← WAF: application protection and operations
03 / 6 · 40 MIN

Parsing and inspection limits

Assess body coverage, JSON fallback, and transformations.

Concept and mechanism

The size accepted by an application can exceed the content made available to WAF for inspection. In the documented AWS WAF with ALB case, inspected body content is limited to the first 8 KiB. A 12 KiB request leaves 4 KiB outside that inspection. Continue analyzes available content; it creates neither a second pass nor automatic truncation of the delivered body. Match treats excess as a rule match, whose action still matters: Match with Count does not itself block. Relate component limits to the import contract and controls that validate complete content.

Guided application

JSON parsing also does not equal schema validation or validation of every business rule. AWS WAF can parse without detecting every invalid aspect of a document; the application remains responsible for validating its contract. When an error triggers fallback, analyze the selected behavior together with the action. Transformations change the representation used for inspection, and sequence order can change results. Do not infer that the backend automatically receives rewritten content. In a legitimate-import exercise, decide sizes, oversize handling, and complementary validation, including regression for formats and clients actually supported by the service.

IN PRACTICE

12 KiB received, 8 KiB inspected: inspection of 4 KiB is unproven.

Common pitfalls

Continue as full coverage; Match as Block; parsing as schema; transformation as rewriting.

Related topics: WAF architecture and coverage · Order, actions, and overrides · Tuning and false positives

Take this idea with you

Connect each decision to the portion actually inspected and the complete contract.

Create account

Reference: AWS WAF inspection and oversize handling · DR WAF 2026-09; selected AWS WAF and OWASP CRS operational concepts