---
name: azion-manage-bots-with-bot-manager
description: >-
  Change what a running Bot Manager instance does: score an address against a reputation Network List, record the effect, and forward the report log.
---

# Manage bots with Bot Manager

You change what a running [Bot Manager](/en/documentation/platform/firewall/#bot-manager) instance does by replacing the JSON object in its **Arguments** section, under the **Functions Instances** tab of the firewall the instance runs on.

Three changes are on this page: scoring a request address against a reputation Network List, recording what a change did without refusing a request, and keeping the report log in a destination of your own. Setting a threshold and taking a rule out of the scoring belong to the calibration loop, which is owned by [Monitor and calibrate Bot Manager](/en/documentation/guides/application-security/bots-and-network/monitor-and-calibrate-bot-manager/).

---

## Prerequisites

- A Bot Manager function instance on a firewall, run by a [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine/) rule. For more information, refer to [Bot Manager quickstart](/en/documentation/platform/firewall/bot-manager/quickstart/).
- Access to Azion Console. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- The ID of each [Network List](/en/documentation/platform/firewall/network-shield/network-lists/) you want a request address scored against.

---

## Score an address against a reputation Network List

`reputation_network_lists` takes an array of Network List IDs. The function checks the address of every request it scores against each list named there, and raises the score once for each list the address is found in.

Azion maintains lists of its own, and Network List `2` is *Azion IP Tor Exit Nodes*, which carries the addresses of Tor exit nodes. A list you build yourself is named the same way, by its ID.

On Bot Manager Lite the argument ships empty, so no list is checked until you name one, and a match is rule `14`, worth 6 points. On Bot Manager the argument defaults to the Azion-managed Network Lists already on the account. For every rule Bot Manager Lite runs and what each one adds, refer to [Bot Manager Lite](/en/documentation/platform/firewall/bot-manager/bot-manager-lite/#rules).

Six points does not reach the threshold of `30` that Bot Manager Lite ships, so an address on a list meets the action when other rules match as well. The list raises the score, and the threshold decides what happens to the request:

```json
{
  "threshold": 30,
  "action": "deny",
  "reputation_network_lists": [2]
}
```

> **Caution**
>
> Nothing validates the arguments object. A misspelled key is stored and read back exactly as typed, the function runs on its default, and no interface returns an error.

To replace the arguments of an instance in Azion Console:

1. **Open the firewall that runs the instance**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, then select the firewall.

2. **Select the Functions Instances tab**

3. **Open the Bot Manager instance**

4. **Enter the arguments object**

   In the **Arguments** section, replace the object with the one above. The installed function carries no argument schema, so the section holds a JSON editor and builds no form from it.

5. **Save the instance**

The instance checks every address the rule sends it against the lists you named. A change to an instance reaches the request path in about two minutes, so a request answered sooner describes the configuration that preceded it.

---

## Record what a change did without refusing a request

A report line is the only account of how one request scored, and the function writes a line only for the requests `internal_logs` selects. The argument ships at `0`.

Set `action` to `allow` so that a request at or above the threshold continues to the application, and `internal_logs` to `2` so that every request produces a line, including one that scores `0`. Replace the object in the same **Arguments** section:

```json
{
  "threshold": 30,
  "action": "allow",
  "internal_logs": 2,
  "reputation_network_lists": [2],
  "log_tag": "bot-reputation"
}
```

`internal_logs` is a number. Written as the string `"2"` it is stored, and the function reads nothing from it. `log_tag` goes into the prefix of each line, which is what tells the lines of this instance apart from another instance's. For the type each argument takes and the default it carries, refer to [Arguments](/en/documentation/platform/firewall/bot-manager/arguments/#fields).

Two values on the line answer what the change did: `matched_rules` names the rules the request matched, and `score` carries their total. On Bot Manager Lite, an address found on a list you named adds rule `14` to `matched_rules` and 6 points to `score`. For where those lines surface and how to query them, refer to [Monitor and calibrate Bot Manager](/en/documentation/guides/application-security/bots-and-network/monitor-and-calibrate-bot-manager/#read-the-report-log-in-real-time-events).

Every request the rule sends the instance now produces a line, and the instance refuses none of them. Return `action` to the value you run in production once the lines answer the question. For how long to hold a window open and what it costs, refer to [Firewall best practices](/en/documentation/platform/firewall/best-practices/#bot-manager).

---

## Send the report log to a destination you own

Report lines surface in [Real-Time Events](/en/documentation/platform/real-time-events/), and the platform ages that data out. A copy in a destination of your own lasts as long as you keep it, and it sits beside the records of the application those requests reached.

[Data Stream](/en/documentation/platform/data-stream/) forwards the same lines from the Functions data source to an endpoint you configure, as the function writes them. Lower `internal_logs` when the observation window closes: at `2` every request produces a line, and that is the volume the stream carries. For the endpoints a stream writes to, refer to [Endpoints](/en/documentation/platform/data-stream/endpoints/).

---

## Next steps

- [Arguments](/en/documentation/platform/firewall/bot-manager/arguments.md): Every argument an instance accepts, with its type, its default, and the values it takes.
- [Monitor and calibrate Bot Manager](/en/documentation/guides/application-security/bots-and-network/monitor-and-calibrate-bot-manager.md): The loop that sets a threshold and takes a rule out of the scoring, read from your own lines.
- [Firewall best practices](/en/documentation/platform/firewall/best-practices.md#bot-manager): What each of these changes costs, and the order in which the decisions arise.
- [Logs](/en/documentation/platform/firewall/bot-manager/logs.md): Every field a report line carries, and the verdicts the classified field records.
