Skip to main content

The WAF view

Your AppSec rules block exploitation attempts before they reach your applications - but that work is invisible until you look at it. The WAF view is the Explorer preset that shows it.

Open the WAF viewโ€‹

Click the WAF pill in the views bar. Everything you know from the Explorer applies - breakdowns, filters, grouping - but scoped to WAF signals: inbound requests your AppSec component flagged or blocked.

The WAF view: application-layer signals broken down by ruleThe WAF view: application-layer signals broken down by rule

Use it to answer questions like: which rules fire the most, which paths are being probed, which sources keep coming back after being blocked.

When the view is emptyโ€‹

An empty WAF view means one of two things, and the page tells you which:

  • Your engines never sent WAF signals. The empty state walks you through installing the AppSec component on your Security Engines.
  • No WAF activity in the selected period. Your setup works; widen the period or enjoy the calm.
The WAF view empty state, pitching the AppSec component setupThe WAF view empty state, pitching the AppSec component setup

Key considerationsโ€‹

  • The view only reflects engines running the AppSec component; log-based scenarios (HTTP bruteforce detected in access logs, for example) live in the main Explorer, not here.
CrowdSec Docs
We use cookies

This site uses cookies to help us improve your experience. You can accept or decline below.