# Bot Manager examples

Copy any of these snippets and change the names and ids for your own account. Each one is the smallest complete form of a single object the rest of the [Bot Manager](/en/documentation/platform/firewall/#bot-manager) documentation describes at length: the arguments an instance runs on, the Rules Engine rule that hands it a request, and the query that returns what it scored. These are configurations to copy rather than a walkthrough, so take them in any order. The [Bot Manager quickstart](/en/documentation/platform/firewall/bot-manager/quickstart/) walks the same objects once, in order, for a reader who has never built them.

An instance scores nothing on its own, and a rule has to name it first. The `run_function` behavior that does the naming takes the id of the **instance**, never the id of the installed function, so the instance exists before the rule can be written. Three of these four snippets carry Azion Console, Azion CLI, and API panels. Reading the report log carries the API panel alone.

---

## An instance on a firewall

- [An instance that scores without refusing](/en/documentation/guides/application-security/bots-and-network/observation-mode.md): Set `action` to `allow` and raise `internal_logs`, so every request is scored, logged, and served.
- [An instance that refuses above the threshold](/en/documentation/guides/application-security/bots-and-network/refuse-above-threshold.md): Set `action` to `deny` on the same object, and read what a request receives once its score reaches the threshold.

---

## The rule that runs it

- [A rule that runs the instance on every request](/en/documentation/guides/application-security/bots-and-network/run-on-every-request.md): Build the Rules Engine rule whose **Run Function** behavior hands every request a firewall receives to one instance.

---

## Reading what it scored

- [Read the report log for one instance](/en/documentation/guides/application-security/bots-and-network/read-the-report-log.md): Query the `functionConsoleEvents` dataset for the lines one instance wrote, and read the values each line carries.

---

## Related resources

- [Bot Manager quickstart](/en/documentation/platform/firewall/bot-manager/quickstart.md): Build the same objects once, in order, in the interface you prefer.
- [Bot scoring](/en/documentation/platform/firewall/bot-manager/bot-scoring.md): Where the score comes from, and what the function does with it at the threshold.
- [Arguments](/en/documentation/platform/firewall/bot-manager/arguments.md): Every argument an instance accepts, with its type, its default, and the values it takes.
- [Logs](/en/documentation/platform/firewall/bot-manager/logs.md): Every field a report line carries, and what each one holds.
- [Firewall best practices](/en/documentation/platform/firewall/best-practices.md#bot-manager): The order to apply these configurations in, and how long to observe before you raise the action.
- [Troubleshoot Firewall](/en/documentation/platform/firewall/troubleshooting.md#bot-manager): What to read when a snippet runs and the result is not what you expected.
