Read the lines
One JSON object per request: ts, edge, client_ip, method, scheme, host, uri, protocol, status, bytes, cache (HIT/MISS), request_time, origin_time, referer, user_agent, country, asn.
- Decompress and filter with any log tool, e.g. jq.
- Load them into Elasticsearch, BigQuery or your SIEM as JSON Lines.
- Search a time window: cdnctl logs grep downloads only the files in that window to your computer and filters them there by IP, status code, path and more.
Expected result: You can answer "what happened to this request" from your own data.
cdnctl equivalent
zcat ./logs/*.jsonl.gz | jq -r 'select(.status >= 500) | [.ts, .host, .uri, .status] | @tsv'
cdnctl logs grep --account $ACCOUNT_UUID --from "2026-09-25 14:00" --to "2026-09-25 15:00" --status 5xx --format table
cdnctl logs grep --account $ACCOUNT_UUID --from 14:00 --ip 203.0.113.0/24 --count