---
name: azion-tune-a-waf-rule-set
description: >-
  Read the requests a rule set matched in the Tuning tab, then turn the legitimate ones into exceptions.
---

# Tune a WAF rule set

You can read the requests a [Web Application Firewall (WAF)](/en/documentation/platform/firewall/#waf) rule set matched from the **Tuning** tab in Azion Console. Selected records become exceptions, so the rule set stops matching those requests and keeps scoring the rest.

Tuning runs in Azion Console only. Neither the [Azion CLI](/en/documentation/devtools/cli/) nor the API carries a tuning path, so both the records and the bulk conversion are reachable from the Console alone.

Tuning is one turn of a loop that starts in `Logging` mode and ends in `Blocking`. For why the loop repeats, refer to [Scoring and modes](/en/documentation/platform/firewall/waf/scoring-and-modes/#tuning).

[Workloads](/en/documentation/platform/workloads/) replaced [Domains](/en/documentation/platform/workloads/domains/), and Tuning names whichever one your account carries. Select the control your Console shows.

---

## Prerequisites

- Access to Azion Console. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- A firewall with the WAF module turned on. Refer to [Set a firewall's main settings](/en/documentation/guides/application-security/firewall-and-waf/firewall-configure-main-settings/).
- A rule set applied to traffic by a `Set WAF` behavior. Refer to [Create and apply a WAF rule set](/en/documentation/guides/application-security/firewall-and-waf/create-waf-rule-set/).
- Traffic scored against that rule set within the last 3 days, which is the longest window Tuning reads.

---

## Filter the Tuning records

A query runs over one time range and at least one workload or domain. Every other filter narrows it.

**Workloads**

To read the records of a rule set applied to a workload:

1. **Open the WAF Rules page**

   Access [Azion Console](https://console.azion.com/) > **Edge Libraries** > **WAF Rules**.

2. **Select the rule set you want to tune**

3. **Select the Tuning tab**

4. **Choose a time range**

   The options run from `Last 1 hour` to `Last 3 days`, which is the longest window available.

5. **Select one or more workloads**

   This filter is required. The screen lists no records until a workload is selected.

6. **(Optional) Select a network list**

   The query then returns only the records whose source address a [Network Lists](/en/documentation/platform/firewall/network-shield/network-lists/) entry holds.

7. **(Optional) Add a field filter**

   Select **Filter**, then choose **Country** or **IP Address**. Select **Apply** to run the query with it.

The Console reports how many records were found. The results list carries one row per internal rule that matched, with the columns **Rule ID**, **Hits**, **Paths**, **IPs**, **Countries**, **Top 10 IP Addresses**, and **Top 10 Countries**.

For example, a query over `Last 12 hours`, two workloads, and the `Blocklist IPs` network list returns only the records those addresses produced.

**Domains**

To read the records of a rule set applied to a domain:

1. **Open the WAF Rules page**

   Access [Azion Console](https://console.azion.com/) > **Edge Libraries** > **WAF Rules**.

2. **Select the rule set you want to tune**

3. **Select the Tuning tab**

4. **Choose a time range**

   The options run from `Last 1 hour` to `Last 3 days`, which is the longest window available.

5. **Select one or more domains**

   This filter is required. The screen lists no records until a domain is selected.

6. **(Optional) Select a network list**

   The query then returns only the records whose source address a [Network Lists](/en/documentation/platform/firewall/network-shield/network-lists/) entry holds.

7. **(Optional) Add a field filter**

   Select **Filter**, then choose **Country** or **IP Address**. Select **Apply** to run the query with it.

The Console reports how many records were found. The results list carries one row per internal rule that matched, with the columns **Rule ID**, **Hits**, **Paths**, **IPs**, **Countries**, **Top 10 IP Addresses**, and **Top 10 Countries**.

For example, a query over `Last 12 hours`, two domains, and the `Blocklist IPs` network list returns only the records those addresses produced.

> **Note**
>
> The **IP Address** field cannot be combined with an IP or CIDR network list, and the **Country** field cannot be combined with a country network list. The Console warns you when a query carries both.

For every filter and column this screen offers, refer to [WAF Exceptions](/en/documentation/platform/firewall/waf/custom-allowed-rules/#tuning).

---

## Create exceptions from the records

Allowing a record writes an exception for that rule ID. One selection produces several of them: the confirmation states that a separate rule is created for each possible attack on each URI.

**Workloads**

To allow records read from a workload:

1. **Select a rule ID in the results list**

   **More Details** opens, listing the occurrences behind that rule ID.

2. **Select the records you want to allow**

   Use the checkbox in the **Field** column. Select as many records as you need.

3. **Select Allow Rules**

4. **Enter the reason for allowing these rules**

   The confirmation asks for that reason, or for any other information about the requests.

The Console reports how many allowed rules were created, and each one appears on the **Allowed Rules** tab. New requests to the selected workloads that match those rule IDs are allowed.

**Domains**

To allow records read from a domain:

1. **Select a rule ID in the results list**

   **More Details** opens, listing the occurrences behind that rule ID.

2. **Select the records you want to allow**

   Use the checkbox in the **Field** column. Select as many records as you need.

3. **Select Allow Rules**

4. **Enter the reason for allowing these rules**

   The confirmation asks for that reason, or for any other information about the requests.

The Console reports how many allowed rules were created, and each one appears on the **Allowed Rules** tab. New requests to the selected domains that match those rule IDs are allowed.

When only part of a selection is written, the Console reports a partial failure and the number created. Select the remaining records and allow them again.

---

## Next steps

- [Check or change the WAF mode](/en/documentation/guides/application-security/firewall-and-waf/how-to-check-your-waf-mode.md): Move the rule set from Logging to Blocking once the records carry no false positives.
- [Create a WAF exception](/en/documentation/guides/application-security/firewall-and-waf/configure-waf-allowed-rules.md): Write a single exception by hand, with its own condition and operator.
- [WAF Exceptions](/en/documentation/platform/firewall/waf/custom-allowed-rules.md): Every field an exception carries, the fifteen match zones, and the Tuning screen itself.
- [Scoring and modes](/en/documentation/platform/firewall/waf/scoring-and-modes.md): Why tuning repeats, and what each mode does to a request that crosses a threshold.
