How-to

The IPs Page

See which client IPs are sending the most traffic, drill into any IP for its behaviour, and escalate to a forensic sample when needed.

3 min readLast updated 22 August 2026
Jump to section

What the IPs page is for

The IPs page sits alongside the Offenders (ASN) and Paths pages as a first-class surface for the third important dimension: who, at the IP level, is sending us traffic?

ASN tells you "which network." Path tells you "which endpoint." IP tells you "which individual client." Combined with ASN and path, it's the answer to "is this one bot or many humans?".

How the list is built

Only the top IPs per ingest batch are captured — typically the top 24 per source. The long tail of single-request visitors aggregates into an *other catch-all, so totals stay accurate even though individual visitors disappear. For deeper investigation, use the forensic IP sampler — see below.

Columns

  • IP — the client IP (IPv4 or IPv6)
  • ASN — the network this IP belongs to, with the friendly name and country flag where known
  • Country — client country from geo-IP (not the ASN headquarters)
  • Top path — the path this IP is most frequently hitting in the current range
  • CF view — Cloudflare's own classification of the address (known bad host, Tor exit, security scanner, monitoring service, search engine, clean). Independent corroboration: Edge's verdict says what the traffic did, this says what the platform already knows about the address itself. Recorded from 21 Aug 2026; older rows show "—"
  • Billed · 7d — bot-scored ad clicks from this IP that the platforms charged for over the last 7 days, from the click-level evidence log. These are the addresses worth excluding first: the matching pill narrows the table to them, and the paste-ready exclusion list lives on the paid channel's drill-down on the Channels page
  • Requests / Share / Bytes — standard volume metrics

Both new columns also come with filters: a Billed clicks · 7d pill and a Cloudflare view selector next to the quick-find pills. "Show me billed addresses Cloudflare already calls bad hosts" is two clicks, and the result is your exclusion-list shortlist.

Typical workflows

  • "Who is hitting this path?" — open Path detail → "Investigate IPs" button → prefilled forensic window. Or scroll the Path detail page to the Top IPs card.
  • "Who is this single IP?" — click any IP in the list → IP detail page → see all paths this IP has touched, request timeseries, ASN/country.
  • "Which IPs does this ASN have?" — open ASN detail → Top IPs in this ASN card.
  • "Copy a blocklist" — from the IPs page, use the Copy blocklist button to get all visible IPs, one per line, formatted for IP-list import.

Pin and ignore

Same pattern as the ASN and Path pages:

  • Pin — float this IP to the top of the list. Use for IPs you're actively watching.
  • Ignore — hide this IP by default. Use for known-good egress IPs (payment gateway webhooks, health check pings).

Pins and ignores are saved to your workspace and shared with your whole team, on every device.

Forensic escalation

The continuous IPs page shows the top-N. When you need the full list for a specific path — every IP that hit it over a short window — click Investigate IPs on any Path detail page. This opens a time-boxed sampler that captures thousands of unique (path, IP) pairs for up to an hour, then auto-expires after 24 hours. You can also scope a forensic window to a single IP from its detail page when you need everything one client did.

Still stuck? Email support or open the support widget in the bottom-right.