Cloudflare Traffic Auditor turns bounded zone analytics into a privacy-conscious traffic and security evidence brief without changing Cloudflare configuration.
It reads Cloudflare's current adaptive HTTP-request and firewall-event datasets for one explicitly connected zone. Traffic totals preserve sampling notes. Security reads deliberately omit IP addresses, paths, query strings, and user agents. Comparisons state what changed while refusing to turn correlation into a deployment, outage, campaign, or attack diagnosis.
What you can do
- summarize_traffic β read estimated requests, visits, bytes, and hourly groups
- inspect_security_events β group recent rule actions by source, action, and country
- compare_traffic β calculate transparent changes across two explicit UTC windows
- build_incident_brief β combine supplied observations with safe next checks
Who it's for
Site operators, security teams, agencies, developers, incident leads, and founders answering βwhat changed?β before touching DNS, cache, WAF, or firewall settings.
How to use it
- Connect a zone-scoped token with Zone Analytics Read permission
- Query a short explicit UTC range and preserve the sampling note
- Compare equal windows before escalating a change
- Review non-identifying security-event groups and any query cap
- Validate hypotheses against origin logs and application telemetry
Getting started
Start with a 24-hour traffic summary and a 200-event security sample. The tool is read-only and never edits DNS, WAF rules, cache settings, rate limits, firewall configuration, or zone state.