions were met, including a request with a matching cookie, query parameter, or authorization header. Cache bypass does not invalidate the cached copy; subsequent requests that do not match the bypass conditions continue to be served from cache. A request for content that is absent from cache after a purge results in MISS, not BYPASS. |
$upstream_response_length | 10485760 | Response length received from the upstream server in bytes. In case of multiple responses, commas and colons are used |
$upstream_addr | 192.0.2.1:80 | IP address and port of the upstream server. When Origin Shielding is active, this reflects the intermediate CDN cache node rather than the origin. |
$gcdn_api_client_id (internal system variable) | 123 | Account ID in the Gcore system |
$gcdn_api_resource_id (internal system variable) | 01 | CDN resource ID in the Gcore system |
$uid_got (internal system variable) | - | Cookie name and received user ID |
$uid_set (internal system variable) | - | Cookie name and provided user ID |
$geoip_country_code | KZ | User’s ISO 3166-1 alpha-2 country code |
$geoip_city | - | User’s city code |
$shield_type (internal system variable) | shield_no | Indicates whether Origin Shielding is enabled:
shield_old – enabled
shield_no – disabled |
$server_addr (internal system variable) / real_server_addr | 198.51.100.1 | IP address of an Anycast zone or CDN server |
$server_port (internal system variable) | 80 | Requested port |
$upstream_status | 206 | HTTP status code returned by the upstream server |
$upstream_connect_time | 0.000 | Number of seconds (accurate to milliseconds) it took to access an origin server |
$upstream_header_time | 0.200 | Number of seconds (accurate to milliseconds) it took to receive a response header from an origin server |
$shard_addr (internal system variable) | 198.51.100.2 | IP address of a CDN server that was first to accept a request if the Cache Sharding feature is enabled |
$geoip2_data_asnumber | asnumber | Number of an autonomous system that sent a request |
$connection (internal system variable) | 2897494295 | Connection serial number |
$connection_requests (internal system variable) | 1 | Current number of requests made through a connection |
$http_traceparent (internal system variable) | 00-d5fe1dc9035165ce36952daf29686b6c-14330be33197dd1a-01 | Incoming client traceparent request header. If the client omits the header, the field contains -; if the value is invalid, the field preserves that value. The CDN-generated replacement is not stored here. See Traceparent header for troubleshooting. |
$http_x_forwarded_proto | - | Initial protocol of an incoming request (HTTP or HTTPS) |
$gcdn_internal_status_code (internal system variable) | - | Initial status code. Possible values are - or one of the internal codes listed below |
$ssl_cipher (internal system variable) | ECDHE-RSA-AES256-GCM-SHA384 | Cipher name used for an established SSL connection |
$ssl_session_id (internal system variable) | 28a4184139cb43cdc79006cf2d1a4ac93bdc**** | Session ID of an established SSL connection |
$ssl_session_reused (internal system variable) | r | Shows whether a session was reused (r) or not (.) |
$sent_http_content_type | application/json | Value of the Content-Type HTTP header, indicating the MIME type of a transmitted file |
$tcpinfo_rtt | 21 | Average time (latency) it takes to transfer a packet to/from a server. The unit of time is microseconds |
$server_country_code | PL | Server’s ISO 3166-1 alpha-2 country code |
$gcdn_tcpinfo_snd_cwnd | 45 | Size of the TCP Congestion window, i.e., the maximum number of TCP segments that the connection can send before an acknowledgment is required |
$gcdn_tcpinfo_total_retrans | 10 | Total number of retransmitted packets over the life of the connection |
$gcdn_rule_id | 100700 | Initial rule ID (beta). Possible values are: -, or 100700 |
$query_string | id=123&sort=asc&filter=active | Contains the raw query parameters from the request URI |
$timestamp (internal system variable) | - | Internal system variable; always produces an empty value |
$ip (internal system variable) | - | Internal system variable; always produces an empty value |
$country (internal system variable) | - | Internal system variable; always produces an empty value |
$media_type (internal system variable) | - | Internal system variable; always produces an empty value |
$size (internal system variable) | - | Internal system variable; always produces an empty value |
$duration (internal system variable) | - | Internal system variable; always produces an empty value |
$session_id (internal system variable) | - | Internal system variable; always produces an empty value |
$domain (internal system variable) | - | Internal system variable; always produces an empty value |
$name (internal system variable) | - | Internal system variable; always produces an empty value |
$edge (internal system variable) | - | Internal system variable; always produces an empty value |
$code (internal system variable) | - | Internal system variable; always produces an empty value |
$region (internal system variable) | - | Internal system variable; always produces an empty value |
$http_x_forwarded_for | 203.0.113.45, 198.51.100.17 | Contains the value of the X-Forwarded-For HTTP request header as sent by the client or added by upstream proxies/load balancers |
$http_cookie | session_id=abc123; theme=dark; csrftoken=9f8e7d | Contains the raw value of the Cookie HTTP request header sent by the client |
$request_method | GET | Contains the HTTP method used by the client for the request |
$request_uri_path | /api/v1/users | Represents the path portion of the request URI, without any query string parameters |
$sent_http_cache_control | max-age=3600, public | Contains the value of the Cache-Control HTTP response header as sent by NGINX to the client. It reflects the caching directives applied to the response, which control how browsers, proxies, and CDNs may cache and reuse the content |
$sent_http_content_length | 53214 | Content-Length sent to the client: the number of body bytes the CDN declared. Compare with $body_bytes_sent to measure truncation. 0 means the header was absent (chunked transfer, no Content-Length, or a row from before the field was added), not that zero bytes were sent. |
$server_protocol | HTTP/1.1 | Contains the protocol version used by NGINX to communicate |
$upstream_http_content_length | 1048576 | Contains the value of the Content-Length HTTP response header received from the upstream server |
$request_uri | /api/v1/users?id=42&sort=asc | Contains the original request URI as sent by the client, including the path and the query string |
$fastedge_field1 (internal system variable) | | Used for passing additional context from FastEdge into raw logs |
$http_last_modified | Wed, 21 Oct 2015 07:28:00 GMT | Value of the Last-Modified request header sent by the client |
$http_accept | text/html,application/xhtml+xml | Value of the Accept request header indicating acceptable response content types |
$http_age | 3600 | Value of the Age request header, typically used by caches to indicate object age in seconds |
$http_head_size | 512 | Size (in bytes) of the HTTP request headers received from the client |
$http_return_head_size | 430 | Size (in bytes) of the HTTP response headers returned to the client |
$sent_http_content_range | bytes 0-1023/4096 | Value of the Content-Range response header sent to the client |
$upstream_http_location | /redirect/path | Value of the Location response header received from the upstream server (commonly for redirects) |
$http_via | 1.1 proxy.invalid | Value of the Via request header, listing the proxies the request passed through |
$quic | H3 | QUIC protocol version negotiated for the connection. Possible values: -, or H3 |
$request_completion | OK | Whether the CDN finished writing the response body. OK means the request completed. An empty value means it did not. Use with $sent_http_content_length and $body_bytes_sent to detect truncated 200 or 206 responses. |
$gcdn_finalize_reason | ok | Why the request stopped producing a body. ok means the body finished. Empty or unset means no reason was recorded. Other values identify the cause: client (client_closed, client_timeout, client_error); upstream (upstream_connect_failed, upstream_connect_timeout, upstream_headers_null, upstream_header_timeout, upstream_body_null, upstream_body_partial, upstream_body_timeout, upstream_ssl_error, upstream_error, upstream_send_timeout); this proxy (internal_error, shutdown); or slice (slice_bad_status, slice_missing, slice_etag, slice_range). |