Skip to content

Canary signals

Canary signals describe persisted Site Canary events for a monitored domain. Canary rules require Site Canaries access.

canary.edge_outcome:unexpected AND
canary.subdomain_depth:>2
canary.policy_mismatch:true

edge_outcome accepts the exact values expected and unexpected. The request metadata fields use absent, partial, same-origin, same-site, or cross-site.

The observed origin and hostname are client-asserted values bound to the edge challenge. An unexpected outcome is evidence to investigate; it does not by itself establish malicious intent.

10 signals

Canary events 10
canary.created_on date
Timestamp when the Canary event was observed
canary.monitored_fqdn string
Configured fully qualified domain name monitored by the Canary
canary.observed_origin string
Client-asserted request origin bound to the edge challenge
canary.observed_hostname string
Client-asserted request hostname bound to the edge challenge
canary.registrable_domain string
Registrable domain derived from the observed hostname
canary.subdomain_depth number
Observed hostname depth below its registrable domain
canary.edge_outcome keyword
Exact edge classification of the Canary event
canary.policy_mismatch boolean
Whether the edge outcome differed from the current classification at ingestion
canary.get_metadata_state keyword
Exact Fetch Metadata state observed on the Canary GET request
canary.check_metadata_state keyword
Exact Fetch Metadata state observed on the Canary check request