Skip to content

Commit 2ea579f

Browse files
Merge pull request #286066 from robertspears/patch-1
Add note to specify minimum rule set for log scrubbing
2 parents 520d499 + 24a0da8 commit 2ea579f

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

articles/web-application-firewall/ag/waf-sensitive-data-protection-configure.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,9 @@ ms.date: 09/05/2023
1212

1313
The Web Application Firewall's (WAF's) Log Scrubbing tool helps you remove sensitive data from your WAF logs. It works by using a rules engine that allows you to build custom rules to identify specific portions of a request that contain sensitive data. Once identified, the tool scrubs that information from your logs and replaces it with _*******_.
1414

15+
> [!NOTE]
16+
> The log scrubbing feature is only supported on Web Application Firewalls running the [latest WAF engine](waf-engine.md). Select OWASP CRS 3.2 or Default Rule Set 2.1 as the managed rule set.
17+
1518
> [!NOTE]
1619
> When you enable the log scrubbing feature, Microsoft still retains IP addresses in our internal logs to support critical security features.
1720

0 commit comments

Comments
 (0)