Skip to main content
Start with the project overview to identify the affected application, then open its domain to narrow the investigation.

Traffic analytics and events

Traffic analytics shows request decisions and traffic breakdowns. Security events lets you inspect individual requests, their method and path, client IP, decision, matched rule, and response status when available. Choose a time range and apply filters before exporting or comparing results. Select an event to open request details. Follow its IP into IP investigation to review related activity. Save reusable criteria under Saved filters, then apply them from the filters list to Security events.

DDoS activity

Open a domain’s DDoS activity to review detected attack windows and associated blocked requests. Correlate the time window with your application’s availability and origin metrics. An empty attack list means there are no recorded attacks in that result; it is not an availability check for your origin.

IP investigation and reference data

Enter a client IP in IP investigation to inspect reputation, network ownership, counts, and available attack or request history. Additional investigation sections require the threat intelligence add-on. Local reputation-tag changes require an eligible plan. Use Security reference to find tag names and network organizations for investigations or traffic rules. Search by name and copy the relevant value into your rule configuration.

Security insights

A domain’s Security insights lists findings, recommendations, and last-seen activity. Open a finding, investigate the underlying requests, and update its status as you address it. Use a silence with the relevant type, labels, and expiry for a known finding. A silence controls insight reporting; it does not create a traffic allow rule.

Interpret freshness

Security data can be served from the latest available snapshot. The console shows when data was updated and whether it is stale. API responses can include X-Aptranet-Data-Updated-At and X-Aptranet-Data-Stale. Preserve this context when exporting results. If data is stale or missing, refresh, widen the time range, and verify that requests reach the protected CDN distribution. Check service status before escalating with the project, domain, UTC time range, and request details. Never include credentials in a support request.