FrontdoorWebApplicationFirewallLog query output

Mike Totton 1 Reputation point

I notice when querying blocks by the DefaultRuleSet in the WAF there is a restriction in size to the output of certain fields. Most importantly the "matchVariableValue" within the "details_m,atches_s" section. As an example, the full classic test script 'lorem ipsum' (483 words) could be submitted to an application as user input and blocked but on querying the block, would only show the first 15 words (100 chars approx) within the matchVariableValue.
Is there a way to increase the output of this field within the query?

Azure Web Application Firewall
{count} votes

1 answer

Sort by: Most helpful
  1. Mike Totton 1 Reputation point

    Apologies, edited this to reply to the above comment

    0 comments No comments