Concept and mechanism
Logs help distinguish intermediate matches from the final decision. In an illustrative AWS WAF record, action=BLOCK with terminatingRuleId identifies the rule ending evaluation; it does not prove every later rule executed. Correlate request identifier, time, protected resource, and application outcome. Protect collected evidence: AWS WAF log-field redaction does not automatically extend to sampling. Establish controls for each collection method and limit sensitive data. A reproducible example using synthetic data often allows investigating a match without carrying customer content into training materials or widely accessible tickets. Retain enough context to explain the decision and who reviewed it.
Guided application
Policy changes need representative tests: browser, API, batch, and imports can have different contracts. Define acceptance, owners, and rollback, then confirm effective configuration after change. AWS WAF can show temporary inconsistencies during propagation; check that hypothesis without ignoring incorrect associations. Pinning a managed-group version also does not remove monitoring: expiration and exceptional provider changes exist. At RUN handover, deliver inventory, exceptions, alerts, contacts, and recovery criteria. CRS references include historical examples; this course teaches selected principles without claiming a latest release. Scenarios are fictional, with no executed WAF lab or attack traffic.
A passing portal does not automatically validate the nightly batch.
Common pitfalls
One sample as convergence; log redaction as every collection; a pinned version as eternal; homepage as complete acceptance.
Related topics: WAF architecture and coverage · Order, actions, and overrides · Parsing and inspection limits
Accept change using evidence from actual paths and recovery capability.
Reference: AWS WAF log fields · DR WAF 2026-09; selected AWS WAF and OWASP CRS operational concepts