Canary signals
Canary signals describe persisted Site Canary events for a monitored domain. Canary rules require Site Canaries access.
Use Canary fields
Section titled “Use Canary fields”canary.edge_outcome:unexpected ANDcanary.subdomain_depth:>2canary.policy_mismatch:trueedge_outcome accepts the exact values expected and unexpected. The request metadata fields use absent, partial, same-origin, same-site, or cross-site.
The observed origin and hostname are client-asserted values bound to the edge challenge. An unexpected outcome is evidence to investigate; it does not by itself establish malicious intent.
Browse signals
Section titled “Browse signals”10 signals
No signals match these filters. Try a shorter term or choose all groups.
Canary events 10
-
canary.created_ondate - Timestamp when the Canary event was observed
-
canary.monitored_fqdnstring - Configured fully qualified domain name monitored by the Canary
-
canary.observed_originstring - Client-asserted request origin bound to the edge challenge
-
canary.observed_hostnamestring - Client-asserted request hostname bound to the edge challenge
-
canary.registrable_domainstring - Registrable domain derived from the observed hostname
-
canary.subdomain_depthnumber - Observed hostname depth below its registrable domain
-
canary.edge_outcomekeyword - Exact edge classification of the Canary event
-
canary.policy_mismatchboolean - Whether the edge outcome differed from the current classification at ingestion
-
canary.get_metadata_statekeyword - Exact Fetch Metadata state observed on the Canary GET request
-
canary.check_metadata_statekeyword - Exact Fetch Metadata state observed on the Canary check request