---
name: azion-run-bot-manager-in-observation-mode
description: >-
  Create a Bot Manager Lite instance with action allow, so every request is scored and none is refused, from Azion Console, the Azion CLI, or the API.
---

# Run Bot Manager in observation mode

You can create a [Bot Manager Lite](/en/documentation/platform/firewall/bot-manager/bot-manager-lite/) instance that scores every request and refuses none, from Azion Console, the Azion CLI, or the API. Use it the first time you put Bot Manager in front of real traffic, while you still have to find out what your own traffic scores.

---

## Prerequisites

- A [firewall](/en/documentation/platform/firewall/) bound to the workload that serves your application, with Bot Manager Lite installed. Refer to the [Bot Manager quickstart](/en/documentation/platform/firewall/bot-manager/quickstart/).
- The [Azion CLI](/en/documentation/devtools/cli/) installed and a configured personal token, for the CLI procedure.
- A personal token, for the API procedure. To create one, refer to [Personal Tokens](/en/documentation/fundamentals/personal-tokens/).

---

## Create the instance

The instance takes one JSON arguments object. `threshold` is the score at which `action` fires, and `30` is the value Bot Manager Lite ships. `action` at `allow` applies nothing at that value, so a request that crosses the threshold is scored, logged, and served like any other. At `2`, `internal_logs` writes one report line per request, including a request that scores `0`. `log_tag` names this instance in those lines, so replace `storefront-bots` with a tag of your own.

```json
{
  "threshold": 30,
  "action": "allow",
  "internal_logs": 2,
  "log_tag": "storefront-bots"
}
```

For every argument an instance accepts, refer to [Arguments](/en/documentation/platform/firewall/bot-manager/arguments/#fields).

**Console**

To create the instance from Azion Console:

1. **Open the firewall bound to your workload**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, then select that firewall.

2. **Select the Functions Instances tab**

3. **Select + Function**

   The button reads **+ Function Instance** while the firewall holds no instance yet.

4. **Name the instance**

   In the **General** section, enter a **Name**, such as `bot-manager-observation`.

5. **Select the Bot Manager Lite function**

   The **Function** section offers the installed function. Only functions that run on a firewall appear in the selector.

6. **Enter the object in the Arguments section**

   Paste it into the JSON editor. The section renders one because Bot Manager Lite ships no argument schema to build a form from.

7. **Select Save**

The instance appears in the **Functions Instances** list, which shows **Name**, **Function**, **Last Editor**, and **Last Modified**. The list shows no argument, so the object you entered is visible only by opening the instance again.

**CLI**

To create the instance with the Azion CLI, save the object as `bmargs.json`:

```json
{
  "threshold": 30,
  "action": "allow",
  "internal_logs": 2,
  "log_tag": "storefront-bots"
}
```

The `--args` flag of `azion create firewall-instance` takes the path to that file, and no inline JSON:

```bash
azion create firewall-instance --name bot-manager-observation --firewall-id <firewall-id> \
  --function-id <function-id> --args bmargs.json --active true
```

```text
Created Firewall Function Instance with ID 12347
```

The Azion CLI confirms the instance with the id it received. Record that id: a [Rules Engine rule](/en/documentation/guides/application-security/bots-and-network/run-on-every-request/) names the instance by it, never by the id of the function.

**API**

Send a `POST` request to the `functions` collection of your firewall, with the name, the id of the installed function, and the arguments in one body. Replace `<firewall-id>` with the id of your firewall, `[TOKEN VALUE]` with your personal token, and `12345` with the id of the installed Bot Manager Lite function:

```bash
curl --request POST \
  --url https://api.azion.com/v4/workspace/firewalls/<firewall-id>/functions \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "name": "bot-manager-observation",
  "function": 12345,
  "active": true,
  "args": {
    "threshold": 30,
    "action": "allow",
    "internal_logs": 2,
    "log_tag": "storefront-bots"
  }
}'
```

The call answers `202`. The body opens with `"state": "pending"`, which means the change is still propagating. Under `data`, it carries the instance as the platform stored it: the `id` it assigned, the `args` echoed back unchanged, and `"azion_form": {}`. That empty form is why Azion Console renders a JSON editor for this function instead of a form. Record the `id`.

> **Note**
>
> The object is not validated. Azion stores every key you send and reads it back as typed, including a key the function never reads. A misspelled `thresold` leaves the threshold at `30`, and no interface reports it. Allow about two minutes after any change before you read anything into a response. Keep the threshold fixed for the whole window: `classified` is relative to the threshold in force, so a change relabels the traffic you are observing. For how the threshold sets it, refer to [Bot scoring](/en/documentation/platform/firewall/bot-manager/bot-scoring/).

---

## Next steps

- [Run Bot Manager on every request](/en/documentation/guides/application-security/bots-and-network/run-on-every-request.md): The rule that hands every request the firewall receives to this instance.
- [Firewall best practices](/en/documentation/platform/firewall/best-practices.md#bot-manager): How long to run an observation window, and what to read from it before you raise the action.
