Skip to content
Tools / Cloudflare Traffic Auditor
Cloudflare Traffic Auditor icon

Cloudflare Traffic Auditor

Explain traffic and security changes without exposing visitor identities

Paid skills show the price before running, and failed paid calls do not charge.

Cloudflare Traffic Auditor turns bounded zone analytics into a privacy-conscious traffic and security evidence brief without changing Cloudflare configuration.

It reads Cloudflare's current adaptive HTTP-request and firewall-event datasets for one explicitly connected zone. Traffic totals preserve sampling notes. Security reads deliberately omit IP addresses, paths, query strings, and user agents. Comparisons state what changed while refusing to turn correlation into a deployment, outage, campaign, or attack diagnosis.

What you can do

  • summarize_traffic β€” read estimated requests, visits, bytes, and hourly groups
  • inspect_security_events β€” group recent rule actions by source, action, and country
  • compare_traffic β€” calculate transparent changes across two explicit UTC windows
  • build_incident_brief β€” combine supplied observations with safe next checks

Who it's for

Site operators, security teams, agencies, developers, incident leads, and founders answering β€œwhat changed?” before touching DNS, cache, WAF, or firewall settings.

How to use it

  1. Connect a zone-scoped token with Zone Analytics Read permission
  2. Query a short explicit UTC range and preserve the sampling note
  3. Compare equal windows before escalating a change
  4. Review non-identifying security-event groups and any query cap
  5. Validate hypotheses against origin logs and application telemetry

Getting started

Start with a 24-hour traffic summary and a 200-event security sample. The tool is read-only and never edits DNS, WAF rules, cache settings, rate limits, firewall configuration, or zone state.

Permissions and setup

  • Cloudflare API Token (secret): Zone-scoped API token with Zone Analytics Read permission and no edit scopes. Official setup
  • Cloudflare Zone ID (credential): Exact zone identifier whose traffic and security analytics may be read.
Summarize TrafficPricing: paid

Read sampled Cloudflare eyeball-request counts, visits, response bytes, and hourly groups for one bounded UTC window.

Returns: Sample-aware traffic totals and hourly groups with an explicit evidence boundary
Inspect Security EventsPricing: paid

Read bounded firewall events without requesting IP addresses, URLs, query strings, request paths, or user-agent values.

Returns: Non-identifying firewall-event evidence and counts with truncation and diagnosis limits
Compare Traffic WindowsPricing: paid

Compare sampled requests, visits, and bytes across two explicit windows without attributing the observed change to a cause.

Returns: Two sample-aware traffic summaries and deterministic percentage changes
Build Incident BriefPricing: paid

Combine caller-supplied traffic and security observations with safe next checks while preserving causal and authorization limits.

Returns: An evidence-only incident brief with safe validation steps and no configuration changes
Loading reviews...

Loading activity...

v0.012026-08-30
  • Initial privacy-conscious release with sampled traffic summaries, security-event groups, window comparison, and incident briefs

Copy these instructions to use Cloudflare Traffic Auditor in Claude, ChatGPT, Copilot, and more.

What you can do with Cloudflare Traffic Auditor

Investigate a Cloudflare traffic change safely

Compare sampled traffic and non-identifying security evidence before touching production configuration.

  1. Call `summarize_traffic` for the exact UTC incident window.
  2. Run `compare_traffic` against an equal baseline and `inspect_security_events` with a bounded cap.
  3. Use `build_incident_brief`, then validate against origin and application telemetry.

Related Tools

Open Page Speed Test
Page Speed Test icon
Page Speed TestPerformance, SEO & Web Vitalsfrom $0.005
β˜…β˜…β˜…β˜…β˜…1

Frequently Asked Questions

Can Cloudflare Traffic Auditor explain a traffic spike?

It can quantify sampled request, visit, byte, and firewall-action changes across explicit UTC windows, but it does not claim an attack, outage, deployment, or campaign caused the movement.

Does the Cloudflare security query return visitor IP addresses?

No. It deliberately omits IP addresses, request paths, query strings, and user agents and requests only action, source, country, ASN, and timestamp evidence.

Can it change Cloudflare DNS, WAF, cache, or firewall settings?

No. It uses Zone Analytics Read data only and has no mutation path for DNS, cache, rate limits, WAF rules, firewall configuration, or zone state.