---
title: Live map
description: The Requests Map follows WAF events from Enterprise zones in real time, with sources, cities, hosts and the live table.
updated: 2026-09-27
sidebarLabel: Live
---

The **Ao Vivo** (Live) screen shows the **Mapa de Requisições** (Requests Map): WAF events arriving in real time, shown on the map as lines converging on the location of your infrastructure.

:::availability
The map uses Cloudflare Instant Logs, available only on Enterprise plan zones. With no Enterprise zone in the account, the screen says: **Nenhuma zona Enterprise nesta conta. O mapa em tempo real usa o Instant Logs da Cloudflare, disponível apenas nesse plano.** (No Enterprise zone in this account. The real-time map uses Cloudflare Instant Logs, available only on that plan.)
:::

## Where to find it

In the side menu, go to **Tráfego** (Traffic) > **Ao Vivo**.

The screen requires the `map.read` permission, which is not part of the default tenant roles. To enable it, contact Guardnet. Without it, the item does not show in the menu and direct access is denied. See [Roles and permissions](/en/advisor/referencia/papeis-e-permissoes/).

## Connect the stream

The map does not connect automatically when the screen opens.

1. Select **Conectar** (Connect).
2. Advisor opens a live stream in Cloudflare: one Instant Logs job per Enterprise zone in the account.
3. Wait for the **Ao vivo** (Live) status.

If the connection is interrupted, select **Reconectar** (Reconnect).

The connection status shows on screen: **Aguardando** (Waiting), **Conectando…** (Connecting…), **Ao vivo** (Live), **Reconectando…** (Reconnecting…), **Sem conexão** (No connection) or **Parcial** (Partial).

:::note
The stream only reads events. It does not change the configuration of your zones or of the Cloudflare account.
:::

## Filter by WAF action

The action filter sets which events show up:

- **Todos** (All): shows every action. This option does not combine with the others.
- **Bloqueado** (Blocked)
- **Desafio** (Challenge)
- **Registrado** (Logged)
- **Ignorado por regra** (Skipped by rule)

By default the screen opens with **Bloqueado**, **Desafio** and **Registrado**. With nothing selected, it shows **Nenhuma ação selecionada** (No action selected).

## Panels

The **IPs**, **Cidades** (Cities), **Hosts** and **Ao vivo** buttons show or hide the panels:

- **IPs de origem** (Source IPs)
- **Cidades** (Cities)
- **Hosts**
- **Ao vivo** (Live): the event table, with the columns **Hora** (Time), **País** (Country), **IP**, **Cidade** (City), **Método** (Method), **URI**, **Regra** (Rule) and **Ação** (Action).

## Map origin

The **Origem do mapa** (Map origin) is the point where attack lines converge. Enter the CEP (Brazilian postal code) of the protected infrastructure's location. With no CEP registered, the map uses Brasília as the origin.

Changing the origin requires the `map.write` permission, which is not part of the default tenant roles. To enable it, contact Guardnet.

---

> Guardnet Docs · https://docs.guardnet.com.br/en/advisor/cloudflare/mapa-ao-vivo/
> Documentation index: https://docs.guardnet.com.br/en/llms.txt
