Skip to content
Start here

Get network traffic time series

client.Radar.NetFlows.Timeseries(ctx, query) (*NetFlowsTimeseriesResponse, error)
GET/radar/netflows/timeseries

Retrieves network traffic (NetFlows) over time.

Security
API Token

The preferred authorization scheme for interacting with the Cloudflare API. Create a token.

Example:Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

Example:X-Auth-Email: user@example.com

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

Example:X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194
Accepted Permissions (at least one required)
User Details WriteUser Details Read
ParametersExpand Collapse
query NetFlowsTimeseriesParams
AggInterval param.Field[NetFlowsTimeseriesParamsAggInterval]Optional

Aggregation interval of the results (e.g., in 15 minutes or 1 hour intervals). Refer to Aggregation intervals. When omitted, the interval is auto-selected from the requested date range; finer intervals are only available for shorter ranges. If the requested interval is too granular for the date range, the request is rejected.

const NetFlowsTimeseriesParamsAggInterval15m NetFlowsTimeseriesParamsAggInterval = "15m"
const NetFlowsTimeseriesParamsAggInterval1h NetFlowsTimeseriesParamsAggInterval = "1h"
const NetFlowsTimeseriesParamsAggInterval1d NetFlowsTimeseriesParamsAggInterval = "1d"
const NetFlowsTimeseriesParamsAggInterval1w NetFlowsTimeseriesParamsAggInterval = "1w"
ASN param.Field[[]string]Optional

Filters results by Autonomous System. Specify one or more Autonomous System Numbers (ASNs) as a comma-separated list. Prefix with - to exclude ASNs from results. For example, -174, 3356 excludes results from AS174, but includes results from AS3356.

Continent param.Field[[]string]Optional

Filters results by continent. Specify a comma-separated list of alpha-2 codes. Prefix with - to exclude continents from results. For example, -EU,NA excludes results from EU, but includes results from NA.

DateEnd param.Field[[]Time]Optional

End of the date range (inclusive). Alternative to dateRange; provide together with dateStart. When requesting comparison series, every series must resolve to the same duration as the main series. Each dateStart/dateEnd is floored to the nearest 15 minutes before evaluation, so windows whose durations match only before alignment may be rejected.

DateRange param.Field[[]string]Optional

Filters results by relative date range ending at the current time, with each value producing a separate series. Use <n>d for days (up to 364d) or <n>w for weeks (up to 52w). Append control to request the equivalent previous period for comparison: the comparison window is shifted back by the current window’s length rounded up to a whole number of weeks, so it keeps the same weekday alignment and does not overlap the current window (e.g. 7dcontrol covers days -14 to -7, 10dcontrol covers days -24 to -14). For example, pass 7d and 7dcontrol to compare this week with the previous week. All series must resolve to the same duration as the main series; relative ranges (including control) satisfy this automatically. Use this parameter or set specific start and end dates (dateStart and dateEnd parameters).

DateStart param.Field[[]Time]Optional

Start of the date range. Alternative to dateRange; provide together with dateEnd. When requesting comparison series, every series must resolve to the same duration as the main series. Each dateStart/dateEnd is floored to the nearest 15 minutes before evaluation, so windows whose durations match only before alignment may be rejected.

Format param.Field[NetFlowsTimeseriesParamsFormat]Optional

Format in which results will be returned.

const NetFlowsTimeseriesParamsFormatJson NetFlowsTimeseriesParamsFormat = "JSON"
const NetFlowsTimeseriesParamsFormatCsv NetFlowsTimeseriesParamsFormat = "CSV"
GeoID param.Field[[]string]Optional

Filters results by Geolocation. Specify a comma-separated list of GeoNames IDs. Prefix with - to exclude geoIds from results. For example, -2267056,360689 excludes results from the 2267056 (Lisbon), but includes results from 5128638 (New York).

Location param.Field[[]string]Optional

Filters results by location. Specify a comma-separated list of alpha-2 codes. Prefix with - to exclude locations from results. For example, -US,PT excludes results from the US, but includes results from PT.

Name param.Field[[]string]Optional

Array of names used to label the series in the response.

Normalization param.Field[NetFlowsTimeseriesParamsNormalization]Optional

Normalization method applied to the results. Refer to Normalization methods. PERCENTAGE_CHANGE requires exactly one comparison series (e.g. a control date range).

const NetFlowsTimeseriesParamsNormalizationPercentageChange NetFlowsTimeseriesParamsNormalization = "PERCENTAGE_CHANGE"
const NetFlowsTimeseriesParamsNormalizationMin0Max NetFlowsTimeseriesParamsNormalization = "MIN0_MAX"
Product param.Field[[]NetFlowsTimeseriesParamsProduct]Optional

Filters the results by network traffic product types.

const NetFlowsTimeseriesParamsProductHTTP NetFlowsTimeseriesParamsProduct = "HTTP"
const NetFlowsTimeseriesParamsProductAll NetFlowsTimeseriesParamsProduct = "ALL"
ReturnsExpand Collapse
type NetFlowsTimeseriesResponse struct{…}
Meta NetFlowsTimeseriesResponseMeta

Metadata for the results.

AggInterval NetFlowsTimeseriesResponseMetaAggInterval

Aggregation interval of the results (e.g., in 15 minutes or 1 hour intervals). Refer to Aggregation intervals.

One of the following:
const NetFlowsTimeseriesResponseMetaAggIntervalFifteenMinutes NetFlowsTimeseriesResponseMetaAggInterval = "FIFTEEN_MINUTES"
const NetFlowsTimeseriesResponseMetaAggIntervalOneHour NetFlowsTimeseriesResponseMetaAggInterval = "ONE_HOUR"
const NetFlowsTimeseriesResponseMetaAggIntervalOneDay NetFlowsTimeseriesResponseMetaAggInterval = "ONE_DAY"
const NetFlowsTimeseriesResponseMetaAggIntervalOneWeek NetFlowsTimeseriesResponseMetaAggInterval = "ONE_WEEK"
const NetFlowsTimeseriesResponseMetaAggIntervalOneMonth NetFlowsTimeseriesResponseMetaAggInterval = "ONE_MONTH"
ConfidenceInfo NetFlowsTimeseriesResponseMetaConfidenceInfo
Annotations []NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotation
DataSource NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource

Data source for annotations.

One of the following:
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceAll NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "ALL"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceAIBots NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "AI_BOTS"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceAIGateway NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "AI_GATEWAY"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceBGP NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "BGP"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceBots NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "BOTS"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceConnectionAnomaly NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "CONNECTION_ANOMALY"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceCT NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "CT"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceDNS NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "DNS"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceDNSMagnitude NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "DNS_MAGNITUDE"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceDNSAS112 NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "DNS_AS112"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceDos NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "DOS"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceEmailRouting NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "EMAIL_ROUTING"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceEmailSecurity NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "EMAIL_SECURITY"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceFw NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "FW"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceFwPg NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "FW_PG"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceHTTP NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "HTTP"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceHTTPControl NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "HTTP_CONTROL"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceHTTPCrawlerReferer NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "HTTP_CRAWLER_REFERER"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceHTTPOrigins NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "HTTP_ORIGINS"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceIQI NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "IQI"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceLeakedCredentials NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "LEAKED_CREDENTIALS"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceNet NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "NET"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceRobotsTXT NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "ROBOTS_TXT"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceSpeed NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "SPEED"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSourceWorkersAI NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsDataSource = "WORKERS_AI"
Description string
EndDate Time
formatdate-time
EventType NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsEventType

Event type for annotations.

One of the following:
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsEventTypeEvent NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsEventType = "EVENT"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsEventTypeGeneral NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsEventType = "GENERAL"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsEventTypeOutage NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsEventType = "OUTAGE"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsEventTypePartialProjection NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsEventType = "PARTIAL_PROJECTION"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsEventTypePipeline NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsEventType = "PIPELINE"
const NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsEventTypeTrafficAnomaly NetFlowsTimeseriesResponseMetaConfidenceInfoAnnotationsEventType = "TRAFFIC_ANOMALY"
IsInstantaneous bool

Whether event is a single point in time or a time range.

LinkedURL string
formaturi
StartDate Time
formatdate-time
Tags []stringOptional
Level int64

Provides an indication of how much confidence Cloudflare has in the data.

DateRange []NetFlowsTimeseriesResponseMetaDateRange
EndTime Time

Adjusted end of date range.

formatdate-time
StartTime Time

Adjusted start of date range.

formatdate-time
LastUpdated Time

Timestamp of the last dataset update.

formatdate-time
Normalization NetFlowsTimeseriesResponseMetaNormalization

Normalization method applied to the results. Refer to Normalization methods.

One of the following:
const NetFlowsTimeseriesResponseMetaNormalizationPercentage NetFlowsTimeseriesResponseMetaNormalization = "PERCENTAGE"
const NetFlowsTimeseriesResponseMetaNormalizationMin0Max NetFlowsTimeseriesResponseMetaNormalization = "MIN0_MAX"
const NetFlowsTimeseriesResponseMetaNormalizationMinMax NetFlowsTimeseriesResponseMetaNormalization = "MIN_MAX"
const NetFlowsTimeseriesResponseMetaNormalizationRawValues NetFlowsTimeseriesResponseMetaNormalization = "RAW_VALUES"
const NetFlowsTimeseriesResponseMetaNormalizationPercentageChange NetFlowsTimeseriesResponseMetaNormalization = "PERCENTAGE_CHANGE"
const NetFlowsTimeseriesResponseMetaNormalizationRollingAverage NetFlowsTimeseriesResponseMetaNormalization = "ROLLING_AVERAGE"
const NetFlowsTimeseriesResponseMetaNormalizationOverlappedPercentage NetFlowsTimeseriesResponseMetaNormalization = "OVERLAPPED_PERCENTAGE"
const NetFlowsTimeseriesResponseMetaNormalizationRatio NetFlowsTimeseriesResponseMetaNormalization = "RATIO"
Units []NetFlowsTimeseriesResponseMetaUnit

Measurement units for the results.

Name string
Value string
Serie0 NetFlowsTimeseriesResponseSerie0
Timestamps []Time
Values []string

Get network traffic time series

package main

import (
  "context"
  "fmt"

  "github.com/cloudflare/cloudflare-go"
  "github.com/cloudflare/cloudflare-go/option"
  "github.com/cloudflare/cloudflare-go/radar"
)

func main() {
  client := cloudflare.NewClient(
    option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"),
  )
  response, err := client.Radar.NetFlows.Timeseries(context.TODO(), radar.NetFlowsTimeseriesParams{

  })
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", response.Meta)
}
{
  "result": {
    "meta": {
      "aggInterval": "FIFTEEN_MINUTES",
      "confidenceInfo": {
        "annotations": [
          {
            "dataSource": "ALL",
            "description": "Cable cut in Tonga",
            "endDate": "2019-12-27T18:11:19.117Z",
            "eventType": "EVENT",
            "isInstantaneous": true,
            "linkedUrl": "https://example.com",
            "startDate": "2019-12-27T18:11:19.117Z",
            "tags": [
              "BOT_CLASS"
            ]
          }
        ],
        "level": 0
      },
      "dateRange": [
        {
          "endTime": "2022-09-17T10:22:57.555Z",
          "startTime": "2022-09-16T10:22:57.555Z"
        }
      ],
      "lastUpdated": "2019-12-27T18:11:19.117Z",
      "normalization": "PERCENTAGE",
      "units": [
        {
          "name": "*",
          "value": "requests"
        }
      ]
    },
    "serie_0": {
      "timestamps": [
        "2019-12-27T18:11:19.117Z"
      ],
      "values": [
        "10"
      ]
    }
  },
  "success": true
}
Returns Examples
{
  "result": {
    "meta": {
      "aggInterval": "FIFTEEN_MINUTES",
      "confidenceInfo": {
        "annotations": [
          {
            "dataSource": "ALL",
            "description": "Cable cut in Tonga",
            "endDate": "2019-12-27T18:11:19.117Z",
            "eventType": "EVENT",
            "isInstantaneous": true,
            "linkedUrl": "https://example.com",
            "startDate": "2019-12-27T18:11:19.117Z",
            "tags": [
              "BOT_CLASS"
            ]
          }
        ],
        "level": 0
      },
      "dateRange": [
        {
          "endTime": "2022-09-17T10:22:57.555Z",
          "startTime": "2022-09-16T10:22:57.555Z"
        }
      ],
      "lastUpdated": "2019-12-27T18:11:19.117Z",
      "normalization": "PERCENTAGE",
      "units": [
        {
          "name": "*",
          "value": "requests"
        }
      ]
    },
    "serie_0": {
      "timestamps": [
        "2019-12-27T18:11:19.117Z"
      ],
      "values": [
        "10"
      ]
    }
  },
  "success": true
}