---
name: azion-create-a-rule-set-at-medium-sensitivity
description: >-
  Create a WAF rule set that carries the eight threat families at medium sensitivity, from Azion Console, the Azion CLI, or the API.
---

# Create a rule set at medium sensitivity

You can create a WAF rule set with every threat family at `medium` from Azion Console, the Azion CLI, or the API. `medium` is the level a family opens on, and the one to start from before any traffic has told you to raise a family.

---

## Prerequisites

- The [Azion CLI](/en/documentation/devtools/cli/) installed and a configured personal token, for the CLI procedure.
- A personal token, for the API request.

---

## Create the rule set

**Console**

To create the rule set from Azion Console:

1. **Open the WAF Rules page**

   Access [Azion Console](https://console.azion.com/) > **Edge Libraries** > **WAF Rules**.

2. **Select + WAF Rule**

3. **Name the rule set**

   In the **General** section, enter `storefront-waf` in **Name**.

4. **Leave every threat family at its default sensitivity**

   The **Threat Type Configuration** section lists the eight families, each opening on *Sensitivity Medium*.

5. **Keep the Active switch turned on**

6. **Save the rule set**

The rule set `storefront-waf` is active with all eight threat families at `medium`, ready to be named in a `Set WAF` behavior.

For the same rule set with one family raised above `medium`, refer to [Create and apply a WAF rule set](/en/documentation/guides/application-security/firewall-and-waf/create-waf-rule-set/).

**CLI**

To create the rule set with the Azion CLI:

```bash
azion create waf --name "storefront-waf"
```

```text
Created WAF with ID 12351
```

The output reports the id of the new rule set, which is the value a `Set WAF` behavior names. A create from the name alone is complete: the rule set comes back active, on ruleset `1` with engine version `2021-Q3` and engine type `score`, with all eight families at `medium`.

**API**

Send a `POST` request to the WAF rule sets endpoint:

```bash
curl --request POST \
  --url https://api.azion.com/v4/workspace/wafs \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "name": "storefront-waf",
  "active": true,
  "product_version": "1.0",
  "engine_settings": {
    "engine_version": "2021-Q3",
    "type": "score",
    "attributes": {
      "rulesets": [1],
      "thresholds": [
        { "threat": "cross_site_scripting", "sensitivity": "medium" },
        { "threat": "directory_traversal", "sensitivity": "medium" },
        { "threat": "evading_tricks", "sensitivity": "medium" },
        { "threat": "file_upload", "sensitivity": "medium" },
        { "threat": "identified_attack", "sensitivity": "medium" },
        { "threat": "remote_file_inclusion", "sensitivity": "medium" },
        { "threat": "sql_injection", "sensitivity": "medium" },
        { "threat": "unwanted_access", "sensitivity": "medium" }
      ]
    }
  }
}'
```

The API answers `202` and echoes the object under `data`, where `"state": "pending"` means the change is still propagating. Record `data.id`: that is the value a `Set WAF` behavior names.

The API accepts fewer than eight entries in `thresholds`, and an array holding one entry creates a rule set that scores only that family. List every family you want scored.

For what a sensitivity level changes, and the threshold each level sets, refer to [Scoring and modes](/en/documentation/platform/firewall/waf/scoring-and-modes/) and [WAF Rule Sets](/en/documentation/platform/firewall/waf/rules-set/#sensitivity-levels).

---

## Next steps

- [Apply a rule set to every request](/en/documentation/guides/application-security/firewall-and-waf/apply-rule-set.md): Put this rule set in front of a request, which nothing does until a Rules Engine rule names it.
- [WAF Rule Sets](/en/documentation/platform/firewall/waf/rules-set.md): Every field a rule set carries, the eight threat families, and the five sensitivity levels.
