Skip to content

WAF logging examples

docs.aws.amazon.com September 1, 2026

You can now use the updated experience to access AWS WAF functionality anywhere in the console. For more details, see Working with the console .

This section provides examples for logging protection pack (web ACL) traffic.

AWS WAF currently reports the location for JSON body inspection as UNKNOWN .

The following log listing is for a web request that matched a rule with CAPTCHA action. The web request has a valid and unexpired CAPTCHA token, and is only noted as a CAPTCHA match by AWS WAF, similar to the behavior for the Count action. This CAPTCHA match is noted under nonTerminatingMatchingRules .

The following log listing is for a web request that matched a rule with CAPTCHA action. The web request didn't have a CAPTCHA token, and was blocked by AWS WAF.

Thanks for letting us know we're doing a good job!

If you've got a moment, please tell us what we did right so we can do more of it.

Thanks for letting us know this page needs work. We're sorry we let you down.

If you've got a moment, please tell us how we can make the documentation better.

Extracted Entities

Companies (1)