Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.
I take it that you are using Azure Front Door WAF and not App gateway WAF.
However, I am afraid "matchVariableName":"HeaderName" is not supported in exclusions.
See : Exclude other request attributes
In particular, when the matchVariableName value is CookieName, HeaderName, PostParamName, or QueryParamName, it means the name of the field, rather than its value, has triggered the rule. Rule exclusion has no support for these matchVariableName values at this time.
Consider taking one of the following actions in that case:
- Disable the rules that give false positives.
- Create a custom rule that explicitly allows those requests. The requests bypass all WAF inspection.
Hope this helps.
Cheers,
Kapil