Skip to content

Many false positives for waf_blocked alarm in idle deployments #7642

@dsotirho-ucsc

Description

@dsotirho-ucsc

Since the waf_blocked alarm is triggered when the % of blocked requests is more than 25% for a given period, the alarm can be tripped by a low number of blocked requests as long as the number of allowed requests in the same period was also low.

Blocked requests (WAF logs)

Image

All requests (API Gateway logs)

Image

Alarm raised

Image

Metadata

Metadata

Assignees

Labels

0 reviews[process] Lead didn't request any changesinfra[subject] Project infrastructure like CI/CD, build and deployment scriptsno demo[process] Not to be demonstrated at the end of the sprintspike:1[process] Spike estimate of one point

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions