Read the score of a blocked request
Query Real-Time Events for the internal rules that matched a request and the score each threat family gave it.
You can read which internal rules matched a blocked request, and the score each threat family gave it, from the Real-Time Events GraphQL API. A blocked response carries 400 and the Bad Request page, with no header naming WAF; its x-azion-request-id header finds the record.
Prerequisites
- A rule applying a rule set in
blockingon the firewall bound to your workload. To create it, refer to Apply a rule set to every request. - A personal token, for the GraphQL query.
Read the request id
Send a request that WAF blocks, and read the x-azion-request-id header in the response:
The response is HTTP/2 400 with the x-azion-request-id header, and its value is the request id the query below filters on.
Query the record of the request
Send a GraphQL query to https://api.azion.com/v4/events/graphql, over the workloadEvents dataset, with a personal token, filtered on the request id and a window around it:
The row returns wafBlock as 1, one entry per internal rule that matched in wafMatch, and one score per threat family in wafScore.
A wafMatch entry is shaped <index>:<ruleId>:<zone>:<varName>, so 1:1013:ARGS:q names rule 1013 on the q argument. A wafScore entry is shaped <index>:$<family>:<score>, so a request has several scores rather than one. upstreamStatus reads 0 because the request never reached an origin.