Create custom rules with AI Assistant
AI Assistant helps you identify and address opportunities to strengthen your protection with custom rules. From Web Security Analytics (WSA), you can use AI Assistant to create custom rules based on applied filters or from remediable insights.
Create a custom rule with AI Assistant
There are 2 different ways you can create a custom rule with AI Assistant:
- Based on applied filters. Ask AI Assistant to “create a custom rule based on the current filters applied,” and it will create a custom rule that you can review and save in the custom rule builder.
Supported dimension types include:- Client information (Client Fingerprint matches)
- Network information (IP Address, AS Number, and GEO matches)
- HTTP information (Request Header, Method, Query, and Host-related matches)
- IP/Geo firewall (Client List matches)
Note that not all filters in WSA are supported. For details, see
Requirements and supported filters.
- From a remediable insight. When you ask AI Assistant to “show remediable insights,” it may suggest the creation of a custom rule that will offer better security protection. If you decide to move forward with creating a new rule, AI Assistant creates or creates and deploys the rule for you. This feature allows you to respond quickly to detected threats without manually entering rule variables or activating a security configuration.
AI Assistant can only immediately create and deploy custom rules from remediable insights. Creating a custom rule based on applied filters requires review of generated rule criteria in custom rule builder and manual activation. Learn more about these options below.
Create a custom rule based on applied filters
To create a custom rule with AI Assistant based on applied filters:
- Navigate to Web Security Analytics.
- Apply the desired filters, ensuring they are supported filters that meet the requirements listed below.
- In the top navigation bar, click AI Assistant.
- Enter: “Create a custom rule based on the current filters applied.”
If the applied filters are supported, AI Assistant generates a custom rule based on them. You will be redirected to the custom rule builder with the filters pre-populated as conditions. Review the generated rule before saving and activating it.
If only some of the applied filters are supported, AI Assistant will generate custom rule conditions only from the supported filters.
Create and deploy a custom rule from a remediable insight
To create and deploy a custom rule with AI Assistant from a remediable insight:
- Navigate to Web Security Analytics.
- In the top navigation bar, click AI Assistant.
- Enter: “Show me remediable insights.”
- Click on the remediable insight you’d like to view. If the recommended action is to create a custom rule, select “Create a custom rule.”
- AI Assistant offers the following options:
- Create the rule on a cloned version of the existing configuration without deploying it.
- Create and deploy the rule on a cloned version of the existing configuration, setting its action to Alert before activation.
- Select your preferred option. You’ll receive a tracking link you can use to actively track the status of the new rule and a notification when your rule is created and/or deployed to production.
[Callout:Info] When deploying and activating your rule, AI Assistant sets the action to Alert by default. You may want to change this to Deny after the rule has been activated.
Track rule creation status
When you request to create and deploy a custom rule from AI Assistant, you’ll receive a confirmation in the chat window indicating that deployment is in progress. This message includes a link to the relevant security configuration page, where you can track the status of your rule.
You can use this tracking link to monitor whether your rule is being created, deployed, or if the process encounters any issues. Once the rule is successfully created and deployed, you’ll receive a notification confirming completion. If the process terminates without success, you’ll receive a notification with details and guidance on next steps.
Manage custom rules created by AI Assistant
After AI Assistant completes your custom rule request, you can manage the rule in Custom Rules.
- View, edit, delete, or clone custom rules. AI Assistant tells you the name it will assign to your rule in the chat box before creating it. You’ll also see this name in your notifications when your request is complete. Once the rule is created, you can search for it by name to manage it:
- Navigate to the policy associated with the rule.
- In the left menu, click Custom Rules and search for the rule by name.
- Click the rule to expand it. Here, you can update the rule action. To edit rule criteria, click View this Custom Rule; the view defaults to edit mode, allowing you to adjust the criteria. To clone or delete the rule, click the ellipsis dropdown to the right of the rule header.
- Edit rule criteria with AI Assistant. Use AI Assistant to modify rule criteria using natural language:
- Navigate to your custom rule as described above.
- In the bottom right of the expanded rule, click View this Custom Rule.
- Click AI Assistant in the bottom right.
- In the chat box, describe the changes you want to make to the custom rule. Press Enter or click the arrow icon to submit your request.
If your requested edit is supported, AI Assistant starts updating the rule by populating it with the match criteria you provided. Review the generated rule and make any necessary changes before clicking Save and activating it from the Custom Rules menu.
Learn more about managing custom rules.
Requirements and supported filters
You can use AI Assistant to create custom rules from applied filters that meet the supported dimensions, operators, and requirements below.
Filter compatibility requirements
Most supported filters have specific compatibility requirements. When using AI Assistant to create custom rules, if a filter isn't listed below as fully compatible, ensure it meets the following requirements:
- Use only one operator per dimension (for example, only Match Any or only Does Not Match Any for Client H2 Fingerprint). Combining multiple operators for a single dimension is not supported.
- Do not use filters with empty values unless the filter specifically supports them. For example, if you set the filter values for “Connecting AS Number
==ANYMatch Any” as AS12345, AS67890, and [empty value], it will not work because this dimension does not support any empty values. - Even if a filter supports empty values, do not use a filter that contains only an empty value. For example, while the User-Agent dimension can accept empty values, AI Assistant cannot create a custom rule from a filter with only “[empty_value]” for “User-Agent
==ANYMatch Any.”
Client information filters
| Filter dimension | Supported operators | Supports empty values? | Compatibility |
|---|---|---|---|
| JA4 Client TLS Fingerprint |
| No | Requirements apply |
| Client H2 Fingerprint |
| No | Requirements apply |
| Client TLS Fingerprint V3 |
| No | Requirements apply |
| Client TLS Fingerprint V2 |
| No | Requirements apply |
Network information filters
| Filter dimension | Supported operators | Supports empty values? | Compatibility |
|---|---|---|---|
| Connecting IP Address |
| Yes | Requirements apply |
| Connecting IP Address CIDR |
| Yes | Requirements apply |
| Connecting IP Subnet |
| Yes | Requirements apply |
| Connecting AS Number |
| No | Requirements apply |
| Connecting Country/Area |
| Yes | Requirements apply |
| End User IP Address |
| Yes | Requirements apply |
| End User IP Address CIDR |
| Yes | Requirements apply |
| End User IP Subnet |
| Yes | Requirements apply |
| End User AS Number |
| No | Requirements apply |
| End User Country/Area |
| Yes | Requirements apply |
HTTP information filters
| Filter dimension | Supported operators | Supports empty values? | Compatibility |
|---|---|---|---|
| User-Agent |
| Yes | Fully compatible* |
| Hostname |
| No | Fully compatible* |
| Path |
| No | Requirements apply |
| Query |
| No | Requirements apply |
| Request Header Set |
| Yes | Requirements apply |
| Accept-Language |
| Yes | Fully compatible* |
| Content-Length |
| Yes | Fully compatible* |
| Method |
| Not applicable | Requirements apply |
| Sec-CH-UA |
| Yes | Fully compatible* |
| Sec-CH-UA-Mobile |
| Yes | Fully compatible* |
| Sec-CH-UA-Arch |
| Yes | Fully compatible* |
| Sec-CH-UA-Platform |
| Yes | Fully compatible* |
| Sec-CH-UA-Platform-Version |
| Yes | Fully compatible* |
| Sec-CH-UA-Model |
| Yes | Fully compatible* |
| Sec-CH-UA-Bitness |
| Yes | Fully compatible* |
| Sec-CH-UA-Full-Version-List |
| Yes | Fully compatible* |
| Sec-CH-UA-Form-Factors |
| Yes | Fully compatible* |
| Sec-CH-UA-Full-Version |
| Yes | Fully compatible* |
| Sec-CH-UA-WoW64 |
| Yes | Fully compatible* |
| Referer |
| Yes | Fully compatible* |
*These filters are fully compatible with custom rule matches. The Filter compatibility requirements above do not apply.
IP/Geo firewall filters
Only Client Lists are supported. Custom rules do not support Network Lists.
| Filter dimension | Supported operators | Supports empty values? |
|---|---|---|
| Client/Network Lists |
| No |
Updated 6 days ago
