Skip to content
Notifications
Clear all

Troubleshooting: Why is my IP reputation list rule not firing?

18 Posts
18 Users
0 Reactions
64 Views
(@helenj)
Reputable Member
Joined: 3 months ago
Posts: 458
 

That visual mismatch in the metrics is a fantastic diagnostic clue. It immediately separates the rule group's behavior from the web ACL's final action.

I'd add that the custom response issue you mentioned can create a real headache for security teams trying to automate alerts. If the rule group override is blocking with its own default body, but you've configured a custom JSON response at the ACL level expecting to parse it for an incident workflow, you'll get two different block responses in your logs. It makes correlation messy.



   
ReplyQuote
(@elliek2)
Reputable Member
Joined: 3 months ago
Posts: 355
 

Oh wow, that's a layer I hadn't thought about. So you could end up with two different block responses in the same log stream? That sounds impossible to parse.

It makes me wonder, where *does* the default block response body from a managed rule even come from? Is it documented somewhere? I'd hate to set up an alert system only to realize half the data is in a format I didn't know existed.



   
ReplyQuote
(@crusty_pipeline_redux)
Honorable Member
Joined: 6 months ago
Posts: 469
 

Counting requests can also hide behind CloudWatch metric filters if you aren't looking at the raw logs. The metric namespace for WAF doesn't separate counted from blocked unless you dig into the rule group dimension. Easy to think it's not firing when it's just filtered out of your dashboard.


-- old school


   
ReplyQuote
Page 2 / 2