Radar
radar
AI
radar.ai
Methods
Retrieves the distribution of unique accounts by model.
Retrieves the distribution of unique accounts by task.
radar.ai.inference.timeseries_groups.summary
Methods
Retrieves the distribution of unique accounts by model over time.
Retrieves the distribution of unique accounts by task over time.
Methods
Retrieves an aggregated summary of AI bots HTTP requests grouped by the specified dimension.
Retrieves AI bots HTTP request volume over time.
Retrieves the distribution of HTTP requests from AI bots, grouped by chosen the specified dimension over time.
Retrieves the distribution of traffic by AI user agent over time.
Annotations
radar.annotations
Methods
Retrieves the latest annotations.
radar.annotations.outages
Methods
Retrieves the latest Internet outages and anomalies.
Retrieves the number of outages by location.
AS112
radar.as112
Methods
Retrieves the AS112 DNS queries over time.
Methods
Retrieves the distribution of DNS queries to AS112 by DNSSEC (DNS Security Extensions) support.
Retrieves the distribution of DNS queries to AS112 by EDNS (Extension Mechanisms for DNS) support.
Retrieves the distribution of DNS queries to AS112 by IP version.
Retrieves the distribution of DNS queries to AS112 by protocol.
Retrieves the distribution of DNS queries to AS112 by type.
Retrieves the distribution of AS112 DNS requests classified by response code.
Methods
Retrieves the distribution of AS112 DNS queries by DNSSEC (DNS Security Extensions) support over time.
Retrieves the distribution of AS112 DNS queries by EDNS (Extension Mechanisms for DNS) support over time.
Retrieves the distribution of AS112 DNS queries by IP version over time.
Retrieves the distribution of AS112 DNS requests classified by protocol over time.
Retrieves the distribution of AS112 DNS queries by type over time.
Retrieves the distribution of AS112 DNS requests classified by response code over time.
Methods
Retrieves the top locations of DNS queries to AS112 with DNSSEC (DNS Security Extensions) support.
Retrieves the top locations of DNS queries to AS112 with EDNS (Extension Mechanisms for DNS) support.
Retrieves the top locations of DNS queries to AS112 for an IP version.
Retrieves the top locations by AS112 DNS queries.
Attacks
radar.attacks
Methods
Retrieves the distribution of layer 3 attacks by bitrate.
Retrieves the distribution of layer 3 attacks by duration.
Retrieves the distribution of layer 3 attacks by targeted industry.
Retrieves the distribution of layer 3 attacks by IP version.
Retrieves the distribution of layer 3 attacks by protocol.
Retrieves the distribution of layer 3 attacks by vector.
Retrieves the distribution of layer 3 attacks by targeted vertical.
Methods
Retrieves the distribution of layer 3 attacks by bitrate over time.
Retrieves the distribution of layer 3 attacks by duration over time.
Retrieves the distribution of layer 3 attacks by targeted industry over time.
Retrieves the distribution of layer 3 attacks by IP version over time.
Retrieves the distribution of layer 3 attacks by protocol over time.
Retrieves the distribution of layer 3 attacks by vector over time.
Retrieves the distribution of layer 3 attacks by targeted vertical over time.
Methods
Retrieves the top layer 3 attacks from origin to target location. Values are a percentage out of the total layer 3 attacks (with billing country). You can optionally limit the number of attacks by origin/target location (useful if all the top attacks are from or to the same location).
This endpoint is deprecated. To continue getting this data, switch to the summary by industry endpoint.
This endpoint is deprecated. To continue getting this data, switch to the summary by vertical endpoint.
Methods
Retrieves the origin locations of layer 3 attacks.
Retrieves the target locations of layer 3 attacks.
Methods
Retrieves the distribution of layer 7 attacks by HTTP method.
Retrieves the distribution of layer 7 attacks by HTTP version.
Retrieves the distribution of layer 7 attacks by targeted industry.
Retrieves the distribution of layer 7 attacks by IP version.
Retrieves the distribution of layer 7 attacks by managed rules.
Retrieves the distribution of layer 7 attacks by mitigation product.
Retrieves the distribution of layer 7 attacks by targeted vertical.
Methods
Retrieves the distribution of layer 7 attacks by HTTP method over time.
Retrieves the distribution of layer 7 attacks by HTTP version over time.
Retrieves the distribution of layer 7 attacks by targeted industry over time.
Retrieves the distribution of layer 7 attacks by IP version used over time.
Retrieves the distribution of layer 7 attacks by managed rules over time.
Retrieves the distribution of layer 7 attacks by mitigation product over time.
Retrieves the distribution of layer 7 attacks by targeted vertical over time.
Methods
Retrieves the top attacks from origin to target location. Values are percentages of the total layer 7 attacks (with billing country). The attack magnitude can be defined by the number of mitigated requests or by the number of zones affected. You can optionally limit the number of attacks by origin/target location (useful if all the top attacks are from or to the same location).
This endpoint is deprecated. To continue getting this data, switch to the summary by industry endpoint.
This endpoint is deprecated. To continue getting this data, switch to the summary by vertical endpoint.
Methods
Retrieves the top origin autonomous systems of layer 7 attacks. Values are percentages of the total layer 7 attacks, with the origin autonomous systems determined by the client IP address.
Methods
Retrieves the top origin locations of layer 7 attacks. Values are percentages of the total layer 7 attacks, with the origin location determined by the client IP address.
Retrieves the top target locations of and by layer 7 attacks. Values are a percentage out of the total layer 7 attacks. The target location is determined by the attacked zone's billing country, when available.
BGP
radar.bgp
Methods
Retrieves BGP updates over time. When requesting updates for an autonomous system, only BGP updates of type announcement are returned.
Methods
Retrieves all ASes in the current global routing tables with routing statistics.
Retrieves all Multi-Origin AS (MOAS) prefixes in the global routing tables.
Retrieves the prefix-to-ASN mapping from global routing tables.
Retrieves real-time BGP routes for a prefix, using public real-time data collectors (RouteViews and RIPE RIS).
Retrieves the BGP routing table stats.
Methods
Retrieves the top autonomous systems by BGP updates (announcements only).
Retrieves the full list of autonomous systems on the global routing table ordered by announced prefixes count. The data comes from public BGP MRT data archives and updates every 2 hours.
Bots
radar.bots
Methods
Retrieves the requested bot information.
Retrieves a list of bots.
Retrieves an aggregated summary of bots HTTP requests grouped by the specified dimension.
Retrieves bots HTTP request volume over time.
Retrieves the distribution of HTTP requests from bots, grouped by chosen the specified dimension over time.
Methods
Retrieves an aggregated summary of HTTP requests from crawlers, grouped by the specified dimension.
Retrieves the distribution of HTTP requests from crawlers, grouped by chosen the specified dimension over time.
Ct
radar.ct
Methods
Retrieves an aggregated summary of certificates grouped by the specified dimension.
Retrieves certificate volume over time.
Retrieves the distribution of certificates grouped by chosen the specified dimension over time.
Datasets
radar.datasets
Methods
Retrieves an URL to download a single dataset.
Retrieves the CSV content of a given dataset by alias or ID. When getting the content by alias the latest dataset is returned, optionally filtered by the latest available at a given date.
Retrieves a list of datasets.
DNS
radar.dns
Methods
Retrieves normalized query volume to the 1.1.1.1 DNS resolver over time.
Methods
Retrieves the distribution of DNS queries by cache status.
Retrieves the distribution of DNS responses by DNSSEC (DNS Security Extensions) support.
Retrieves the distribution of DNS queries by DNSSEC (DNS Security Extensions) client awareness.
Retrieves the distribution of DNSSEC-validated answers by end-to-end security status.
Retrieves the distribution of DNS queries by IP version.
Retrieves the distribution of DNS queries by matching answers.
Retrieves the distribution of DNS queries by DNS transport protocol.
Retrieves the distribution of DNS queries by type.
Retrieves the distribution of DNS queries by response code.
Retrieves the distribution of DNS queries by minimum response TTL.
Methods
Retrieves the distribution of DNS queries by cache status over time.
The preferred authorization scheme for interacting with the Cloudflare API. Create a token.
Example: Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
User Details Write User Details Read
Aggregation interval of the results (e.g., in 15 minutes or 1 hour intervals). Refer to Aggregation intervals.
Filters results by Autonomous System. Specify one or more Autonomous System Numbers (ASNs) as a comma-separated list. Prefix with -
to exclude ASNs from results. For example, -174, 3356
excludes results from AS174, but includes results from AS3356.
Filters results by continent. Specify a comma-separated list of alpha-2 codes. Prefix with -
to exclude continents from results. For example, -EU,NA
excludes results from EU, but includes results from NA.
End of the date range (inclusive).
Filters results by date range. For example, use 7d
and 7dcontrol
to compare this week with the previous week. Use this parameter or set specific start and end dates (dateStart
and dateEnd
parameters).
Start of the date range.
Format in which results will be returned.
Filters results by location. Specify a comma-separated list of alpha-2 codes. Prefix with -
to exclude locations from results. For example, -US,PT
excludes results from the US, but includes results from PT.
Array of names used to label the series in the response.
Specifies whether the response includes empty DNS responses (NODATA).
Filters results by DNS transport protocol.
Filters results by DNS query type.
Filters results by DNS response code.
Filters results by country code top-level domain (ccTLD).
Retrieves the distribution of DNS responses by DNSSEC (DNS Security Extensions) support over time.
Retrieves the distribution of DNS queries by DNSSEC (DNS Security Extensions) client awareness over time.
Retrieves the distribution of DNSSEC-validated answers by end-to-end security status over time.
Retrieves the distribution of DNS queries by IP version over time.
Retrieves the distribution of DNS queries by matching answers over time.
Retrieves the distribution of DNS queries by DNS transport protocol over time.
Retrieves the distribution of DNS queries by type over time.
Retrieves the distribution of DNS queries by response code over time.
Retrieves the distribution of DNS queries by minimum answer TTL over time.
Methods
Retrieves the top autonomous systems by DNS queries made to 1.1.1.1 DNS resolver.
Retrieves the top locations by DNS queries made to 1.1.1.1 DNS resolver.
radar.email
Domain types
Methods
Retrieves the distribution of emails by ARC (Authenticated Received Chain) validation.
Retrieves the distribution of emails by DKIM (DomainKeys Identified Mail) validation.
Retrieves the distribution of emails by DMARC (Domain-based Message Authentication, Reporting and Conformance) validation.
Retrieves the distribution of emails by encryption status (encrypted vs. not-encrypted).
Retrieves the distribution of emails by IP version.
Retrieves the distribution of emails by SPF (Sender Policy Framework) validation.
Methods
Retrieves the distribution of emails by ARC (Authenticated Received Chain) validation over time.
Retrieves the distribution of emails by DKIM (DomainKeys Identified Mail) validation over time.
Retrieves the distribution of emails by DMARC (Domain-based Message Authentication, Reporting and Conformance) validation over time.
Retrieves the distribution of emails by encryption status (encrypted vs. not-encrypted) over time.
Retrieves the distribution of emails by IP version over time.
Retrieves the distribution of emails by SPF (Sender Policy Framework) validation over time.
Methods
Retrieves the distribution of emails by ARC (Authenticated Received Chain) validation.
Retrieves the distribution of emails by DKIM (DomainKeys Identified Mail) validation.
Retrieves the distribution of emails by DMARC (Domain-based Message Authentication, Reporting and Conformance) validation.
Retrieves the distribution of emails by malicious classification.
Retrieves the proportion of emails by spam classification (spam vs. non-spam).
Retrieves the distribution of emails by SPF (Sender Policy Framework) validation.
Retrieves the proportion of emails by spoof classification (spoof vs. non-spoof).
Retrieves the distribution of emails by threat categories.
Retrieves the distribution of emails by TLS version.
Methods
Retrieves the distribution of emails by ARC (Authenticated Received Chain) validation over time.
Retrieves the distribution of emails by DKIM (DomainKeys Identified Mail) validation over time.
Retrieves the distribution of emails by DMARC (Domain-based Message Authentication, Reporting and Conformance) validation over time.
Retrieves the distribution of emails by malicious classification over time.
Retrieves the distribution of emails by spam classification (spam vs. non-spam) over time.
Retrieves the distribution of emails by SPF (Sender Policy Framework) validation over time.
Retrieves the distribution of emails by spoof classification (spoof vs. non-spoof) over time.
Retrieves the distribution of emails by threat category over time.
Retrieves the distribution of emails by TLS version over time.
Entities
radar.entities
Methods
Retrieves IP address information.
Methods
Retrieves the requested autonomous system information. (A confidence level below 5
indicates a low level of confidence in the traffic data - normally this happens because Cloudflare has a small amount of traffic from/to this AS). Population estimates come from APNIC (refer to https://labs.apnic.net/?p=526).
Retrieves the requested autonomous system information based on IP address. Population estimates come from APNIC (refer to https://labs.apnic.net/?p=526).
Retrieves a list of autonomous systems.
Retrieves AS-level relationship for given networks.