Override expressions
Set an override expression for the HTTP DDoS Attack Protection managed ruleset to define a specific scope for sensitivity level or action adjustments.
For example, you can set different sensitivity levels for different request URI paths: a medium sensitivity level for URI path A and a low sensitivity level for URI path B.
Available expression fields
You can use the following fields in override expressions:
cf.client.botcf.threat_scorehttp.cookiehttp.hosthttp.refererhttp.request.urihttp.request.uri.pathhttp.request.uri.queryhttp.request.full_urihttp.request.methodhttp.request.versionhttp.request.cookieshttp.user_agenthttp.x_forwarded_forip.geoip.asnumip.geoip.continentip.geoip.countryip.geoip.is_in_european_unionip.srcsslcf.tls_client_auth.cert_verified
Refer to Fields in the Rules language documentation for more information.