Skip to content

WAF event logs

GET
/analytics/waf-logs
curl --request GET \
--url 'https://api.nsin.ir/analytics/waf-logs?domain=example.com&period=3h&limit=100&offset=0' \
--header 'Authorization: Bearer <token>'

Requests the WAF evaluated, with the rules that fired and the score they produced. Entries where dryRun is true were logged only — the request was not actually blocked.

domain
required
string

The domain name (for example example.com). These endpoints take the domain as a query parameter rather than a path segment.

Example
example.com
period
string
default: 24h
Allowed values: 3h 6h 12h 24h 7d 30d

Time window, ending now. Buckets are hourly up to 24h and daily for 7d and 30d. An unrecognised value falls back to 24h.

limit
integer
default: 100
offset
integer
0
hostname
string

Substring match on hostname.

action
string

The action taken.

ruleId
string

A CRS rule id that fired.

clientIp
string
country
string
rayId
string
blocked
boolean

Restrict to blocked or non-blocked requests.

A page of WAF events.

Media type application/json
object
data
Array<object>
object
ts
string format: date-time
domainId
integer
recordId
integer
hostname
string
node
string
rayId
string
clientIp
string
country
string
clientPort
integer
method
string
uri
string
httpVersion
string
action
string
blocked
boolean
dryRun

True when the rule only logged; the request was not blocked.

boolean
score

Anomaly score reached.

integer
paranoia
integer
threshold
integer
status
integer
ja4
string
ja4h
string
userAgent
string
headers
string
body
string
ruleIds
Array<integer>
messages
Array<string>
ruleData
Array<string>
variables
Array<string>
severities
Array<integer>
tags
Array<string>
total
integer
limit
integer
offset
integer
Example generated
{
"data": [
{
"ts": "2026-04-15T12:00:00Z",
"domainId": 1,
"recordId": 1,
"hostname": "example",
"node": "example",
"rayId": "example",
"clientIp": "example",
"country": "example",
"clientPort": 1,
"method": "example",
"uri": "example",
"httpVersion": "example",
"action": "example",
"blocked": true,
"dryRun": true,
"score": 1,
"paranoia": 1,
"threshold": 1,
"status": 1,
"ja4": "example",
"ja4h": "example",
"userAgent": "example",
"headers": "example",
"body": "example",
"ruleIds": [
1
],
"messages": [
"example"
],
"ruleData": [
"example"
],
"variables": [
"example"
],
"severities": [
1
],
"tags": [
"example"
]
}
],
"total": 1,
"limit": 1,
"offset": 1
}

The domain query parameter is missing.

Media type application/json

The single error shape used by every endpoint.

object
error
required

Human-readable description of what went wrong.

string
Examples
Example missing
{
"error": "domain is required"
}

Missing, malformed, revoked or expired API key — or the owning account is inactive.

Media type application/json

The single error shape used by every endpoint.

object
error
required

Human-readable description of what went wrong.

string
Examples
Example invalidKey
{
"error": "invalid API key"
}

The domain’s plan does not include the feature this endpoint needs (monitoring for most sections, logs for raw and top-N request data).

Media type application/json

The single error shape used by every endpoint.

object
error
required

Human-readable description of what went wrong.

string
Example
{
"error": "read-only API key"
}

No such domain, or it is not visible to this account. Domains you cannot access are reported as not found rather than forbidden.

Media type application/json

The single error shape used by every endpoint.

object
error
required

Human-readable description of what went wrong.

string
Example
{
"error": "read-only API key"
}

The key exceeded its request budget (300 requests per minute by default).

Media type application/json

The single error shape used by every endpoint.

object
error
required

Human-readable description of what went wrong.

string
Examples
Example limited
{
"error": "rate limit exceeded"
}

The analytics backend is temporarily unreachable. Retry; no data is lost.

Media type application/json

The single error shape used by every endpoint.

object
error
required

Human-readable description of what went wrong.

string
Examples
Example unavailable
{
"error": "analytics unavailable"
}