Monitoring, notifications and audit
Dashboard The Dashboard shows traffic across all services over 24 hours, 3 days or 7 days: Summary cards: requests, average latency and bandwidth, plus counts of each block type (WAF, ML, rate limits, blocklist, IP intel, auth failures, bot challenges, malware and behaviour). Charts: request volume, a latency breakdown by pipeline stage, volume by service, bandwidth, a block breakdown, the asset cache and security events. In a cluster you can view all nodes or one node. Security events Page Shows WAF Events Requests blocked (or audited) by the WAF, grouped by service, path and rule. You can create whitelist rules from here. ML Events Requests flagged by the ML WAF (licensed). ACME Events Certificate issuance and renewal attempts. Exception Requests Visitors' requests to lift a block. Audit Log Every administrative change and sign-in. Audit log Security Events > Audit Log records who changed what and when: services, settings, WAF and whitelist rules, users, blocks, and sign-ins. You can filter by type, action, user, status and time, and expanding a row shows the old and new value of each field. Entries are kept for 90 days by default (Settings > Logging & Audit > Audit Retention). Email notifications Configure SMTP under Settings > Notifications > SMTP Email Configuration: host, port, username, password, from address, and encryption (STARTTLS, SSL/TLS or none). Send a test email to check it. Each administrator chooses the events they want on their Profile page under Notification Subscriptions, delivered by email or Pushover. Events you can subscribe to: WAF and ML blocks Malware detections Automatic behaviour blocks New and reviewed exception requests Admin sign-ins Tunnel enabled, disabled or disconnected, and all of a tunnel's upstreams down License expiring Email templates for each event can be edited under Settings > Notifications > Email Templates, using merge tags such as {{service_name}} and {{client_ip}}. The same SMTP settings deliver the one-time codes for Email Code sign-in.
NullWard documentation