---
title: Query analytics timeseries
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/python)

[Analytics Query](https://developers.cloudflare.com/api/python/resources/analytics_query)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Query analytics timeseries

analytics\_query.timeseries(strdataset, AnalyticsQueryTimeseriesParams\*\*kwargs) -> [AnalyticsQueryTimeseriesResponse](<https://developers.cloudflare.com/api/python/resources/analytics_query#(resource)%20analytics_query%20%3E%20(model)%20analytics_query_timeseries_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/analytics/query/{dataset}/timeseries

Returns time-bucketed analytics data for a dataset. Includes time slots, each containing the requested stats, group-by dimensions, and resolution-controlled bucket size (e.g. `hour`, `day`).

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`Zero Trust Read`

##### ParametersExpand Collapse

account\_id: str

maxLength32

[Link to this property](<#(resource)%20analytics_query%20%3E%20(method)%20timeseries%20%3E%20(params)%20default%20%3E%20(param)%20account_id%20%3E%20(schema)>)

dataset: str

[Link to this property](<#(resource)%20analytics_query%20%3E%20(method)%20timeseries%20%3E%20(params)%20default%20%3E%20(param)%20dataset%20%3E%20(schema)>)

<details>

<summary>

filters: Iterable\[Filter]

Filters to apply before aggregating results.

</summary>

name: str

Specifies the column name to filter on. Requires a valid column for the target dataset (e.g. <code>country</code>, <code>allowed</code>, <code>appId</code>).

<a href="#(resource)%20analytics_query%20%3E%20(method)%20timeseries%20%3E%20(params)%20default%20%3E%20(param)%20filters%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

op: str

Filter operator. Common values: <code>eq</code>, <code>neq</code>, <code>in</code>, <code>not_in</code>, <code>gt</code>, <code>lt</code>, <code>gte</code>, <code>lte</code>.

<a href="#(resource)%20analytics_query%20%3E%20(method)%20timeseries%20%3E%20(params)%20default%20%3E%20(param)%20filters%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20op">Link to this property</a>

<details>

<summary>

values: Sequence\[Union\[str, bool, float]]

Values to match against. Type depends on the column.

</summary>

One of the following:

str

<a href="#(resource)%20analytics_query%20%3E%20(method)%20timeseries%20%3E%20(params)%20default%20%3E%20(param)%20filters%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20values%20%3E%20(items)%20%3E%20(variant)%200">Link to this property</a>

bool

<a href="#(resource)%20analytics_query%20%3E%20(method)%20timeseries%20%3E%20(params)%20default%20%3E%20(param)%20filters%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20values%20%3E%20(items)%20%3E%20(variant)%201">Link to this property</a>

float

<a href="#(resource)%20analytics_query%20%3E%20(method)%20timeseries%20%3E%20(params)%20default%20%3E%20(param)%20filters%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20values%20%3E%20(items)%20%3E%20(variant)%202">Link to this property</a>

</details>

<a href="#(resource)%20analytics_query%20%3E%20(method)%20timeseries%20%3E%20(params)%20default%20%3E%20(param)%20filters%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20values">Link to this property</a>

</details>

[Link to this property](<#(resource)%20analytics_query%20%3E%20(method)%20timeseries%20%3E%20(params)%20default%20%3E%20(param)%20filters%20%3E%20(schema)>)

from\_: Union\[str, datetime]

The start of the query time range (inclusive). RFC3339 format with timezone is required (e.g. `2024-11-05T00:00:00Z`).

formatdate-time

[Link to this property](<#(resource)%20analytics_query%20%3E%20(method)%20timeseries%20%3E%20(params)%20default%20%3E%20(param)%20from%20%3E%20(schema)>)

group\_by: Sequence\[str]

Specifies the column names to group results by. Requires valid columns for the target dataset.

[Link to this property](<#(resource)%20analytics_query%20%3E%20(method)%20timeseries%20%3E%20(params)%20default%20%3E%20(param)%20groupBy%20%3E%20(schema)>)

resolution: str

Time bucket size for grouping results. Controls the granularity of the returned time slots.

[Link to this property](<#(resource)%20analytics_query%20%3E%20(method)%20timeseries%20%3E%20(params)%20default%20%3E%20(param)%20resolution%20%3E%20(schema)>)

stats: Sequence\[str]

Specifies the stat names to include in results. Requires valid stats for the target dataset (e.g. `attemptsTotal`, `bytesTotal`).

[Link to this property](<#(resource)%20analytics_query%20%3E%20(method)%20timeseries%20%3E%20(params)%20default%20%3E%20(param)%20stats%20%3E%20(schema)>)

to: Union\[str, datetime]

Specifies the end of the query time range (exclusive). Requires RFC3339 format with timezone.

formatdate-time

[Link to this property](<#(resource)%20analytics_query%20%3E%20(method)%20timeseries%20%3E%20(params)%20default%20%3E%20(param)%20to%20%3E%20(schema)>)

##### ReturnsExpand Collapse

<details>

<summary>

class AnalyticsQueryTimeseriesResponse: …

</summary>

resolution: str

The resolution used for time bucketing.

<a href="#(resource)%20analytics_query%20%3E%20(model)%20analytics_query_timeseries_response%20%3E%20(schema)%20%3E%20(property)%20resolution">Link to this property</a>

slots: List\[Dict\[str, object]]

Time-bucketed result rows. Each slot contains a <code>time_bucket</code> field plus the requested stats and group-by dimensions.

<a href="#(resource)%20analytics_query%20%3E%20(model)%20analytics_query_timeseries_response%20%3E%20(schema)%20%3E%20(property)%20slots">Link to this property</a>

</details>

[Link to this property](<#(resource)%20analytics_query%20%3E%20(model)%20analytics_query_timeseries_response%20%3E%20(schema)>)

### Query analytics timeseries

Python

HTTPTypeScriptPythonGoTerraform

```
import os
from datetime import datetime
from cloudflare import Cloudflare

client = Cloudflare(
    api_token=os.environ.get("CLOUDFLARE_API_TOKEN"),  # This is the default and can be omitted
)
response = client.analytics_query.timeseries(
    dataset="shadow_it",
    account_id="023e105f4ecef8ad9ca31a8372d0c353",
    filters=[{
        "name": "allowed",
        "op": "eq",
        "values": [True],
    }],
    from_=datetime.fromisoformat("2024-11-01T00:00:00"),
    group_by=["country", "allowed"],
    resolution="day",
    stats=["attemptsTotal"],
    to=datetime.fromisoformat("2024-11-08T00:00:00"),
)
print(response.resolution)
```

200 example

400 example

400 example

403 example

403 example

```
{
  "errors": [],
  "messages": [
    {
      "code": 1000,
      "message": "API in beta: expect breaking changes."
    }
  ],
  "result": {
    "resolution": "hour",
    "slots": [
      {
        "appName": "Slack",
        "bytesTotal": 1048576,
        "time_bucket": "2024-11-05T00:00:00Z"
      },
      {
        "appName": "Slack",
        "bytesTotal": 2097152,
        "time_bucket": "2024-11-05T01:00:00Z"
      }
    ]
  },
  "success": true
}
```

```
{
  "errors": [
    {
      "code": 11005,
      "message": "art.api.parameter.invalid"
    }
  ],
  "messages": [
    {
      "code": 1002,
      "message": "Parameter 'from' has invalid value '2024-11-05 00:00:00'. Should be of type: 'RFC3339'"
    }
  ],
  "result": null,
  "success": false
}
```

```
{
  "errors": [
    {
      "code": 11005,
      "message": "art.api.parameter.invalid"
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "API in beta: expect breaking changes."
    }
  ],
  "result": null,
  "success": false
}
```

```
{
  "errors": [
    {
      "code": 11003,
      "message": "art.api.resource.insufficient_permissions"
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "API in beta: expect breaking changes."
    }
  ],
  "result": null,
  "success": false
}
```

```
{
  "errors": [
    {
      "code": 11003,
      "message": "art.api.resource.insufficient_permissions"
    }
  ],
  "messages": [],
  "result": null,
  "success": false
}
```

##### Returns Examples

200 example

400 example

400 example

403 example

403 example

```
{
  "errors": [],
  "messages": [
    {
      "code": 1000,
      "message": "API in beta: expect breaking changes."
    }
  ],
  "result": {
    "resolution": "hour",
    "slots": [
      {
        "appName": "Slack",
        "bytesTotal": 1048576,
        "time_bucket": "2024-11-05T00:00:00Z"
      },
      {
        "appName": "Slack",
        "bytesTotal": 2097152,
        "time_bucket": "2024-11-05T01:00:00Z"
      }
    ]
  },
  "success": true
}
```

```
{
  "errors": [
    {
      "code": 11005,
      "message": "art.api.parameter.invalid"
    }
  ],
  "messages": [
    {
      "code": 1002,
      "message": "Parameter 'from' has invalid value '2024-11-05 00:00:00'. Should be of type: 'RFC3339'"
    }
  ],
  "result": null,
  "success": false
}
```

```
{
  "errors": [
    {
      "code": 11005,
      "message": "art.api.parameter.invalid"
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "API in beta: expect breaking changes."
    }
  ],
  "result": null,
  "success": false
}
```

```
{
  "errors": [
    {
      "code": 11003,
      "message": "art.api.resource.insufficient_permissions"
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "API in beta: expect breaking changes."
    }
  ],
  "result": null,
  "success": false
}
```

```
{
  "errors": [
    {
      "code": 11003,
      "message": "art.api.resource.insufficient_permissions"
    }
  ],
  "messages": [],
  "result": null,
  "success": false
}
```