Skip to content

Revise WAF rule creation details and update date#30960

Open
alexmoraru7 wants to merge 1 commit into
cloudflare:productionfrom
alexmoraru7:patch-49
Open

Revise WAF rule creation details and update date#30960
alexmoraru7 wants to merge 1 commit into
cloudflare:productionfrom
alexmoraru7:patch-49

Conversation

@alexmoraru7
Copy link
Copy Markdown
Contributor

Updated the date and improved the clarity of the description and features of the WAF rule generation from Threat Events.

Summary

Screenshots (optional)

Documentation checklist

  • Is there a changelog entry (guidelines)? If you don't add one for something awesome and new (however small) — how will our customers find out? Changelogs are automatically posted to RSS feeds, the Discord, and X.
  • The change adheres to the documentation style guide.
  • If a larger change - such as adding a new page- an issue has been opened in relation to any incorrect or out of date information that this PR fixes.
  • Files which have changed name or location have been allocated redirects.

Updated the date and improved the clarity of the description and features of the WAF rule generation from Threat Events.
---

Cloudforce One users can now turn Threat Events indicators into active defense. With this update, users can instantly generate a WAF rule that matches the dynamic list of IP addresses returned by any of their **Saved Views**.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This needs a gif with a demo or at least a screenshot.

date: 2026-05-27
---

Cloudforce One users can now turn Threat Events indicators into active defense. With this update, users can instantly generate a WAF rule that matches the dynamic list of IP addresses returned by any of their **Saved Views**.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Link to Threat Events dev docs would be nice.

This new integration bridges the gap between threat discovery and threat mitigation:
* When you identify an active threat pattern—such as an ongoing campaign targeting a specific industry or using a known indicator type—you can pivot from investigation to mitigation in a single click
* Instead of writing complex, static IP rules, this functionality allows you to leverage the specific filtering logic you have already defined and saved within your Threat Events ecosystem
* Automating the generation of the WAF rule expression from your threat views eliminates manual copying errors, ensuring that the right malicious infrastructure is blocked instantly
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Linking to WAF rule expression dev doc here would be helpful.

You can implement these rules through both the dashboard UI and via the API / Terraform:

* **Dashboard:** Navigate to **Cloudflare Dashboard > Application Security > Threat Intelligence > Manage Views**, select your desired view, and click **Create WAF Rule**. This will automatically pre-populate the WAF rule builder with the matching threat event IP indicators.
* **API:** You can also automate this workflow by utilizing the **WAF Rule Builder API** alongside your Threat Events saved views endpoints.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Link to API docs here would be appreciated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants