Bot Manager quickstart
Create a Bot Manager Lite instance on a firewall, run it from a Rules Engine rule, and read the score the function gave a bot-shaped request.
This guide instructs you through scoring your first request with Bot Manager Lite, the edition you install for yourself from Marketplace.
- Create a function instance on your firewall, carrying the arguments the function runs on.
- Run that instance from a Rules Engine rule, on every request the firewall receives.
- Send a bot-shaped request and read the score the function gave it.
Bot Manager Lite scores each request against a published set of static rules, which carry signatures for credential stuffing, vulnerability scanning, and site scraping. Bot Manager, the full edition, is enabled on request through the Azion Service Delivery team, and it adds a dynamic score and Reputation Intelligence on top of those rules. Both editions are configured the same way, so the stages below do not change with the edition.
Five objects put a request under inspection, and each one links to the next:
- The installed function is the Bot Manager Lite code, installed once from Marketplace into the account.
- The firewall carries the Functions module, which is what runs an installed function.
- The function instance on that firewall holds the arguments the function runs on.
- The Rules Engine rule on the same firewall carries a
run_functionbehavior, which names that instance. - The workload serving your application is bound to that firewall through its deployment.
An installed function scores nothing on its own. All five objects have to exist.
Select the interface you will use. The prerequisites and every stage below follow that choice.
Prerequisites
- An Azion account.
- Bot Manager Lite installed from Marketplace. The install runs in Azion Console, whatever interface the stages below use: access Azion Console > Marketplace, select the Bot Manager Lite integration from the search field, and select Install. The function then appears in Functions, under Edge Libraries, where a Vendor column marks it as a Marketplace install. For more information, refer to Install Bot Manager Lite.
- A firewall with the Functions module turned on. The module is in the firewall’s Main Settings, in the Modules section, and a firewall created with the Azion CLI has it turned on already. For more information, refer to Set a firewall’s main settings.
- A workload serving your application and bound to that firewall. The binding sits on the workload’s deployment.
- Turning on a product or a module can generate usage costs. For the metrics Bot Manager is billed on, refer to Pricing.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Create a Bot Manager Lite instance on your firewall
A function instance carries its whole configuration in one JSON object. Four arguments are enough for a first run:
threshold and action are the pair that decides the outcome: the function applies action to a request whose score reaches threshold, and 30 with deny are the values Bot Manager Lite ships. internal_logs at 2 writes a report line for every request, including one that scores 0. log_tag identifies this instance in those lines, so replace storefront-bots with a tag of your own. For every argument an instance accepts, refer to Arguments.
To create the instance in Azion Console:
Access Azion Console > Firewalls, then select that firewall.
On a firewall that carries no instance yet, the same action reads + Function Instance.
In the General section, enter a Name. For example: bot-manager-lite.
In the Function section, select the Bot Manager Lite function. The selector lists only the functions in the account that run on a firewall.
In the Arguments section, enter the object. Bot Manager Lite carries no argument schema, so the section holds a JSON editor and builds no form from it.
The instance appears under Functions Instances, which lists its Name, Function, Last Editor, and Last Modified. The form carries no Active control and the list carries no Status column: Azion Console creates every instance active.
Run the instance from a Rules Engine rule
A Rules Engine for Firewall rule decides which requests reach the instance. Its run_function behavior names one instance, and the rule below runs yours on every request the firewall receives.
To create the rule in Azion Console:
In Azion Console, go to Firewalls, select your firewall, then select the Rules Engine tab.
Enter a name for the rule. For example: Run Bot Manager on every request. The description is optional.
In the Criteria section, select the Request Uri variable, the starts with operator, and / as the argument.
In the Behaviors section, select Run Function. A second control appears, carrying the placeholder Select an function: it lists the function instances on this firewall, so select the one you named.
The firewall runs the instance on every request it receives. A rule carries at most one Run Function behavior.
Verify that a request is scored
The check is the same whichever interface built the instance. Your workload answers on a domain of the form <id>.map.azionedge.net, written below as <your-workload-domain>.
A new instance and a new rule take time to reach Azion’s distributed infrastructure. A change to an instance reaches the request path in about two minutes. Wait before you read anything into a response.
Verify by reading the report log, not by trying to get refused. At the threshold of 30 this guide sets, a bot-shaped request is scored and still served, so the log is where the result is.
Send a request with no user agent, which is what a scripted client sends:
Then read the line the function wrote. The report log is served by the functionConsoleEvents dataset. Send the query below to https://api.azion.com/v4/events/graphql with an Authorization: Token [TOKEN VALUE] header, and a tsRange covering the moment of the request:
The query answers 200 and returns one record per line the function wrote. functionId is the id of the installed function, and configurationId is the id of the workload the request arrived on, not the id of the firewall. line carries the whole report line, which opens with the prefix and continues as one JSON object:
The second bracket of the prefix carries the log_tag you set, which is how you tell one instance from another. Four values in the object answer the question this guide asked. score is 28. matched_rules is [1, 10, 18, 19, 20], the rules that produced that score, rule 1 among them for the empty user agent. action reads allow, and classified reads legitimate. For every field a line carries, refer to Logs.
Nothing was refused, and that is the result to expect: 28 is below the threshold of 30, so the score never reached the value at which deny fires. The request was inspected, scored, and served, which is what you set out to prove.
What a lower threshold changes is the action, not the score. A request whose score reaches the threshold has action applied to it, and deny answers HTTP 403 with Azion’s default error page. The classification moves with the threshold as well: classified is a verdict relative to the threshold in force, so the same score of 28, from the same matched rules, reads legitimate under a threshold of 30 and bad bot under a threshold that 28 reaches. Learn what your own traffic scores before you lower it.