Excluded Events in WAF

Someiah C S 60 Reputation points
2024-02-26T10:08:56.1633333+00:00

We've got WAF enabled in detection mode and have set up some exclusion rules to cut down on false positives. Now, I'm curious about the ratio of excluded events to matched events. Is there a way to view the logs of excluded events or run a query to generate a dashboard for visualization?

Azure Web Application Firewall
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 36,316 Reputation points Microsoft Employee
    2024-02-26T11:40:44.93+00:00

    @Someiah Coimbatore Sampath Kumar ,

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I understand that you would like to compare the false positives with and without Exclusion Lists. Currently, I am afraid WAF Exclusions are not logged.

    • When you configure exclusions in the WAF policy settings, those requests matching the exclusion criteria will bypass the WAF rules and won't be logged as security events.
    • Only custom rules are logged.
    • See : WAF Firewall log
    • User's image
    • I can check once internally if this includes WAF Exclusions or not - however I highly doubt that Exclusion List is included.

    Cheers,

    Kapil.


0 additional answers

Sort by: Most helpful