Manage bots with Bot Manager
Change what a running Bot Manager instance does: score an address against a reputation Network List, record the effect, and forward the report log.
You change what a running Bot Manager instance does by replacing the JSON object in its Arguments section, under the Functions Instances tab of the firewall the instance runs on.
Three changes are on this page: scoring a request address against a reputation Network List, recording what a change did without refusing a request, and keeping the report log in a destination of your own. Setting a threshold and taking a rule out of the scoring belong to the calibration loop, which is owned by Monitor and calibrate Bot Manager.
Prerequisites
- A Bot Manager function instance on a firewall, run by a Rules Engine for Firewall rule. For more information, refer to Bot Manager quickstart.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
- The ID of each Network List you want a request address scored against.
Score an address against a reputation Network List
reputation_network_lists takes an array of Network List IDs. The function checks the address of every request it scores against each list named there, and raises the score once for each list the address is found in.
Azion maintains lists of its own, and Network List 2 is Azion IP Tor Exit Nodes, which carries the addresses of Tor exit nodes. A list you build yourself is named the same way, by its ID.
On Bot Manager Lite the argument ships empty, so no list is checked until you name one, and a match is rule 14, worth 6 points. On Bot Manager the argument defaults to the Azion-managed Network Lists already on the account. For every rule Bot Manager Lite runs and what each one adds, refer to Bot Manager Lite.
Six points does not reach the threshold of 30 that Bot Manager Lite ships, so an address on a list meets the action when other rules match as well. The list raises the score, and the threshold decides what happens to the request:
To replace the arguments of an instance in Azion Console:
Access Azion Console > Firewalls, then select the firewall.
In the Arguments section, replace the object with the one above. The installed function carries no argument schema, so the section holds a JSON editor and builds no form from it.
The instance checks every address the rule sends it against the lists you named. A change to an instance reaches the request path in about two minutes, so a request answered sooner describes the configuration that preceded it.
Record what a change did without refusing a request
A report line is the only account of how one request scored, and the function writes a line only for the requests internal_logs selects. The argument ships at 0.
Set action to allow so that a request at or above the threshold continues to the application, and internal_logs to 2 so that every request produces a line, including one that scores 0. Replace the object in the same Arguments section:
internal_logs is a number. Written as the string "2" it is stored, and the function reads nothing from it. log_tag goes into the prefix of each line, which is what tells the lines of this instance apart from another instance’s. For the type each argument takes and the default it carries, refer to Arguments.
Two values on the line answer what the change did: matched_rules names the rules the request matched, and score carries their total. On Bot Manager Lite, an address found on a list you named adds rule 14 to matched_rules and 6 points to score. For where those lines surface and how to query them, refer to Monitor and calibrate Bot Manager.
Every request the rule sends the instance now produces a line, and the instance refuses none of them. Return action to the value you run in production once the lines answer the question. For how long to hold a window open and what it costs, refer to Firewall best practices.
Send the report log to a destination you own
Report lines surface in Real-Time Events, and the platform ages that data out. A copy in a destination of your own lasts as long as you keep it, and it sits beside the records of the application those requests reached.
Data Stream forwards the same lines from the Functions data source to an endpoint you configure, as the function writes them. Lower internal_logs when the observation window closes: at 2 every request produces a line, and that is the volume the stream carries. For the endpoints a stream writes to, refer to Endpoints.