Skip to main content

Query

Query helps you investigate security activity for a specific identifier across your tenant's traffic configurations. You can search by Incident ID or IP address and review correlated activity from both application and network security services.

What Query Is Used For

Use Query when you need to:

  • Investigate a specific support case using an Incident ID
  • Investigate suspicious client behavior using an IP address
  • Review security activity from multiple services in one workflow

Figure 1: Query page

Supported Search Inputs

Query supports two input types:

  • Incident ID
  • IP address (IPv4 and IPv6)

Time Range and Time Zone

  • Presets: 24h, 3d, 7d, 14d and 30d
  • All query processing and displayed timestamps use the tenant time zone

How Query Works

When you submit an Incident ID query: Query searches for the exact Incident ID event and displays a detail-first event view. No timeline filtering is required for an Incident ID search.

When you submit an IP address query: Query runs a cross-traffic-configuration search for the selected time range, defaulted to 7 days.

The Activity Timeline provides a high-level view of activity across:

  • Application Security
  • Network Security

The timeline includes:

  • Event volume over time
  • Service-level breakdown by security capability

Application and Network Security Events

Query displays service-specific event tables for:

  • WAF
  • Rate Limiting
  • IP Access Control
  • Bot Protection
  • Network DDoS

For IP Reputation, summary cards show key context about an IP in our threat feed:

  • First seen and last seen
  • Attack types summary
  • Target traffic configuration

Event Definitions

Query normalizes activity from multiple services:

  • WAF event: Request blocked or logged by WAF
  • Rate Limiting event: Request blocked by configured rate limits
  • IP Access Control event: Request blocked by default policy, IP, ASN, or country controls
  • Bot Protection event: Request that fails bot challenge
  • Network DDoS event: Attack-window activity from sampled network telemetry