← WAF: application protection and operations
06 / 6 · 40 MIN

Logs, changes, and RUN handover

Correlate decisions and prepare policy changes with regression and recovery.

Concept and mechanism

Logs help distinguish intermediate matches from the final decision. In an illustrative AWS WAF record, action=BLOCK with terminatingRuleId identifies the rule ending evaluation; it does not prove every later rule executed. Correlate request identifier, time, protected resource, and application outcome. Protect collected evidence: AWS WAF log-field redaction does not automatically extend to sampling. Establish controls for each collection method and limit sensitive data. A reproducible example using synthetic data often allows investigating a match without carrying customer content into training materials or widely accessible tickets. Retain enough context to explain the decision and who reviewed it.

Guided application

Policy changes need representative tests: browser, API, batch, and imports can have different contracts. Define acceptance, owners, and rollback, then confirm effective configuration after change. AWS WAF can show temporary inconsistencies during propagation; check that hypothesis without ignoring incorrect associations. Pinning a managed-group version also does not remove monitoring: expiration and exceptional provider changes exist. At RUN handover, deliver inventory, exceptions, alerts, contacts, and recovery criteria. CRS references include historical examples; this course teaches selected principles without claiming a latest release. Scenarios are fictional, with no executed WAF lab or attack traffic.

IN PRACTICE

A passing portal does not automatically validate the nightly batch.

Common pitfalls

One sample as convergence; log redaction as every collection; a pinned version as eternal; homepage as complete acceptance.

Related topics: WAF architecture and coverage · Order, actions, and overrides · Parsing and inspection limits

Take this idea with you

Accept change using evidence from actual paths and recovery capability.

Create account

Reference: AWS WAF log fields · DR WAF 2026-09; selected AWS WAF and OWASP CRS operational concepts