WAF rule language
Reference for writing and reviewing WAF rulesets, for custom rules and Cloud rulesets alike.
Use this reference when writing rules in Firewall → Custom rules or reviewing a Cloud ruleset. Write custom WAF rules covers editing, testing and publishing the unsigned local ruleset. Cloud releases use the same rule language inside a signed envelope.
- Ruleset format defines the JSON document, profiles and rule metadata.
- Rule flow explains conditions, field scope, captures and operands.
- Targets lists selectable request, message and response fields.
- Facts and limits lists parser facts and bounded work settings.
- Transformations lists value normalization steps.
- Operators lists comparisons and detection operations.
- Detectors and patterns explains lists, lexicons and token patterns.
- Tokenizers lists grammar classes, token fields, contexts and options.
- Scoring and integrity tests explains score attribution and release checks.
- Feature versions gives the minimum Clearplane version for each construct.
- Examples shows tested seed fragments, a challenge rule and an exclusion ruleset.