Open MihaiBojin opened 8 hours ago
Extract events:
SELECT
zone_id,
data->>'kind' as kind,
data->>'action' as action,
data->>'clientIP' as client_ip,
data->>'clientAsn' as client_asn,
data->>'userAgent' as user_agent,
data->>'description' as description,
data->>'edgeColoName' as edge_colo_name,
data->>'clientCountryName' as client_country_name,
data->>'clientRequestPath' as client_request_path,
data->>'clientRequestQuery' as client_request_query,
data->>'clientRequestScheme' as client_request_scheme,
data->>'clientASNDescription' as client_asn_description,
data->>'clientRequestHTTPHost' as client_request_http_host,
data->>'clientRequestHTTPProtocol' as client_request_http_protocol,
data->>'clientRequestHTTPMethodName' as client_request_http_method_name,
data->>'leakedCredentialCheckResult' as leaked_credential_check_result,
count(*) as cnt
FROM public.cf_waf_logs_adaptive
-- WHERE datetime >= CURRENT_DATE - INTERVAL '1 day' AND datetime < CURRENT_DATE + INTERVAL '1 day'
GROUP BY 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17
ORDER BY cnt DESC;