Override expressions
Set an override expression for the HTTP DDoS Attack Protection managed ruleset to define a specific scope for sensitivity level or action adjustments.
For example, you can set different sensitivity levels for different request URI paths: a medium sensitivity level for URI path A and a low sensitivity level for URI path B.
You can use the following fields in override expressions:
cf.client.botcf.threat_scorehttp.cookiehttp.hosthttp.refererhttp.request.urihttp.request.uri.pathhttp.request.uri.queryhttp.request.full_urihttp.request.methodhttp.request.versionhttp.request.cookieshttp.user_agenthttp.x_forwarded_forip.srcip.src.asnumip.src.continentip.src.countryip.src.is_in_european_unionsslcf.tls_client_auth.cert_verified
Refer to the Fields reference in the Rules language documentation for more information.