Events Bug ? Query String Empty

Hi, i'm facing a weird bug apparently, and i'm on it since hours as i played with quite some settings over the last days... but i think its actually a real bug... in Security > Events (or new dash Security > Analytics > Events)... i used to see the Query String field an be able to understand some behaviors and things that i had to deal with, create rules accordingly and so... also was able to spot wrongly blocked things also based on that, and was able to filter based on query string... now rules still works and apply but i'm at bling all are showing empty query string... (except in some rare cases when an image is involved like part is /favicon.ico then there is a query string... the rest of the time its simply empty...) please if its not a bug and you may have an idea what can be causing that let me know as its driving me crazy... thank you a lot.
3 Replies
TeslaVision Streams & Servers
Is it a general bug like you all have same issue as i have or is it something related to me and maybe i messed up with something ? (even if i don't see how i could mess with something that technically exist but is just not showing up in the logs... Maybe some feature impacts the logging of query string ? ) please can someone check if this is happening on his side as well or is it a "me thing"... :-/ if you have WAF rules... and anything in event logs... can you check if you are getting any Query String stored in logs please ? i don't understand really what is happening... but in event logs query string is not empty only when path is /favicon.ico or any .js file... but for .php query string is always empty now... (its really annoying to not understand what is causing that) ? i don't get how you came to such answer... i'm reading again i don't see what is hard to understand in the issue i'm facing... i have api.php... no matter the query string it doesn't show up anymore in Event logs... (except when sent get or head to a path that is not .php but .ico or .js...) so yes there is a query string in the request and as i said WAF rules based on those queries (old rules or even new one that i created for test purpose) do work like if i block on query string that contains "TestQueryString" it actually gets blocked by cloudflare properly... but in Events it shows the blocked request but showing empty in the Query String field (which is a little problematic as outside of test purpose how can i make any difference with query string showing as empty...) ... Can anyone check? ... i see another guy on CF community opened a thread with same/similar issue and getting no answers as well... is this some kind of Taboo thing or something ? (https://community.cloudflare.com/t/security-analytics-events-query-string-empty-query-string-it-should-be-able-to-rec/786172) 👋 bumping... it seems that anything that contain "username" or "password" is now not showing for some reason... is there an option or something to get that to show up back ? hello ? Bump
Idle
Idle•3w ago
are you confusing query string with path maybe you can provide a sample string
TeslaVision Streams & Servers
No i'm not confusing, i'm talking about the query string. Any that contain "password=" is not showing up anymore... Those are all plain usernames and password that i already see anyway... I don't get why it would be skiped from appearing in events? Bump again xD Still trying to understand if its a bug, if its intentionally like this now, or if there is a setting that result in this... ▲▲▲ O_o now they seems to be back... I again see the query strings... Was it a cloudflare bug or something at the end? As no one answers its hard to know if its me somehow triggering this or is there a change of any setting that makes this to happen for a period of time... Or was it a simple bug frop CF to everyone...

Did you find this page helpful?