What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use AWS WAF metrics to spot unusual rule activity, then inspect sampled requests and detailed logs to determine what matched and whether legitimate application traffic was affected. A metric spike or rule match is a lead to investigate—not proof of a false positive. Validate the request against expected application behavior, test a narrow change in Count mode where appropriate, and review the same signals again after the change.

This guide is specific to AWS WAF, whose current documentation calls a web ACL a “protection pack (web ACL).” Metric names, sampling behavior, and rule actions differ across WAF products.

Enable the signals you need before tuning

AWS recommends using web ACL logging, CloudWatch metrics, and request sampling when testing protections. They answer different questions: metrics show patterns across time and rules, while samples and logs help explain individual requests.

  • CloudWatch metrics: See aggregate activity by web ACL, rule, rule group, and other available dimensions.
  • Sampled requests: Review examples associated with matches in the WAF console.
  • Web ACL logs: Examine request details and rule-match information. AWS supports delivery to CloudWatch Logs, Amazon S3, and Amazon Data Firehose.

AWS’s testing guidance recommends enabling these signals so you can assess candidate rules before relying on them in enforcement. AWS’s logging documentation describes log configuration and destinations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Find unusual rule activity in metrics

Start with the web ACL traffic overview dashboards or view metrics in AWS WAF and CloudWatch. Core metrics include AllowedRequests, BlockedRequests, and CountedRequests; AWS also documents CAPTCHA, Challenge, and other metrics. WAF metrics are reported once a minute. Available dimensions can include web ACL, rule, rule group, resource type, country, device, attack type, and managed rule group or rule. Which dimensions are available depends on the metric.

Use the dimensions that narrow the signal to a candidate rule and relevant traffic. Compare activity over the periods that make sense for your application; AWS does not prescribe a universal lookback window or threshold for declaring a rule problematic. A sudden change is a reason to inspect requests, not to assume the rule is blocking legitimate traffic.

Check configuration when metrics appear missing

Absence of a metric does not always mean absence of traffic or matches. AWS notes that an Application Load Balancer associated with a web ACL that has no rules or other active configurations will not have sampled requests or CloudWatch metrics. Metric visibility can also depend on rule-group ownership and action overrides: Count-action rules inside some rule groups do not emit web ACL-dimension metrics.

Labels can provide additional context through label metrics, but they are not a complete inventory. AWS documents that metrics store at most 100 labels for a single request. See AWS’s AWS WAF metrics documentation for metric and dimension details.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use samples and logs to determine what matched

Once metrics point to a candidate, inspect sampled requests and detailed log records for the relevant rule and request context. Look at the route, method, request fields, labels, and match details, then compare them with the expected application flow. AWS’s logging examples show that a record can include both a terminating rule and non-terminating matches within a rule group. The final action is not necessarily the only match worth investigating.

A false positive is a legitimate request classified as an attack and blocked. Confirm that the request is legitimate by checking the intended route and behavior, the user flow, and relevant code or WAF changes around when the match began. AWS’s Guidelines for Implementing AWS WAF notes that QA testing after code or WAF changes can identify false positives, while some issues only become apparent in production when test coverage is incomplete.

Test a candidate rule without changing request handling

For a protection you are evaluating, Count mode records matches without deciding whether to allow or block the request. Review those matches in metrics, samples, and logs before choosing an enforcing action. AWS describes Count as counting the request without deciding whether to allow or block it in its rule action documentation.

If the rule belongs to a rule group, AWS’s preparation guidance says to test with a rule-action override in the web ACL. Changing a shared rule group itself can affect every web ACL that uses it. Count mode provides observation, but the test plan still needs to reflect the rule and the application behavior at stake.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose the narrowest mitigation that addresses the confirmed case

The right change depends on who controls the rule and how narrowly the legitimate request can be distinguished. Prefer an exception limited to the confirmed route, parameter, label, or traffic scope over a broad allow rule. AWS outlines these options in Monitoring and tuning your AWS WAF protections.

Situation Possible mitigation Scope to consider
A custom rule’s inspection criteria incorrectly match a legitimate request Adjust the inspection criteria, such as a regex pattern, text transformations, or the IP address source used for inspection. Refine the condition that causes the confirmed match.
A known class of legitimate requests should bypass a later rule Add an earlier mitigating rule that explicitly allows the identified requests. Limit the earlier rule to the legitimate request class; AWS notes that a matching request then does not reach the later rule.
A suspicious condition matches, but a known condition identifies the false positive Combine conditions with logical rule statements so the known false-positive condition is excluded. Exclude only the validated exception.
A supported rate-based or managed rule group reference statement evaluates requests that should be excluded Add a scope-down statement. Keep only the confirmed excluded traffic out of that evaluation.
A label-producing rule group adds a label associated with the false positive Use a label-match rule after the group to handle the problematic label; Count mode may first help identify the labels. Target the label and affected request behavior rather than broadly disabling inspection.

Retest both sides of the tradeoff: the legitimate flow that triggered the false positive and the malicious traffic the protection is intended to catch. AWS notes that scanners can check known cases but cannot guarantee complete protection.

Verify the change and keep watching

After changing a rule, repeat the same checks: review relevant metrics, sampled requests, and logs; run application or QA tests for the affected flow; and observe production behavior. AWS recommends alarms for selected WAF rules when predefined thresholds are exceeded, but the threshold should reflect your application rather than a universal value. Production-only false positives can indicate that QA did not cover the affected behavior.

Use the pattern that found the issue as the ongoing tuning loop: observe aggregate activity, investigate request-level evidence, validate the application behavior, test a narrow change, and observe again.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.