SIEM action and attack-type exceptions

Action exceptionsDescription
'*'Excludes all actions.
alertLogs an alert when the threshold is reached.
denyBlocks the request and sends a response.
all_customAll of your custom actions.
abortTerminates the connection without sending an HTTP response to the client or forwarding the request to origin.
allowLogs the request and bypasses protections.
delayWaits 1-3 seconds before responding.
ignoreDoesn't log the request and halts further evaluation.
tarpitKeeps the connection open, but doesn't respond.
Attack type exceptionsDescription
ipgeoAttacks from specific IPs, subnets, geographic areas, and more.
rateHigh-rate clients that send requests at an excessive rate. These attacks are configured in your rate policy.
urlProtectionApplication-layer DDoS attacks defended against by URL Protection.
slowpostSlow POST attacks, featuring extremely slow request rates.
customrulesThe custom rules you created to handle scenarios not covered by standard rules.
wafKnown attacks mitigated by web application firewall (WAF) protections.
apirequestconstraintsAttacks on your API, featuring excessively large requests.
clientrepAttacks from known malicious clients.
malwareprotectionAttacks from malware in uploaded files at the edge.
botmanagementBot activity, with protections specified in Bot Manager .
aprProtectionUser account takeover attacks, with protections specified in Account Protector.
aifirewallprotectionThreats against your AI applications.
bdeBehavioral DDoS attacks.