Notifications
Clear all
Topic starter
17/07/2026 2:27 pm
Just got burned by this. The advertised price per rule is cheap, but you pay per *rule evaluation*. A single complex request can trigger dozens of evaluations across your rule groups, blowing up the bill.
Example: You have 10 rules in a web ACL. One request matches rule #5 and is blocked. You still pay for the evaluation of rules 1-4 and 6-10.
* Nested rule groups are the worst. Each rule inside counts.
* High-traffic sites with many custom rules? Check your Cost Explorer for `AWSWAF`.
Mitigation? Be ruthless:
* Combine IP match conditions into single rules where possible.
* Use fewer, more targeted rules.
* Monitor your "EvaluatedRequests" metric like a hawk.
// chris
metrics not myths