Use Profile Analysis in Security Analytics to investigate profile detections.
Profile Analysis classifies requests with these statuses:
- Conforms: The evaluated request matched its applicable profile.
- Violates: The evaluated request did not match its applicable profile.
- Not evaluated: No applicable profile is available, or the profile does not apply.
Sampled violations include structured details about the first detected validation failure:
| Detail | Meaning | Example |
|---|---|---|
| Location | The request component containing the violation. | body |
| Error class | A stable, broad category for grouping similar violations. | constraint_violation |
| Error detail | An optional, specific reason within the error class. | number_not_in_range |
| Target | An optional parameter, header, cookie, or JSON body path associated with the violation. | $.items[0].quantity |
The error detail or target can be empty when the other fields fully describe the violation. For example, a missing request body has the missing_required error class without a target.
For all possible error classes and details, refer to Fields.
-
In the Cloudflare dashboard, go to Security > Analytics.
Go to Analytics ↗ -
Open Profile Analysis and select a profile.
-
Review conformance trends over your selected time range.
-
Inspect sampled violations for the request component and affected field.
-
Review each sampled violation reason before configuring mitigation.
-
Filter by
cf.schema_validation.learned.violatedorcf.schema_validation.uploaded.violatedto inspect the corresponding source.
A non-conforming request is not necessarily malicious. Releases, new clients, and valid edge cases can produce violations.
Cloudflare runs an always-on detection after a profile becomes available. Detection does not block requests by itself.
After reviewing representative traffic, refer to Enforce profiles with Custom Rules.