Skip to main content

Log schema and field definitions

The exported log schema includes standard CDN request fields, internal status codes, and a sample log line.

The format below does not include every available field — for instance, $timestamp_request_start, $masked_remote_addr, $query_string, and $quic are in the field table but not shown here. The actual log output depends on which fields are selected, their order, and the delimiter and separator configured in the policy. When fields are added to the log schema, an email notification is sent about the update. WAAP fields are appended separately, as described in WAAP log fields.
The table lists the standard CDN request fields. WAAP fields are documented separately. Fields labeled “internal system variable” relate to the internal CDN system and can be ignored for most analytics use cases; other fields help with traffic analysis or statistics.
The $timestamp variable always produces an empty value. Use [$time_local] for a Common Log Format timestamp or $timestamp_request_start for request-start time in Unix epoch milliseconds. No client port field is available.
Internal status codes identify the CDN rule or feature that generated a response.When a Secure Token link passes the authenticity check, $secure_link is set to the link extracted from the request URI. That successful validation does not produce a 403 or 410.
For HTTP(S) targets, Logs Uploader sends a JSON request payload to the configured endpoint. The v field in the payload identifies the schema version ("v":"10"). This metadata belongs to the JSON envelope rather than the selectable CDN log fields, so it does not appear in the sample log line or field table.The version increments when fields are added, renamed, or removed. New fields are added in a backward-compatible way where possible, so most schema changes do not require parser updates. Breaking changes are announced in advance through standard CDN update notifications. Check the v value in downstream parsers before processing a batch with an unsupported schema version.HTTP(S) payload structureEach request delivers one batch of log lines. The payload is a JSON object whose logs array contains the raw log lines selected and formatted by the policy (the same text that would appear in a file delivered to an S3 or FTP target). The v field is metadata in that JSON envelope. It identifies the Logs Uploader schema version and can change when exported log fields are added, renamed, or removed. It is not one of the selectable CDN log fields.
The receiver must return a 2xx HTTP status code. Any other status code is treated as a delivery failure; Logs Uploader retries the batch and records the error in delivery logs accessible through Gcore Support.
If Use compression is enabled on the HTTP(S) target, the request body is gzip-compressed and the Content-Encoding: gzip header is included. Decompress the body before parsing.

WAAP log fields

When a CDN resource has WAAP enabled, Logs Uploader appends WAAP security event fields to each request log line. CDN access data and the matching WAAP verdict share one entry — no separate file and no extra Logs Uploader setup. When a policy override suppresses a finding, the entry includes policy_override with the override ID, target type, and target references. The field is omitted when no override matched.

WAAP fields appear only when WAAP Status is Active on CDN → CDN resources. The toggle is in that resource’s Security settings. After WAAP is enabled, the next exported batch includes the new fields at the end of the line, so positional parsers keep working. Parsers that reject unknown columns must accept the WAAP fields first. The v field in HTTP(S) payloads increments when the schema changes.

DDoS protection logs are not exported through Logs Uploader. Only per-request WAAP security events are included. DDoS attack analytics remain available through the WAAP API and dashboard.
These fields are appended to each request log line when WAAP is enabled on the resource.
WAAP fields are best-effort: a field is empty ("") when WAAP did not compute a value for the request — no rule matched, or the request was served before WAAP analysis completed. Treat empty values as “not applicable”, not “zero”. policy_override is the exception: the field is omitted when no override matched.
The $waap_decision field gives the final security verdict that WAAP applied at the edge:The $waap_optional_action field describes any additional action applied alongside the decision:
Challenged requests are recorded as blocked. Logs are written at the edge as soon as the response is sent, before WAAP knows whether the client will solve the challenge. When the client passes the challenge, subsequent requests from the same session are exported with $waap_decision="passed" and $waap_passed_incident_id pointing back to the original incident. Trace the final outcome by joining the two log lines on the session identifier. The full per-incident result is also available through the WAAP Request Details API.

Troubleshooting

Authentication complete confirms that Logs Uploader can reach the destination. It does not mean a batch has arrived.

Batches are delivered at the end of the policy Time interval (minimum 5 minutes). Wait at least one full interval after generating CDN traffic.

If the covered resources receive no requests during an interval and Include empty logs is off, no batch is delivered. Turn the option on in the policy to confirm delivery without traffic. For a file-based target, an empty log file is about 20 bytes.

For S3, FTP, SFTP, and SLS, the bucket, directory, or logstore must already exist — Logs Uploader does not create missing paths. The credentials must allow writes: s3:PutObject (and often s3:GetBucketLocation) on S3, write access to the FTP/SFTP directory, or Write on an SLS logstore.

An HTTP(S) receiver must return 2xx before the request times out. Any other status is a delivery failure and is retried. If compression is on, the receiver must accept Content-Encoding: gzip.

A configuration limited to Specific Resources only exports those resources. All Resources includes resources created later.

Delivery error details are not shown in the portal. Contact Gcore Support for delivery logs for a target or time range.