You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在CloudWatch日志中查找AWS WAF的COUNT模式规则记录?

问题

首次为AWS负载均衡器配置WAF以提升网站安全性,计划先以COUNT模式运行排查误报后再启用拦截。已添加两个AWS托管规则集并设置为COUNT模式,规则配置如下:

规则1:ECSAWSManagedRulesCommonRuleSet

{
  "Name": "ECSAWSManagedRulesCommonRuleSet",
  "Priority": 10,
  "Statement": {
    "ManagedRuleGroupStatement": {
      "VendorName": "AWS",
      "Name": "AWSManagedRulesCommonRuleSet"
    }
  },
  "OverrideAction": {
    "Count": {}
  },
  "VisibilityConfig": {
    "SampledRequestsEnabled": true,
    "CloudWatchMetricsEnabled": true,
    "MetricName": "AWSManagedRulesCommonRuleSetMetric"
  }
}

规则2:ECSAWSManagedRulesSQLiRuleSet

{
  "Name": "ECSAWSManagedRulesSQLiRuleSet",
  "Priority": 11,
  "Statement": {
    "ManagedRuleGroupStatement": {
      "VendorName": "AWS",
      "Name": "AWSManagedRulesSQLiRuleSet"
    }
  },
  "OverrideAction": {
    "Count": {}
  },
  "VisibilityConfig": {
    "SampledRequestsEnabled": true,
    "CloudWatchMetricsEnabled": true,
    "MetricName": "AWSManagedRulesCommonRuleSetMetric"
  }
}

在AWS WAF控制台的流量概览页“Top 10规则”组件中能看到各规则的计数,但使用以下CloudWatch查询语句筛选COUNT动作时无法找到任何记录:

fields @timestamp, @message
| filter webaclId = "redacted"
| filter action = "COUNT"
| sort @timestamp desc
| limit 20

需要解决该问题,找到对应的日志记录。

解决方案
  • 验证WAF日志关联配置
    确认WAF已正确配置日志目标(如CloudWatch Logs日志组),且当前查询的是该日志组。若WAF未开启日志或日志目标配置错误,将无法查询到记录。可在WAF控制台的“日志和指标”页面检查日志配置状态。

  • 调整CloudWatch查询的字段筛选逻辑
    使用托管规则集的OverrideAction设置COUNT时,日志中的action字段可能并非直接为"COUNT",需查看terminatingRuleAction或nonTerminatingMatchingRules中的动作值。尝试修改查询语句:

    fields @timestamp, @message
    | filter webaclId = "redacted"
    | filter (action = "COUNT" OR terminatingRuleAction = "COUNT" OR arraycontains(nonTerminatingMatchingRules[*].action, "COUNT"))
    | sort @timestamp desc
    | limit 20
    

    也可展开@message字段查看日志结构,确认COUNT动作对应的具体字段名称。

  • 考虑日志采样率与延迟
    即便开启了SampledRequestsEnabled,WAF日志采用比例采样机制,部分COUNT动作的请求可能未被采样。同时CloudWatch日志存在延迟,建议等待10-15分钟后再查询。

  • 修正规则MetricName配置错误
    第二个规则的MetricName错误复用了第一个规则的名称,虽不直接影响日志,但会导致指标统计混乱,建议修改为AWSManagedRulesSQLiRuleSetMetric,避免后续排查混淆。

内容的提问来源于stack exchange,提问作者Omiron

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 23:13:26