Observed window: 2026-09-17 10:12:01 → 19:59:11 UTC (≈9h47m) · 559 client-facing requests · 441 origin/forward legs
r/f).
30 equal-width bins across the full observed window
Same timeline bins as RPS, shown separately (no dual-axis)
559 client-facing requests
404 + 5xx = 0 in this sample — shown instead: 4xx (WAF-blocked + rate-limited) by normalized endpoint
Normalized paths (IDs/tokens collapsed); minimum 2 samples per endpoint
Top request sources, ranked by volume — click column headers to sort
| IP | Requests | Blocked (403/429) | Top Status | WAF Reason | # Hosts | Sample User-Agent |
|---|
Describe what you want in plain English — this runs entirely in your browser via a small pattern-matcher (no AI, no API calls, nothing leaves your machine). It maps common phrasings to fields it knows about (ARL/URI, IP, status, method, host, reason, user-agent, latency) and shows you the exact AWK command it built, which you can edit directly below.
Supports $1…$N, $0, $NF, NR, NF,
== != ~ !~ < <= > >= && || !, string concatenation, and print.
Pipe into sort [-n -r -u], uniq [-c], head/tail [-N],
grep [-v -i] PATTERN, or wc -l.
| Metric | Value |
|---|
Latency figures use the edge log's positional numeric field inferred as processing time (ms) — no published
field schema was available for this log format, so treat as a best-effort proxy rather than certified origin timing.
Format: Akamai edge/WAF delivery log, record types r (client request) and f (origin/forward leg).