Raise the sensitivity of one threat family
Set a higher sensitivity on one WAF threat family from the API, and keep the other seven where they are.
You can raise the sensitivity of one threat family from the API and leave the other seven where they are. The body below raises sql_injection to high and keeps the other seven families at medium.
Prerequisites
- An existing rule set, such as
storefront-waf. To create one, refer to Create a rule set at medium sensitivity. - A personal token.
Raise the family
Send a PATCH request to the rule set endpoint, with all eight families in thresholds:
The API answers 202, and the rule set reads back carrying exactly the eight entries you sent.
A PATCH replaces the whole thresholds array rather than merging it entry by entry. Send all eight families, including the seven you are not changing: a body carrying only sql_injection leaves the rule set scoring that family alone. Send each family once: a repeated threat is answered with 500 and the error 10067 Internal Server Error rather than a validation message. The array holds at most eight entries, one per family, and sensitivity takes highest, high, medium, low, or lowest.
For what a level changes in the score a family blocks on, refer to Scoring and modes and WAF Rule Sets.