Fastly Next-Gen WAF Capture Guide For Unified aiFObserve
Best Capture Source
Use Fastly Next-Gen WAF request/security events and, where possible, pair them with Fastly delivery logs for byte counts, service IDs, backend names, and edge location context.
Basic Logging
- request timestamp
- request ID
- client IP
- host
- path or URL
- method
- response status
- action or outcome
- signal, rule, or tag
- site or workspace
- user agent
- request size and response size, if present
Extended Logging
- service ID and version
- site ID or corp/workspace ID
- agent or module mode
- rule ID, signal name, tag name, severity
- anomaly score or threshold
- backend/origin name
- edge POP/region
- request headers used for identity and trace correlation
- API route, account, tenant, or application metadata from custom headers
User And App Identity
- explicit identity headers from upstream auth or API gateway
- host/path/API route
- service ID, site ID, workspace/corp identifier
- user agent
For AI APIs, add a sanitized header such as X-Audit-User or X-Audit-Tenant at the upstream auth layer and include only that header in logs.
AI Provider And Location Evidence
Keep service ID, backend/origin, edge POP, host, and route. These support provider and data boundary reporting.