Skip to content
Notifications
Clear all

Help: Can't get regex pattern match to work on request body.

1 Posts
1 Users
0 Reactions
40 Views
(@devops_rookie_2025)
Prominent Member
Joined: 4 months ago
Posts: 467
Topic starter   [#13639]

Hey everyone! 😊

I'm trying to set up a WAF rule to block a specific pattern in the request body, but it's just not catching anything. I'm pretty new to this, so I'm probably missing something basic.

Here's my JSON rule. I want to match the string `"malicious_string"` in the body:

```json
{
"Name": "BlockBodyPattern",
"Priority": 1,
"Statement": {
"ByteMatchStatement": {
"FieldToMatch": {
"Body": {}
},
"PositionalConstraint": "CONTAINS",
"SearchString": "malicious_string",
"TextTransformations": [
{
"Priority": 0,
"Type": "NONE"
}
]
}
},
"Action": {
"Block": {}
},
"VisibilityConfig": {
"SampledRequestsEnabled": true,
"CloudWatchMetricsEnabled": true,
"MetricName": "BlockBodyPattern"
}
}
```

I've attached this to a web ACL on an ALB. The rule is active, but even when I send a test POST request with that exact string in the body, the request goes through. No block, and the metric shows zero matches.

Could someone please explain what I might have wrong? A beginner-friendly breakdown would be super helpful! Thanks in advance to anyone who takes a look.



   
Quote