AWS WAF (Classic)

eventNameDescriptionSampleRule
anyCatch-all entry for AWS WAF (Classic) rules that match the service but not a specific eventName.NN
CreateByteMatchSetThis is AWS WAF Classic documentation.YN
CreateGeoMatchSetThis is AWS WAF Classic documentation.YN
CreateIPSetThis is AWS WAF Classic documentation.YN
CreateRateBasedRuleThis is AWS WAF Classic documentation.YN
CreateRegexMatchSetThis is AWS WAF Classic documentation.YN
CreateRegexPatternSetThis is AWS WAF Classic documentation.YN
CreateRuleThis is AWS WAF Classic documentation.YN
CreateRuleGroupThis is AWS WAF Classic documentation.YN
CreateSizeConstraintSetThis is AWS WAF Classic documentation.YN
CreateSqlInjectionMatchSetThis is AWS WAF Classic documentation.YN
CreateWebACLThis is AWS WAF Classic documentation.YN
CreateWebACLMigrationStackCreates an AWS CloudFormation WAFV2 template for the specified web ACL in the specified Amazon S3 bucket.NN
CreateXssMatchSetThis is AWS WAF Classic documentation.YN
DeleteByteMatchSetThis is AWS WAF Classic documentation.YN
DeleteGeoMatchSetThis is AWS WAF Classic documentation.YN
DeleteIPSetThis is AWS WAF Classic documentation.YY
DeleteLoggingConfigurationThis is AWS WAF Classic documentation.NY
DeletePermissionPolicyThis is AWS WAF Classic documentation.NN
DeleteRateBasedRuleThis is AWS WAF Classic documentation.YN
DeleteRegexMatchSetThis is AWS WAF Classic documentation.YN
DeleteRegexPatternSetThis is AWS WAF Classic documentation.YN
DeleteRuleThis is AWS WAF Classic documentation.YY
DeleteRuleGroupThis is AWS WAF Classic documentation.YY
DeleteSizeConstraintSetThis is AWS WAF Classic documentation.YN
DeleteSqlInjectionMatchSetThis is AWS WAF Classic documentation.YN
DeleteWebACLThis is AWS WAF Classic documentation.YY
DeleteXssMatchSetThis is AWS WAF Classic documentation.YN
GetByteMatchSetThis is AWS WAF Classic documentation.NN
GetChangeTokenThis is AWS WAF Classic documentation.YN
GetChangeTokenStatusThis is AWS WAF Classic documentation.NN
GetGeoMatchSetThis is AWS WAF Classic documentation.NN
GetIPSetThis is AWS WAF Classic documentation.NN
GetLoggingConfigurationThis is AWS WAF Classic documentation.NN
GetPermissionPolicyThis is AWS WAF Classic documentation.NN
GetRateBasedRuleThis is AWS WAF Classic documentation.NN
GetRateBasedRuleManagedKeysThis is AWS WAF Classic documentation.NN
GetRegexMatchSetThis is AWS WAF Classic documentation.NN
GetRegexPatternSetThis is AWS WAF Classic documentation.NN
GetRuleThis is AWS WAF Classic documentation.NN
GetRuleGroupThis is AWS WAF Classic documentation.NN
GetSampledRequestsThis is AWS WAF Classic documentation.NN
GetSizeConstraintSetThis is AWS WAF Classic documentation.NN
GetSqlInjectionMatchSetThis is AWS WAF Classic documentation.NN
GetWebACLThis is AWS WAF Classic documentation.NN
GetXssMatchSetThis is AWS WAF Classic documentation.NN
ListActivatedRulesInRuleGroupThis is AWS WAF Classic documentation.YN
ListByteMatchSetsThis is AWS WAF Classic documentation.YN
ListGeoMatchSetsThis is AWS WAF Classic documentation.YN
ListIPSetsThis is AWS WAF Classic documentation.YN
ListLoggingConfigurationsThis is AWS WAF Classic documentation.YN
ListRateBasedRulesThis is AWS WAF Classic documentation.YN
ListRegexMatchSetsThis is AWS WAF Classic documentation.YN
ListRegexPatternSetsThis is AWS WAF Classic documentation.YN
ListRuleGroupsThis is AWS WAF Classic documentation.YN
ListRulesThis is AWS WAF Classic documentation.YN
ListSizeConstraintSetsThis is AWS WAF Classic documentation.YN
ListSqlInjectionMatchSetsThis is AWS WAF Classic documentation.YN
ListSubscribedRuleGroupsThis is AWS WAF Classic documentation.YN
ListTagsForResourceThis is AWS WAF Classic documentation.NN
ListWebACLsThis is AWS WAF Classic documentation.YN
ListXssMatchSetsThis is AWS WAF Classic documentation.YN
PutLoggingConfigurationThis is AWS WAF Classic documentation.NN
PutPermissionPolicyThis is AWS WAF Classic documentation.NN
TagResourceThis is AWS WAF Classic documentation.NN
UntagResourceThis is AWS WAF Classic documentation.NN
UpdateByteMatchSetThis is AWS WAF Classic documentation.YN
UpdateGeoMatchSetThis is AWS WAF Classic documentation.YN
UpdateIPSetThis is AWS WAF Classic documentation.YN
UpdateRateBasedRuleThis is AWS WAF Classic documentation.YN
UpdateRegexMatchSetThis is AWS WAF Classic documentation.YN
UpdateRegexPatternSetThis is AWS WAF Classic documentation.YN
UpdateRuleThis is AWS WAF Classic documentation.YN
UpdateRuleGroupThis is AWS WAF Classic documentation.YN
UpdateSizeConstraintSetThis is AWS WAF Classic documentation.YN
UpdateSqlInjectionMatchSetThis is AWS WAF Classic documentation.YN
UpdateWebACLThis is AWS WAF Classic documentation.NN
UpdateXssMatchSetThis is AWS WAF Classic documentation.YN

any: AWS WAF (Classic) (catch-all)

#
Service
waf

Description

Catch-all entry for AWS WAF (Classic) rules that match the service but not a specific eventName.

CreateByteMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "4bf108c9-c199-4a48-b0a2-c1dbefe4aa7e",
  "eventName": "CreateByteMatchSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:01:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2e2dc844-6003-49c2-b2bb-fa848b6c096f",
  "requestParameters": {
    "changeToken": "f4429e97-7a98-4d62-81a1-7dc7dd3498d1",
    "name": "dwfix-bytematch"
  },
  "responseElements": {
    "byteMatchSet": {
      "byteMatchSetId": "a5de4750-5fa4-4e84-ae8a-ca719eba6434",
      "byteMatchTuples": [],
      "name": "dwfix-bytematch"
    },
    "changeToken": "f4429e97-7a98-4d62-81a1-7dc7dd3498d1"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateGeoMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "eea16c1a-089f-43f8-9910-e548bf8c4720",
  "eventName": "CreateGeoMatchSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:01:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f4b1631c-28f6-4ba7-8e6f-ddd78f736c0d",
  "requestParameters": {
    "changeToken": "cfcbbb9b-673f-4338-be65-e540d09add70",
    "name": "dwfix-geo"
  },
  "responseElements": {
    "changeToken": "cfcbbb9b-673f-4338-be65-e540d09add70",
    "geoMatchSet": {
      "geoMatchConstraints": [],
      "geoMatchSetId": "7899ac26-5121-403e-9e0c-ce1850a96b86",
      "name": "dwfix-geo"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateIPSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "b2b11f7a-40cb-4184-b19d-f8efa1766d57",
  "eventName": "CreateIPSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:01:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ba34cf9f-ed44-406a-8314-6f2d2b40f389",
  "requestParameters": {
    "changeToken": "85835655-4141-4442-a8dd-f9ae91fc710c",
    "name": "dwfix-ipset"
  },
  "responseElements": {
    "changeToken": "85835655-4141-4442-a8dd-f9ae91fc710c",
    "iPSet": {
      "iPSetDescriptors": [],
      "iPSetId": "cb2975a3-a4e2-4897-bfed-c68cd457c1a8",
      "name": "dwfix-ipset"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateRateBasedRule

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "939eecf7-82f3-4324-9bd8-b36f37e59a6e",
  "eventName": "CreateRateBasedRule",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:02:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b064ff0a-94d9-43cd-926e-1b019125a663",
  "requestParameters": {
    "changeToken": "9b46641d-e77e-44e0-a1e8-c0cb5f921912",
    "metricName": "dwfixraterule",
    "name": "dwfix-raterule",
    "rateKey": "IP",
    "rateLimit": 2000
  },
  "responseElements": {
    "changeToken": "9b46641d-e77e-44e0-a1e8-c0cb5f921912",
    "rule": {
      "matchPredicates": [],
      "metricName": "dwfixraterule",
      "name": "dwfix-raterule",
      "rateKey": "IP",
      "rateLimit": 2000,
      "ruleId": "1f7d68c2-9bef-4100-8301-312701a41eff"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateRegexMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "75355794-49be-4f0d-9a89-63fbb1f1ea0c",
  "eventName": "CreateRegexMatchSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:01:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a63d40d5-9e10-4480-99ac-329a8110ad1d",
  "requestParameters": {
    "changeToken": "afc86060-ec4e-436f-bf39-7064f3fd409c",
    "name": "dwfix-regexmatch"
  },
  "responseElements": {
    "changeToken": "afc86060-ec4e-436f-bf39-7064f3fd409c",
    "regexMatchSet": {
      "name": "dwfix-regexmatch",
      "regexMatchSetId": "edd62990-9a81-456b-8629-70d61ac63670",
      "regexMatchTuples": []
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateRegexPatternSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "3aa247c9-cfbd-4689-8bdf-f1193ca8dbc5",
  "eventName": "CreateRegexPatternSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:01:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "51d6add4-2339-4686-8d9b-eff3db00605d",
  "requestParameters": {
    "changeToken": "1eb56960-98cb-48b1-bb54-8b55cac26d8f",
    "name": "dwfix-regexpattern"
  },
  "responseElements": {
    "changeToken": "1eb56960-98cb-48b1-bb54-8b55cac26d8f",
    "regexPatternSet": {
      "name": "dwfix-regexpattern",
      "regexPatternSetId": "4d03be78-2428-4693-baa6-cd0f7c0223d9",
      "regexPatternStrings": []
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateRule

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "97b52919-4466-4cc8-bf95-b8e454a252e0",
  "eventName": "CreateRule",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:01:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cd337ce9-5119-45fa-bcbb-6afe38450d69",
  "requestParameters": {
    "changeToken": "d3801aef-05f8-4ad8-ad8c-aa1d041f127c",
    "metricName": "dwfixrule",
    "name": "dwfix-rule"
  },
  "responseElements": {
    "changeToken": "d3801aef-05f8-4ad8-ad8c-aa1d041f127c",
    "rule": {
      "metricName": "dwfixrule",
      "name": "dwfix-rule",
      "predicates": [],
      "ruleId": "757b887e-be5c-4e44-9da0-a176fe57bc54"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateRuleGroup

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "d9f1828f-d475-4882-9a8a-9394b4721894",
  "eventName": "CreateRuleGroup",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:02:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cd3344f0-4e42-4ac0-a944-801c3f7f9751",
  "requestParameters": {
    "changeToken": "fea95a58-9900-450d-aa8c-856ce9f7027d",
    "metricName": "dwfixrulegroup",
    "name": "dwfix-rulegroup"
  },
  "responseElements": {
    "changeToken": "fea95a58-9900-450d-aa8c-856ce9f7027d",
    "ruleGroup": {
      "metricName": "dwfixrulegroup",
      "name": "dwfix-rulegroup",
      "ruleGroupId": "6840b012-bd28-45b4-80a0-8705b6315b69"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateSizeConstraintSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "51beeec4-2f3f-4622-88f2-39dd8fa419da",
  "eventName": "CreateSizeConstraintSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:01:53Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "82fe8cf6-ece4-463a-98ca-3e593c3846d1",
  "requestParameters": {
    "changeToken": "ce244985-50ab-4661-a5f8-9c6a3d34b8f2",
    "name": "dwfix-sizeconstraint"
  },
  "responseElements": {
    "changeToken": "ce244985-50ab-4661-a5f8-9c6a3d34b8f2",
    "sizeConstraintSet": {
      "name": "dwfix-sizeconstraint",
      "sizeConstraintSetId": "a5bd2ee4-c916-4c7d-a485-6812ac4ec0f5",
      "sizeConstraints": []
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateSqlInjectionMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "8cbf42a2-9a2e-4f5c-a4f5-ff5a8fd348b8",
  "eventName": "CreateSqlInjectionMatchSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:01:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f65940db-0784-46cc-8ca4-b1062e008bd6",
  "requestParameters": {
    "changeToken": "0e5df6c9-7c3c-4169-8e23-f62d7f75af57",
    "name": "dwfix-sqli"
  },
  "responseElements": {
    "changeToken": "0e5df6c9-7c3c-4169-8e23-f62d7f75af57",
    "sqlInjectionMatchSet": {
      "name": "dwfix-sqli",
      "sqlInjectionMatchSetId": "cda8ca42-a903-4245-b168-9e4cc0657dea",
      "sqlInjectionMatchTuples": []
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateWebACL

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "errorCode": "WAFBadRequestException",
  "errorMessage": "AWS WAF Classic (v1) support will end on September 30, 2025. Effective May 1st, 2025, the creation of new WebACL v1 is no longer permitted.",
  "eventCategory": "Management",
  "eventID": "b91f9bc9-a468-4156-a007-ed0f3ec2c203",
  "eventName": "CreateWebACL",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:02:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f85c1d15-181e-44d5-9f3d-3d47f7aec2f5",
  "requestParameters": {
    "changeToken": "6c834dd7-2eb9-48b6-aace-957243b76f0b",
    "defaultAction": {
      "type": "ALLOW"
    },
    "metricName": "dwfixwebacl",
    "name": "dwfix-webacl"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateWebACLMigrationStack

#
Service
waf

Description

Creates an AWS CloudFormation WAFV2 template for the specified web ACL in the specified Amazon S3 bucket.

CreateXssMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "baa671ea-7e82-4f95-9912-bc355750c1e7",
  "eventName": "CreateXssMatchSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:01:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "460b7d5c-31e7-4b7e-9e23-8e01e641ff09",
  "requestParameters": {
    "changeToken": "67a9bc74-0dee-46b5-a9ff-dc9a2574c631",
    "name": "dwfix-xss"
  },
  "responseElements": {
    "changeToken": "67a9bc74-0dee-46b5-a9ff-dc9a2574c631",
    "xssMatchSet": {
      "name": "dwfix-xss",
      "xssMatchSetId": "4e1a5ece-cd89-4173-b6e0-a4e57136f6e5",
      "xssMatchTuples": []
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteByteMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "2673675c-186c-465d-ba18-259bb5d0fdd9",
  "eventName": "DeleteByteMatchSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:02:16Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "710bde7a-2d3d-4468-8a20-314a730530c6",
  "requestParameters": {
    "byteMatchSetId": "a5de4750-5fa4-4e84-ae8a-ca719eba6434",
    "changeToken": "fa6895e9-4e90-486c-893a-072b53873854"
  },
  "responseElements": {
    "changeToken": "fa6895e9-4e90-486c-893a-072b53873854"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteGeoMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "d3b2a88d-f72a-48aa-ab96-8dbd0229fca2",
  "eventName": "DeleteGeoMatchSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:02:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "25935961-84ac-4efd-851c-f4569e462208",
  "requestParameters": {
    "changeToken": "be6e6c11-f2f5-43c8-8306-c55d06b24a82",
    "geoMatchSetId": "7899ac26-5121-403e-9e0c-ce1850a96b86"
  },
  "responseElements": {
    "changeToken": "be6e6c11-f2f5-43c8-8306-c55d06b24a82"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteIPSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "3e5e26e6-66e9-416e-9669-c24eb70424a6",
  "eventName": "DeleteIPSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:02:17Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9fc66223-afe7-4acc-b5d8-3d9609a5f23c",
  "requestParameters": {
    "changeToken": "5ff1cca9-6565-4d99-8a62-c726997412cd",
    "iPSetId": "cb2975a3-a4e2-4897-bfed-c68cd457c1a8"
  },
  "responseElements": {
    "changeToken": "5ff1cca9-6565-4d99-8a62-c726997412cd"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

DeleteLoggingConfiguration

#
Service
waf

Description

This is AWS WAF Classic documentation.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

DeletePermissionPolicy

#
Service
waf

Description

This is AWS WAF Classic documentation.

DeleteRateBasedRule

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "cb33d34c-91e3-45ba-beaf-cd23031e716d",
  "eventName": "DeleteRateBasedRule",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:02:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ad4307f7-430f-4eb8-a290-626d795391f7",
  "requestParameters": {
    "changeToken": "3e72da87-aa9e-4189-8074-83d62cf8d623",
    "ruleId": "1f7d68c2-9bef-4100-8301-312701a41eff"
  },
  "responseElements": {
    "changeToken": "3e72da87-aa9e-4189-8074-83d62cf8d623"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteRegexMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "3328fbcd-5e33-4179-a7e8-231d4e95795f",
  "eventName": "DeleteRegexMatchSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:02:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "218056ec-1e5d-4dc5-983d-0724f40635a0",
  "requestParameters": {
    "changeToken": "1204cc08-9728-436d-8b8b-cd1fb56e2d4c",
    "regexMatchSetId": "edd62990-9a81-456b-8629-70d61ac63670"
  },
  "responseElements": {
    "changeToken": "1204cc08-9728-436d-8b8b-cd1fb56e2d4c"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteRegexPatternSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "a1653d49-2500-4dfa-bbf5-bd45d35fbca8",
  "eventName": "DeleteRegexPatternSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:02:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "048af850-536a-45f4-81f6-d15f03859583",
  "requestParameters": {
    "changeToken": "fb13355e-6c60-424c-9474-14f497f92b2f",
    "regexPatternSetId": "4d03be78-2428-4693-baa6-cd0f7c0223d9"
  },
  "responseElements": {
    "changeToken": "fb13355e-6c60-424c-9474-14f497f92b2f"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteRule

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "0f815483-f6bb-42d9-b870-0dcc64ddc9a4",
  "eventName": "DeleteRule",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2022-07-20T21:40:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "111111111111",
  "requestID": "2089be3e-28ea-4349-b505-db72c81c272a",
  "requestParameters": {
    "changeToken": "c5daf4cb-68e1-425f-b52d-49a32a7f187f",
    "ruleId": "5a9b1c4a-a999-4bb2-9f51-555f086ff34f"
  },
  "responseElements": {
    "changeToken": "c5daf4cb-68e1-425f-b52d-49a32a7f187f"
  },
  "sourceIPAddress": "67.171.71.185",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "aws-cli/2.7.3 Python/3.9.13 Darwin/21.5.0 source/x86_64 prompt/off command/waf.delete-rule",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLFLKADUVG",
    "accountId": "111111111111",
    "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
    "principalId": "AIDAYTOGP2RLI4PXTGCEU",
    "type": "IAMUser",
    "userName": "gowthamaraj_cli"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS WAF Rule or Rule Group Deletion source medium: Identifies the deletion of an AWS Web Application Firewall (WAF) rule or rule group. WAF rules and rule groups enforce critical protections for web applications by filtering malicious HTTP requests, blocking known attack patterns, and enforcing access controls. Deleting these rules—even briefly—can expose applications to SQL injection, cross-site scripting, credential-stuffing bots, or targeted exploitation. Adversaries who have gained sufficient permissions may remove WAF protections as part of a broader defense evasion or impact strategy, often preceding data theft or direct application compromise.T1562, T1562.007↳ also matches DeleteRuleGroup

Splunk #

References #

DeleteRuleGroup

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "683b858a-1efe-4667-9dab-4c3b3b675bdb",
  "eventName": "DeleteRuleGroup",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:02:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1a212563-0d65-4f36-9291-3e2563f86141",
  "requestParameters": {
    "changeToken": "b40f42f0-8b7d-4556-a3d7-e70034b331b7",
    "ruleGroupId": "6840b012-bd28-45b4-80a0-8705b6315b69"
  },
  "responseElements": {
    "changeToken": "b40f42f0-8b7d-4556-a3d7-e70034b331b7"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS WAF Rule or Rule Group Deletion source medium: Identifies the deletion of an AWS Web Application Firewall (WAF) rule or rule group. WAF rules and rule groups enforce critical protections for web applications by filtering malicious HTTP requests, blocking known attack patterns, and enforcing access controls. Deleting these rules—even briefly—can expose applications to SQL injection, cross-site scripting, credential-stuffing bots, or targeted exploitation. Adversaries who have gained sufficient permissions may remove WAF protections as part of a broader defense evasion or impact strategy, often preceding data theft or direct application compromise.T1562, T1562.007↳ also matches DeleteRule

Splunk #

DeleteSizeConstraintSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "6ee26a39-22f5-4a14-ac1b-f7ba9c688231",
  "eventName": "DeleteSizeConstraintSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:02:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c604bbff-9510-485a-9314-8d5d94c415a2",
  "requestParameters": {
    "changeToken": "fa5fd4e3-e73f-49bf-9365-a923bc5137bb",
    "sizeConstraintSetId": "a5bd2ee4-c916-4c7d-a485-6812ac4ec0f5"
  },
  "responseElements": {
    "changeToken": "fa5fd4e3-e73f-49bf-9365-a923bc5137bb"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteSqlInjectionMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "57aa1002-f208-4c0e-8d1a-caa04d071c87",
  "eventName": "DeleteSqlInjectionMatchSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:02:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "93b1c44d-369a-493a-8bdd-971213f67247",
  "requestParameters": {
    "changeToken": "39c2cee0-e3fe-421c-9037-bdb0fcc1de0b",
    "sqlInjectionMatchSetId": "cda8ca42-a903-4245-b168-9e4cc0657dea"
  },
  "responseElements": {
    "changeToken": "39c2cee0-e3fe-421c-9037-bdb0fcc1de0b"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteWebACL

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "c8fd51ac-676d-4d5d-aa5a-7e642cf5bb97",
  "eventName": "DeleteWebACL",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2022-07-20T21:32:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "111111111111",
  "requestID": "55fd5189-5f86-4052-8e8e-993faf1753e8",
  "requestParameters": {
    "changeToken": "11eb19d6-d960-4398-8761-6a8fbf8fc425",
    "webACLId": "6a9771ff-7d94-4fec-a049-e42da0bc7347"
  },
  "responseElements": {
    "changeToken": "11eb19d6-d960-4398-8761-6a8fbf8fc425"
  },
  "sourceIPAddress": "67.171.71.185",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "aws-cli/2.7.3 Python/3.9.13 Darwin/21.5.0 source/x86_64 prompt/off command/waf.delete-web-acl",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLFLKADUVG",
    "accountId": "111111111111",
    "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
    "principalId": "AIDAYTOGP2RLI4PXTGCEU",
    "type": "IAMUser",
    "userName": "gowthamaraj_cli"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS WAF Access Control List Deletion source medium: Identifies the deletion of an AWS Web Application Firewall (WAF) Web ACL. Web ACLs are the core enforcement objects in AWS WAF, defining which traffic is inspected, allowed, or blocked for protected applications. Deleting a Web ACL removes all associated rules, protections, and logging configurations. Adversaries who obtain sufficient privileges may delete a Web ACL to disable critical security controls, evade detection, or prepare for downstream attacks such as web-application compromise, data theft, or resource abuse. Because Web ACLs are rarely deleted outside of controlled maintenance or infrastructure updates, unexpected deletions may indicate potential defense evasion.T1562, T1562.007

Splunk #

References #

DeleteXssMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "3b7d54e1-46f3-4a39-a401-9ca6078178a2",
  "eventName": "DeleteXssMatchSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:02:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1f6c1774-7f84-4db9-9aa3-1dbe0b8b9b9d",
  "requestParameters": {
    "changeToken": "cdeb202a-732c-405d-a12d-6a0f386d8f44",
    "xssMatchSetId": "4e1a5ece-cd89-4173-b6e0-a4e57136f6e5"
  },
  "responseElements": {
    "changeToken": "cdeb202a-732c-405d-a12d-6a0f386d8f44"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetByteMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

GetChangeToken

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: waf:GetChangeToken on resource: arn:aws:waf::811596193553:changetoken/*",
  "eventID": "f95ee58b-5cde-4050-bfd1-cb463667e4e",
  "eventName": "GetChangeToken",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2019-07-25T09:41:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "4fe15518-aec0-11e9-90d9-7d0a378c9cca",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

GetChangeTokenStatus

#
Service
waf

Description

This is AWS WAF Classic documentation.

GetGeoMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

GetIPSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

GetLoggingConfiguration

#
Service
waf

Description

This is AWS WAF Classic documentation.

GetPermissionPolicy

#
Service
waf

Description

This is AWS WAF Classic documentation.

GetRateBasedRule

#
Service
waf

Description

This is AWS WAF Classic documentation.

GetRateBasedRuleManagedKeys

#
Service
waf

Description

This is AWS WAF Classic documentation.

GetRegexMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

GetRegexPatternSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

GetRule

#
Service
waf

Description

This is AWS WAF Classic documentation.

GetRuleGroup

#
Service
waf

Description

This is AWS WAF Classic documentation.

GetSampledRequests

#
Service
waf

Description

This is AWS WAF Classic documentation.

GetSizeConstraintSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

GetSqlInjectionMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

GetWebACL

#
Service
waf

Description

This is AWS WAF Classic documentation.

GetXssMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

ListActivatedRulesInRuleGroup

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: waf:ListActivatedRulesInRuleGroup on resource: arn:aws:waf::811596193553:rulegroup/*",
  "eventID": "d576e412-77b8-4b50-8fd2-fde3a7e6913e",
  "eventName": "ListActivatedRulesInRuleGroup",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2019-07-25T09:41:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "4fea753a-aec0-11e9-8bc7-1f01bb4ed705",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListByteMatchSets

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: waf:ListByteMatchSets on resource: arn:aws:waf::811596193553:bytematchset/*",
  "eventID": "83d3af73-af46-445e-9da4-ca6cac65aef1",
  "eventName": "ListByteMatchSets",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2019-07-25T09:41:04Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "51ecfbbf-aec0-11e9-90d9-7d0a378c9cca",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListGeoMatchSets

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: waf:ListGeoMatchSets on resource: arn:aws:waf::811596193553:geomatchset/*",
  "eventID": "ec432fab-40c2-4659-aa1a-843531fb4585",
  "eventName": "ListGeoMatchSets",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2019-07-25T09:41:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "519e6732-aec0-11e9-aea5-12072bdc265",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListIPSets

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: waf:ListIPSets on resource: arn:aws:waf::811596193553:ipset/*",
  "eventID": "d0fb9da3-22d0-4591-bdc3-a0bc11ab731c",
  "eventName": "ListIPSets",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2019-07-25T09:41:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "51a7b5c6-aec0-11e9-b86b-5bf7bcc16cec",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListLoggingConfigurations

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: waf:ListLoggingConfigurations on resource: arn:aws:waf::811596193553:webacl/*",
  "eventID": "6f9e5069-df71-46be-b668-0f2911a1c14a",
  "eventName": "ListLoggingConfigurations",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2019-07-25T09:41:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "508f676c-aec0-11e9-90d9-7d0a378c9cca",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListRateBasedRules

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: waf:ListRateBasedRules on resource: arn:aws:waf::811596193553:ratebasedrule/*",
  "eventID": "1082adec-4642-42d3-be10-90718dd19c6f",
  "eventName": "ListRateBasedRules",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2019-07-25T09:41:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "4f80dd76-aec0-11e9-90d9-7d0a378c9cca",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListRegexMatchSets

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: waf:ListRegexMatchSets on resource: arn:aws:waf::811596193553:regexmatch/*",
  "eventID": "26e78e93-c305-4116-9809-f2a474973c",
  "eventName": "ListRegexMatchSets",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2019-10-19T23:49:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "812758ca-f2cb-11e9-93ec-aff86f97cc5f",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "213.253.166.5",
  "userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ListRegexPatternSets

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: waf:ListRegexPatternSets on resource: arn:aws:waf::811596193553:regexpatternset/*",
  "eventID": "01dfd418-62f0-4c32-b6d7-646574f361588",
  "eventName": "ListRegexPatternSets",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2019-10-19T23:49:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "122c5a0e-f2cb-11e9-9e49-6de521f468115",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "213.253.166.5",
  "userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ListRuleGroups

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: waf:ListRuleGroups on resource: arn:aws:waf::811596193553:rulegroup/*",
  "eventID": "982cdc92-cafd-48eb-ba36-f681142ad8",
  "eventName": "ListRuleGroups",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2019-07-25T09:41:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "515e50ec-aec0-11e9-aea5-12072bdc265",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListRules

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: waf:ListRules on resource: arn:aws:waf::811596193553:rule/*",
  "eventID": "b70f7f8c-b1e0-4cde-9b02-10feae98a435",
  "eventName": "ListRules",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2019-07-25T09:41:04Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "294570b2-aec0-11e9-90d9-7d0a378c9cca",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListSizeConstraintSets

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: waf:ListSizeConstraintSets on resource: arn:aws:waf::811596193553:sizeconstraintset/*",
  "eventID": "3d2c67ce-7755-4460-ac09-ffb48d4eff58",
  "eventName": "ListSizeConstraintSets",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2019-07-25T09:41:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "4f81ef62-aec0-11e9-8bc7-1f01bb4ed705",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListSqlInjectionMatchSets

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: waf:ListSqlInjectionMatchSets on resource: arn:aws:waf::811596193553:sqlinjectionset/*",
  "eventID": "670c756b-4206-4bdb-9816-4bc2d6c62e34",
  "eventName": "ListSqlInjectionMatchSets",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2019-07-25T09:41:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "503c8c71-aec0-11e9-90d9-7d0a378c9cca",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListSubscribedRuleGroups

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: waf:ListSubscribedRuleGroups on resource: arn:aws:waf::811596193553:rulegroup/*",
  "eventID": "69e5a701-91c0-41f2-a9e1-08f6277f299c",
  "eventName": "ListSubscribedRuleGroups",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2019-07-25T09:41:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "106202-aec0-11e9-8bc7-1f01bb4ed705",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListTagsForResource

#
Service
waf

Description

This is AWS WAF Classic documentation.

ListWebACLs

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventID": "15070e6-cc12-4782-b5ad-45e24b5beb5a",
  "eventName": "ListWebACLs",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2017-02-20T00:28:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.03",
  "recipientAccountId": "811596193553",
  "requestID": "7275bcd8-f703-11e6-b68b-f4e8eef5563f",
  "requestParameters": {
    "limit": 20
  },
  "responseElements": null,
  "sourceIPAddress": "255.253.125.115",
  "userAgent": "console.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "ASIAJMSH5T0Q30UARNB7",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:root",
    "principalId": "811596193553",
    "sessionContext": {
      "attributes": {
        "creationDate": "2017-02-19T15:37:15Z",
        "mfaAuthenticated": "true"
      }
    },
    "type": "Root"
  }
}

References #

ListXssMatchSets

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: waf:ListXssMatchSets on resource: arn:aws:waf::811596193553:xssmatchset/*",
  "eventID": "f97f3981-c0d2-4e6e-854a-63a8faf10d2d",
  "eventName": "ListXssMatchSets",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2019-07-25T09:41:04Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "51fa69ad-aec0-11e9-8bc7-1f01bb4ed705",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

PutLoggingConfiguration

#
Service
waf

Description

This is AWS WAF Classic documentation.

PutPermissionPolicy

#
Service
waf

Description

This is AWS WAF Classic documentation.

TagResource

#
Service
waf

Description

This is AWS WAF Classic documentation.

UntagResource

#
Service
waf

Description

This is AWS WAF Classic documentation.

UpdateByteMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "1759d945-f470-41c9-91fd-442e40374868",
  "eventName": "UpdateByteMatchSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:01:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ba6e76db-8583-45cc-88ef-f13784d73c18",
  "requestParameters": {
    "byteMatchSetId": "a5de4750-5fa4-4e84-ae8a-ca719eba6434",
    "changeToken": "a81844e6-227b-4381-97d5-7865790eb434",
    "updates": [
      {
        "action": "INSERT",
        "byteMatchTuple": {
          "fieldToMatch": {
            "type": "URI"
          },
          "positionalConstraint": "STARTS_WITH",
          "targetString": {
            "address": 8,
            "bigEndian": true,
            "capacity": 6,
            "hb": [
              47,
              97,
              100,
              109,
              105,
              110
            ],
            "isReadOnly": false,
            "limit": 6,
            "mark": -1,
            "nativeByteOrder": false,
            "offset": 0,
            "position": 0
          },
          "textTransformation": "NONE"
        }
      }
    ]
  },
  "responseElements": {
    "changeToken": "a81844e6-227b-4381-97d5-7865790eb434"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateGeoMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "15d3d439-dcf9-46d6-b56f-999f46aa3049",
  "eventName": "UpdateGeoMatchSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:01:53Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "21e9153e-d632-4678-9a28-e41ca9ee47e8",
  "requestParameters": {
    "changeToken": "3522171b-327f-471a-ba66-3e7c95763b74",
    "geoMatchSetId": "7899ac26-5121-403e-9e0c-ce1850a96b86",
    "updates": [
      {
        "action": "INSERT",
        "geoMatchConstraint": {
          "type": "Country",
          "value": "CN"
        }
      }
    ]
  },
  "responseElements": {
    "changeToken": "3522171b-327f-471a-ba66-3e7c95763b74"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateIPSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "a4e24ea8-9ab0-4c55-a8b9-9eb5809ad42d",
  "eventName": "UpdateIPSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:01:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7f9dded9-e337-4e36-b2c3-22d41a77b6ae",
  "requestParameters": {
    "changeToken": "1e1bd240-82bf-4b30-a917-5af7cfa02fc1",
    "iPSetId": "cb2975a3-a4e2-4897-bfed-c68cd457c1a8",
    "updates": [
      {
        "action": "INSERT",
        "iPSetDescriptor": {
          "type": "IPV4",
          "value": "192.0.2.1/32"
        }
      }
    ]
  },
  "responseElements": {
    "changeToken": "1e1bd240-82bf-4b30-a917-5af7cfa02fc1"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateRateBasedRule

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "0d268cec-34d7-44ee-a5a8-f5852467818e",
  "eventName": "UpdateRateBasedRule",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:02:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "bed88752-9ea5-4942-b755-1c2c91511299",
  "requestParameters": {
    "changeToken": "7514f5df-d066-4bca-b38f-ea4e202c8355",
    "rateLimit": 5000,
    "ruleId": "1f7d68c2-9bef-4100-8301-312701a41eff",
    "updates": []
  },
  "responseElements": {
    "changeToken": "7514f5df-d066-4bca-b38f-ea4e202c8355"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateRegexMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "1c754042-8e8b-4374-9fdb-8b83efd3ac8c",
  "eventName": "UpdateRegexMatchSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:01:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3c25f417-0ee4-43b0-83a2-e455fb426b66",
  "requestParameters": {
    "changeToken": "8a2b2d42-a166-4877-ac21-7c1c0626eb43",
    "regexMatchSetId": "edd62990-9a81-456b-8629-70d61ac63670",
    "updates": [
      {
        "action": "INSERT",
        "regexMatchTuple": {
          "fieldToMatch": {
            "data": "User-Agent",
            "type": "HEADER"
          },
          "regexPatternSetId": "4d03be78-2428-4693-baa6-cd0f7c0223d9",
          "textTransformation": "LOWERCASE"
        }
      }
    ]
  },
  "responseElements": {
    "changeToken": "8a2b2d42-a166-4877-ac21-7c1c0626eb43"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateRegexPatternSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "f14dc57a-a859-4504-9e66-4ef98dca0dac",
  "eventName": "UpdateRegexPatternSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:01:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "106bd33e-f9f2-4610-8ffa-22be25f5dc9f",
  "requestParameters": {
    "changeToken": "dacfe669-e717-4674-9312-b8d76f2fa4ba",
    "regexPatternSetId": "4d03be78-2428-4693-baa6-cd0f7c0223d9",
    "updates": [
      {
        "action": "INSERT",
        "regexPatternString": "badbot"
      }
    ]
  },
  "responseElements": {
    "changeToken": "dacfe669-e717-4674-9312-b8d76f2fa4ba"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateRule

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "b8a55b10-f15b-4e9c-83b0-47770cf06141",
  "eventName": "UpdateRule",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:01:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1a302042-91c9-418c-8d11-2c8a6eb9c7fb",
  "requestParameters": {
    "changeToken": "6c0942d5-a51b-4391-888c-3906395380c3",
    "ruleId": "757b887e-be5c-4e44-9da0-a176fe57bc54",
    "updates": [
      {
        "action": "INSERT",
        "predicate": {
          "dataId": "cb2975a3-a4e2-4897-bfed-c68cd457c1a8",
          "negated": false,
          "type": "IPMatch"
        }
      }
    ]
  },
  "responseElements": {
    "changeToken": "6c0942d5-a51b-4391-888c-3906395380c3"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateRuleGroup

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "8999119a-ccf0-4ea9-a47e-dddb0bf37c25",
  "eventName": "UpdateRuleGroup",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:02:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "40821e13-1946-44b5-8cf3-a5d8f89dd274",
  "requestParameters": {
    "changeToken": "678874a1-ffbb-4965-a582-aa3edfe1293b",
    "ruleGroupId": "6840b012-bd28-45b4-80a0-8705b6315b69",
    "updates": [
      {
        "action": "INSERT",
        "activatedRule": {
          "action": {
            "type": "BLOCK"
          },
          "priority": 1,
          "ruleId": "757b887e-be5c-4e44-9da0-a176fe57bc54",
          "type": "REGULAR"
        }
      }
    ]
  },
  "responseElements": {
    "changeToken": "678874a1-ffbb-4965-a582-aa3edfe1293b"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateSizeConstraintSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "f28fbf9f-23d3-4eca-b6b2-0d8a60d67da2",
  "eventName": "UpdateSizeConstraintSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:01:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8604196d-51bc-4423-a8e8-fae1046f32e9",
  "requestParameters": {
    "changeToken": "036d0a45-d174-41e2-9d28-981f8a541f08",
    "sizeConstraintSetId": "a5bd2ee4-c916-4c7d-a485-6812ac4ec0f5",
    "updates": [
      {
        "action": "INSERT",
        "sizeConstraint": {
          "comparisonOperator": "GT",
          "fieldToMatch": {
            "type": "BODY"
          },
          "size": 8192,
          "textTransformation": "NONE"
        }
      }
    ]
  },
  "responseElements": {
    "changeToken": "036d0a45-d174-41e2-9d28-981f8a541f08"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateSqlInjectionMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "9266acd9-f32d-4088-8486-6c4f14a61ae5",
  "eventName": "UpdateSqlInjectionMatchSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:01:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e8ece215-04ea-483d-886f-26840376b8a2",
  "requestParameters": {
    "changeToken": "93ead574-30be-4739-bfa9-1d12c63b0371",
    "sqlInjectionMatchSetId": "cda8ca42-a903-4245-b168-9e4cc0657dea",
    "updates": [
      {
        "action": "INSERT",
        "sqlInjectionMatchTuple": {
          "fieldToMatch": {
            "type": "QUERY_STRING"
          },
          "textTransformation": "URL_DECODE"
        }
      }
    ]
  },
  "responseElements": {
    "changeToken": "93ead574-30be-4739-bfa9-1d12c63b0371"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateWebACL

#
Service
waf

Description

This is AWS WAF Classic documentation.

UpdateXssMatchSet

#
Service
waf

Description

This is AWS WAF Classic documentation.

Example CloudTrail Event #

{
  "apiVersion": "2015-08-24",
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "d3020ebf-dd6c-49b5-8211-79b1f37f342d",
  "eventName": "UpdateXssMatchSet",
  "eventSource": "waf.amazonaws.com",
  "eventTime": "2026-06-29T21:01:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "70c5b6f6-5f1f-4372-a84c-e3a6bad36d97",
  "requestParameters": {
    "changeToken": "fa1912bf-d6a1-47ea-a6ca-b6cb5c094ef5",
    "updates": [
      {
        "action": "INSERT",
        "xssMatchTuple": {
          "fieldToMatch": {
            "type": "BODY"
          },
          "textTransformation": "HTML_ENTITY_DECODE"
        }
      }
    ],
    "xssMatchSetId": "4e1a5ece-cd89-4173-b6e0-a4e57136f6e5"
  },
  "responseElements": {
    "changeToken": "fa1912bf-d6a1-47ea-a6ca-b6cb5c094ef5"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "waf.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}