# Link11 WAAP Documentation

Link11 offers a network security software suite, including robust WAAP (Web Application and API Protection). This is the documentation for the Link11 WAAP ("L11WAAP") SaaS system.

## Release Notes

* [June 2, 2026](/v5-release-notes#june-2-2026)
* [April 27, 2026](/v5-release-notes#april-27-2026)
* [April 9, 2026](/v5-release-notes#april-9-2026)
* [Older](/v5-release-notes#march-10-2026)

## Known Issues

* Available [here](/known-issues).

## User Guide

The manual is organized into the following sections, accessible through the sidebar table of contents:

* **Introduction to Link11 WAAP**: general information about the system and its capabilities
* **How It Works**: an overview of how L11WAAP filters traffic
* **Console UI Walkthrough**: a detailed explanation of the user interface
* **Using the Product**: some tips and best practices
* **Reference Information**


# Release Notes

## June 2, 2026 <a href="#june-2-2026" id="june-2-2026"></a>

### What's New

* **Client reporting of False Positives**: By default, a client user who is blocked will see a page that links [here](https://www.link11.com/en/request-block/). If the client believes the request should have been allowed, they can use this page to report the event as a False Positive, for further assessment by the Link11 customer.&#x20;
* **Live traffic monitoring**: The Dashboard, Events Log, and AI Management pages now offer a [Live data mode](/console-walkthrough/analytics/dashboard#date-time-selection-and-live-data-mode), where the display refreshes periodically to show the latest analytics.

### Fixes

* **Content Filtering exemptions**: Resolved an issue in Content Filter Profiles where even if the\
  &#x20;`cf-all` tag was included in the Ignore list, requests with malformed bodies would still be blocked.
* **Certificate error reporting**: Resolved an issue that could occur when a CA certificate was required but not presented; the Events Log would display the load balancer IP instead of the client IP.&#x20;
* **Initial stage of Passive Challenges**: Resolved an issue where client browser consoles would report errors.
* **Certificates in the API**: Resolved an issue where Swagger was showing an incomplete Certificates model.
* **Events Log matching queries**: Resolved an issue where choosing "Show Matching" for a blocking reason would not always return complete results.&#x20;

## April 27, 2026 <a href="#april-27-2026" id="april-27-2026"></a>

### What's New

* **Certificate Naming**: When creating or editing certificates, admins can now specify custom names.
* **CRL validation**: When using mTLS, Certificate Revocation Lists are now supplied as CDPs (CRL Distribution Points). CRLs are parsed and validated immediately after definition, and the most recent successful downloads are now shown in the UI.
* **Publishing transparency**: When a publish action fails due to a common error, the system will now produce more descriptive error messages.

### Fixes

* **Content Filtering**: Resolved an issue where excluding a category of signatures (e.g., libinjection) would not exempt them from evaluation against requests.

## April 9, 2026 <a href="#april-9-2026" id="april-9-2026"></a>

### What's New

* **Infrastructure as Code**: Link11 WAAP now has a [Terraform provider](/using-the-product/how-do-i.../use-terraform-with-link11-waap).

## March 10, 2026 <a href="#march-10-2026" id="march-10-2026"></a>

### What's New

* **Bypass WAAP, preserve E2E encryption**: Customers using the Link11 Load Balancer can now configure ACLs so that specific traffic will bypass WAAP and be passed directly through to the origin. To enable this feature, contact support.

* **Hiding implementation details and reducing false positives in vulnerability scans**: Responses sent from the Link11 load balancer will no longer contain the `Server` header.

* **Enhanced request metadata**: Enriched IP-related information (geolocation and ASN/org) is now available to Edge Functions, and can be forwarded to the backend in request headers. Use cases include analytics, logging, access control, etc.

* **Reduced error page sizes**: Images used in custom response pages are now stored on the CDN. This reduces bandwidth usage and server load during attacks.

* **Consistent block pages**: Clients of protected systems now receive a uniform, branded experience when their requests are blocked. Previously, some system-level blocks (such as unrecognized hosts) would result in an unbranded generic response, instead of the customized page defined for the Block [action](/console-walkthrough/security/actions).

* **Enhanced availability of client IPs**: Proxy Templates now support multiple (up to five) headers for passing real client IPs.

### Fixes

* **Updating CRLs**: Resolved an mTLS issue where Client Revocation Lists could not be updated.

* **Content Filtering Profiles**: Resolved an issue where tags unrelated to Content Filtering could be added to the Active and Report lists.

* **Events Log queries**: Resolved an issue where requests with multiple reasons for blocking or monitoring could be included in query results, despite the queries being structured to exclude them.

* **Ruleset naming**: Resolved an issue where different types of security settings were being treated as the same type when evaluating potential name collisions.

* **Redundant challenges**: Resolved an issue where a site using iframes could challenge clients multiple times. This could result in bad UX, especially for sites using interactive challenges.

* **Global Filter tagging**: Resolved an issue where system-managed Global Filters could fail to tag matching requests.

* **Request logging**: Resolved an issue where requests with invalid urlencoded characters were not being logged correctly.

## January 18, 2026 <a href="#january-18-2026" id="january-18-2026"></a>

### What's New

* **Enhanced AI crawler control**: The [AI Management Dashboard](/console-walkthrough/analytics/ai-management) now provides additional analytics, and the ability to manage AI crawler activity directly from the Dashboard.
* **Global alerts for Dynamic Rules**: Security Alerts can now be configured to send alerts for all sites/server groups in the planet, including those created in the future.

### Fixes

* **Bot detection**: Resolved an issue that allowed potential bypass of passive bot challenges.
* **Certificate generation**: Resolved an issue where certificates would not be generated from the Server Groups Editor.
* **Dynamic Rules**: Resolved an issue where certain header-based Rules weren't being displayed correctly in the UI.
* **Interface updates**: Resolved several minor UI issues and added some input validation.

## December 23, 2025 <a href="#december-23-2025" id="december-23-2025"></a>

### What's New

* **Global Filter tag visibility**: The main Global Filters page now includes a Tags column, so that tags are visible without opening the Editor.
* **Link11 Secure CDN trusted sources**: Secure CDN's nodes have been added to Proxy Templates as trusted traffic sources. Also, the Global Filter for Secure CDN IPs has been renamed to “Secure CDN Link11 Trusted Source“.

### Fixes

* **Counting tagged requests:** Resolved an issue preventing the creation of certain security rulesets that counted tagged requests.
* **CDN Purge page**: Resolved an issue where the UI included the Purge CDN Cache page when there was no supported CDN provider.
* **Analytics**: Resolved an issue preventing successful log queries for requests with large field values (headers, cookies, or arguments).
* **Certificate Revocation Lists**: Resolved an issue where CRLs in DER format were not being downloaded correctly.
* **Analytics queries**: Resolved an issue where the Dashboard, Events Log, and AI Management Dashboard were not consistently using local times vs. UTC.

## November 24, 2025 <a href="#november-24-2025" id="november-24-2025"></a>

### What's New

* **AI traffic analytics:** The new [AI Management Dashboard](/console-walkthrough/analytics/ai-management) provides analytics of requests originating from AI crawlers.
* **AI traffic management**: AI crawlers can be [blocked](/console-walkthrough/analytics/ai-management#how-to-manage-ai-crawlers) or otherwise managed as needed; configuration can be set up per-crawler and at various scopes (from globally down to individual URLs). Visitors referred by these services (e.g., chatgpt.com) can also be handled uniquely if desired.
* **Dynamic management of Trusted Sources**: Each Proxy Template includes a list of trusted sources: IP ranges from which Link11 WAAP will accept traffic (for example, load balancers or a CDN). Previously, the list of trusted IP ranges had to be managed manually. Now, Global Filters can also be added as Trusted Sources; when a Filter is updated, the linked Proxy Template will be updated dynamically as well.

## November 3, 2025

### Fixes

* **Country identification**: Resolved an issue where requests from a certain country were being misidentified as originating from elsewhere.
* **URL-based Content Filtering exemptions**: Resolved an issue where narrowly-scoped exclusions were not occurring.

## October 6, 2025

### What's New

* **Custom traffic log annotations**: Edge Functions can now be used to inject [custom messages](/console-walkthrough/sites/edge-functions#adding-custom-messages-to-log-events) into events for better visibility, monitoring, debugging, etc.

### Fixes

* **Excessive request sizes**: Resolved an issue where excessively-large requests were blocked, but the reason was not logged.
* **Log exceptions**: Resolved an issue where a name-resolution exception would produce excessive error messages.

## September 8, 2025

### What's New

* **Control over Log Exporter data**: To better manage syslog messages, admins can now define maximum-length limits for various Log Exporter fields. Exported data values will be truncated to those limits.
* **URL-based exemption from Content Filtering**: Content Filtering Profiles now include an [Exclusions](/console-walkthrough/security/content-filter/profiles#exclusions) list. Requests with specific destination URLs can be fully or partially exempted from evaluation against Content Filtering Rules.

## August 18, 2025

### What's New

* **Tag visibility via Edge Functions**: Post-processing Edge Functions can now access information about the tags attached to the request.

### Fixes

* **Malformed body inspection**: Resolved an issue where requests with malformed bodies were not being fully inspected. As part of this bug fix, all *Content Filter Profiles* had the `malformed-body` tag added to their *Ignore* sections. To enable content filtering on malformed bodies, this tag can be removed; however, note that this can potentially result in performance degradation and False Positive alarms.
* **mTLS cancellation:** Resolved an issue where mTLS, when previously enabled but subsequently disabled, was still being enforced.

## July 28, 2025

### What's New

* **CRLs (Client Revocation Lists) for mTLS:** When mTLS has been enabled for communication with clients, admins can use CRLs to verify client certificates. Unauthorized or compromised clients will be rejected without waiting for certificate expiration.
* **Enhanced traffic data exporting**: Log Exporters now include an option to [include a Base64-encoded representation](/console-walkthrough/system/log-exporters#include-encoded-request-data) of the HTTP request (its headers, cookies, and query arguments). Customers can now extract and inspect the auth token and other metadata required for customer identification and security analysis.
* **Modal display of entities in Tag Finder**: In the Tag Finder, the user can view a list of security entities that use or can generate a specific tag, and can open each one. Previously, entities were opened in their appropriate editors; now, to preserve session context, each one opens in a read-only window.
* **Security Policy path map search capability**: When editing a Security Policy, the Path Mapping table now has Filter fields at the top of each column for quickly finding specific entries. Regex is supported.
* **Multi-regional independent load balancing**: For planets spanning multiple regions, individual load balancers can now be defined, each with distinct settings. Each load balancer can have a list of preferred datacenters to which it will send its traffic for processing, so that admins can ensure optimal routing within geographic regions.

### Fixes

* **Dashboard Top Metrics query building**: Resolved an issue that could occur when examining a Top Metric, where the *Events Log (matching)* option would open the Events Log, but without pre-populating the query.
* **Let's Encrypt certificate generation**: Resolved an issue where using the *Redirect HTTP to HTTPS* Edge Function could prevent the generation of Let's Encrypt certificates.

## July 7, 2025

### What's New

* **Validation of customer backends for mutual TLS**: Previously, admins could configure mTLS so that Link11 WAAP would validate end users, and customer backends would validate L11WAAP. This release adds support for validation of customer origins by L11WAAP.
* **Additional certificate visibility**: The Certificates page now includes a consolidated column for cloud providers and a new column showing whether the certificate was issued by Let's Encrypt.
* **Passive challenge cookies**: As part of the recent Link11 rebranding, passive challenge cookies have been renamed. (Previously, they were `rbzid` ; now, they are named `waap_id`.) Admins should ensure that if any security rulesets (such as Rate Limit Rules, Dynamic Rules, etc.) were based on these cookies, that these rulesets are updated.

### Fixes

* **User interface**: Resolved some minor issues in the UI.
* **Edge Function redirects**: Resolved an issue where requests redirected during the *Request Pre Processing* phase were not being logged.
* **SSL certificate renewal**: Resolved an issue where customers using Link11 load balancing could have difficulties when auto-renewing certificates.
* **Adding a Backend Service**: Resolved an issue where an existing Backend Service configuration couldn't be duplicated.

## June 17, 2025

### What's New

* **Extended mTLS support**: Mutual TLS is now supported between L11 WAAP and customer backends.
* **Easier use of Edge Functions**: Edge Functions can now be connected to Security Polices from within the Edge Functions Editor.
* **Enhanced HTML pages for Block actions**. Previously, blocking Actions included a minimalistic default response. Actions that still contain this default (a *Content* value of *access denied*) will be upgraded to a rich HTML page, based on the customization tokens introduced in release v5.3.15. Admins can also create their own customized response pages.

### Fixes:

* **Content Filtering triggers**: Resolved an issue that could occur when a Content Filter Rule blocked a request, but in the logs, the trigger for the block would be misidentified.
* **Dashboard chart rendering**: Resolved an issue where charts would not correctly respond when the user zoomed in or out.
* **Events blocked by origin**: Resolved an issue where requests blocked by the backend could be shown in the Dashboard as "passed".
* **Log Exporter behavior**: Resolved an issue where Log Exporters that aren't correctly configured would generate excessive amounts of traffic data.
* **Truncated event data**: Resolved an issue where excessively large requests (those exceeding the maximum allowable log entry size) were not being correctly truncated in the Events Log.

## May 21, 2025 <a href="#may-21-2025" id="may-21-2025"></a>

### What's New

* **Enhanced granularity for Dashboard queries**: When querying traffic data for the Dashboard, admins can now filter by domain.
* **Self-generated SSL certificates**: Customer systems can now communicate directly with Let's Encrypt to generate or renew their own certificates using the ACME protocol. In previous releases, the resulting challenges from LE would be dropped; now, Link11 WAAP will pass LE responses through to the customer backend.
* **SSL private key security**: Planets can now be configured so that certificates cannot be downloaded or replaced.
* **Enhanced Events Log display for large quantities of arguments**: In the April 17 release, it became possible (using an internal setting) to defer argument retrieval until the admin chose to see them. In the current release, this has been refined further; when a large quantity of arguments is displayed, the UI will present them in a user-friendly table that includes search capabilities.
* **Enhanced granularity when offloading IP blocking**: In Dynamic Rules, when offloading IP blocking to Link11's Layer 3 protection, admins can now use Include/Exclude tags to narrow down the applicable scope of the Rules.

### Fixes

* **User agent visibility**: Resolved an issue in the Events Log where long user-agent strings were being truncated.
* **Events Log results display**: Resolved an issue where the dropdown list offering different quantities of results was sorted incorrectly.
* **Proxy Template creation**: Resolved an issue where a Proxy Template containing an Advanced Configuration could not be duplicated.
* **Analytics date/time specification**: Resolved an issue where the date/time selection control was displaying some options on a transparent background.
* **Site-level Rate Limit Rules**: Resolved an issue where site-level Rules were not backwards-compatible with certain automated updates.
* **Quarantined IP duplication**: Resolved an issue where a misbehaving IP could be added to the Quarantine list more than once.
* **Log Exporter unavailability**: Resolved an issue where a certificate without a CN could make Log Exporter configurations unavailable.
* **Query parameters display in the Events Log**: Resolved an issue where requests could be shown with duplicated parameters.
* **UI issues**: Resolved several minor issues in the web console.

## April 28, 2025 <a href="#april-28-2025" id="april-28-2025"></a>

### What's New:

* **Rebranding**: The Link11 WAAP interface has been throughly updated, presenting a new look as part of Link11's rebranding.
* **Enhanced Events Log filtering**: Events Log queries can now be filtered by domain.
* **Customizable block responses**: Admins have additional ways to customize the responses to blocked requests.
* **Edge Function flexibility**: Admins have additional options for timing the execution of Edge Functions.

### Fixes:

* **Duplicate tags in Content Filter Profiles**: Resolved an issue where the Content Filter Profiles Editor could display tags twice in the *Ignore Content Filter Tags* field.

## April 17, 2025 <a href="#april-17-2025" id="april-17-2025"></a>

### What's New:

* **Improved Dashboard performance**: The Dashboard is now more responsive when the planet is undergoing a large attack.
* **Improved Events Log performance**: Events Log entry display is now more performant for requests containing large, or a large number of, arguments. Argument retrieval can be deferred until the user selects them for viewing.
* **Easier applications of Rate Limit Rules**: A Rate Limit Rule can now be attached to all Security Polices with a single action in the UI. Admins can then delete individual attachments as desired.
* **Immediate SSL certificate generation**: When a domain is added to a Server Group, and the change is saved, a Let's Encrypt certificate can be generated for it immediately. (Previously, this did not occur until the changes were published.)
* **Improved visibility of Global Filters, Dynamic Rules, Server Groups, and Proxy Templates**: Each of these list pages has a new column, showing more information to reduce clickthroughs to the respective Editor pages. The new columns are:
  * For Global Filters: whether or not the Filter is system-managed, and the numbers of Sections and Entries in the Filter's Rule list
  * For Dynamic Rules: the Target field
  * For Server Groups: the number of hosts
  * For Proxy Templates: the usage of Advanced Configuration
* **Improved visibility for passed requests**: Requests sent to the customer origin now receive additional tags (`sent-to-origin` and `upstream-status:xxx`). Use cases include better analysis of potential False Positives, and using Dynamic Rules to exclude requests that reached the origin.
* **AWS CDN purging**: AWS CDN caches can now be purged from within the Link11 WAAP interface.
* **Additional mTLS options**: For communication with clients, admins can now configure a Server Group with these options:
  * Do not request a CA certificate
  * Request and require a valid CA certificate
  * Request but not require a certificate. If the client provides a certificate, it must be valid for communication to continue.

### Fixes:

* **Global Filter editing**: Resolved an issue where the Global Filters editor had high latency when a Filter contains a large number of sections.
* **PEM file import**: Resolved an issue preventing the import of PEM files in Windows format (with CRLF end of lines).
* **Custom backend configuration**: Resolved an issue where Proxy Template Custom Configuration Code location-level commands to add headers were not working.
* **Log Exporter configuration**: Resolved an issue preventing Log Exporters from having their ports changed.
* **Security Policy paths**: Resolved an issue preventing multiple Security Policies from containing the same path mapping.
* **Load Balancing certificates**: Resolved an issue where CA certificates were displayed in the list of potential certificates for the LB.

## March 24, 2025 <a href="#march-24-2025" id="march-24-2025"></a>

### What's New:

* **More flexibility when configuring Rate Limits**: Admins can now apply a rate limit to an entire site.
* **Improved CAPTCHAs**: Interactive challenges are now more robust. (Some potential methods of bypassing them are no longer possible.)

### Fixes:

* **Dashboard**: Resolved an issue where the Topx table would sometimes fail to load.
* **SSL certificates**: Resolved an issue preventing server certificates from being replaced.
* **SSO session expiration**: Resolved an issue where a user logged in via SSO could potentially lose unsaved configuration changes when the SSO token expires. Now, unsaved data is maintained through the expiration/re-login process.
* **UI**: Resolved an issue where the Tag info panel would sometimes fail to open.

## March 5, 2025 <a href="#march-5-2025" id="march-5-2025"></a>

### What's New:

* **End-to-end encryption now supported:** Client traffic can now be forwarded to the customer origin while remaining SSL encrypted, e.g. to satisfy PCI 3DS requirements. To enable this feature, contact Support.
* **Assigning Rate Limit Rules to multiple paths**: Admins can now assign a Rate Limit Rule to all defined paths within a site, which creates a separate entry for each path automatically. Individual entries can then be edited or deleted as necessary.
* **mTLS (mutual TLS) support between clients and L11WAAP**: Admins can now upload CA certificates and assign them to Server Groups. Clients attempting to access the specified sites will be required to present certificates, the issuers of which will be validated. This feature was already available when using Link11 load balancers (although it needs to be configured by Support); now it is available for AWS NLB as well, through the user interface and API.
* **Multiple load balancers now supported**: Within the Link11 private cloud, admins can now create multiple load balancer configurations, e.g. various ports can now be opened for a single planet.

### **Fixes**

* **Duplicate quarantined IPs**: Resolved an issue where during an attack, a hostile IP could be added to the Quarantine list multiple times.
* **Offloaded IP blocking**: Resolved an issue where an IP that was offloaded to Layer 3 protection would not be blocked immediately.
* **Internal service resilience**: Resolved an edge case where if a certain internal service crashed, the system would not try to restart it.
* **Creating Mobile Application Groups**: Resolved an issue where duplicating an existing Mobile Application Group would fail.
* **UI:** Added some minor improvements to the web console.

## February 10, 2025 <a href="#february-10-2025" id="february-10-2025"></a>

### What's New:

* **SDK for mobile applications**: The L11WAAP Mobile SDK, previously only available for v2.x, is now available for v5. This is a unique client certification mechanism for iOS and Android apps. In use, the SDK signs the application, authenticates the device, and verifies user identity, adding a cryptographic HMAC signature to each request. The SDK provides a reliable and secure mechanism to confirm that the traffic is originating from a legitimate app user and not a bot or emulator.
* **Additional protocol for Log Exporters**: There is now an "Untrusted" option for Log Exporters' Transport protocol, where TLS will be used, but Link11 will not verify the certificate.
* **Improved visibility and performance for requests with malformed bodies**: When a request has a large malformed body, the entire body is no longer displayed in the Events Log or exported via Log Exporters. Instead, it is truncated to 500 characters, and the displayed/exported event includes a message to this effect.

### Fixes:

* **Dynamic Rules Editor performance**: Resolved an issue where the Dynamic Rules Editor page in the UI would take several seconds to load.
* **Additional resilience for Dynamic Rules**: Resolved an edge case when offloaded IPs are quarantined. Previously, if an admin unblocked the IP, and the initial unblocking attempt failed, the unblocking process would not be retried.&#x20;
* **Content Filter Profiles tag editing**: Resolved an issue where editing a tag list (e.g., the *Active* allowlist) would remove the tags already on the list.
* **Improved web console**: Resolved some minor issues in, and added some improvements to, the UI.

## January 13, 2025 <a href="#january-13-2025" id="january-13-2025"></a>

### What's New:

* **Improved table search**: For various tables in the interface (displaying lists of policies, security rulesets, etc.), it is now easier to find a specific entry:
  * Search fields are displayed at the top of the list. (Previously, they were hidden unless the Filter button was selected.)
  * The search fields now support regex. (Example: entering `^Api` will filter the list to only show entries starting with `Api`.)
* **Easier selection within dropdown lists**: Dropdown controls are now easier to use: all options in each list are sorted, and if more than five options are available, the list also contains a Search capability.
* **Removed certificate limits for load balancers in the Link11 Cloud**: When L11WAAP is deployed in the Link11 Cloud, the number of certificates per load balancer is now unlimited.
* **Improved consistency of Security Policy API**: Some legacy field names were updated.
* **Improved consistency for Autonomous System references**: Within the UI and API, some legacy terminology was updated. When mentioning an AS, L11WAAP now consistently refers to it as "organization" rather than "company".

### Fixes:

* **Error-handling of quarantined IPs**: Resolved an issue where a request sent from a quarantined IP with a specific syntax error would be blocked, but would not be correctly represented in traffic analytics.
* **Error-handling when publishing**: Resolved an issue where a failed publish operation would not recover gracefully.

## December 24, 2024 <a href="#december-24-2024" id="december-24-2024"></a>

### What's New:

* **Configuring traffic event streaming within the UI**: Configuring event streaming to external destinations (e.g., SIEMs) was previously available only through the API. This feature is now available through the web console as well.

### Fixes:

* **Analytics**: Resolved an issue where under certain conditions, the Events Log was not displaying the X-Forwarded-Port headers for requests.
* **Backend SaaS**: Improved error handling in the backend services for several edge cases.
* **UI**: Resolved several minor issues.&#x20;

## December 10, 2024 <a href="#december-10-2024" id="december-10-2024"></a>

### What's New:

* **Additional ability to purge CDN caches**: The Purge CDN Cache command now supports Link11's Secure CDN.
* **Additional options for exporting traffic events**: When using Log Exporters to stream event data to an external destination (e.g. a SIEM solution), admins can now choose to export all events, or only events where requests were blocked by L11WAAP. Admins can also choose to export events for all server groups (i.e., sites), or only specific server groups.&#x20;

### Fixes:

* **Dynamic Rules**: Resolved an issue when editing Dynamic Rules that are configured to offload IP blocking to Link11's Layer 3 protection, and that are currently being triggered by one or more IPs. (When such a Rule was deactivated, the triggering IPs would be removed from quarantine, but would still be blocked until the original quarantine period had expired.)
* **Events Monitoring**: Resolved an issue where requests that triggered a Monitor action were not being assigned correct tags for their status.
* **Security Alerts**: Resolved an issue preventing Security Alerts from being created when they were based upon newly-created Dynamic Rules.
* **Security Policies**: Previously, each Policy contained an unused field named "match". This has now been removed.
* **SSL**: Resolved an issue where importing a PFX file with multiple domain names would result in an extra space being added to each name after the initial one.
* **SSL**: Resolved an issue that could occur when renewing multiple certificates; if a certificate could not be renewed, the remaining renewals would not be attempted.

## November 4, 2024 <a href="#november-04-2024" id="november-04-2024"></a>

### What's New:

* **Purging CDN caches**: Admins can now purge CDN caches from within L11WAAP, without needing to contact support.
* **Offload IP blocking to Link11 Layer 3 protection**: When a Dynamic Rule is blocking a hostile IP, the blocking can be offloaded to Link11's Layer 3 protection. The hostile requests will be blocked before they reach the WAAP, which will increase performance.&#x20;
* **iCloud IP lists**: Global Filters now include a list of iCloud IPs, so admins can, if desired, create distinct handling and security rulesets for requests from those IPs.
* **Log Exporter / Event Streaming**: In previous versions, L11WAAP could export log data and stream traffic events to external destinations such as SIEM solutions. This has now been enabled for v5 via the API. Setup details are [here](/using-the-product/how-do-i.../stream-event-data-to-a-siem-solution-or-other-destination).
* **Advanced configuration**: Link11 advanced support users can now create customized capabilities for customers by defining custom code in Proxy Templates. Note: This capability should only be used by advanced support, as improper use of this capability can severely damage the system.

### Fixes:

* **API**: Resolved an issue where Security Policy path mapping entries were not being validated correctly (duplicate values were being allowed).
* **Backend Services**: Resolved an issue where the interface for new backend creation included an incorrect default value for the Host field.
* **Events Log**: Resolved an issue where selecting an entry to show additional details could display an empty panel.

## September 22, 2024 <a href="#september-22-2024" id="september-22-2024"></a>

### What's New:

* **Dynamic Rules** and **Rate Limit Rules:** OR or AND operators were added to the Include and Exclude tag lists, providing more precision and flexibility when specifying the scope of rule enforcement.

### Fixes:

* **Security Alerts**: Resolved an issue where alerts were not being sent.
* **UI**: Resolved several minor issues.

## September 12, 2024

### What's New:

* **Security Alerts**: A [security alerting feature](/console-walkthrough/system/security-alerts) has been added (similar to a feature previously available in version 2). When Dynamic Rules are violated, email alerts can be sent to specified addresses.&#x20;
* **SSL**: Admins can now set SSL protocols and SSL ciphers on a server group level via the API. (Previously, these values were hardcoded in a backend file.)&#x20;

### Fixes:

* **Publishing** Resolved an issue where multiple publish operations in a short time were not succeeding.
* **Server Groups**: Resolved an issue where a domain could be assigned to more than one group.
* **SSO**: Resolved an issue with Azure SSO (from [this Microsoft error](https://techcommunity.microsoft.com/t5/microsoft-entra/aadsts75011-error-on-edge-azure-ad-joined-machines/m-p/2575051)) where users could not login via PIN or Face ID using the Edge browser.&#x20;
* **UI**: Resolved some minor issues.

## August 14, 2024

### What's New:

* **API**: The Swagger display has been updated to reflect API v4.2.
* **API**: When a "publish configuration" command is sent before a previous publish operation has completed, a 503 error will be returned. API users should use a retry mechanism to ensure that publish commands are successful.
* **Global Filters**: When creating an IP-based filter, users can now specify ipv6 addresses with subnet > 32
* **Traffic logs**: Requests that are blocked because they caused processing errors are now shown in the logs.
* **UI**: Reblaze logos in the documentation and web console now reflect Reblaze Technologies' new role as part of the Link11 Group.

### Fixes:

* **Dashboard**: Resolved an issue where a request with an invalid (null) status would prevent data from being displayed.
* **Dashboard**: Resolved an issue where the Response Status Graph was not filtering results according to user selection of "By Origin" or "By Reblaze".
* **Events Log**: Resolved an issue where a POST request with a malformed JSON payload was not being correctly reflected in the logs.
* **Events Log**: The "Copy Request as Curl" command now includes the protocol in the curl string.
* **Proxy Templates**: When an invalid CIDR is added to the list of Trusted Sources, an error message is now displayed in the UI.
* **Publishing**: Resolved an issue where, when publishing a configuration change, a "validation failed" error could occur if a temporary file already existed.
* **SSL certificates**: Resolved an issue where a failure to renew certificates with more than one domain could cause an internal error.
* **System performance**: Resolved an issue where internal database queries could potentially hang. Now a timeout is enforced; if it is triggered, a 408 code is returned.

## July 24, 2024

### What's New:

* **Backend Services**: it is now possible to
  * define multiple ports per host for HTTP and HTTPS
  * define multiple hosts when setting up Port Bridge mode
  * define multiple ports when setting up the other modes (Per Request, HTTP Always, and HTTPS Always)
* **Proxy Templates**: A new configuration option enables sites to accept requests with client body sizes above 5 MB.
* **Traffic analytics**: In the Dashboard and Events Log, the date/time query control now allows the specification of seconds; previously, only hours and minutes could be specified. Timestamps now default to zero seconds (i.e., the query parameter defaults to the beginning of the specified minute); when seconds are zero, they are not displayed in the timestamps.

### Fixes:

* **API**: Resolved an issue with the`/accounts/api-keys`route, which was not correctly accepting the API key.
* **Backend Services**: Resolved an issue where Port Bridge Mode was not working correctly for ALBs (application load balancers).
* **Content Filter Rules**: Resolved an issue where a Rule could be configured with an invalid Match parameter.
* **Edge Functions**: Resolved an issue where Edge Function identifiers submitted via the API were not being validated correctly, potentially resulting in 502 errors.
* **Events Log**: Modified the units for Reblaze time (from ms to seconds), so that it is consistent with other metrics.
* **SSO Configuration**: Resolved an issue where Azure SSO was not working correctly.

### Known Issues

* **SSL Certificates**: When upgrading from Reblaze v2.x to v5, existing SSL certificates will be retained. However, when they expire, they will not auto-renew. To enable auto-renewal for migrated certificates, contact support.

## July 3, 2024

### What's New:

* **Events Log**: the events display has been revamped and is now easier to use. Selecting an event now displays a window with several sections: the most important data on the top, followed by one or more expandable sections with various categories of additional information.
* **Edge Functions**: when a user defines custom Lua code, its syntax is now validated before being accepted.
* **Publishing**: when a user submits configuration changes for the backend, the changes are now validated before being accepted.
* **SSL policies**: default policies for load balancers are now `min tls 1.2 - modern` (for GCP) and `ELBSecurityPolicy-TLS13-1-2-2021-06` (for AWS). This change applies to new planets only.

### Bug Fixes:

* **Analytics**: in the Dashboard and Events Log, the preset time period selectors (e.g., "Last hour") were not being reset when the timeframe changed.
* **Backend services**: when creating a new backend service, it was possible that an internal id would not be assigned correctly.
* **Content Filter Rules**: when creating a new rule, it was possible that an internal id would not be assigned correctly.
* **Dynamic Rules**: if a Rule's ID contained a hyphen, an internal error would occur, and the Rule would not be effectual.
* **Events Log**: when a host name included a port, under certain conditions the port would be appended again.
* **Events Log**: When a request included arguments, the "Copy as Curl" menu option was not composing curl commands correctly.
* **Events Log**: When a request triggered a "Skip" action, under certain conditions it could be reported as a "Block reason".
* **Events Log**: for data-heavy queries, there could be a significant delay between the query's completion and the UI's refresh.
* **Proxy Templates**: when creating a new template, the header host was not being set correctly.
* **SSL Certificates**: the Certificates page in the console would not load if its timeouts were exceeded.
* **SSL Certificates**: all expiring certificates were being renewed. Now, unused certificates are not renewed.
* **SSL Certificates**: under certain conditions, certificate replacements were being reported as having failed, even when they succeeded.
* **Swagger UI** was not correctly accepting load balancer names in the Load Balancer DELETE/PUT API routes.
* **Tags**: for short tags, it was difficult to click on the portion of the tag that opens the Tag Finder.
* **User accounts**: an uncommon structure for email addresses was not being accepted.
* **UI cleanup**: in a few places, long strings were not being displayed correctly. Some inconsistencies in capitalization, font colors, and spacing were corrected.

### Known Limitations:

* **Events Log**: when viewing events that occurred before this software version was deployed, incomplete "block reason" data will be shown for events blocked due to "general reasons" or "content filter rule" violations.

## June 12, 2024

### What's New:

* **Global Filters**: Entries within a Global Filer's Rule can now be edited from within the table. (Previously, they had to be deleted and re-created.)

### Bug Fixes:

* **Backend Services**: under certain conditions, users could define multiple hosts in bridge mode.
* **Dashboard**: retrieved data was not always being cleared between searches.
* **DNS Records**: multiple values were concatenated in a single line. Now, they are displayed in separate rows.
* **Dynamic Rules**: Target entry was not displayed correctly if it included an underscore.
* **Events Log**: displayed keys and values could be vertically misaligned.
* **Events Log**: large data files could overflow the text display.
* **Flow Control**: arguments with long strings could overflow the input control.
* **Login screen**: empty input fields were not displaying errors.
* **Tag Finder**: could display incorrect tag usage.
* **Tag Finder**: header row of tags table was too short.
* **Traffic data queries**: certain inputs were not being validated for data types.
* **Traffic filtering**: Headers with invalid (non-UTF) characters would throw runtime errors. Now, they are blocked with 400 response codes.
* **Web console**: "User Guide" link was not pointing to the most recent version.
* **Web console**: various minor issues with table column widths, redundant tooltips, and others.

## May 21, 2024

### What's New:

* **Traffic filtering**: Headers larger than 64k are now supported.
* **Analytics**: the date/time control for queries was accepting AM/PM time specifications. Now, for consistency with graphs and logs, it accepts 24-hour time specifications.
* **Content Filter Profiles**: previously, the "Ignore Content Filter Tags" list accepted all types of tags, and there was different behavior when matches were found for CF tags versus non-CF tags. To improve consistency, this list now only accepts Content Filter Rule and libinjection tags.
* **Security entities**: previously, selecting "New" would create an entity (e.g., a Global Filter) with default values that could be edited. This created friction if the selection of "New" was inadvertent, because the unwanted entity would then need to be deleted. Now, entities are not actually created until the user selects "Save".

### Bug Fixes:

* **Dynamic Rules**: when the Action of a Dynamic Rule was changed, any traffic sources currently in quarantine from the Rule did not have their action changed.&#x20;
* **Edge Functions**: the Edge Function Editor page was not displaying the function's Automatic Tag (`edge-function`).
* **Edge Functions**: when multiple Edge Functions were assigned to the same path, the Events Log was not reporting all of their tags.
* **Security Policies**: when a Policy did not include any Rate Limit Rules or Edge Functions, the console failed to display a "No data found" message.
* **SSL Certificates**: When certificates were generated from a server group with multiple domains on “Match Host/Authority Headers”, Let's Encrypt was only generating a certificate for the last domain on the list.

## May 14, 2024

### What's New:

* **Reblaze v5 is released**; a thorough restructuring of Reblaze, from UI to architecture. Compared to previous versions, v5 provides a much more intuitive workflow, better analytics, numerous performance enhancements, more powerful traffic filtering, and much more.&#x20;


# Known Issues

For known issues or limitations in the current version of Link11 WAAP.

## Log Exporters

| Issue                                                                                                                                                | Workaround/solution                                                                                                               |
| ---------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| The Log Exporter feature is not enabled by default. When trying to create a new Log Exporter, the Save procedure fails and an error message appears. | Before attempting to create a Log Exporter for the first time, [contact support](/support) to enable this feature on your planet. |


# Introduction to Link11 WAAP

Product overview, architecture, and how it works

## Welcome!

Link11 offers an all-in-one WAAP platform. It includes a next-gen Web Application Firewall (WAF), autoscaling Denial of Service (DoS)/Distributed Denial of Service (DDoS) protection, advanced bot management, real-time traffic monitoring & control, full historical logs & analytics, and more.&#x20;

Link11 WAAP runs on the customer’s clouds of choice, whether the Link11 Network and Web Security solution, or any of the top-tier public cloud providers (AWS, Azure, and GCP). It protects web applications, services and microservices, and API endpoints.

## Platform overview&#x20;

L11WAAP deploys as a reverse proxy, continually analyzing incoming traffic. Benign traffic is passed through to the customer's origin, while hostile traffic is blocked and denied access.&#x20;

The platform's overall architecture is as follows:&#x20;

<figure><img src="/files/VaQ53k9jr59GYuV4Ry5F" alt=""><figcaption></figcaption></figure>

### Cloud-based web security

* L11WAAP deploys and runs in the customer's choice of clouds, whether private (Link11) or public (AWS, GCP, or Azure).&#x20;
* All incoming traffic is routed through L11WAAP and scrubbed as it passes through. Latency is negligible (generally 1.5 milliseconds or less).&#x20;
* Hostile traffic is blocked before it reaches the protected network. Legitimate traffic has normal access to the requested resources.&#x20;
* Attackers cannot reach, or even find, the targeted web platform.
* Bandwidth, compute, and other resources scale automatically as needed.&#x20;
* Remote management ensures minimal obligations (of time or expertise) from onsite staff.
* L11WAAP supports various methods of authentication such as Basic, Digest, and Kerberos. (Note that NTLM cannot work with reverse proxies, and thus L11WAAP does not support NTLM sites/applications.)&#x20;

### Full integration

L11WAAP is integrated with, and runs natively on, multiple cloud platforms. It leverages the advantages of each. Examples:

* When L11WAAP runs on Link11, customers can use Secure CDN, Link11 load balancing, Infrastructure DDoS for offloading Layer 3 protection, and more.
* On GCP, L11WAAP can act as the 'threat detection engine' for Cloud Armor, automating and extending its capabilities, and blocking attacks at the edges.
* On Azure, L11WAAP integrates with Azure Security Center to fit smoothly into existing customer workflows.
* On AWS, L11WAAP integrates with AWS WAF and Shield, adding granularity, control, and many other additional capabilities to AWS's native security features.


# Traffic Filtering Process

<figure><img src="/files/F4oFsyMMiyzVo1xvV62X" alt=""><figcaption></figcaption></figure>

## Introduction

Link11 WAAP subjects incoming requests to a multi-stage filtering process.

Below is a high-level description of the overall process. For a more in-depth review of the various stages and how to configure them, see their detailed discussion in the Console UI Walkthrough section of this manual, as linked to below in each description.

When processing an incoming request, L11WAAP enforces the applicable security rulesets. As shown above, some types of rulesets are applicable to all requests, while others will vary depending on each request's destination URL and/or the tags attached to the request. To see how L11WAAP decides which rulesets are applicable to a request, see the [Policy Mapping](/how-link11-waap-works/policy-mapping-and-traffic-routing) page.

## Overview

Link11 WAAP acts as a proxy for the backend that it protects. It receives incoming requests, and examines them for potential threats. Requests that pass inspection are passed through to the backend. Those that do not pass inspection trigger an [Action](/console-walkthrough/security/actions), which often is either a blocking action or a [bot challenge](/reference-information/hostile-bot-detection-lwcsi). Along the way, L11WAAP logs the request and the actions that occur, which are available to admins via analytics and dashboards.

The diagram above shows the progression of incoming requests through this process, shown from left to right. When a request successfully passes a stage, it proceeds to the next stage, as designated by a green arrow. When it does not, it follows the red arrow instead. Black arrows show activities that occur independent of a request's evaluation.

## Stages/components of traffic filtering

### "Request Pre-Processing" Edge Functions

Before any other processing occurs, L11WAAP can execute one or more [Edge Functions](/console-walkthrough/sites/edge-functions). An Edge Function consists of custom Lua code; it allows admins to extend the system's capabilities as desired.

Each Edge Function contains a [Phase](/console-walkthrough/sites/edge-functions#phase) parameter. When this is set to `Request Pre Processing`, the Function is executed immediately, before other processing occurs.

### Initialization

L11WAAP uses a [tag-based system](/how-link11-waap-works/tagging) when processing and evaluating requests. At various points during processing, tags are attached to a request based on its source, content, and other characteristics.

Subsequently, the attached tags can be the basis for decisions about the disposition of the request.

In this stage of processing, each request receives a [specific set of system tags](/how-link11-waap-works/tagging#attached-during-initialization). For example, every request will be tagged with `all`, along with tags for the geolocation of the traffic source.

This stage is also when L11WAAP performs [policy mapping](/how-link11-waap-works/policy-mapping-and-traffic-routing): determining which security rulesets should be enforced upon the request.

### Global Filters

The [Global Filters](/console-walkthrough/security/global-filters) stage has two primary purposes:

* Attaching tags when the request matches specified criteria.&#x20;
* Executing an [Action](/console-walkthrough/security/actions) depending on the tags that were attached. In some situations, admins will decide to stop ths system's processing at the Global Filter stage. For example, an admin can decide that if the traffic source is found on a hostile IP list, there is no point in analyzing it further; it should just be blocked.

### Flow Control

In this stage, [Flow Control Policies](/console-walkthrough/security/flow-control-policies) are evaluated. Flow Control allows admins to define and enforce sequences (flows) of requests submitted by traffic sources.&#x20;

Example: a web application has a login page. A legitimate user will submit a GET request to access the page, followed by a POST request with login credentials. Conversely, a threat actor waging a brute-force attack might conserve resources by submitting a series of POSTS, without any GETs. A Flow Control Policy can allow the legitimate user to access the page, while excluding the threat actor.

### Global Rate Limits

Rate limiting restricts the rate at which the system will accept requests from traffic sources. When a limit is exceeded, an action can be taken.

In this stage, rate limiting is enforced upon incoming requests, regardless of their destination URLs. The limits are defined in [Rate Limit Rules](/console-walkthrough/security/rate-limit-rules) with [Global mode](/console-walkthrough/security/rate-limit-rules#global-mode) enabled.

### Rate Limits

In this stage, path-specific rate limiting is enforced. Admins can define different parameters for the limits, depending on the request's destination URL.

Path-specific rate limiting can be configured in two places within the system:

* [Rate Limit Rules](/console-walkthrough/security/rate-limit-rules) that do not have [Global mode](/console-walkthrough/security/rate-limit-rules#global-mode) enabled.
* [Proxy Templates](/console-walkthrough/sites/proxy-templates), which allow for IP-based rate limiting to be defined for all applications based upon them.

### ACL Profiles

An [ACL Profile](/console-walkthrough/security/acl-policies) defines what will happen to a request, based on the tags that it contains. Admins can assign a variety of available actions that will be performed.

As shown in the diagram above, three outcomes are possible:

* The request triggers an [Action](/console-walkthrough/security/actions).
* The request is passed, and then subjected to content filtering.
* The request is passed, but is exempted from content filtering.&#x20;

### Content Filtering

In this stage, the applicable [Content Filter Profile](/console-walkthrough/security/content-filter/profiles) is used to evaluate the request. Each Profile defines the applicability of various [Content Filter Rules](/console-walkthrough/security/content-filter/rules).

This stage fulfills the traditional role of a WAF, which is to examine the content of a request for threat signatures and take action when a match is found.

However, Content Filtering within L11WAAP is much more powerful than this. Admins can configure Content Filter Profiles to allow or block requests if they do have specific characteristics, or if they don't.

### "Request Post-Processing" Edge Functions

When an [Edge Function](/console-walkthrough/sites/edge-functions) has a [Phase](/console-walkthrough/sites/edge-functions#phase) setting of `Request Post Processing`, L11WAAP will execute it as the final step in its processing, before sending the request to the backend.

### Customer Backend

When a request has passed all of the system's processing, it is forwarded to the backend. The backend's response is then obtained, and returned to the client. L11WAAP's interaction with the backend is configured in [Proxy Templates](/console-walkthrough/sites/proxy-templates) and [Backend Services](/console-walkthrough/sites/backend-services).

{% hint style="info" %}
After the request is received from the backend, additional Edge Functions can be run: those with Phase settings of `Response Pre Processing` and `Response Post Processing`.
{% endhint %}

### Actions

Various stages of processing can result in an [Action](/console-walkthrough/security/actions) being executed. Often, this is a blocking action, but [other actions are possible](/console-walkthrough/security/actions#type) as well, including the acceptance of the request and bypassing the remainder of the filtering process.

### Logging

L11WAAP stores all requests and their details, and makes them accessible in the [Events Log](/console-walkthrough/analytics/events-log).

### Analytics and Dashboards

The [Dashboard](/console-walkthrough/analytics/dashboard) and [Events Log](/console-walkthrough/analytics/events-log) provide customizable displays of traffic and events.

### Dynamic Rules and Quarantines

L11WAAP periodically reviews the most recent tranche of incoming requests and evaluates them using [Dynamic Rules](/console-walkthrough/security/dynamic-rules). Unlike the other stages of analysis described above, this is done after the requests have been processed, and the resulting responses have been returned to the user.

Dynamic Rules are not meant to pass or block specific requests. Instead, they are used to analyze the overall behavior of traffic sources, as shown in the requests they have recently submitted.&#x20;

When a traffic source violates a Dynamic Rule, the traffic source is quarantined. Until the quarantine expires, two things occur:

* The traffic source is added to the [Quarantine](/console-walkthrough/security/quarantined) list, where admins can monitor it.
* The traffic source can also be banned, which means that future requests will be blocked. (As shown in the diagram above, this is done by adding the traffic source to an internal system-maintained Global Filter, automatically.)&#x20;


# Traffic Reporting and Analytics

How Link11 WAAP reports on the requests it receives

## Metrics

The Link11 WAAP [Dashboard](/console-walkthrough/analytics/dashboard) and [Events Log](/console-walkthrough/analytics/events-log) provide intuitive yet powerful ways of viewing your traffic.

Data is reported in terms of several statistics:&#x20;

| Statistic      | Comment                                                                                                                                                                                                   |
| -------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Hits**       | Total incoming requests                                                                                                                                                                                   |
| **Humans**     | Requests originating from humans.                                                                                                                                                                         |
| **Bots**       | Requests originating from traffic sources not (yet) verified to be human. Most of the requestors will be bots, but some will not be. More on this below.                                                  |
| **Passed**     | Requests accepted by L11WAAP and passed upstream to the origin (i.e., the web server, API endpoint, etc.).                                                                                                |
| **Blocked**    | Requests deemed to be hostile, and blocked.                                                                                                                                                               |
| **Challenges** | Requests that were challenged. The [challenge process](/how-link11-waap-works/traffic-reporting-and-analytics#the-challenge-process) is an important part of L11WAAP's traffic processing, as seen below. |

The Dashboard provides a variety of ways to view your traffic. Some of them include all of the above metrics in the same view, while others include a subset.

<figure><img src="/files/XqEMyhtKXKjXtqfMmuE6" alt=""><figcaption><p>This graph shows Hits, Blocked, Passed, and Bots</p></figcaption></figure>

<figure><img src="/files/GBKuNQZA2g3HfK0og1OS" alt=""><figcaption><p>The Countries view shows all the metrics</p></figcaption></figure>

## The Challenge Process

Link11 WAAP includes a multi-layered mechanism for distinguishing between human users and bots.

In the interface, this mechanism is summarized as "challenges." Requests from non-authenticated users will be challenged, i.e., they will undergo a process through which L11WAAP ascertains if the traffic source can be verified as a human user or not.&#x20;

When a traffic source successfully passes the challenge, it will not be challenged again for the remainder of the session. For legitimate users, this entire process happens quickly (in a few milliseconds), and is **invisible** to the user. Users will perceive no impediment or latency in their access to the requested resources.

For more details on this mechanism, see [Hostile bot detection](/reference-information/hostile-bot-detection-lwcsi).

{% hint style="info" %}
As noted above, this is the "typical" process that occurs in normal use. There are a variety of situations in which it might not be followed. For example, sometimes L11WAAP is configured to allowlist certain IP addresses, and not to challenge them.&#x20;

The discussion below will be based on the typical process described above.
{% endhint %}

## How Requests Are Reflected in L11WAAP's Statistics

The process described above will result in the following statistics being incremented.

For each challenge that was not passed:

* **Hits**
* **Challenge**
* **Bots**

If the challenge was passed:

* **Hits**&#x20;
* **Challenge**
* **Bots** (see explanation below)
* **Hits** (incremented a second time for the post-challenge resubmission of the request)
* **Passed**
* **Humans**

## Counting Bots

{% hint style="info" %}
**Within L11WAAP, a request that does not have authenticating cookies is counted as a bot.**
{% endhint %}

As a result, the Bot count can sometimes be incremented even when the visitors are humans. Examples:

* When a human user visits an L11WAAP-protected site for the first time, **the first request does not yet have the authenticating cookies**.&#x20;
* Static files (images, etc.) are often exempted from challenges for performance reasons. Direct requests for those URLs from a new visitor will not have cookies.
* Sometimes, trusted IPs are whitelisted and exempted from challenges. They never receive authenticating cookies.

Therefore, although *most* of the Bot count represents non-human requests to your web application, the Bot metric is not an *exact* count of this.&#x20;

### Relationships of Traffic Metrics

When working with L11WAAP's traffic statistics, the following relationships can be helpful.

*Hits = Passed + Blocked + Challenges*

*Hits = Humans + Bots*

## Active Challenges versus Passive Challenges

The process described on this page is the **active** challenge process. Out of the box, this is the challenge process that Link11 WAAP uses.

{% hint style="info" %}
**We recommend that whenever possible, customers also enable&#x20;*****passive*****&#x20;challenges.**&#x20;
{% endhint %}

Passive challenges still include[ ](/reference-information/hostile-bot-detection-lwcsi/environmental-detection-and-browser-verification)[Environmental detection and browser verification](/reference-information/hostile-bot-detection-lwcsi/environmental-detection-and-browser-verification), while adding three additional benefits:

* **They enable** [**biometric behavioral verification**](/reference-information/hostile-bot-detection-lwcsi/biometric-behavioral-verification): a much more powerful means of identifying automated traffic, and an important part of L11WAAP's behavioral analysis.
* **In some situations, active challenges can interfere with certain metrics** such as those provided by Google Analytics. (The initial referrer information is lost.) If this is a problem, active challenges can be disabled. In this situation, passive challenges can provide effective bot protection instead.&#x20;
* **When caching is being done by a CDN**, active challenges will not occur for pages being served from the cache. Passive challenges are necessary for L11WAAP to perform bot detection in this situation.

{% hint style="info" %}
**If possible, we recommend that customers use both active and passive challenges.**
{% endhint %}

To learn more about passive challenges, go here: [Enabling passive challenges. ](/using-the-product/best-practices/enabling-passive-challenges)


# Policy Mapping and Traffic Routing

<figure><img src="/files/uiNsn3RqCbtNQUDLvZnM" alt=""><figcaption></figcaption></figure>

## Overview

When L11WAAP processes incoming requests (as described in the discussion of the [traffic filtering process](/how-link11-waap-works/traffic-filtering-process)), the system must perform:

* **Policy mapping**: deciding which security rulesets are applicable to the request.
* **Traffic routing**: If the request successfully passes through the filtering process, the system must decide how and where to route it to the protected backend.

As shown in the diagram above, a fundamental component within L11WAAP is the [Server Group](/console-walkthrough/sites/server-groups). Generally, admins will configure a Server Group to represent a domain. Each Server Group specifies:

* A [Security Policy](/console-walkthrough/security/security-policies), used for policy mapping.
* The [Proxy Template](/console-walkthrough/sites/proxy-templates) that the Server Group is based upon.&#x20;
* The domain's [SSL Certificate](/console-walkthrough/sites/ssl/certificates).

## Policy mapping

During the traffic filtering process, some stages of processing (for example, [Global Filtering](/console-walkthrough/security/global-filters)) are universal; the same rulesets are enforced upon all requests.&#x20;

However, other stages of processing will vary. Admins can specify different rulesets for enforcement, depending on the request's destination URL. For these stages, policy mapping is necessary.

When a request is received, it is first matched with the appropriate Server Group. As shown above, every Server Group includes a [Security Policy](/console-walkthrough/security/security-policies), which is the foundation for policy mapping.&#x20;

Each Security Policy includes a list of paths (which are usually expressions, although individual URLs can be specified too). It associates each path with several rulesets:

* [Content Filter Profile](/console-walkthrough/security/content-filter/profiles) (which defines the threat signatures, content requirements, and other restrictions to enforce upon the request according to its content)
* [Rate Limit Rule(s)](/console-walkthrough/security/rate-limit-rules) (which restrict the rates at which traffic sources can submit requests)
* [ACL Profile](/console-walkthrough/security/acl-policies) (which define the disposition of requests, depending on the [tags](/how-link11-waap-works/tagging) that it received during processing)

The request's destination URL is evaluated against the list of paths, to find the best match. The rulesets associated with that path are the ones used to process the request. For more information, see the explanation of [Security Policy path mapping](/console-walkthrough/security/security-policies#path-mapping).

## Traffic routing

When a request has successfully passed through traffic filtering, L11WAAP forwards it to the customer's backend, accepts the backend's response, and returns the response to the client.

To do this, the system must know how to route requests to the backend. This is configured in [Security Policies](/console-walkthrough/security/security-policies).

Each Security Policy includes a list of paths (which are usually expressions, although individual URLs can be specified too). Each path is associated with, among other things, a [Backend Service](/console-walkthrough/sites/backend-services).&#x20;

When a request is processed, its destination URL is evaluated against the list of paths, to find the best match. The Backend Service associated with that path is the one to which L11WAAP will send the request, and then receive the response, and so on.


# Tagging

## Overview

Link11 WAAP uses an intuitive tag-based system for evaluating and processing traffic.

As an incoming request is analyzed and processed, internal tags are generated and attached to it:

* [System tags](#system-tags) are generated automatically by L11WAAP.
* Some system tags are always attached to the request. Other tags will vary, depending on the policies and security rulesets that were applied, or the disposition of the request.&#x20;
* Admins can define additional [user tags](#user-tags) for specific circumstances.
* During processing, tags can be used to make decisions about how the request is handled. For example, an [ACL Profile](/console-walkthrough/security/acl-policies) might block all requests that contain a specific tag.&#x20;
* Tags will also be attached to reflect decisions that were made. For example, a request that was blocked because it violated a [Rate Limit Rule](/console-walkthrough/security/rate-limit-rules) will be assigned a tag containing that Rate Limit Rule's name.&#x20;
* Once processing is complete, all of the request's tags are included in the traffic analytics and logs. They can also be accessed by [Edge Functions](/console-walkthrough/sites/edge-functions#accessing-tag-data).

{% hint style="info" %}
When using tags to make decisions during the [traffic filtering process](/how-link11-waap-works/traffic-filtering-process), only tags that were generated before the relevant step are available. For example, `sent-to-origin` and `upstream-status:xxx` are only available for use in [Dynamic Rules](/console-walkthrough/security/dynamic-rules#name), because they are not attached until after L11WAAP has passed the request to the customer origin.
{% endhint %}

## Tag categories

As mentioned above, there are two types of tags:

* **System tags** are created automatically by L11WAAP.&#x20;
* **User tags** are defined by admins.

## System tags

System tags are attached to the request at different stages of traffic processing. In the UI, they are displayed in blue, as in this Security Policy example:

<figure><img src="/files/9jQynWUnLTFnMSJJZkJi" alt=""><figcaption><p>The dropdown list is for administering user tags, described further below.</p></figcaption></figure>

### Attached during initialization

One of the earliest stages of the [traffic filtering process](/how-link11-waap-works/traffic-filtering-process) is the Initialization stage. Here, L11WAAP attaches a variety of tags to the request, based on its characteristics.&#x20;

Every request receives certain tags, including `all` and several tags according to its source (the IP address, geolocation, etc.).&#x20;

#### Examples

* `all`
* `geo-country:france`
* `geo-city:paris`&#x20;
* `geo-region:idf`&#x20;
* `geo-subregion:75`&#x20;
* `geo-continent-code:eu`&#x20;
* `geo-asn:12322`&#x20;
* `geo-continent-name:europe`
* `ip:82-64-131-193`&#x20;

### Attached during processing

As L11WAAP processes a request, it will attach system tags to reflect what happened to the request during processing.&#x20;

Some types of system tags will always be attached (assuming that the request makes it far enough into the processing sequence). For example, every request receives tags that reflect the [Security Policy](/console-walkthrough/security/security-policies) that it matched.

Other system tags will depend on the disposition of the request. For example, requests which violate a security ruleset (such as a Rate Limit Rule) or fulfill a condition (such as being the last request in a Flow Control Policy sequence) will receive tags with descriptive names.&#x20;

{% hint style="info" %}
Some system tags have their names generated during processing. When tag names are generated from underlying values (IP addresses, security rule names, etc.), hyphens will replace spaces and special characters.
{% endhint %}

System tags that can potentially be attached are shown at the appropriate places in the UI (generally, in the [Editor page](/how-link11-waap-works/ui-overview-and-common-elements#editor-pages) for a security ruleset or setting).

#### Examples:

#### Generic

* `bot` or `human` (`bot` is assigned to all requests unless the traffic source passes a [bot challenge](/reference-information/hostile-bot-detection-lwcsi), in which case its requests receive `human`)
* `sent-to-origin` L11WAAP passed the request and sent it to the customer origin&#x20;
* `upstream-status:xxx` The response status code from the customer origin, if any

#### Security rulesets

(Note: below, `xxx`is a placeholder for the name of the entity that was used.)

* `aclname:xxx`&#x20;
* `securitypolicy-entry:xxx`
* `securitypolicy:xxx`
* `contentfilterid:xxx`
* `contentfiltername:xxx`&#x20;

#### Triggered by mechanisms, e.g. Content Filters

* `cf-rule-id:xxx`
* `cf-rule-category:xxx`
* `cf-rule-subcategory:xxx`
* `cf-rule-risk:xxx`&#x20;

#### Libinjection tags

If a request matches a libinjection check during Content Filtering, the following tags will be added:

* `cf-rule-id:libinjection-sqli` or `-xss` (per case)
* `cf-rule-risk:libinjection`
* `cf-rule-category:libinjection`
* `cf-rule-subcategory:libinjection-sqli` or `-xss` (per case)

{% hint style="info" %}
While processing a request, there is other information that might get attached to a request. For example, when a Global Filter matches a request and its Action is set to "Monitor", this will be shown in the Events Log with a Monitor reason named `Global filter:[name of the Global Filter]`. These are not tags, since they cannot be used in ACL Policies and so on.
{% endhint %}

{% hint style="info" %}
Sometimes a request will get two separate tags that seem to be redundant. For example:

* `securitypolicy:default-security-policy`
* `securitypolicy-entry:default`

When a Security Policy is mapped to a request, a tag is generated for the Policy itself, and for the path-map entry within that Policy that was used. If the names are similar (which is true for default values, as in the example), then the tags can appear to be redundant.
{% endhint %}

## User tags

User tags are defined and configured by admins, typically in a **Tags** field in a ruleset [Editor page](/how-link11-waap-works/ui-overview-and-common-elements#editor-pages).

**Admin-defined tags do not replace the system tags.** Rather, when a request triggers a security ruleset, all of the specified tags (system and user) are attached to it.

### Administration

Admin-defined Tags are created and selected via the **Tags** dropdown list. Initially, it appears as in this Security Policy example:

<figure><img src="/files/9jQynWUnLTFnMSJJZkJi" alt=""><figcaption></figcaption></figure>

When expanded, the **Tags** list looks like this:

<figure><img src="/files/oRI9FLitxytDMkBcbvbp" alt=""><figcaption></figcaption></figure>

### Adding user tags

To add an existing user tag, find it in the list (or start typing its name into the Search field), and select its checkbox.

To define a new user tag, type its name into the Search field and hit Enter. The tag will be created, and will be automatically selected for use.

{% hint style="info" %}
**Unlike system tags, admin-defined tags do not need to be unique.** Therefore, admins can use them to combine different categories of requests for later processing. For example, there might be several different [Global Filters](/console-walkthrough/security/global-filters), each of which defines a category of requests to be allowlisted. An admin might specify the same tag (e.g., `trusted`) for each one, and then have that tag configured in an [ACL Profile](/console-walkthrough/security/acl-policies) to be exempted from content filtering.

Note that the **Tags** field will accept more than one tag, separated by spaces. This provides even more flexibility, such as the ability to create a hierarchy of tag categories.
{% endhint %}

### Removing user tags

<figure><img src="/files/4STtRgcapoPdmwvaSUfM" alt=""><figcaption></figcaption></figure>

When editing a security entity, hovering the cursor over the **Tags** control will display an **X** at the end of the control. Clicking on this will remove all tags from the entity.

As shown above, hovering over a tag will also show an **x** on that tag. Click on it to remove only this specific tag from the entity.

When a tag is removed from an entity, and no other entity uses this tag, it will also be removed from the list of available tags displayed within the **Tags** list.&#x20;

If it is needed again in the future, it can be restored by defining it again as a new tag (i.e., by entering it into the Search field and selecting Enter).

### Displaying tag usage

Sometimes, admins will wish to see a list of all uses of a specific tag. Examples:

* When examining a request in the Events Log, an admin might want to verify the source of a particular tag.&#x20;
* When editing a security configuration, it can be useful to see which other configurations generate or rely on a particular tag.
* An admin might also want to see all requests in the Events Log which had a specific tag attached.

For this purpose, L11WAAP provides the **Tag Finder** feature.&#x20;

## Tag Finder

The Tag Finder lists all current usages of a given tag. It works for both system tags and user tags.

To open the Tag Finder in the UI, simply click the tag. Here's an example (a tag named `static-content`) from a Global Filter:

<figure><img src="/files/4STtRgcapoPdmwvaSUfM" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
The Tag Finder is available when editing various types of security entities, and also from the Events Log.
{% endhint %}

When a tag is clicked, the Tag Finder panel will appear with a list of all the entities that use or can generate that tag:

<figure><img src="/files/K7yT6nOBGWvoTFTGfIfL" alt=""><figcaption></figcaption></figure>

In this example, along with the Global Filter that is currently being edited, the tag is also used in two Rate Limit Rules.

As shown above, hovering the cursor over an entry will display a button that will open the relevant security entity in a "Viewer" (read-only) window, where its attributes are displayed.

At the bottom, there is also a button to open the Events Log, pre-populated with a filter to display all requests that have this tag attached. (This button does not appear if the Events Log is already open.)

## Tag evaluation

At various stages of filtering, a request's tags can trigger events. For example, a [Global Filter Rule list](/console-walkthrough/security/global-filters#rule-list) can be based on tags; if a request's tags match the defined criteria, the Filter's Action will occur. Similarly, [ACL Profiles](/console-walkthrough/security/acl-policies) include [lists](/console-walkthrough/security/acl-policies#acl-lists) of tags.

In these situations, tags are evaluated according to exact matches. For a match to occur, the tag must  be the exact same as the criteria.

For this reason, Content Filter Rules include a hierarchy of tags, from rule-specific tags (useful for allowlisting specific signatures) to broader categories (useful for ACLs).

In other situations, admins should consider how tags are evaluated, to ensure that the system produces the expected behavior. This is especially important for tags that are structured as *\<tag-name>*`:`*\<value>*, because the system will only match the full specification.

For example, a request that contains an uploaded file (*myimage.jpg*) will, if the file isn't inspected, receive the tag of `file-skipped:myimage-jpg`. An admin might try to block all file-upload requests by creating a Global Filter with a Rule matching `file-skipped` , but this will not work. A Rule that contains only the first part of a tag will never match any requests.


# UI Overview and Common Elements

Features and conventions found throughout the user interface

The Link11 WAAP UI has several main parts:

* In the left-hand sidebar, there is the [console menu](#console-menu). By default, it is collapsed; it will slide out when clicked on, or the "**>**" button is selected.
* The right-hand part of the window varies, depending on what the user has selected. If [traffic analytics](/console-walkthrough/analytics) are not currently displayed, typically this will be a [List page](#list-page-administration) or an [Editor page](#editor-pages).
* Most pages have common UI elements, described below.
* Most pages have a section for [versioning](/console-walkthrough/system/version-control).&#x20;

These parts are described below, along with a discussion of how L11WAAP is configured and administered through the UI, and some common UI elements that are found throughout the interface.

## Console Menu

This consists of the following sections:

* Analytics
* Security
* Sites
* System

The first section contains L11WAAP's reporting capabilities. The others are for configuring L11WAAP.&#x20;

## Configuration and Administration

The configuration sections use a common structure for administration, with two types of pages:

* **List page**: Displays all the entries for that configuration type.
* **Editor page**: Provides the ability to edit a specific entry.

### List page administration

<figure><img src="/files/92tWVQJqGPmHyJY1wy0q" alt=""><figcaption><p>An example List page</p></figcaption></figure>

Most L11WAAP settings are collections of individual entries. The List page allows admins to manage these collections.

#### Viewing entries&#x20;

When a configuration type is selected in the sidebar menu (e.g., [Global Filters](/console-walkthrough/security/global-filters), shown above), its List page is shown. By default, it shows all the current entries for that configuration type.

The display can be filtered by selecting the funnel icon on the upper right. The list can be downloaded by selecting the download button next to the funnel.

#### Adding an entry

To add a new entry, select the "**+ New**" button at the top right of the list.

After adding an entry, [publish the changes](/console-walkthrough/system/publish-changes).

#### Deleting an entry

Deleting an entry can be done from the list of entries, or from the entry's Editor page.

* From the list, hover the cursor over the entry, then select the trash icon that appears at the end of the entry.&#x20;
* From the Editor page, select the "**Delete**" button at the top.

You will be asked to confirm the deletion.

After deleting an entry, [publish the changes](/console-walkthrough/system/publish-changes).

#### Editing an entry

Hovering the cursor over an entry in the list will reveal an "edit" icon at the right end of the entry. Select this to open that entry in the appropriate Editor page.

### Editor pages

<figure><img src="/files/tctckVa4fvQ6XXnvFx2P" alt=""><figcaption><p>An example Editor page, for Global Filters</p></figcaption></figure>

Editor pages allow admins to manage individual entries within a collection of configuration settings.

#### Navigation

Selecting the "**<-"** button on the upper left will navigate back to the [List page](#list-page-administration).

#### Selecting the entry being displayed

Within an Editor page, the entry being displayed can be changed by selecting the pulldown list at the upper left. (The name shown for the currently-displayed entry is part of the pulldown list.)

#### Modifying an entry

After editing an entry, be sure to save your changes with the **"Save"** button at the top of the Editor page, and then [publish the changes](/console-walkthrough/system/publish-changes).

{% hint style="info" %}
Note that if you make configuration changes, but do not select the **"Save"** button before navigating to a different page, your changes will not be retained, and you will not be prompted or asked to confirm.
{% endhint %}

#### Duplicating an entry

To clone the entry being displayed, select the "**Duplicate**" button on the upper right.

#### Downloading an entry

To download the information in the entry being displayed, select the "**Download**" button on the upper right.

#### Deleting an entry

To delete the entry being displayed, select the "**Delete**" button on the upper right. As mentioned above, entries can also be deleted from the appropriate List page.

### Versions and Branches

L11WAAP maintains versions for most of its configuration data. Admins can roll back or forward to a different version at any time.

#### Versioning

Within the UI, most pages contain a Version History section at the bottom.&#x20;

This section displays previous versions of configurations, and allows you to revert/restore the system to any saved configuration. By default, it is collapsed:

<figure><img src="/files/0Jex039P0KFdWp2zkk9r" alt=""><figcaption></figcaption></figure>

Expanding it reveals its contents:

<figure><img src="/files/RnPWP3c1u1GaGXiN9Iui" alt=""><figcaption></figcaption></figure>

To select a different version, hover the cursor over the end of the desired configuration's entry. A button will appear with an icon representing the "restore" operation.

Select this button. Once the process is complete, [publish](/console-walkthrough/system/publish-changes).&#x20;

## List and Table Filters

Throughout the interface, there are various lists and tables. Most of them have filter fields: text boxes at the top of each column, which will accept expressions to filter the displayed entries.

Here's an example of the Global Filters list, with `crawler` entered into the filter for the *Name* column:

<figure><img src="/files/OOr87gARbDQ3sFEgN5qk" alt=""><figcaption></figcaption></figure>

As shown here, entering an expression will filter the results to display only matching entries, if any. Multiple filter fields can be used simultaneously; they will be combined with a logical AND.

{% hint style="info" %}
The filter fields support regex.
{% endhint %}

## Tag selector

Many settings include [tags](/how-link11-waap-works/tagging), as in this Security Policy example:

<figure><img src="/files/9jQynWUnLTFnMSJJZkJi" alt=""><figcaption></figcaption></figure>

The dropdown list allows admins to add one or more [user tags](/how-link11-waap-works/tagging#user-tags). Below the list, the [system tags](/how-link11-waap-works/tagging#system-tags) are displayed.

Administration and management of tags is described in detail here: [Tagging](/how-link11-waap-works/tagging).&#x20;

## Include and Exclude Filter Lists

The Editor pages for some types of security rules ([Dynamic Rules](/console-walkthrough/security/dynamic-rules), [Flow Control Policies](/console-walkthrough/security/flow-control-policies), and [Rate Limit Rules](/console-walkthrough/security/rate-limit-rules)) contain two lists labeled *Include* and *Exclude*.&#x20;

By default, a security rule will be enforced for all incoming requests within its scope. The *Include* and *Exclude* lists can be used to limit the scope of this enforcement.

Each list can contain one or more tags:

* If the *Exclude* list contains any tags, a request is exempted from enforcement if it matches the list.
* If the *Include* list contains any tags, a request is exempted from enforcement unless it matches the list.

### What it means to "match" the list

Rate Limit Rules and Dynamic Rules have **or**/**and** selectors for their *Include* and *Exclude* tag lists. These selectors become visible when more than one tag has been added to a list.

* When a list is set to `or`, a request will match if it contains *any* of the tags in the list.
* When a list is set to `and`, a request will match only if it contains *all* of the tags in the list.

Note that for any security rule, its two lists are separate, and can be set to different modes.&#x20;

Flow Control Policy tag lists do not have or/and selectors. These lists operate in `or` mode; therefore,  a request will match a list if it contains any of the tags in the list.

### **Important details about the Include/Exclude process**

* The *Exclude* list is evaluated before the *Include* list, and takes priority. See example below.
* The *Include* list is not exhaustive. In other words, for the security rule to be enforced, all of the request's tags do not need to be listed in *Include*. However, if the *Include* list contains any tags, the request must have at least one (in OR mode) or all (in AND mode) of them, for it to be subjected to enforcement.
* An empty *Include* list is treated as if it contains `all`. This is a system tag that all requests have. In other words, by default, the security rule will be enforced on every request (unless the request matches the *Exclude* list).

{% hint style="info" %}
As mentioned above, *Exclude* takes priority over *Include*. Example: a request has been tagged with`foo`. A security rule has *Include*`foo`and *Exclude*`all`. The request will be excluded from evaluation by this rule.
{% endhint %}

To add a tag to a list, select the "**+**" button. To remove a tag, hover the cursor over it and select the "**x**" that appears on it. To remove all tags, hover the cursor over the tag list and select the "**X**" that appears at the end of the list. &#x20;

## Connections to Security Policies

[Security Policies](/console-walkthrough/security/security-policies) map security rulesets to paths within [Backend Services](/console-walkthrough/sites/backend-services). The connections can be made within the Security Policies Editor.

These 'parent-to-child' relationships can also be configured within some of the Editor pages for the 'child' entities: [Rate Limit Rules](/console-walkthrough/security/rate-limit-rules), and [Edge Functions](/console-walkthrough/sites/edge-functions).

The *Connections to Security Policies* list contains all of the paths within [Security Policies](/console-walkthrough/security/security-policies) that use the child entity, and it allows admins to link the entity to additional Security Policies. In this context, a "connection" defines the scope within which the entity will be executed/enforced (assuming the entity is otherwise configured appropriately, e.g. the Rate Limit Rule is in *Active mode*).

Connections are created by adding entries to the list, confirming them by selecting the checkbox at the end of the entry, saving the changes, then publishing.&#x20;

Admins can define individual connections, or multiple connections at once:

* When *Security Policies Name* is set to a specific Security Policy, three options are available:
  * **Match path** creates one connection to the path(s) defined in the *Path or Expression* field. See note below about multiple path definitions.
  * **Site Level** creates a single connection to all paths within the site. This option is unavailable when an existing connection to this Policy contains a value in the *Path or Expression* field.
  * **Add to all** creates a separate connection for *each* path defined in the Security Policy. This is useful for Security Policies with a large number of paths; admins can automatically create multiple connections, then edit or delete the individual entries as needed.
* When *Security Policies Name* is set to `All Security Policies`, **Site level** and **Add to all** function the same as described above, except that connections will be created for every Security Policy. Any unwanted connections can then be deleted.

{% hint style="info" %}
The *Path or Expression* field can contain multiple path definitions. The pulldown offers a list of previously-created definitions; to create a new one, enter it into the textbox. When all necessary definitions are available, select their corresponding checkboxes.
{% endhint %}

{% hint style="info" %}
When a Policy has been connected at the Site Level, it will no longer appear for additional connections in the dropdown list of Policies.
{% endhint %}

&#x20;


# Analytics

The Analytics section contains the UI for viewing traffic.&#x20;

If you have not used Link11 WAAP before, read this first: [Traffic Reporting and Analytics](/how-link11-waap-works/traffic-reporting-and-analytics).

Otherwise, the Analytics UI is documented here:

* [Dashboard](/console-walkthrough/analytics/dashboard)
* [Events Log](/console-walkthrough/analytics/events-log)
* [AI Management](/console-walkthrough/analytics/ai-management)


# Dashboard

An overview of traffic activity

<figure><img src="/files/LhMtEqjwDNvS0hcSUegP" alt=""><figcaption><p>The Dashboard page, with the "Top Metrics" section at bottom set to Countries.</p></figcaption></figure>

The Dashboard page displays all incoming traffic and the actions executed in response to the different traffic events.&#x20;

The user interface has three main sections:&#x20;

1. [Query specification](#query-specification)
2. [Timelines](#timelines)
3. [Top Metrics](#top-metrics)

Note also that the Top Metrics section includes some tools for [quickly building queries](#building-queries-while-investigating-security-events), often useful when investigating security events.

## **Query specification**

### Constructing a query

The controls at the top allow you to easily filter the display to show only the data you want. Initially, it asks you to supply a query.&#x20;

<figure><img src="/files/JLtGabHqUYRDpnRbtQjO" alt=""><figcaption></figcaption></figure>

Adding a query to the Search field and selecting the magnifying glass icon will display the results.&#x20;

If the Search field is left empty, Link11 WAAP will display all results that match the selected Server Group (if any) and the parameters in the date/time selection field.

### Server Group selection

On the upper right, there is a dropdown list of [Server Groups](/console-walkthrough/sites/server-groups) (which in most deployments, correspond to domains). Selecting one will add a filter parameter that will restrict query results to that Server Group. If no Server Group is selected, traffic data will be returned for all of them.

Server Group filtering can also be done manually, by entering a parameter and value (`server_group="$SERVER_GROUP_NAME"`) into the Search field. The dropdown list will reflect this specification.&#x20;

{% hint style="info" %}
If a Server Group is manually specified with an operator other than "equals" (e.g., `server_group~"api")`, the dropdown list will not be able to reflect this. In this situation, the UI's controls will not fully represent the query that is being run.
{% endhint %}

### Date/Time selection and Live Data mode

Selecting the "calendar" icon shows a control for selecting the query data.

Two modes are available: absolute time (where data are shown for a specific range of dates/times), or live data (where the most recent data are shown, and the display is regularly refreshed).

#### Absolute time mode

When selecting times, hours and minutes are required, while seconds are optional. To specify seconds, simply click in the time selection box and type them, as shown in the "**To**" field below. When seconds are not specified, the beginning of the specified minute will be used.

<figure><img src="/files/PveGQk1rhSWKvxRGVHdY" alt=""><figcaption></figcaption></figure>

#### Live data mode

When this toggle is enabled, several buttons appear, providing a choice of refresh intervals. Then, selecting **Apply With Live Data** will set the display to always show the most recent tranche of data (as specified by the *Relative Time Range* selection), refreshed periodically (according to the *Refresh Every* interval selection).

### Filter syntax

Queries consist of field names, operators, and arguments. Multiple filters can be combined (separating them with commas), and are evaluated with a logical AND. Some examples:

* Show blocked requests: `blocked=true`
* Show requests from the United States: `country="United States"`
* Show requests with status codes in the 200s: `status>199,status<=299`
* Show requests containing the string `contentfilter` in their reason for being blocked: `reason~"contentfilter"`

{% hint style="info" %}
For a full explanation and more examples, see the documentation of [Query Filter Syntax](/reference-information/query-filter-syntax-and-best-practices).
{% endhint %}

### Copying a query

If you have constructed a query that you want to use for another purpose, select the "duplicate" icon next to the magnifying glass icon. A text string for the query will be copied to your clipboard.

### Transferring a query to the Events Log

To transfer the current query to the [Events Log](/console-walkthrough/analytics/events-log), simply select the "**Open Events Log**" button on the upper right. (Note that in order for the query to transfer, it must have been run already.)

### Additional options

<figure><img src="/files/RfQ8s6zqJD7rRWNC7AQZ" alt=""><figcaption></figcaption></figure>

The kebab (vertical three-dot) menu on the far right offers three options:

* **Filter Information**: Links to a page in the user documentation describing syntax and best practices for constructing queries.
* **Query History**: Shows the history of your queries in the current page (Dashboard or Events Log; separate histories are maintained for each). Each entry provides a **Restore** button, to restore that query to the Search field. Selecting the **Search** button will then re-run that query.
* **Apply Previous Query**: Restores the previous query to the Search field. Selecting the **Search** button will then re-run that query.

## Working with the Dashboard charts

### Data categories

Link11 WAAP reports data according to several categories, summarized here:

| **Hits**       | Total amount of requests                                                                                                                                                             |
| -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Passed**     | Requests that reached the upstream server.                                                                                                                                           |
| **Blocked**    | Requests that were blocked by L11WAAP.                                                                                                                                               |
| **Humans**     | Requests that passed L11WAAP's human vs. bot challenge process.                                                                                                                      |
| **Bots**       | Requests with originators that were not (yet) verified as humans. For a full explanation, see [Counting Bots](/how-link11-waap-works/traffic-reporting-and-analytics#counting-bots). |
| **Challenges** | Requests that were served with bot detection challenges.                                                                                                                             |

For a full explanation of these categories and their relationships to each other, see this page: [Traffic Reporting and Analytics](/how-link11-waap-works/traffic-reporting-and-analytics).

### Time scale&#x20;

The charts display all data for the query's time period.

{% hint style="info" %}
Normally, the time period is shown in the date/time selection control. However, if the query string shown in the Search field contains a date/time period, the one in the Search field will override the selection control.
{% endhint %}

To adjust the time period shown in the charts, modify the query in the Search field or date/time control.&#x20;

{% hint style="info" %}
If you merely wish to inspect a smaller portion of the current period, you can drag the cursor over the corresponding portion of the chart. The query will be adjusted automatically to focus only on this time period.
{% endhint %}

### Showing data for points in time

Hovering the cursor over a chart will display the values at that point on the graph.

<figure><img src="/files/HXoZ4Dy5gWBHIFRyZ9sT" alt=""><figcaption></figcaption></figure>

### Quickly filtering data categories

You can filter the items being shown in a chart by selecting the data categories in the legend to enable/disable them.

<figure><img src="/files/j16pOwgLKgfdrj2fKFga" alt=""><figcaption><p>Filtering the chart to show only Hits and Blocked requests, by disabling Passed and Bots.</p></figcaption></figure>

## **Timelines**

### **Passed vs. Blocked**

This chart shows the traffic that was processed by L11WAAP: requests which passed through to the upstream servers, and requests that were blocked. Hits are distributed by time and sorted into three different categories: Humans, Challenges, and Blocked.&#x20;

### **Response Status**

Counts the number of status codes in a certain time period.&#x20;

HTTP Status response codes are divided into five categories:

* **1xx** - Informational Response&#x20;
* **2xx** - Request Successful&#x20;
* **3xx** - Request for Redirection&#x20;
* **4xx** - Client Error
* **5xx** - Server Error&#x20;

For a detailed list of response codes, [go here](/reference-information/response-codes).&#x20;

### Unique Sessions and IPs

How many unique sessions and IP addresses were active at any given time.

### **Total Bandwidth (Bytes)**

Total bandwidth for all proxies.

### **Requests Count**

The number of network requests during a certain period of time.&#x20;

### **Bandwidth (Bytes)**

Bandwidth for the current proxy.

### Latency

The time (in milliseconds) consumed by L11WAAP's processing.&#x20;

## Top Metrics

The bottom part of the Dashboard displays traffic statistics according to a variety of "top" or "most frequent" metrics: the Top Applications, Top Countries, Top Targets, etc.

Each metric contains a list of entries. Where appropriate, entries representing blocked requests are shown in red.

In most of these lists, right-clicking on the entries will display a menu with options to copy the corresponding value to the clipboard, automatically rebuild the current query to show only (or exclude) that value, or show the Events Log with requests matching (or excluding) that value.

Most of the Top Metrics lists display their results according to [the data categories described above](#data-categories) (i.e., Hits, Humans, Bots, etc.)

Some of the lists include values for Down (the amount of traffic that originated from the upstream server towards the clients) and Up (the amount of traffic that originated from the client towards the upstream server).

{% hint style="info" %}
In the Top Metrics lists, rows are marked as red when they have a **blockage rate above 30%.** The blockage rate is the ratio of requests blocked by the system to the number of total network requests: `blockage rate = (challenged requests + requests blocked by Link11 WAAP + requests blocked by the origin) / (total requests)`
{% endhint %}

{% hint style="info" %}
In the Top Metrics lists, **Hits greater than 999** are specified in **short scale notation**. They contain a coefficient and a suffix (`K`, `M`, `B`, or `T`) with zero or one decimals of precision. Specifically:

* Values from 0-999 are given in full.
* Values from 1,000-999,999 are "1.0K" to "999K".
* Values from 1,000,000-999,999,999 are "1.0M" to "999M".
* Values from 1,000,000,000-999,999,999,999 are "1.0B" to "999B".
* Values from 1,000,000,000,000-999,999,999,999,999 are "1.0T" to "999T".

The full value can be displayed by hovering the cursor over the number.

Note that in the Hits column, these short-scale values are quantities (the amount of hits), not sizes (i.e., they do not represent bytes). They should not be confused with columns such as *Down* and *Up,* which use similar suffixes when describing bandwidth in bytes.
{% endhint %}

### **Appli**cations

Shows all protected sites for the current L11WAAP deployment.&#x20;

### **Countries**&#x20;

Shows incoming traffic sorted by country. Each country's flag is shown by its name.&#x20;

### **Sources**

Shows traffic data according to IP address. The ASN (autonomous system number) is included where appropriate.

### **Sessions**

Shows the nature of user sessions. Sessions that pass L11WAAP's bot mitigation challenge are identified as originating from humans, and are listed here according to a user cookie containing RBZ in the cookie ID. Sessions that did not pass the challenge are shown with `-` for the ID.

### **Targets**

Shows the URLs that were accessed the most frequently.&#x20;

### **Blocked & Monitored**

Shows the most common reasons why requests are being blocked or monitored during the time period.&#x20;

### **Referers**

Shows the referers that were extracted from the request headers.

### **Browsers**

Shows all the user agents that initiated requests for the application(s).

### **Organizations**

Shows all of the ASNs (Autonomous System Numbers) from which requests were sent. The ASN can identify individual entities, or larger networks: for example, a telecom provider or a cloud provider.

### **Total Time**

Shows a list of URIs, with the total latency for each.&#x20;

### **WAAP Time**

Shows a list of URIs, with the latency for each from L11WAAP.&#x20;

### **Origin Time**

Shows a list of URIs, with the latency for each due to the upstream server.&#x20;

## Building queries while investigating security events

When security incidents occur, the investigator will frequently submit a succession of queries, often starting from a broad scope and then drilling down into a narrower focus while trying to discern the underlying cause.

Link11 WAAP provides several tools in the Top Metrics section to make this process easier. The entries in each list can be right-clicked to display a popup menu, as shown below.

<figure><img src="/files/qePyzi0LrFZwbIvwqZmH" alt=""><figcaption></figcaption></figure>

In this example, the admin is observing the *Organizations* list in the Top Metrics section, and has right-clicked on the top entry.

The options in the menu will do the following.

**Copy value to clipboard**: Copies the value of whatever was right-clicked to the clipboard. In the example above, this string would be copied: `ASN4766 Korea Telecom`.

**Show matching**: Adds a filter parameter (for whatever was right-clicked) to the existing query in the Search field at the top of the page. Submitting the modified query will restrict the results to requests that match the field and value that was selected. In the example above, the following string would be added to the query: `organization="ASN4766 Korea Telecom"`.

**Hide matching**: Adds a filter parameter (for whatever was right-clicked) to the existing query in the Search field at the top of the page. Submitting the modified query will exclude requests that match the field and value that was selected. In the example above, the following string would be added to the query: `organization!="ASN4766 Korea Telecom"`.

**Events Log (matching)**: The same as **Show matching**, except that it opens the Events Log with the modified query.

**Events Log (other)**: The same as **Hide matching**, except that it opens the Events Log with the modified query.

{% hint style="info" %}
The Events Log has [similar query-building capabilities](/console-walkthrough/analytics/events-log#building-queries-while-investigating-security-events) when displaying a request.
{% endhint %}


# Events Log

Revealing the composition and details of your traffic

<figure><img src="/files/CGDgyC1NsxyWUIuZCscx" alt=""><figcaption></figcaption></figure>

## Overview

This page provides the ability to review and analyze the most recent traffic, up to and including real time. It is a powerful tool for traffic control; if a security event occurs, this page will allow you to quickly find its root cause.&#x20;

Running a query will display a list of requests matching the specified criteria. Each request can be expanded to display additional details.&#x20;

{% hint style="info" %}
By default, expanding an entry will display all of its data. When a request contains thousands of arguments, or very large arguments, the data retrieval can negatively affect the performance of the Events Log display. \
\
If your planet commonly receives such requests, the Events Log can be configured to only retrieve the arguments when the *Arguments* tab is selected in the *Additional Details* display, which will improve performance. To enable this, [contact support](/support).
{% endhint %}

The Events Log page contains two primary sections:

* Query specification
* Query results

## Query specification

This section determines the events, if any, that will be displayed in the Query results section.

The top part of this section is identical to the [Query specification section on the Dashboard page](/console-walkthrough/analytics/dashboard#query-specification), except that it contains a button to transfer the current query criteria to the Dashboard. (Note that in order for the query to transfer, it must have been run already.)

The Events Log also provides three additional controls:&#x20;

<figure><img src="/files/JmihNuXa2qYG7DncKYrk" alt="" width="294"><figcaption></figcaption></figure>

#### **Download** button

This downloads a JSON file containing complete log data for the requests in the current query results, in this structure:&#x20;

```bash
[{$REQUEST1},{$REQUEST2},...{$REQUESTn}]
```

&#x20;      ...where each $REQUEST has this structure:

```bash
$FIELD1:$VALUE1,
$FIELD2:$VALUE2,
...
$FIELDn:$VALUEn
```

&#x20;      ...and the $FIELDs are the **Field names** described [here](/reference-information/api/api-access-to-traffic-data#field-names).&#x20;

#### **Filter** button

Selecting this button will display a row of controls at the top of the query results. Entering text into a control will quickly filter the results list, to display only those events which match the filter. For example, to only display "Passed" requests, enter `P` into the **Result** control.

<figure><img src="/files/KwGa7sbf1KTymMc13jWS" alt=""><figcaption></figcaption></figure>

#### **Number of results pulldown**

This specifies the number (200, 500, 1000, 1500, or 2000) of the results displayed.

## Query results

When a query is run, a list of matching events is shown. See screenshot at the top of this page for an example.

Clicking on an event will open a window with more information, including two expandable sections: **Additional details** and **Messages**. (The latter will only appear if there are messages in the event.)

<figure><img src="/files/1677zAuhanRsPszMa0jb" alt=""><figcaption><p>The user has expanded the "Additional details" section.</p></figcaption></figure>

Some of the data shown comes from the request itself, while some of it was added during L11WAAP's processing. Important information in the latter category includes:

* **Block reason**: if the request was blocked, the reason will be shown. In the example above, a Global Filter blocked the request. (To conserve compute resources, L11WAAP stops processing a request when a blocking action is triggered. Thus, it's possible that additional problems with the request would have been discovered if further stages of traffic filtering had been performed.)
* **Monitor reason**: if the request triggered at least one [Action](/console-walkthrough/security/actions) with a Type of "Monitor", the source(s) of this will be shown. Note that Block reasons and Monitor reasons are not mutually exclusive; a request can have both types simultaneously.
* **Tags**: the various [tags](/how-link11-waap-works/tagging) that were attached to the request during processing, shown in blue. User-defined tags are shown in the top section; system-defined tags are shown in the **Additional details** section.
* **Messages**: this section appears if the system has added any messages to the event. These can include [custom admin-defined messages injected by an Edge Function](/console-walkthrough/sites/edge-functions#adding-custom-messages-to-log-events).

{% hint style="info" %}
The UI displays the most important request data. Full details of an event can be obtained by using the [**Download**](#download-button) button or the **Copy Request as JSON** command, described below.
{% endhint %}

### Improving performance by deferring argument retrieval

By default, when the Events Log responds to a query, all arguments in the requests will be retrieved. In some environments, incoming requests can contain excessively large arguments, or a large number of arguments, either of which can delay the delivery of the results.

If this situation arises frequently, there is an internal system setting that will defer argument retrieval until a button is clicked (the **Show All Arguments** button in the **Arguments** tab). This can improve Events Log performance, and will also make it easier to find specific arguments (because argument data will be displayed in a table with search capabilities).

To enable this feature, contact [support](/support). Note that if this setting is enabled, it will no longer be possible to (successfully) run queries based on arguments, since argument data will not be available when the queries are processed.

## Building queries while investigating security events

When security incidents occur, the investigator will frequently submit a succession of queries, often starting from a broad scope and then drilling down into a narrower focus while trying to discern the underlying cause.

L11WAAP provides some tools to make this process easier. When viewing an event, right-clicking on one of its values will reveal a popup menu, as shown below.

<figure><img src="/files/e3vEzMzrExgH4cr9TEAJ" alt=""><figcaption><p>The user right-clicked on "Blocked by origin".</p></figcaption></figure>

The menu options are as follows.

**Copy Request as Curl**: Copies a [curl](https://curl.se/) command containing this request to the clipboard, so that an admin can re-submit that exact request to the system. This can be useful in various situations, e.g., to test a security setting that was modified.

**Copy Request as JSON**: Copies the request's log data to the clipboard as JSON for further analysis, including the data and tags added by L11WAAP. The log data structure is the same as described above for the [**Download button**](#download-button), except that only one request will be returned.

**Copy Value to Clipboard**: Copies whatever was right-clicked to the clipboard.&#x20;

**Show Matching**: Adds a filter parameter (for whatever was right-clicked) to the existing query in the Search field at the top of the page. Submitting the modified query will restrict the results to requests that match the field and value that was selected. In the example above, the following string would be added to the query: `result="Blocked by origin"`.

**Hide Matching**: Adds a filter parameter (for whatever was right-clicked) to the existing query in the Search field at the top of the page. Submitting the modified query will exclude requests that match the field and value that was selected. In the example above, the following string would be added to the query: `result!="Blocked by origin"`.

{% hint style="info" %}
The Dashboard has [similar query-filtering capabilities in its Top Metrics section](/console-walkthrough/analytics/dashboard#building-queries-while-investigating-security-events).
{% endhint %}

## How anomalies are handled

### Excessive request sizes

Potentially, a very large request could exceed the maximum allowable size of a log entry. This makes it impossible for the system to capture all the request's data in the log.

In this situation, the system will truncate the log entry by omitting some of the request's details, and the log entry will contain a notice of this.

Omissions will occur in this order:

1. Additional log entries (the last section in the Events Log)
2. Parameters (arguments/headers/cookies, but see note below on protected headers), in this order :
   1. Ignored parameters
   2. Examined parameters
   3. Examined parameters that triggered an Action
3. Monitor reasons
4. Block reasons that were not final
5. Content from the main block reason (e.g., a large value of a parameter), noting the omission with an ellipsis (`...`)&#x20;

{% hint style="info" %}
The following headers are protected from being omitted when parameters are examined:&#x20;

* accept
* connection
* content-length
* content-type
* host
* user-agent
* via
* x-cloud-trace-context
* x-forwarded-for
* x-forwarded-port
* x-forwarded-proto
  {% endhint %}

### Large malformed bodies

Requests with large (longer than 500 characters) malformed bodies will have their bodies truncated in the Events Log, and in the events exported via [Log Exporters](/console-walkthrough/system/log-exporters).

In the event data, the body will be preceded by this message: `The request contains a malformed body (displaying only first 500 characters):`.

Note: 500 characters is the default limit, but this can be changed if necessary. To do this, contact [Customer Support](/support).

### Malformed JSON payloads

If a POST request with `content-type`: `application/json` contains a malformed JSON payload, the system will not be able to process the payload.&#x20;

The event data (in the Events Log entry and any active Log Exporters) will contain an error message, noting that a malformed body was received. However, the system will be unable to parse the body to count the number of arguments. Thus, in the event data, the request will have a tag of `args:0`, even though strictly speaking, arguments might have been present.

Note also that the payload will not be subjected to content filtering. Thus, the disposition of the request will depend solely on whether or not it violated other security rulesets (e.g., rate limiting).


# AI Management

<figure><img src="/files/Vzr9bC21UUx8dHfytnHr" alt=""><figcaption></figcaption></figure>

## Overview

As part of its security suite, Link11 includes robust bot management, including tracking of individual types of bots.&#x20;

The AI Management Dashboard provides additional granularity for managing AI crawlers specifically.

## The AI Management Dashboard&#x20;

This Dashboard provides analytics that display AI crawler activity. It is divided into three sections, in this order (top to bottom):

* The query filters for the analytics, similar to the [Query Specification section of the main analytics Dashboard](/console-walkthrough/analytics/dashboard#query-specification).
* A graphical summary of crawler activity for the specified time range. Dragging the cursor over a portion of the chart will adjust the display to focus only on this time period.
* Activity by individual crawlers, and the disposition of their requests. The entries here also allow [filtering of analytics results](#filtering-query-results), and provide some ability to [manage crawler requests](#how-to-manage-ai-crawlers).

{% hint style="info" %}
The *Passed* and *Blocked* metrics are the number of requests Link11 passed to the origin or blocked, respectively. For these purposes, requests which made it to the origin but were blocked there are counted as "passed."
{% endhint %}

{% hint style="info" %}
At this time, it is not possible to break out statistics for Copilot and Gemini crawlers, as they are indistinguishable from the standard Bing and Google spiders. Note that in the crawler-specific analytics, some entries have a *Type* of `Search crawler`: these entries contain combined statistics for the search spiders and the AI bots.
{% endhint %}

## How to Manage AI Crawlers

Crawler activity can be managed by configuring a dedicated set of [Global Filters](/console-walkthrough/security/global-filters) that identify them.

{% hint style="info" %}
The availability of configuration options are dependent on the user's [Access Level](/console-walkthrough/system/users-management).
{% endhint %}

This configuration can be done in different ways, depending on the desired scope.

### Global management

To globally configure handling for all requests from a specific crawler, edit the appropriate Global Filter and set its *Action* parameter to the desired setting. This will then be reflected in the *Action* column in the bottom section of the Dashboard.

{% hint style="info" %}
Example: to globally block the ChatGPT crawler, edit the *AI ChatGPT* Global Filter and set its *Action* to `Global filter block`.&#x20;
{% endhint %}

{% hint style="info" %}
Note that this Action only applies to AI/search crawlers; it does not apply to visitors referred from the AI/search platforms. To manage the latter, see [How to Manage AI Referrals](#how-to-manage-ai-referrals), below.
{% endhint %}

To edit a Global Filter, the most convenient way is to find the appropriate crawler entry in the bottom section of the window. Each entry includes a three-dot menu where:

* The relevant Filter's *Action* can be directly set to `Block` or `Monitor (tag only)`.
* Or, if other Filter parameters need to be updated too, the Filter itself can be [edited](/console-walkthrough/security/global-filters#individual-parameters).

{% hint style="info" %}
The Dashboard shows which Global Filters have blocking or monitoring Actions. If a Global Filter has a different type of Action (for example, *https redirect*), its Action is displayed as `Custom`.
{% endhint %}

{% hint style="warning" %}
After changing a Global Filter's *Action*, or editing the Filter directly and saving the edits, the updates must be [published](/console-walkthrough/system/publish-changes).&#x20;
{% endhint %}

### Path-dependent management

To block or otherwise manage AI bot requests for specific parts of the system, follow this procedure:

* Open the appropriate Global Filter for editing (the one which identifies the crawler in question).
* Ensure that the Filter’s *Action* parameter is set to `monitor (tag only)`. If the *Action* or any other parameter is changed, save the changes.
* In the Filter’s *Tags* field, note the specific tag that the system will attach to all requests generated by the crawler. Or, you can define your own.
* Next, for each part of the protected system where crawler activity should be controlled, determine the [ACL Profile](/console-walkthrough/security/acl-policies) that is in effect. (ACL Profiles are assigned to paths by [Security Policies](/console-walkthrough/security/security-policies).)
* Add the crawler’s Tag to the appropriate column within each ACL Profile. (To block the requests, the *Enforce Deny* column can be used.)
* Publish the changes.

## How to Manage AI Referrals

In the Dashboard's bottom section, visitors that originate from AI/search services are reported in the *Referral Visits* column. Sometimes it is desirable to set up unique management for them.&#x20;

Referred-visitor management is **not** related to the *Action* column, because this column shows the current settings of the crawler-specific Global Filters. Thus, those Actions only apply to crawler requests.

Instead, Link11 includes specific "Referral" Global Filters that can be used for this purpose. For example, the *AI ChatGPT Referral* Filter will match every request that has its *referer* header set to `https://chatgpt.com/`.&#x20;

These Filters can be used to block, or trigger other specific handling, of these requests, by using the procedures explained [above](#how-to-manage-ai-crawlers). The only difference is that the editing is performed on the referral-specific Filters, instead of the crawler-specific Filters.

## Filtering Query Results

As noted above, the analytics provided by the Dashboard reflect the following:

* The query filters for the analytics display (top section of the window), as in the [Query Specification section of the main analytics Dashboard](/console-walkthrough/analytics/dashboard#query-specification).
* The graphical summary (middle section), which can be narrowed by dragging the cursor over the desired time period.

In the bottom section, each crawler entry includes an eye icon. This toggles the inclusion of that crawler's statistics in the main analytics display.

Each entry also has a three-dot control, which will open this contextual menu:

<figure><img src="/files/zMpXMlCw2RbE3eivT8Mf" alt=""><figcaption></figcaption></figure>

This provides the ability to:

* Edit the Global Filter for that crawler, or change the Filter's Action, as discussed [previously](#how-to-manage-ai-crawlers).
* Hide (i.e., exclude the statistics from) all other crawlers.
* Open the Events Log, filtered to display the crawler's requests, for more in-depth analysis.


# Security

The Security section of the UI provides configuration options for basic security rulesets and policies. The pages in this section document the configuration for these security settings.&#x20;

If you are not yet familiar with how Link11 WAAP filters traffic, and how the various settings below fit into this process, it is recommended that you read this overview first: [The traffic filtering process](/how-link11-waap-works/traffic-filtering-process).

* [Global Filters](/console-walkthrough/security/global-filters)
* [Flow Control Policies](/console-walkthrough/security/flow-control-policies)
* [Security Policies](/console-walkthrough/security/security-policies)
* [Rate Limit Rules](/console-walkthrough/security/rate-limit-rules)
* [ACL Profiles](/console-walkthrough/security/acl-policies)
* [Actions](/console-walkthrough/security/actions)
* [Dynamic Rules](/console-walkthrough/security/dynamic-rules)
* [Quarantined](/console-walkthrough/security/quarantined)
* Content Filter:

  * [Profiles](/console-walkthrough/security/content-filter/profiles)
  * [Rules](/console-walkthrough/security/content-filter/rules)


# Global Filters

Assigning tags and (potentially) executing an Action

<figure><img src="/files/92tWVQJqGPmHyJY1wy0q" alt=""><figcaption></figcaption></figure>

## Overview

This page allows you to administer Global Filters. These are applied to each request early in the [traffic filtering process](/how-link11-waap-works/traffic-filtering-process).&#x20;

A Global Filter has two purposes:

* It can assign one or more [tags](/how-link11-waap-works/tagging) to an incoming request. Subsequently, the tags can be used to make decisions about how the request is processed. After processing, a request's tags remain associated with it, and they are available for display in traffic analytics.
* It also contains an [Action](/console-walkthrough/security/actions), which can be executed when the Filter's conditions are met.

For each request, Link11 WAAP will evaluate all active Global Filters. The request will receive tags from all Filters which match it.

After all Filters have been evaluated, L11WAAP will execute the [highest-priority Action](/console-walkthrough/security/actions#type) found in those Filters which matched the request.&#x20;

## Two types of Global Filters

There are two types of Global Filters:

* **System-managed**, which are maintained by Link11.
* **Admin-managed**, which are maintained by customer admins.

They vary in their visibility, alterability, and sources for *Rule* lists (i.e., the criteria for determining if a Filter should be applied to the request being analyzed).

### System-managed Global Filters

These are provided and maintained by Link11. Most use external datafeeds as the sources of their *Rule* lists.&#x20;

Datafeed-based Filters are updated regularly by Link11. Admins can also trigger an immediate refresh by selecting the **Update now** button on the Editor page.&#x20;

Most system-managed Filters are visible to admins in the interface, with the ability to edit some of their parameters.&#x20;

Depending on traffic conditions, some additional Filters might exist that are not visible to admins. Each active [Dynamic Rule](/console-walkthrough/security/dynamic-rules) creates an internal Global Filter to enforce its restrictions. These are managed automatically by the system, and are mentioned here purely for informational purposes.

{% hint style="info" %}
Changing system-managed Global Filters might result in unexpected behavior. For example, the *Let's Encrypt Requests* Global Filter is necessary for customers who want to use Let's Encrypt to [generate or renew their own SSL certificates](/using-the-product/how-do-i.../generate-or-renew-my-own-ssl-certificates).
{% endhint %}

### **Admin-managed Global** Filters

These are created and managed by admins. They are fully editable within the interface.

Typically, admins will manually create and manage their *Rule* lists, although these Filters can also be based on external data sources.

## Administration

The administration of Global Filters follows the List/Editor UI conventions described [here](/how-link11-waap-works/ui-overview-and-common-elements).

{% hint style="info" %}
When a Global Filter is used as a [Trusted Source in a Proxy Template](/console-walkthrough/sites/proxy-templates#trusted-sources), it cannot be deleted until it is removed from the Trusted Sources list.
{% endhint %}

The main List page (shown above) lists all current Global Filters. The Editor page (discussed below) enables administration of individual entries.

## Components

Each Global Filter consists of:

* *Tag(s)* to assign to requests that match the *Rule* list.
* *Rule* list: The possible characteristics that a request could match (e.g., a list of IP addresses that it might originate from).
* An *Action* that, if a match occurs, will be executed after all active Global Filters have been evaluated, unless a higher-priority Action overrides it.
* General parameters for administrative purposes.

Each of these is described in depth below.

## Individual Parameters

The discussion below will focus on admin-managed Filters. For system-managed Filters, the parameters that are editable will work the same as discussed below.&#x20;

<figure><img src="/files/tctckVa4fvQ6XXnvFx2P" alt=""><figcaption><p>A Global Filter, opened in its Editor</p></figcaption></figure>

### General parameters

* *Name*. A description that will be displayed within the L11WAAP interface.
* *Active*. By default, this Global Filter will be evaluated for all incoming requests. To deactivate it, unselect this toggle.
* *Description*: Information about this Filter, for use within the interface.
* *Source*: For datafeed-based Global Filters, this contains the URL of the source. Otherwise, this field should be set to `self-managed`.

### Tags

This field contains one or more [user tags](/how-link11-waap-works/tagging#user-tags) (separated by spaces) that will be assigned to all requests that fulfill the *Rule* list. Example: `internal team-devops`

### Action

The choices for this parameter are administered in the [Actions](/console-walkthrough/security/actions) page.

The Action that is selected here will be applied globally to all requests that match the *Rule* list.

{% hint style="info" %}
If a request triggers an Action, the Action is performed after all Global Filters have been evaluated and all applicable tags have been attached to the request.
{% endhint %}

### Rule list

The *Rule* list is generated in different ways, depending on the source of the data.&#x20;

#### Datafeed-based Global Filters

Many Global Filters obtain their Rules from an external source, specified by the URL in the *Source* field. Some are maintained by Link11; others can be created and maintained by admins.

* **System-managed Global Filters based on datafeeds** are maintained automatically. Their underlying data sources are refreshed every 24 hours, and the Global Filters are updated automatically.
* **Admin-managed Global Filters based on datafeeds** are initially created by entering the URL of the source file into the *Source* field, then selecting the **Update now** button that appears. L11WAAP will then populate the *Rule* list automatically. To refresh the Rule List, simply select the **Update now** button again.

#### "Self-managed" Global Filters

Many Global Filters will be based on criteria that are not found in an external feed. In this situation, the *Source* field will say `self-managed`. &#x20;

Typically, most admin-managed Filters will have this setting, with their *Rule* lists being created and maintained manually (described below). It is also possible for a system-managed Filter to have this *Source* setting.&#x20;

{% hint style="info" %}
To avoid confusion, note that "self-managed" does not mean "managed by admins instead of the system". Rather, it means "using Rules defined directly by specific criteria instead of being pulled from a datafeed".
{% endhint %}

### Manually creating a Rule list

<figure><img src="/files/cIzJKIbe8Bgd2b2GaeHv" alt=""><figcaption></figcaption></figure>

When a new Global Filter is created, its *Rule* list will be empty, as shown above.

A Rule list contains one or more Sections. Each Section contains one or more Entries, where each Entry defines a match condition for evaluating requests. Sections can also contain one or more nested Sections.

When a Section contains multiple items (whether Entries or other Sections), its **Section Relation** button defines the logical condition (either AND or OR) to apply among those items.

Example: A Rule list contains two sections, with the overall Section Relation set to AND. The first section has criteria `a, b, c` and the second has `i, j, k` . Within each section, the Section Relation is set to OR. Thus, for a request `x`, the evaluation will be `((x==a) OR (x==b) OR (x==c)) AND ((x==i) OR (x==j) OR (x==k))`.&#x20;

#### Defining a Section

To create a new Section, select the **+ New Section** button. (If this button is not available, verify that the **Source** field is set to `self-managed`.)

#### Defining an entry

To create an Entry within a Section, select the **+ New Entry** button. The following dialog will appear:

<figure><img src="/files/G3yvtEjNgVucse0hvwsY" alt=""><figcaption></figcaption></figure>

For some of the criteria categories, the dialog will appear as it is above. Multiple entries can be made at once, with each entry on a separate line. Each line contains the value, plus a pound sign (#) followed by an optional individual **annotation** (a label for display within the L11WAAP interface). If individual annotations are not provided, then L11WAAP will assign the content of the *Annotation* field to each entry. Example:

<figure><img src="/files/xhdlWd82h6cknPDgFORu" alt=""><figcaption></figcaption></figure>

For other categories, one entry can be made at a time. Annotations are defined in the Annotation field, and are not preceded by a pound sign.&#x20;

<figure><img src="/files/Qw7WCChMPZaOCE7WcirG" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Most Rule criteria are case sensitive. The exception is Header, where the criteria are not case sensitive.
{% endhint %}

#### Category and Match

The *Match* parameter will vary, depending on the chosen *Category*.&#x20;

| Category             | Match                                                 | Comments                                                                                                                                                             |
| -------------------- | ----------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Argument             | *Name*: exact match, case sensitive. *Value*: regex   |                                                                                                                                                                      |
| ASN                  | Exact match for ASN number                            |                                                                                                                                                                      |
| Authority            | Regex                                                 | Combination of the domain and (optional) port                                                                                                                        |
| Cookie               | *Name*: exact match, case sensitive. *Value*: regex   |                                                                                                                                                                      |
| Country              | Exact match                                           |                                                                                                                                                                      |
| Header               | *Name*: exact match, case insensitive. *Value*: regex |                                                                                                                                                                      |
| IP Address           | Exact match for IP, CIDR                              |                                                                                                                                                                      |
| Method               | Regex                                                 |                                                                                                                                                                      |
| Organization         | Regex                                                 | Example: the Organization for ASN `AS15169` is `Google LLC`.                                                                                                         |
| Path                 | Regex                                                 |                                                                                                                                                                      |
| Path Matching Name   | Exact match                                           |                                                                                                                                                                      |
| Query                | Regex                                                 |                                                                                                                                                                      |
| Region               | Regex                                                 |                                                                                                                                                                      |
| Security Policy Name | Exact match                                           |                                                                                                                                                                      |
| Subregion            | Regex                                                 |                                                                                                                                                                      |
| Tag                  | Exact match                                           | Exact matching must be considered when constructing Rules for tags in  the *\<tag-name>:\<value>* format. [More info](/how-link11-waap-works/tagging#tag-evaluation) |
| URI                  | Regex                                                 | Path + query                                                                                                                                                         |

{% hint style="info" %}
Currently, there is not a category for a request's protocol. However, you can still create a protocol-based Global Filter by specifying an appropriate *Tag*, for example `scheme:http` or `scheme:https`. This is useful when blocking or redirecting unencrypted HTTP traffic ([how to do this](/using-the-product/how-do-i.../redirect-or-block-http-traffic)).
{% endhint %}

#### Examples

Here are some sample entries for the various categories. (Note that when the Rule list is displayed like this, for criteria that consist of Name and Value fields, the system displays a colon between them. This colon is not included when entering the criteria.)

<figure><img src="/files/UkUmbPcnh7RF5jJHk6Zv" alt=""><figcaption></figcaption></figure>

### Editing the Rules list

A *Rule* list for admin-managed Global Filters can be edited. Hover the cursor over the Entry that you wish to edit, and an "edit" button (a pencil icon) will appear. Select this button, and the Entry can be edited. After editing is complete, select the "confirm" button (a checkmark), then save the changes, and publish them.


# Flow Control Policies

Tagging valid or invalid session flow patterns

<figure><img src="/files/fPhsqvkgapt4sqYWmFU2" alt=""><figcaption></figcaption></figure>

## **Overview**

**Flow Control Policies** allow admins to define "flow" sequences of submitted requests. As incoming traffic is received, the requests are evaluated against the active Policies. If a defined sequence is completed--in other words, if the listed requests are received in the specified order--the Policy will attach one or more tags to the final request in the sequence. The tags can subsequently trigger an action (allow, block, challenge, etc.)&#x20;

Link11 WAAP includes several types of behavioral profiling and control. Flow Control Policies are one type of behavioral control that are defined by admins. They can allow, or disallow, traffic sources that display specific patterns of behavior.

**Use case example**: A web application has a login page. A legitimate user session will begin with a `GET` request, followed by a `POST`. However, threat actors who are waging brute-force login attacks will typically just send a series of `POST`s. A Flow Control Policy can be the basis for blocking every `POST` request that was not preceded by a `GET`.

## Usage within applications and APIs

A Flow Control Policy's purpose is to assign its defined *Tags* to the last request in defined flow sequences. The *Tags* can then be used in [Rate Limit Rules](/console-walkthrough/security/rate-limit-rules) or [ACL Profiles](/console-walkthrough/security/acl-policies) to trigger specific actions. Usually, a [Global Filter](/console-walkthrough/security/global-filters) is involved in the process as well (see the implementation example below).

Unlike some other types of security settings, Flow Control Policies are not assigned to paths in [Security Policies](/console-walkthrough/security/security-policies), because a Flow Control Policy can incorporate multiple paths within an application or API.

Instead, each Policy has its applicable scope defined by the *Active*, *Include*, and *Exclude* parameters, as described below.

### Implementation example

To implement the `GET`/`POST` example mentioned above, an admin would create the following configuration:

* A Global Filter would assign a tag (e.g., `method-post`) to all `POST` requests sent to `/login`.
* A Flow Control Policy would assign a tag (e.g., `login-flow`) to each `POST` that was preceded by a `GET`.
* An ACL Profile would *Block/Skip* all requests tagged with `login-flow`, and *Block/Apply* all requests tagged with `method-post`.

## Administration

The main page (shown above) lists all current Flow Control Policies.

The administration (addition/deletion/editing/versioning) of Policies follows the conventions described [here](/how-link11-waap-works/ui-overview-and-common-elements#configuration-and-administration).

## Components

Each Flow Control Policy consists of:

* A flow sequence: A list of two or requests that are expected to be received in the sequence shown, within the specified *Time frame*.
* *Tag(s)* to assign to the final request in the defined flow sequence.
* *Include/Exclude*: Tags to define the scope within which this Policy is enforced.
* *Count by* parameters for identifying distinct flow sequences within incoming traffic. In other words, these settings tell the system how to separate incoming requests into distinct groups, each of which will be evaluated separately for flow sequence analysis. Usually, admins will want to enforce flow sequences on individual users (for example, according to IP address).&#x20;
* General parameters for administrative purposes.

Each of these is described in depth below.

## Individual parameters

<figure><img src="/files/Va7Zn5GlaBDzUoeKkSBE" alt=""><figcaption><p>A Flow Control Policy, opened within its Editor page</p></figcaption></figure>

### **Name**

A name for this Policy, to be used within the interface. A [system tag](/how-link11-waap-works/tagging#system-tags) (shown below the *Tags* field) will include it as well.

### Active

When this toggle is selected, the Policy will be enforced within its defined scope.&#x20;

### Time Frame

This defines the time available for the flow sequence to be completed. When the first request in the sequence is received, an internal timer begins. The final request must be received within the *Time Frame* in order for the *Tags* to be assigned.

### Count by

At any given time, an application might receive a variety of incoming requests from different users simultaneously, each of which might be at a different stage of a flow sequence. For Flow Control Policies to work successfully, the system must be able to differentiate among all the various streams of incoming traffic, and perform stateful evaluations of each one separately.

The *Count by* parameter allows admins to define how this differentiation is done. For example, a common configuration is `Attribute` / `IP Address`. When the application is receiving requests from multiple IP addresses simultaneously, the requests from each IP will be considered as a separate and distinct set for Flow Control purposes. On the other hand, if it is possible that users will sometimes share IP addresses, then a better choice might be `Attribute` / `Session ID`.

Admins have a variety of configuration options for this parameter. Incoming requests can be processed according to specific headers, cookies, arguments, or attributes.&#x20;

Multifactorial *Count by* definitions can be set up by selecting "**New entry**" and editing the controls that appear. When incoming requests are evaluated, the *Count by* definitions are combined with a logical `AND`.&#x20;

### Tags

Enter one or more unique tags, separated by spaces. When a series of incoming requests matches the flow control sequence, the tags listed here will be attached to the final request.

In addition to these admin-defined tags, the system also shows some system tags that will be attached as well.

### Description

Information about this Policy, for use within the interface.

### Include and Exclude

These are lists of tags that can limit the applicable scope for this Policy. Their use is described on the [UI Overview](/how-link11-waap-works/ui-overview-and-common-elements#include-and-exclude-filter-lists) page.

### Flow Control Sequence

This is an admin-defined sequence of at least two steps.

The system maintains stateful histories of each traffic stream defined by the *Count by* parameter. When a series of incoming requests matches the Flow Control Sequence exactly, the final request has the defined *Tags* attached.

Each step in the sequence is defined by a Method, Host, and Path, along with any optional parameters added by an admin.&#x20;

A new Flow Control Policy includes a two-step sequence by default. To add additional steps, select the "**Add Step**" button.


# Security Policies

Applying security rules to paths and resources

<figure><img src="/files/mfI3UnmgdtoJlcUlwmzg" alt=""><figcaption></figcaption></figure>

## **Overview**

**Security Policies** assign security rulesets to specific paths within applications and APIs. When a request is received, Link11 WAAP finds the Security Policy assigned to its destination Server Group (i.e., the destination site). That Policy then specifies the security rules to enforce upon the request, according to its destination URL.

Each Security Policy also includes a definition of the Session ID to use within its scope. This is an important setting, as discussed below.

## Usage within applications and APIs

Security Policies are used within [Server Groups](/console-walkthrough/sites/server-groups). Every Server Group includes a Security Policy.

<figure><img src="/files/uiNsn3RqCbtNQUDLvZnM" alt=""><figcaption></figcaption></figure>

Every L11WAAP deployment contains a default Security Policy. This default Policy cannot be deleted. Admins can define additional Policies as well.

## Administration

The main page (shown at the top of the page) lists all current Security Policies.

The administration (addition/deletion/editing/versioning) of Policies follows the conventions described [here](/how-link11-waap-works/ui-overview-and-common-elements#configuration-and-administration).

## Components

Each Security Policy contains the following:

* A list of paths or scopes within which this Policy will be applied.
* The [Content Filter Profile](/console-walkthrough/security/content-filter/profiles), [ACL Profile](/console-walkthrough/security/acl-policies), and (optional) [Rate Limit Rule(s)](/console-walkthrough/security/rate-limit-rules) that will be enforced on requests sent to the specified paths.
* Optional Edge Functions(s) to run when requests are sent to the specified paths.
* One or more *Tags* that will be attached to requests sent to the specified paths.
* What to use as a Session ID for requests sent to the specified paths. This is used elsewhere by the system; for example, [Rate Limit Rules can be enforced on a per-session basis](/console-walkthrough/security/rate-limit-rules#rate-limiting-within-sessions).
* General parameters for administration.

## Individual parameters

<figure><img src="/files/M9kdFiPiOKytzojLfpNw" alt=""><figcaption></figcaption></figure>

### Name

A name for this Policy, to be used within the interface. A [system tag](/how-link11-waap-works/tagging#system-tags) (shown below the *Tags* field) will include it as well.

### Description

Information about this Policy, for use within the interface.

### Tags

A list of one or more tags, separated by spaces. Whenever this Security Policy is applied to a request, these tags will appear in the Events Log.

In addition to these admin-defined tags, the system also shows some [system tags](/how-link11-waap-works/tagging#system-tags) that will be attached as well.

### Main Session ID & Other Session IDs

Some types of settings within L11WAAP allow admins to track user activity and enforce security rules based on the user's Session ID. (Examples of this include [Flow Control Policies ](/console-walkthrough/security/flow-control-policies)and [Rate Limit Rules](/console-walkthrough/security/rate-limit-rules).)&#x20;

However, the definition of a Session ID can vary. The optimal combination of request parameters can differ, depending on the circumstances.

The *Main Session ID* and *Other Session IDs* define the request parameters that should be combined and used as the Session ID within the scope of this Security Policy.

*Main Session ID*: This is the header, cookie, argument, or attribute that will be the Session ID by default.

*Other Session IDs*: This is a list of additional headers, cookies, arguments, and/or attributes that might, or might not, be available, depending on the situation. When they are available, they are combined with the *Main Session ID* to form the Session ID used by L11WAAP.

Example: the *Main Session ID* is set to `Header` / `user_id`, and *Other Session IDs* contains one entry for an authentication token (`Header` / `auth_token)`. Initially, the Session ID will consist of the `user_id` alone. Once the user is authenticated and the requests begin to include `auth_token` too, the Session ID will then be a combination of those two values.&#x20;

Another example: the *Main Session ID* is set to `Header` / `user_id`. In *Other Session IDs*, there is one definition (`Header` / `device_id`) for a field that is sent by a mobile application.&#x20;

* If the user is using the mobile application, then `device_id` will be included in the incoming requests, and the Session ID will be a combination of `user_id` and `device_id`.
* If the user is using a browser instead, then `device_id` will not be defined, and the Session ID will consist solely of `user_id`.

{% hint style="info" %}
The choice of parameters for the Session ID should be carefully considered, because it can affect the performance of various security settings and rules. Sometimes, a narrowly-defined Session ID is better, while in other situations, a broader definition should be used.&#x20;

For example, an admin has defined a [Rate Limit Rule](/console-walkthrough/security/rate-limit-rules) based on Session ID. A threat actor then begins a session in a web browser, copies its session tokens, and tries to use them in a brute force attack across different IPs and distributed networks in the cloud.&#x20;

* If the applicable Security Policy has a Session ID based on the session tokens, then the Rate Limit Rule will detect and block the attack.&#x20;
* If however the Session ID also includes the IP address, then a Rate Limiting Rule would maintain separate counts for each of the various IPs that are used, and the Rule would not perform as the admin had intended.
  {% endhint %}

### Path Mapping

This is a list of paths, and the security settings (Content Filter Profiles, ACL Profiles, Backend Service, Rate Limit Rules, and Edge Functions) assigned to each one.

Every incoming request targets a specific URL. L11WAAP finds the best match for that URL in the Path Mapping list, and applies the security settings defined for it, along with whatever settings are contained in the special **Site Level** path definition (see below).

{% hint style="info" %}
The "best match" is determined by regex evaluation. The order in which the paths are listed in the interface does not matter. If multiple admin-defined Path Maps could match a request's destination, the longest matching regex will determine which Path Map gets selected. If no regex matches, then the `Default`  Path Map will be selected.
{% endhint %}

Out of the box, Security Policies can contain three special path definitions:

* **Root**: Will be selected for requests sent to the root level of the site.
* **Site Level**: Will be selected for all requests sent to the site (see note below).
* **Default**: Will be selected for requests that do not match any other specific path definitions.

{% hint style="info" %}
The **Site Level** definition behaves differently than other path definitions; it is *always selected* and added to the best-matching path definition for the request (including the **Default** definition). Thus, if **Site Level** contains any settings, they are used in addition to the settings contained in the best-matching definition.
{% endhint %}

#### Managing the Path Maps

A new Security Policy will include several Path Maps. Clicking on a listing will expand it for editing.

<figure><img src="/files/7vkW2u3IL5D9fFBBL2L3" alt=""><figcaption></figcaption></figure>

#### Creating Path Maps

To add a new Path Map, select an existing one, expand it, and select "**Fork Path Mapping"** at the bottom. The existing one will be cloned, and the new one will be displayed for editing.

{% hint style="info" %}
Note that the controls at the top of the window are for administering Security Policies, which generally correspond to domains. Administering Path Maps (for paths and URLs *within* the specified domain) is done in the *Path Mapping* list.
{% endhint %}

#### Path Map Fields

| **Field**                  | **Value**                                                                                                                                                                                                     |
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Name**                   | A descriptive label for use within the interface.                                                                                                                                                             |
| **Path or Expression**     | An expression for the path, expressed as PCRE (Perl Compatible Regular Expressions).                                                                                                                          |
| **Content Filter Profile** | The [Content Filter Profile](/console-walkthrough/security/content-filter/profiles) applied to this path. Its name will be displayed in green if it is active; if displayed in red, it is currently disabled. |
| **ACL Profile**            | The [ACL Profile](/console-walkthrough/security/acl-policies) applied to this path. Its name will be displayed in green if it is active; if displayed in red, it is currently disabled.                       |
| **Backend service**        | The [Backend Service](/console-walkthrough/sites/backend-services) associated with this path. Requests that pass through L11WAAP without being blocked will be forwarded here.                                |
| **Rate Limit Rules**       | The [Rate Limit Rule(s](/console-walkthrough/security/rate-limit-rules)) assigned to this path.                                                                                                               |
| **Edge functions**         | The [Edge Function(s)](/console-walkthrough/sites/edge-functions) assigned to this path.                                                                                                                      |

In addition to editing the fields discussed above, the expanded *Path Mapping* dialog also provides the ability to:

* Activate or deactivate the Content Filter Profile (by changing its *active mode* toggle).
* Activate or deactivate the ACL Profile (by changing its *active mode* toggle).
* Add an existing Rate Limit Rule to this Path Map, via the **+** **New** button. (The **+ New** button will only be shown if there are Rate Limit Rules available.) An existing Rate Limit Rule can be removed by selecting the trash icon at the end of its entry.
* Add an existing Edge Function to this Path Map, via the **+** **New** button. (The **+ New** button will only be shown if there are Edge Functions available.) An existing Edge Function can be removed by selecting the trash icon at the end of its entry.
* Create a copy of this Path Map, and open it for editing, via the "**Fork Path Mapping**" button.


# Rate Limit Rules

Controlling the rates of incoming requests

<figure><img src="/files/Rf5KK4InTTWXrtg7XZEG" alt=""><figcaption></figcaption></figure>

## Overview

There are many web threats that are built upon requests which otherwise might seem benign: credential stuffing, enumeration, payment card validation, coupon/gift code discovery, and more.&#x20;

Rate limiting defends against these malicious activities by restricting the rates at which traffic sources can successfully submit requests. When a limit is exceeded, an action can be taken; for example, subsequent requests from that traffic source can be blocked for a defined period of time.

For more information, see the detailed discussion below of [how rate limits are enforced](#how-rate-limits-are-enforced).

## Usage within applications and APIs

A Rate Limit Rule can be enforced globally by enabling its *Global mode* setting. Otherwise, the Rule's scope will be defined by its [Connections to Security Policies](#connections-to-security-policies).&#x20;

In both cases, enforcement is also subject to the Rule's *Active mode* setting and the constraints of its [Include/Exclude filters](#include-exclude).

{% hint style="info" %}
If you define a Rate Limit Rule, but its *Global mode* setting is not enabled and the Rule is not connected to any Security Policies, it will not have any effect within your applications/APIs.
{% endhint %}

## Administration

The main page lists all current Rate Limit Rules.

The administration (addition/deletion/editing/versioning) of these Rules follows the conventions described [here](/how-link11-waap-works/ui-overview-and-common-elements#configuration-and-administration).

## Components

Each Rate Limit Rule consists of the following:

* Settings to define the scope (the *Global mode*, *Active mode*, *Include/Exclude* lists, and *Connections to Security Policies*). These specify the requests upon which this Rule will be enforced.
* A rate limit (defined by the combination of *Time Frame*, *Count by* / *Event*, *Number of events*, and *Time frame*).
* Action(s) to perform when a violation occurs (*Action*, and *Ban mode*)
* General parameters for administration.

These parameters are described below.&#x20;

{% hint style="info" %}
Note that while Rate Limit Rules can be used for simple rate limiting (e.g., enforcing limits on the rate of requests from an IP), they can do much more than this. See [How rate limits are enforced](#how-rate-limits-are-enforced) below for an in-depth discussion and examples.
{% endhint %}

## Individual parameters

<figure><img src="/files/Q5hNhdNXCl1uqYSGdab8" alt=""><figcaption></figcaption></figure>

### Name

A name for this Rule, to be used within the Link11 WAAP interface. A [system tag](/how-link11-waap-works/tagging#system-tags) (shown below the *Tags* field) will include it as well.

{% hint style="info" %}
It can be helpful to use descriptive names based on the Rule's parameters. For example, a Rule that limits 50 requests per username, per 60 seconds, could be named "RL 50/60s username". This makes administration straightforward, and also clarifies events in the traffic logs.&#x20;
{% endhint %}

### Active mode

When this setting is enabled, this Rate Limit Rule will be enforced globally (if the *Global mode* setting is enabled) or within the paths configured in all connected [Security Policies, ](/console-walkthrough/security/security-policies)subject to the scope defined by the *Include* and *Exclude* lists. To deactivate the Rule, deselect this setting.&#x20;

This can be helpful when a Rule is not performing as expected, and needs to be reconsidered. Rather than having to go find all the places where the Rule is being used, admins can simply deactivate it here, which will take effect across the entire platform.

### Global mode

When enabled, this Rule will be enforced globally, subject to the *Active mode* setting and the scope defined by the *Include* and *Exclude* lists.

### Description

Information about this Rule, for use within the interface.

### Count by / Event

These parameters tell the system how to count incoming events for rate limiting purposes. See "How rate limits are enforced," below.

### Number of events

The maximum allowable number of events within the *Time frame.*

### Time frame

The time period within which the *Number of events* limit is enforced, specified in seconds.&#x20;

Frequently, an admin will want to constrain user activity within short periods of time (e.g., only allow three login attempts per minute). However, the optimal setting for *Time frame* will often be a much larger period of time. This is explained in more detail below: [multi-tiered rate limiting](#multi-tier-rate-limiting).

### Action

An action to execute when the *Number of events* limit is exceeded within the *Time frame*. The available actions are defined on the [Actions](/console-walkthrough/security/actions) page. (Note that this can be, but doesn't need to be, a blocking action.)&#x20;

### Ban mode

Enables the blocking of a Rule violator for a longer time period than the *Time frame*. See discussion below: [Banning traffic sources](#banning-traffic-sources).&#x20;

### Tags

A list of one or more tags, separated by spaces. These will be attached to requests from traffic sources that have exceeded a rate limit.

In addition to these admin-defined tags, the system also shows some [system tags](/how-link11-waap-works/tagging#system-tags) that will be attached as well.

### Include / Exclude

By default, an active Rate Limit Rule will be enforced upon all requests globally (if the *Global mode* setting is enabled), or upon incoming requests targeting URLs to which this rule has been assigned via a Security Policy.

The *Include* and *Exclude* tag lists can be used to further constrain the enforcement of this Rule. Their use is described on the [UI Overview](/how-link11-waap-works/ui-overview-and-common-elements#include-and-exclude-filter-lists) page.

### Connections to Security Policies

The list of Security Policies that include this Rate Limit Rule. Each Security Policy defines the paths within Backend Services for which the Rule will be applicable.

For a discussion of how to use this control, see [Connections to Security Policies](/how-link11-waap-works/ui-overview-and-common-elements#connections-to-security-policies).

## How rate limits are enforced

Above, Rate Limit Rules were described as if the system will count incoming requests, while monitoring the count to see if it has exceeded the *Number of events*. This is true sometimes, but not always.

A more accurate description is that a Rate Limit Rule counts events, as specified in the *Event* field. Frequently, this field will be set to `HTTP request`, which means that indeed, an internal counter will be incremented every time a request is received. However, there are more powerful ways to configure a Rule beyond this.

To illustrate how Rate Limit Rule parameters can be used, we'll discuss several examples. We'll start with simple use cases and finish with more complicated situations.

{% hint style="info" %}
The examples below are for individual Rate Limit Rules.\
\
Note that it's possible for multiple Rules to be in-scope simultaneously, e.g. when several Rules have their *Global* setting enabled. When a request is received, all applicable Rate Limit Rules are evaluated. If it exceeds the thresholds of multiple Rules, Link11 WAAP will compare their *Actions* and execute the one that has the [highest priority](/console-walkthrough/security/actions#prioritization).
{% endhint %}

### Limiting incoming requests

**Example 1:** Let's say an admin wants to define a rate limit as follows:

"Allow each unique IP address to send up to three requests to `/login`. If more than three requests are sent within one minute, block them."

To configure this, the following parameters would be set:

* *Time frame*: 60 seconds
* *Count by*: `Attribute` / `IP Address`&#x20;
* *Event*: `HTTP request`
* *Number of events*: 3

...and then this Rate Limit Rule would be connected to a Security Policy that includes `/login` in its *Path Mapping*.

### The "Count by" field

As shown in the example above, L11WAAP maintains an internal counter for every unique value of the *Count by* parameter(s).&#x20;

In the example, a separate counter is maintained for each IP address that is sending traffic. When a request is received from an IP, that IP's counter is incremented, and the system checks to ensure that the counter's value hasn't exceeded the *Number of events*.

Each counter is reset to zero once the *Time frame* has passed (starting when the first request was received).

#### Multiple Count by settings

The *Count by* parameter can be multifactorial. In other words, admins can select "**New Entry**" and add additional *Count by* settings. When this is done, an internal counter is maintained for every unique *combination* of these settings.

**Example 2:** an admin configures the *Count by* section with two lines: `Attribute` / `IP Address` and `Header` / `user_id`. When the first request is received, an internal counter is created (set to a value of one) for this unique combination of IP and user\_id. A second request is then received, originating from the same IP and from the same user; this causes the internal counter to be incremented up to two. A third request is then received from the same IP but with a different user\_id; this causes a new internal counter to be created (and set to a value of one) for this combination.&#x20;

**Example 3:** multiple *Count by* settings can be used to create site-level rate limiting. Let's say that there are three sites: `www.example.com`, `api.example.com`, and `mobile.example.com`. If the *Count by* section has `Attribute` / `Session ID` and `Header` / `host`, then the system will enforce separate rate limit counts for each site.

### Rate limiting within sessions

**Example 4:** an admin wants to rate limit the activity within each user session, regardless of the IP that is being used. For this purpose, the admin can set the *Count by* parameter to `Attribute` / `Session ID`.&#x20;

Note that the composition of a Session ID might vary, according to context. Therefore, the system allows admins to define it within Security Policies, as explained [here](/console-walkthrough/security/security-policies#main-session-id-and-other-session-ids).

Each time a request is received, the system examines its destination's path to see which Security Policy applies. That Policy's definition of Session ID is used for any active Rate Limit Rules connected to it.

If a Rate Limit Rule is "Active" and "Global", but is not connected to a Security Policy, then the system will use the requestor's IP Address as the default Session ID for rate limiting purposes. In this situation, if actual session-based rate limiting is needed, then admins will need to specify the appropriate combination of headers, cookies, arguments, etc. manually in the *Count by* section.

### Limiting different types of Events

As mentioned earlier, the rate limiting system does not directly count requests; instead, it counts events.

The four examples above have the *Event* field set to its default of `HTTP request`. This means that the receipt of a request is an event, and therefore, each request will cause an internal counter to be incremented.

Other *Event* settings are possible; admins can specify a header, cookie, argument, or attribute. When this is done, an internal counter is maintained for each *Count by* value, and incremented each time a **new*****,*****&#x20;previously unobserved** *Event* value is encountered in a request.

Therefore, if an *Event* is defined as something other than `HTTP request`, the Rate Limit Rule constrains the **number** of allowable *Event* values for any given *Count by* value.&#x20;

**Example 5:** Let's say we want to allow an individual user to login from a maximum of two ASNs within one hour. (Perhaps the user is accessing our web application from a coffee shop's WiFi, and then a few minutes later, leaves the coffee shop and begins using the cell network instead.) We want to allow this possibility; however, if we receive requests from the same user originating from three or more ASNs within an hour, we want to treat this traffic more suspiciously. \
\
This is not possible merely by specifying two *Count by* conditions, as described above in the "Multiple Count by settings" section. If we set up two conditions (`Argument` / `Username` and `Attribute` / `Organization`) with a *Number of events* of 2, and assign it to our login form, then this will merely limit the number of times that the user can login from **each** ASN within an hour. \
\
Instead, we set up one *Count by* condition (`Argument` / `Username`), and then set the Event to `Attribute` / `Organization`. Now the *Number of events* will apply to the number of Organizations that are observed for each specific Username.

**Example 6:** Your L11WAAP deployment includes some Rate Limit Rules out of the box. One of them might be a global Rule with settings similar to these:

* *Time frame* 3600
* *Count by* `Cookie` / `waap_id`
* *Event* `Attribute` / `IP Address`&#x20;
* *Number of events* 5

L11WAAP sets a cookie (*waap\_id*) for all users who interact with it. This can serve as a global identifier for users, across all domains, sites, applications, etc., even if individual sites/apps track users with different methods (whether user id, authentication tokens, and so on).

The example Rule shown above allows any particular user to have up to five IP addresses within an hour. When a sixth IP is encountered, it will execute the *Action*.

### Multi-Tier Rate Limiting

A common use case for Rate Limit Rules is the following:

* Allow incoming requests until the *Number of events* has been reached.
* Each subsequent request within the same *Time frame* will trigger the *Action*.

However, it is often necessary to create multiple tiers of Rate Limiting:

* Allow the requests until the first *Number of events* is reached.&#x20;
* Each subsequent event will trigger the first tier's *Action*, until the second *Number of events* is reached.
* Each subsequent event will trigger the second tier's *Action*, until the third *Number of events* is reached.
* And so on.

For this purpose, multiple Rate Limit Rules can be created and set to be active within the same scope. This allows for increasingly restrictive actions to be taken as the number of events within the same *Time frame* increases.

**Example 7:** one possible use of multi-tier Rate Limits is to allow a certain amount of activity, and then verify that the user is human before allowing the activity to continue, while still enforcing reasonable boundaries. To do this, the Rules might look like this:

* *Number of events* 3, *Action* `monitor [tag only]`
* *Number of events* 7, *Action* `challenge`
* *Number of events* 10, *Action* `default blocking`

The system would behave as follows:

* The first three events would be allowed.&#x20;
* Events 4-7 would be allowed, but the requests would be tagged.
* Event 8 would subject the user to a bot challenge. If the challenge is failed, subsequent requests would be blocked.
* Events 9 and 10 would be allowed.
* Subsequent events would be blocked.

Earlier, it was mentioned that the optimal *Time frame* for a Rate Limit Rule might be quite long. Multi-tier Rate Limits are the reason for this; the *Time frame* must be long enough to accommodate all of the previous tiers.

## Blocking persistent violators

When its *Time frame* expires, a rate limit will reset, and its internal counter will be set to zero.

This means that the rate limiting described above cannot, on its own, fully defeat persistent attackers.

{% hint style="info" %}
**Example**: Access to a login form is rate-limited to four requests per minute. An attacker tries to brute-force the login, and sends 60 requests per minute. The Rate Limit Rule allows the first four requests, but then blocks the next 56 requests. \
\
However, after the minute has passed, the rate limit resets. The attacker is allowed another four attempts before being temporarily blocked again. This cycle can continue for as long as the attacker wishes. In effect, the rate limit is not preventing the attack; it is merely slowing it from 60 attempts per minute down to four attempts per minute.
{% endhint %}

To accomplish this, L11WAAP provides two capabilities: [Ban mode](#ban-mode-1), and [Dynamic Rules](#dynamic-rules).&#x20;

Both allow admins to define granular Rate Limit Rules with short time frames and maintain precise control of various situations, while still being able to block persistent violators for much longer periods of time.&#x20;

### Banning traffic sources

When *Ban mode* is enabled, the *Ban duration* field appears. These two values allow admins to configure a longer-term blocking action for rate limit violators.&#x20;

When a Rate Limit Rule is violated (i.e., an event occurs that exceeds the *Number of Events*), and *Ban mode* is enabled, the offending traffic source is banned immediately.&#x20;

Beginning with the request that triggered the ban, L11WAAP will reject all activity from the offending traffic source, for the length of time specified in *Ban duration*.

### Dynamic Rules

A [Dynamic Rule](/console-walkthrough/security/dynamic-rules) is similar to a Rate Limit Rule with Ban mode enabled. It too defines an allowable threshold of events that can occur within a certain period of time. If that threshold is violated, an action occurs.

However, there are some important differences:

* When configuring a Dynamic Rule, an admin can choose to block violators, but can also choose a non-blocking [Action](/console-walkthrough/security/dynamic-rules#action).
* If blocking is selected, the blocking can be [offloaded](/console-walkthrough/security/dynamic-rules#offloading-blocking-actions) to Link11's Layer 3 protection.
* Dynamic Rules are enforced globally, unless their [scope](/console-walkthrough/security/dynamic-rules#include-and-exclude) is otherwise constrained.
* Violators of a Dynamic Rule will appear in the [Quarantined](/console-walkthrough/security/quarantined) list. Admins can manually remove them from this list (which ends the quarantine early) if desired.
* When a Dynamic Rule is violated, a [Security Alert](/console-walkthrough/system/security-alerts) can be sent.


# ACL Profiles

Executing actions based on a request's tags

<figure><img src="/files/VTFpBQQQuf3ZYNCxxsSt" alt=""><figcaption></figcaption></figure>

## Overview

When a request is processed by Link11 WAAP, a number of [tags](/how-link11-waap-works/tagging) are assigned to it during the early stages of the [traffic filtering process](/how-link11-waap-works/traffic-filtering-process).&#x20;

As one of the final stages of processing, the relevant **ACL (Access Control List) Profile** for this request is evaluated.&#x20;

The ACL Profile defines what will happen to a request, based on the tags that it contains. Admins can assign a variety of available actions that will be performed.

## Usage within applications and APIs

An ACL Profile is assigned to paths/URLs within applications and APIs via [Security Policies](/console-walkthrough/security/security-policies).

When a request is received, the system checks its destination URL, and uses the ACL Profile that best matches it.

Out of the box, the system includes a default ACL Profile. It can (and usually should) be edited, but it cannot be deleted. It is used for all URLs where no other Profile has been assigned.

## Administration

The main page lists all current ACL Profiles.

The administration (addition/deletion/editing/versioning) of Profiles follows the conventions described [here](/how-link11-waap-works/ui-overview-and-common-elements#configuration-and-administration).

## Components

Each ACL Profile consists of the following:

* Six **ACL Lists**, shown in the UI as six columns organized into four sections. (These *Lists* are not labeled in the interface, but *ACL Lists* will be our designation here in the documentation.) Each *List* contains zero or more tags; these tags are compared to the request's tags. The first *List* with a matching tag causes an event to occur. See the full explanation of this process below.
* An *Action* to execute under certain circumstances (see below).
* *Tags* that are attached to requests that are evaluated using this Profile.
* General parameters for administration.

## How an ACL Profile works

As mentioned above, an ACL Profile includes six *ACL Lists*, each of which is shown in a separate column in the interface. Each one includes a list of zero or more tags.

When a request is processed, its tags are compared to the ones in the *Lists*. The *Lists* are evaluated in order from left to right.&#x20;

* If a match is not found, the next *List* is evaluated.&#x20;
* If a match is found, then one of the following occurs:
  * The request is subjected to a [bot challenge](/reference-information/hostile-bot-detection-lwcsi). If it passes, ACL processing continues.
  * The request is exempted from bot challenges, and ACL processing continues.
  * The request is passed to the Content Filter Profile for further inspection.
  * The request is passed, and is exempted from content filtering.
  * The [Action](/console-walkthrough/security/actions) is executed, and processing ends.

Here is a flowchart of this process, with the evaluation of each *ACL List* column shown as a decision.

<figure><img src="/files/PrnvGaLLIeJy16wY8GZM" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
Tags are evaluated according to exact matches. This must be considered when using tags with the structure *\<tag-name>:\<value>*. [More info](/how-link11-waap-works/tagging#tag-evaluation)
{% endhint %}

### ACL Lists and some typical applications

| ACL List                  | Comment                                                                                                                                                                                                                                                                                                                                                                                                             |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Enforce Deny**          | Triggers the Action. (In most situations, admins will choose an action that blocks the request. This is a useful way to quickly filter out, with minimal computing overhead, large numbers of requests that are obviously hostile or otherwise unwanted.)                                                                                                                                                           |
| **Bypass**                | Allows the request, and bypasses/exempts it from subsequent evaluation by Content Filter Profiles. (Note that any `Response` phase [Edge Functions](/console-walkthrough/sites/edge-functions) will still be executed.)                                                                                                                                                                                             |
| **Bot Challenge / Skip**  | Skip the *Bot Challenge* / *Apply* stage (the process by which non-human traffic is identified and blocked), and continue processing. An example usage is to allow search engine spiders.                                                                                                                                                                                                                           |
| **Bot Challenge / Apply** | If the requestor has not previously been verified to be human, a bot challenge will be issued. If the challenge is passed, the request will continue in the evaluation process. Otherwise the Action is triggered. A common use of this column is to add the `all` tag, which means to challenge all requests that haven't already passed a challenge, or didn't match a tag in *Bypass* or *Bot Challenge / Skip*. |
| **Block / Skip**          | Passes the request to the Content Filter Profile process for further inspection.                                                                                                                                                                                                                                                                                                                                    |
| **Block / Apply**         | Triggers the Action.                                                                                                                                                                                                                                                                                                                                                                                                |

{% hint style="info" %}
An ACL Profile that blocks requests will only apply to the paths/URLs in the [Security Policy](/console-walkthrough/security/security-policies) where this ACL Profile has been assigned. \
\
If you want to block requests globally for specific tags, this can be done by assigning an Action within a [Global Filter](/console-walkthrough/security/global-filters).
{% endhint %}

{% hint style="warning" %}
**Be cautious when adding the "all" tag to an ACL List.** In most situations, that action will be performed for *all* requests for which a match was not found in any columns to the left.&#x20;

One common use is the *Bot Challenge / Apply* column, as noted above. This means that all requestors (except for those which matched one of the columns to the left) will be challenged and verified to be humans.

Another possible use is to place "all" in the *Block / Apply* column, to create a positive security model. (This will block all requests which did not explicitly meet any of the conditions for *Bypass* or *Block / Skip*.) But even this usage can be risky. Unless all the potential conditions for allowing a request are fully and correctly defined, this can result in False Positive errors, and some legitimate requests will be blocked and filtered.

In other columns, "all" can have serious consequences. For example, placing it in the *Enforce Deny* column will block *all* incoming traffic to which this ACL Profile is applied. On the other hand, placing it in the *Bypass* column will *allow* all incoming traffic (and exempt it from being scrubbed by the Content Filter Profiles!), except for those requests which matched a tag in the *Enforce Deny* column.&#x20;

Summary: before using the "all" tag in an ACL Profile, carefully consider its ramifications.
{% endhint %}

## Individual parameters

<figure><img src="/files/l1USCTPY3LWIUZB75PqP" alt=""><figcaption></figcaption></figure>

### ACL Lists

These six columns are explained above: [How an ACL Profile works](/console-walkthrough/security/acl-policies#how-an-acl-profile-works).

### Name

A name for this Profile, to be used within the interface. A [system tag](/how-link11-waap-works/tagging#system-tags) (shown below the *Tags* field) will include it as well.

### Description

Information about this Profile, for use within the interface.

### Action

The action that is performed when a request matches a tag in *Enforce Deny* or *Block / Apply*, or the requestor fails a bot challenge. The actions available here are the defined [Actions](/console-walkthrough/security/actions) that are relevant for the *Enforce Deny* and *Block / Apply* columns (thus, "monitor" and "challenge" types aren't available here).

### Tags

A list of one or more tags, separated by spaces. Whenever this ACL Profile is used to evaluate a request, these tags will appear in the traffic logs.

In addition to these admin-defined tags, the system also shows some [system tags](/how-link11-waap-works/tagging#system-tags) that will be attached as well.


# Actions

Actions to perform in response to traffic analysis

<figure><img src="/files/5AYDbL8z1vQGJiZ1uf7D" alt=""><figcaption></figcaption></figure>

## Overview

At various stages in the traffic filtering process, Link11 WAAP can execute an action according to the characteristics of the request. These actions are defined within **Actions**.

Out of the box, L11WAAP includes several default Actions for admins to select. Additional ones can also be defined.

## Usage within applications and APIs

Actions are available at various stages of the [traffic filtering process](/how-link11-waap-works/traffic-filtering-process), e.g. [Global Filters](/console-walkthrough/security/global-filters), [Rate Limit Rules](/console-walkthrough/security/rate-limit-rules), [ACL Profiles](/console-walkthrough/security/acl-policies), and [Content Filter Profiles](/console-walkthrough/security/content-filter/profiles).&#x20;

As shown in the diagram below, different types of Actions can occur at various stages. An Action can terminate the processing of a request by blocking it, but other Actions (Skip, Challenge, and Monitor) are available as well, with different outcomes. See the description below of the [Type parameter](/console-walkthrough/security/actions#type).

<figure><img src="/files/F4oFsyMMiyzVo1xvV62X" alt=""><figcaption></figcaption></figure>

## Administration

The main page lists all current Actions.

The administration (addition/deletion/editing/versioning) of Actions follows the conventions described [here](/how-link11-waap-works/ui-overview-and-common-elements#configuration-and-administration).

## Components

An Action consists of the following:

* The *Type* of the action
* Additional *Type*-specific parameters
* *Tag(s)* to attach to requests that triggered this action
* General parameters for administration

## Individual parameters

<figure><img src="/files/g8ZpLI3YJTfK7z6Iu292" alt=""><figcaption></figcaption></figure>

### Name

A name for this Action, to be used within the interface.

### Description

Information about this Action, for use within the interface.

### Type

This parameter will be one of the values below.

| Setting                   | Effect                                                                                                                                                                                                                                                                                                                                                                                                    |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Skip**                  | Adds the tag(s) to the request, then skips the remainder of the traffic evaluation process (similar to the *Bypass* option in [ACL Profiles](/console-walkthrough/security/acl-policies#action-lists-and-some-typical-applications)). Note that any `Response` phase [Edge Functions](/console-walkthrough/sites/edge-functions) will still be executed (as they are not part of the evaluation process). |
| **Block**                 | Adds the tag(s) to the request, and sends a response to the user with the defined *Response headers*, *Status code*, and *Content*.                                                                                                                                                                                                                                                                       |
| **Challenge**             | Adds the tag(s) to the request, and issues a [bot challenge](/reference-information/hostile-bot-detection-lwcsi) to verify that the user is human.                                                                                                                                                                                                                                                        |
| **Interactive Challenge** | Adds the tag(s) to the request, and issues an [interactive challenge](/console-walkthrough/system/interactive-challenge) to verify that the user is human.                                                                                                                                                                                                                                                |
| **Monitor**               | Adds the tag(s) to the request, and continues to the next stage of [traffic processing](/how-link11-waap-works/traffic-filtering-process) without responding to the user. Admins can also define *Request headers* to add to the request as it is passed upstream.                                                                                                                                        |

#### Prioritization

Sometimes Link11 WAAP must choose one of several potential Actions. For example, when a request matches the conditions for multiple [Global Filters](/console-walkthrough/security/global-filters), each Filter will include an Action. The system must execute the highest-priority one.

The priority hierarchy is, from highest to lowest:

* Skip
* Block
* Challenges (bot and/or interactive)
* Monitor

### Tags

A list of one or more tags, separated by spaces. When this Action is triggered, these tags will appear in the traffic logs.

### Request headers (only available for `monitor` Actions)

Additional header(s) to add to the request, which will be sent to the backend.

### Status code (only available for `block` Actions)

The status code returned to the user.&#x20;

### Response Headers (only available for `block` Actions)

A list of header(s) to add to the response that is sent to the user, specified as the header name and its value. Example: `content-type` and `text/html`.&#x20;

### Content (only available for `block` Actions)

The response sent to the user, of the appropriate format and type. Example: if there is a Request Header of `content-type` and `text/html`, then this should begin with `<html>` and end with `</html>`.

This field can contain tokens (preceded and followed by `%`, as shown in the example below), to customize the response sent to the client:

| Token        | Comment                                                                                                                 |
| ------------ | ----------------------------------------------------------------------------------------------------------------------- |
| Client\_IP   | The client's IP address                                                                                                 |
| Timestamp    | The request's timestamp                                                                                                 |
| Status\_Code | The HTTP status code being returned to the client                                                                       |
| Host\_Domain | Domain of the destination URL                                                                                           |
| Request\_ID  | A unique identifier for the request, used internally by Link11 WAAP (and which also appears in the Events Log)          |
| Session\_ID  | A unique identifier for the client's session, used internally by Link11 WAAP (and which also appears in the Events Log) |

By default, Link11 WAAP comes with a rich HTML page, as shown in the screenshot above.

Here's an example of the *Content* for a simpler token-based response:

```
Access Denied

Request was:
received at %Timestamp%
from IP address %Client_IP%
sent to %Host_Domain%
and was answered with response code %Status_Code%.
```


# Dynamic Rules

Banning or monitoring traffic sources that violated defined limits

<figure><img src="/files/jHKxsGd3zw7uPbHP3HdH" alt=""><figcaption></figcaption></figure>

## Overview

The Dynamic Rules section defines security rulesets that evaluate various criteria over time. When traffic sources commit activities that exceed defined thresholds, those traffic sources can be banned, or merely reported on within the Dashboard and Events Log.&#x20;

Note that **Dynamic Rules do not block individual requests based on their content; they define actions to take against the&#x20;*****sources*****&#x20;of requests.** Individual incoming requests are blocked elsewhere, e.g., in [ACL Profiles](/console-walkthrough/security/acl-policies) or in processing stages that include [Actions](/console-walkthrough/security/actions).

Dynamic Rules have similarities to [Rate Limit Rules](/console-walkthrough/security/rate-limit-rules): both types of Rules include thresholds and time frames, and each Rule includes an allowable number of events that can occur within a defined period of time.

However, there is an important difference:

* Rate Limit Rules are evaluated while an incoming request is being processed. A violation will result in an action being taken against that request.&#x20;
* Dynamic Rules are evaluated later, during periodic queries of the traffic logs. They are used to examine requests in the traffic log that have already been passed or blocked. A violation will result in an action being taken against *future* requests from the responsible traffic source.

Dynamic Rules have many potential uses. A common one arises from the nature of Rate Limit Rules, which can only block persistent attackers for short periods of time (as discussed [here](/console-walkthrough/security/rate-limit-rules#blocking-persistent-violators)). Dynamic Rules can place violators into [quarantine](/console-walkthrough/security/quarantined) for extended periods of time, during which all requests from those traffic sources are blocked.&#x20;

Lastly, although Dynamic Rules are commonly used with Rate Limit Rules, they can be used independently as well, and have many other potential applications.

## How a Dynamic Rule works

<figure><img src="/files/F4oFsyMMiyzVo1xvV62X" alt=""><figcaption></figcaption></figure>

Dynamic Rules work together with [Global Filters](/console-walkthrough/security/global-filters) and the [Quarantine](/console-walkthrough/security/quarantined) list.

When a Dynamic Rule is created, Link11 WAAP auto-generates a corresponding [dynamic Global Filter](/console-walkthrough/security/global-filters#dynamic-global-filters). Initially, the Global Filter will not have any effect on incoming traffic.

{% hint style="info" %}
Dynamic Global Filters are managed automatically by L11WAAP. They are not visible to, or editable by, admins. They are described here so that admins understand how the system operates.
{% endhint %}

As incoming requests are received and processed, L11WAAP periodically queries the traffic logs, and uses the Dynamic Rules to evaluate the most recent requests.&#x20;

{% hint style="info" %}
The timing and frequency of these evaluations will depend on the *Threshold* parameters defined for the currently active Dynamic Rules. L11WAAP selects the optimal frequency for promptly identifying Rule violators, while still minimizing the number of queries and amount of data that must be pulled from the traffic logs for analysis.
{% endhint %}

When a traffic source is found to have violated a Dynamic Rule, the following occurs:

* A [Security Alert](/console-walkthrough/system/security-alerts) will be sent (if any were configured for this Dynamic Rule and the relevant Server Group).
* The Rule's Global Filter is updated automatically to include the offending traffic source.
* The traffic source is added to the Quarantine list.

For all subsequent requests from that traffic source, the Global Filter will:

* Attach the Dynamic Rule's *Tags*
* And execute the Rule's *Action.*

This situation will continue until either of the following occurs:

* The Rule's *Quarantine time* expires
* Or an admin manually removes the traffic source from the Quarantine list (see more below about the effects of this).&#x20;

At that point, the traffic source will no longer be on the Quarantine list, and will also be removed from the Global Filter.

{% hint style="info" %}
In the discussion above, "traffic source" describes the source(s) that sent the requests which violated the Dynamic Rule. This might be a single entity, or multiple entities, depending on the admin's choice of the *Target* parameter.\
\
For example, an admin could choose to enforce a Dynamic Rule on each IP address separately, or on all requestors collectively within a country, or on all requestors collectively who submitted a certain header or argument, etc.
{% endhint %}

{% hint style="info" %}
Appearing on the "Quarantine" list does not necessarily mean that a traffic source has been banned. It only means that a traffic source has exceeded a Dynamic Rule, and that currently, its requests will trigger the Rule's Action. \
\
Often, this will be a blocking action. However, admins might also choose to merely monitor the traffic source's behavior without banning it.
{% endhint %}

### Offloading blocking actions

When the planet is deployed on a Link11 private cloud, and a Dynamic Rule is configured with an IP blocking action, admins have the ability to offload the IP blocking to Link11's Layer 3 protection. \
\
During DDoS attacks, these requests will be blocked before they reach L11WAAP; therefore, this will increase performance, and reduce the scaling necessary for the system to handle the attack. During this time, the traffic sources will still be listed on the [Quarantined](/console-walkthrough/security/quarantined) page, and will be designated there as having been offloaded.

Note that while offloaded blocking is occurring, the blocked requests will not be received by L11WAAP; thus, they will not be counted toward violations of other Dynamic Rules or Rate Limit Rules.

## Exempting a traffic source from evaluation

Traffic sources can be exempted from Dynamic Rule enforcement by adding one of their tags to the Rule's *Exclude* list.

### Eliminating False Positives

If a traffic source is being incorrectly quarantined, it should be manually deleted from the Quarantined list. The next time that Dynamic Rules are evaluated, the following will occur:

* The quarantine will end.
* The Dynamic Rule's corresponding Global Filter will be updated, so that requests from this traffic source will no longer receive the Rule's *Tags* and *Action*.
* The Dynamic Rule will be automatically updated to allowlist the traffic source, by adding a tag for the traffic source's IP (or whatever identifier is being used as the *Target*) to the *Exclude* list.

## Usage within applications and APIs

Unlike some other types of security settings, Dynamic Rules are not assigned to paths in [Security Policies](/console-walkthrough/security/security-policies).

Instead, each Policy has its applicable scope defined by the *Active mode*, *Include*, and *Exclude* parameters, as described below.

## Administration

The main window (shown above) lists all current Dynamic Rules.

The administration (addition/deletion/editing/versioning) of Dynamic Rules follows the conventions described [here](/how-link11-waap-works/ui-overview-and-common-elements#configuration-and-administration).

## Components

<figure><img src="/files/hAUhEryM7C00JjfFoZQA" alt=""><figcaption></figcaption></figure>

A Dynamic Rule consists of the following:

* Parameters defining its applicable scope \[*Active mode*, *Include*, and *Exclude]*
* The definition of an entity, i.e. how to combine incoming requests for counting purposes \[*Target*]
* The behavioral limits for each entity \[*Number of events*, *Time frame*]
* What the system should do when the behavioral limits are exceeded \[*Action*], which part of the system should do it \[*Offload IP blocking*], and how long it should be done \[*Quarantine time*]
* *Tag*(s) to attach to requests that are currently being quarantined
* General parameters for administration \[*Name*, *Description*]

## Individual parameters

### Name

A name for this Rule, to be used within the interface.&#x20;

### Active mode

When this is enabled, this Rule will be applied within the scope defined by the *Include* and *Exclude* lists. Otherwise, it will not be enforced.&#x20;

{% hint style="info" %}
When *Active mode* is changed to "off", admins should check the [Security Alerts](/console-walkthrough/system/security-alerts) list, to see if any Alerts are based upon this Dynamic Rule. As long as the Rule remains inactive, it will not fire any Alerts.
{% endhint %}

### Description

Information about this Rule, for use within the interface.

### Target

The entity that will be evaluated for this Dynamic Rule, and that will be quarantined if the Rule is violated.&#x20;

For example, selecting `IP` means that each IP address in the traffic logs will have its requests counted separately, and if a violator is found, that IP will be quarantined. On the other hand, selecting `ASN` will combine all requests from all IPs within each ASN, and a violation will result in all IPs from that ASN being quarantined.

Some values for *Target* also require an associated value for *Target key,* e.g. the name of a specific header, cookie, etc.

### Offload IP blocking

As described [above](#offloading-blocking-actions), admins can choose to block Dynamic Rule violators with Link11's Layer 3 protection. This option will be available when the planet is deployed on a Link11 private cloud, and an IP blocking action is selected.

When this option is enabled, and the change is [published](/using-the-product/best-practices/publish-your-changes), it will apply to new violations of the Dynamic Rule. In other words, traffic sources currently in quarantine will continue being blocked by L11WAAP until the quarantine expires.

### Number of events

The number of permissible requests within the specified *Time frame*. Exceeding this number is a violation of the Rule and triggers the *Action*.

### Time frame

The period of time within which the *Number of events* is enforced.&#x20;

### Action

The action to take when the *Target* exceeds the *Number of events* during the *Time frame*.

### Quarantine time

The period of time to keep the traffic source in quarantine, and execute the *Action* for its requests.

### Tags

The tag(s) to include in the Global Filter that is constructed for this Dynamic Rule.

### Include and Exclude

The *Include* and *Exclude* tag lists define the applicable scope of this Dynamic Rule. Their use is described on the [UI Overview](/how-link11-waap-works/ui-overview-and-common-elements#include-and-exclude-filter-lists) page.

## **Example use cases for Dynamic Rules**&#x20;

### **Banning rate-limit violators for specific URLs**

Unlike Rate Limit Rules (which can be enforced against specific target URLs via Security Policies), Dynamic Rules are global by default.

However, they can still be limited to specific paths/targets by using a Global Filter to attach descriptive tag(s) to the appropriate requests, and then using the tag(s) in the Dynamic Rule's *Include* and *Exclude* lists.

### Limiting enforcement to certain categories of requests

Global Filters can be used to limit enforcement of a Dynamic Rule to certain types of requests (e.g., HTTP methods, non-static files, etc.).&#x20;

For example, to enforce a Dynamic Rule only upon POST requests, a Global Filter could attach `method-post` to all incoming POST requests, and the Dynamic Rule would only *Include* `method-post`.&#x20;

### **Using cookies to ban an attacker who is switching IPs**

By using a cookie threshold, it is possible to quarantine hostile traffic originating from the same source, even if the attacker is changing IP addresses. This can be done by selecting a *Target* of cookie, with a *Target key* of `waap_id` (the cookie that L11WAAP sets for all traffic sources).


# Quarantined

Display and manage the list of quarantined traffic sources

<figure><img src="/files/ui55DyF3qeJVtQlWXMmc" alt=""><figcaption></figcaption></figure>

## Overview

The **Quarantined List** page shows a list of traffic sources that have triggered one or more [Dynamic Rules](/console-walkthrough/security/dynamic-rules). While a traffic source is on this list, Link11 WAAP responds to all of its requests automatically with the Dynamic Rule's *Action*.

This is often used to ban a persistent violator of other security rulesets, but it can also be used merely to monitor a traffic source for a period of time. An explanation of the quarantining process is [here](/console-walkthrough/security/dynamic-rules#how-a-dynamic-rule-works).

## Administration and Use

### Viewing quarantines

Each quarantined traffic source will have an entry in the list. Long lists will be broken up across multiple pages, which can be navigated using the controls at the bottom of the page.

The overall list can be sorted according to the values in each column by using the Filter control at the top.&#x20;

### Cancelling quarantines and preventing False Positives

Traffic sources will be automatically removed from the Quarantine list when their quarantines have expired.

They can also be manually deleted. In the UI, this is done by selecting the trash icon at the end of an entry in the Quarantined List.

{% hint style="info" %}
"Manual deletion" refers to deletion by an admin through either the UI or the API. Both methods produce the same results, as described below.
{% endhint %}

When a traffic source is manually deleted from the list, L11WAAP understands this to mean that the quarantine was a False Positive.&#x20;

Therefore, when the next cycle of Dynamic Rule evaluation occurs, the Rule's corresponding Global Filter will be updated by removing the traffic source from its *Rule* list. Subsequent requests from that traffic source will not automatically receive the Rule's *Tags* and *Action*., unless/until that traffic source violates the Dynamic Rule again.

To exempt the traffic source from further Dynamic Rule enforcement, an admin should add appropriate tag(s) to the Dynamic Rule's *Exclude* list.

{% hint style="info" %}
If L11WAAP has quarantined a traffic source and you wish to reverse this decision, the procedure above (editing the Quarantine list) should be performed. L11WAAP will update the corresponding Dynamic Rule and Global Filter automatically.\
\
Do not try to accomplish this by editing the Global Filter itself (which is non-editable in the UI, but could still be changed via API). Manually editing the Global Filter will not work; the next time Dynamic Rules are evaluated, the system will take everything that's currently quarantined and add it back to the Global Filter.
{% endhint %}


# Content Filter

This section provides settings for content filtering:

{% content-ref url="/pages/-LuhREt20YEkB4JdQWYa" %}
[Content Filter Profiles](/console-walkthrough/security/content-filter/profiles)
{% endcontent-ref %}

{% content-ref url="/pages/-LuhRUcnzXG-FalaisNk" %}
[Content Filter Rules](/console-walkthrough/security/content-filter/rules)
{% endcontent-ref %}


# Content Filter Profiles

Filtering requests based on their content

<figure><img src="/files/M8KHVgakmwINOOkkNclz" alt=""><figcaption></figcaption></figure>

## Overview

Content Filtering is the final stage of traffic processing. This fulfills the role of a traditional WAF, which is to examine the content of a request for specific signatures and take specific actions when matches are found.

A Content Filter Profile associates signatures ([Content Filter Rules](/console-walkthrough/security/content-filter/rules)) with specific actions, and includes some other parameters as well.&#x20;

### Circumstances where content filtering will not occur

{% hint style="info" %}
A request will not be subjected to content filtering if any of these are true:

* It was blocked during a previous stage of processing.
* It triggered a Skip action in a [Global Filter](/console-walkthrough/security/global-filters), or Bypass in the [ACL Profile.](/console-walkthrough/security/acl-policies)
* Its destination URL matches a [Security Policy](/console-walkthrough/security/security-policies) which does not have an active Content Filter Profile assigned to it.

As discussed below, there are also several stages within the content filtering process where some or all of a request might be exempted from filtering.
{% endhint %}

## Usage within applications and APIs

A Content Filter Profile is assigned to paths/URLs within applications and APIs via [Security Policies](/console-walkthrough/security/security-policies).

When a request is received, the system checks its destination URL, and uses the Profile that best matches it.

Out of the box, the system includes a default Content Filter Profile. It can be edited, but it cannot be deleted. It is used for all URLs where no other Profile has been assigned.

## Administration

The main page lists all current Content Filter Profiles.

The administration (addition/deletion/editing/versioning) of Profiles follows the conventions described [here](/how-link11-waap-works/ui-overview-and-common-elements#configuration-and-administration).

## The Content Filtering process

Content filtering is a multi-step process:

1. **Data Masking:** sensitive data in the request is masked, so that it does not appear in traffic logs.
2. **Content Type Checking:** if one or more *Restrict content type* settings are enabled, they are enforced.
3. **Allowlisting**: if the request has one or more specified tags in the *Ignore* list, it is exempted from further processing.&#x20;
4. **Content Filtering**: several forms of content limits are checked. The request's parameters (its destination URL, headers, cookies, and arguments) are then examined. Tags are added to the request based on [Content Filter Rules](/console-walkthrough/security/content-filter/rules), except for the Rules (if any) that were configured to be ignored.
5. **Tag Evaluation**: the request's tags are evaluated for reporting and/or action purposes.

Each step is described in more detail below. For context, here is a graphic showing the controls/sections within the UI that are used in each step:

<figure><img src="/files/5NJ7Z68QETY8iuK6sQGn" alt=""><figcaption><p>Click to expand this image.</p></figcaption></figure>

And here is a flowchart of the process described below, with captions along the top representing the relevant steps:

<figure><img src="/files/sNxERTE3CQU9EOa5Rn7P" alt=""><figcaption><p>Click to expand this image.</p></figcaption></figure>

### Step 1: Data Masking

For parameters listed in the [Constraints](#constraints) list with the *Mask?* option enabled, their values are replaced by hashes of these values with the *Masking seed*.

### Step 2: Content Type Checking

If the *Ignore Body* setting is not enabled, and one or more *Restrict content type* settings are enabled, the request is evaluated against them. If the request cannot be parsed according to one of the specified types, the *Action* will be executed.&#x20;

### Step 3: Allowlisting

Before content filtering is performed, the tags that are already attached to the request are evaluated. (These tags could be the result of [Global Filters](/console-walkthrough/security/global-filters), [Rate Limit Rules](/console-walkthrough/security/rate-limit-rules), or [Flow Control Policies](/console-walkthrough/security/flow-control-policies).)

If any tag is found in the *Ignore* list, the request is exempted from content filtering (i.e., [Step 4](#step-4-content-filtering) and [Step 5](#step-5-tag-evaluation) below do not occur). This allows certain requests to be allowlisted (for example, if they are from a trusted source), avoiding the overhead of unnecessary processing.

{% hint style="info" %}
Link11 WAAP deployments include two default tags in the *Ignore* list:

* &#x20;`let-s-encrypt` enables customers to use Let's Encrypt to [generate or renew their own SSL certificates](/using-the-product/how-do-i.../generate-or-renew-my-own-ssl-certificates).
* `malformed-body` prevents Content Filtering from being applied to malformed request bodies. Removing this tag from *Ignore* will result in tighter security, but can potentially result in performance degradation and False Positive alarms.
  {% endhint %}

### Step 4: Content Filtering

Each parameter (the target URL and each header, cookie, and arg) of the request is processed.&#x20;

The target URL is compared to the [Exclusions](#exclusions) list, which potentially exempts the URL and other request parameters from evaluation against specific Content Filter Rules.

Then the non-URL parameters are examined. Each parameter and its value are compared to the entries in the [Constraints](#constraints) list: the entries in its *All* section and also the relevant parameter-type section (either *Headers*, *Cookies*, or *Arguments*). The *Constraints* list allows the following to be defined:

* The parameters, if any, whose values should be masked.
* The parameters, if any, whose values should be restricted to regex definitions.
* The parameters, if any, which should be exempted from evaluation against specific Content Filter Rules.

For each parameter, the processing occurs in the order described below, until one of the following happens:

* the parameter is exempted from further inspection
* the *Action* is triggered (which also terminates the processing of the request)
* the parameter completes its processing

At that point, the next parameter is processed, until none remain.

**Parameter processing in detail**

* The relevant *Max Count* limit is checked (excluding decoded content). If it is active and the parameter exceeds the limit, the *Action* is triggered.&#x20;
* The relevant *Max Length* limit is checked (excluding decoded content). If it is active and the parameter exceeds the limit, the *Action* is triggered.&#x20;
* If the *Ignore Alphanumeric input* option is enabled, and all the parameter's content is alphanumeric, this parameter is exempted from further inspection.
* If the parameter is the request's target URL:
  * The URL is evaluated against the [Content Filter Rules](/console-walkthrough/security/content-filter/rules). Link11 WAAP iterates through the Rules, and for each one:
    * If the URL matches an active entry in the *Exclusions* list, and any of the Rule's tags are listed in the entry's *Ignore Content Filter Tags***,** this Rule is skipped and its tag(s) are not attached.
    * Otherwise, the Rule's *Match* string is compared to the URL. If a match is found (i.e., if the request's path matches the Rule's signature), the Rule's tags are attached to the request.
* If the parameter is a header, cookie, or argument:
  * If one or more *Constraints* entries have a definition for *Parameter* that matches the parameter's name, the entry that most closely matches it is selected. If an entry was selected, and the parameter's value does not match the entry's *Matching Value*, and the entry's *Restrict?* option is enabled, the *Action* is triggered.
  * The parameter is evaluated against the Content Filter Rules. Link11 WAAP iterates through the Rules, and for each one:
    * If the parameter matches an entry (in both *Parameter* and *Matching Value*), and any of the Rule's tags are listed in the entry's *Ignore Content Filter Tags***,** this Rule is skipped and its tag(s) are not attached.
    * Otherwise, the Rule's *Match* string is compared to the parameter's value. If a match is found, the Rule's tags are attached to the request.
* This parameter has now completed its processing, and the next parameter in the request is selected.

{% hint style="info" %}
A parameter can be exempted from all Content Filtering Rules by including `cf-all` in its *Ignore Content Filter Tags.*
{% endhint %}

{% hint style="info" %}
When the *Action* is triggered, it is executed immediately, and no further content filtering occurs for that request. Therefore, if a request contains more than one type of attack, one will appear in the logs while the remainder will not.
{% endhint %}

### Step 5: Tag Evaluation

All the request's tags, including the list of new tags accumulated in the previous step from Content Filter Rule evaluation, are now compared to the *Report* and *Active* tag lists.

During this process, a request's tags are divided into two categories:&#x20;

* **Specific** tags produced by individual rules (and designated with the Rule name: `cf-rule-id-XXX`)&#x20;
* **General** tags (`cf-all` and all other tags that are not specific)

Specific tags are processed first. This allows admins to set up general configurations for threat categories, while still being able to make exceptions for how specific Content Filter Rules are handled.

The request's list of tags are processed as follows:&#x20;

1. All specific tags are compared to the *Report* list. For each tag that is found there, the relevant Content Filter Rule name will be added to the Events Log's *Monitor reason* field for the request.
2. All general tags are compared to the *Report* list. For each tag that is found there, the relevant Content Filter Rule name will be added to the Events Log's *Monitor reason* field for the request.
3. If any of the specific tags are found in the *Active* list, the *Action* is executed, and processing ceases.
4. If any of the general tags are found in the *Active* list, the *Action* is executed, and processing ceases.

{% hint style="info" %}
Note that in the UI, the *Ignore* list appears next to the *Active* and *Report* lists. However, the *Ignore* list is processed earlier in the content filtering process (see **Step 3: Allowlisting**, above). If any of a request's tags match one in the *Ignore* list, that request is exempted from content filtering.
{% endhint %}

{% hint style="warning" %}
An entry in *Ignore* always "wins". It is dangerous to put anything other than specific tags into it.
{% endhint %}

## Configuring a Positive Security model

Content Filter Profiles can be used as part of a positive security model (where by default, all requests are rejected, except for those identified as being legitimate).

This can be done by ensuring that each parameter (header, argument, or cookie) that could appear within a request is listed in the *Constraints* list, with an appropriate *Matching Value,* and with the *Restrict?* option enabled.

As described above, during processing, each parameter in the incoming request will be evaluated according to the applicable *Matching Value*.

* If it matches, this parameter will pass the test.
* If it does not match, the *Restrict?* setting will cause the *Action* to be executed.

{% hint style="info" %}
If a positive security model is correctly implemented, with *all* possible parameters appropriately defined in the list of *Constraints*, then **Step 5: Tag Evaluation** would seem to be irrelevant. Invalid requests will trigger the *Action* before the *Active* and *Report* lists are evaluated, and only valid ones would remain when these lists are evaluated; thus, in theory, these lists could be left empty. However, to compensate for potential errors or omissions, it is still wise to include general high-risk tags (such as the *cf-rule-risk:5)* anyway.
{% endhint %}

## Components

<figure><img src="/files/KGPjMcIg4rLfzxg8Y91h" alt=""><figcaption></figcaption></figure>

A Content Filter Profile consists of the following:

* Settings for parsing the request (*Restrict content type*, *Decoding*, *Ignore Alphanumeric Input*, *Ignore Body*)
* Settings for processing the request (*Action*, *Tags*)
* Content filtering parameters (the *Constraints* and *Exclusions* lists)
* Parameters for [Step 3: Allowlisting](#step-3-allowlisting) (the *Ignore* list), and [Step 5: Tag Evaluation](#step-5-tag-evaluation) (*Active* and *Report* lists)
* Masking parameters for concealing sensitive information in logs and analytics (*Masking seed*, and *Mask?* setting for individual parameters)
* General administration parameters (*Name*, *Description*)

## Parameters

### Global Parameters

In this context, "global" means "applying to the entire request."

#### Name

A name for this Profile, to be used within the interface. A [system tag](/how-link11-waap-works/tagging#system-tags) (shown below the *Tags* field) will include it as well.

#### Description

Information about this Profile, for use within the interface.

#### Masking seed

An admin-defined string for salting the hash when masking private data. See discussion of the *Mask?* field, below.&#x20;

#### Action

The action that can be executed under the various circumstances described above in [The Content Filtering Process](#the-content-filtering-process).

#### Tags

A list of one or more tags, separated by spaces. Whenever this Content Filter Profile is applied to a request, these tags will appear in the traffic logs.

In addition to these admin-defined tags, the system also shows some [system tags](/how-link11-waap-works/tagging#system-tags) that will be attached as well.

#### Ignore Alphanumeric Input

When this is selected, this Content Filter Profile will not inspect requests that only contain alphanumeric characters. This reduces computational overhead by not evaluating alphanumeric requests. (Hostile requests such as SQLi, XSS, etc., will contain some non-alphanumeric characters.)&#x20;

#### Ignore Body

When this is selected, this Content Filter Profile will not inspect the body of the request.

#### Restrict content type

If *Ignore Body* is not selected, and one or more Content Types are checked, L11WAAP will expect the request to conform to one of them. If the body cannot be parsed according to one of the specified types, the *Action* will be executed. If no Types are checked, no restrictions are enforced.&#x20;

{% hint style="info" %}
This setting can be a useful way to easily block a variety of attacks. For example, when "Multipart Form" is not selected, a user cannot upload any files, thus preventing malware uploads.&#x20;
{% endhint %}

#### Decoding

Which decoding standard(s) should be used.

{% hint style="info" %}
When one or more decoding standards are not applicable, they should be unselected here. This will reduce processing time and overhead.
{% endhint %}

### Allowlisting settings

#### The Ignore list

This list is evaluated before content filtering occurs, as described above in [Step 3](#step-3-allowlisting).&#x20;

{% hint style="info" %}
The interface has three separate places where a tag can be configured to be ignored: here in this section's *Ignore* column, and also in the *Constraints* and *Exclusions* lists (discussed below). \
\
The setting here is global, and will apply to all tags attached to the request. The settings in the *Constraints* and *Exclusions* lists apply only to the evaluation of specific parameters.
{% endhint %}

### The Active and Report lists

These lists define what happens to a request, depending on its tags.&#x20;

They are evaluated after content filtering rules have been evaluated. See the description above of [Step 5](#step-5-tag-evaluation).&#x20;

{% hint style="warning" %}
If a potential tag is not included in the *Active* or *Report* lists, it is effectively in *Ignore* mode. That tag cannot result in the request being blocked, regardless of the severity of the threat signature (i.e., the Content Filter Rule) that produced the tag. \
\
Along with ensuring that all potential tags are properly configured, it is also recommended that each Content Filter Rule has an appropriate Risk Level defined, and that each Content Filter Profile has the highest risk-level tags (e.g., `cf-rule-risk:5`, `cf-rule-id:libinjection-sqli`, and`cf-rule-id:libinjection-xss`) included in the *Active* mode. This ensures that the highest-risk requests will still be blocked.&#x20;
{% endhint %}

### Constraints

These settings define how L11WAAP processes individual parameters within a request during [Step 4](#step-4-content-filtering).

#### Max length

The maximum allowable length of the value for this parameter type (header, cookie, or arg).

#### Max length limit active mode

When enabled, *Max length* is enforced.

#### Max count

The maximum allowable number of this parameter type (headers, cookies, or args).

#### Max count limit active mode

When enabled, *Max count* is enforced.

#### Parameter

The parameter whose value will be compared to the *Matching Value*. This can be provided as a specific *Name* (e.g., `sessionid`), or as a *Regex* to match multiple parameters (e.g., `user_.+`). Note that a *Name* will be marked with `ABC`, while a *Regex* will be marked with `<>`.

#### Matching Value

A regex pattern. If a parameter's value matches it, the *Ignore Content Filter Tags* become relevant. If it does not match, the *Restrict?* option becomes relevant.

#### Restrict?

If a parameter does not match the *Matching Value*, and *Restrict?* is selected, then the *Action* is executed.&#x20;

#### Mask?

Some requests might contain private data which should not be saved to a traffic log. Parameters which match the *Matching Value* and for which *Mask?* is set will be masked / hashed when they are written to the logs, salted with the *Matching Seed* from the global settings.

#### Ignore Content Filter Tags

A parameter whose value matches its *Matching Value*, or which does not match but *Restrict?* is not enabled, will be evaluated against the Content Filter Rules. For each Rule that it matches, that Rule's tags will be attached. Sometimes it is desirable to exempt a parameter from the effects of certain Rules. For example, some Rules filter out special characters; if a parameter can legitimately contain these characters, it would make sense to exempt that parameter from those specific filters. To do this, add the tags from those Rules to this list. These tags will then be ignored for this parameter.

{% hint style="info" %}
Properties are defined in the same way for *Headers*, *Cookies*, and *Arguments* within their respective tabs.
{% endhint %}

### Exclusions

This is similar to the *Constraints* list, and also is used during [Step 4](#step-4-content-filtering), except that it can exempt parameters from Content Filter Rule evaluation based on the request's destination URL.

If a request's URL matches an entry's *Domain* and *Path,* then the entry's *Ignore Content Filter Tags* will exempt the URL and other request parameters from being evaluated against Content Filter Rules containing any of the tags.

Matches depend on the *Case Insensitive* setting, and whether or not the *Active* setting is enabled.

{% hint style="info" %}
When creating an *Exclusion*, note that by default, *Active* is off.
{% endhint %}

{% hint style="warning" %}
If any *Exclusion* entries are specified, the *Path* should be chosen carefully. If the Path is too broadly defined, false negatives can occur.&#x20;

Example: if *Path* is `^/foo`, then a target URL of `/foo/$attack-string` will be exempted from inspection against the Content Filter Rules specified in the *Ignore Content Filter Tags*. Conversely, a *Path* of `^/foo/$` will not match, and the URL will be inspected.&#x20;
{% endhint %}


# Content Filter Rules

Signatures of threats and other potential issues

<figure><img src="/files/4cTDhyIpr4VywBtxKncw" alt=""><figcaption></figcaption></figure>

## Overview

A traditional WAF evaluates incoming requests according to a list of threat signatures, and flags the request if any matches are found.

Within Link11 WAAP, Content Filter Rules provide the equivalent of these signatures, although they are more powerful and flexible than those within a traditional WAF.&#x20;

When a request undergoes the [content filtering process](/console-walkthrough/security/content-filter/profiles#the-content-filtering-process), its content is compared to the Rules administered here. When a request matches a Rule, various tags will be attached to it. Those tags can be evaluated, and can cause actions to be taken on the request.

## Usage within applications and APIs

Content Filter Rules are defined globally within the system, and are available to all Content Filter Profiles.&#x20;

The usage of Content Filter Profiles within applications and APIs is explained [here](/console-walkthrough/security/content-filter/profiles#usage-within-applications-and-apis).&#x20;

## Administration

The main page lists all current Content Filter Rules.

The administration (addition/deletion/editing/versioning) of Rules follows the conventions described [here](/how-link11-waap-works/ui-overview-and-common-elements#configuration-and-administration).

{% hint style="info" %}
Out of the box, L11WAAP includes a wide variety of well-tested Content Filter Rules. Usually, there will be no need to edit their *Match* criteria (which can be quite complicated). Before deleting or editing a default Rule, admins should consider the implications of doing so.&#x20;

If edits are made, and later it becomes desirable to restore an edited Rule to its original form, an admin can revert it using the Versioning capabilities at the bottom of the page.

Alternately, the original request can be duplicated to preserve it, and marked with an appropriate tag (e.g., `inactive`) which could then be added to the appropriate *Ignore* lists.
{% endhint %}

{% hint style="info" %}
For most of the included Rules, their categories and subcategories should make their functions clear. If you have any questions about the purpose of a specific Rule, feel free to [contact Support](/support).
{% endhint %}

## Components

<figure><img src="/files/BfZH0SpKy8oG6GOphQEX" alt=""><figcaption></figcaption></figure>

A Content Filter Rule consists of the following:

* The signature for this Rule. Usually, this represents the characteristics that makes a request hostile. (*Match*)
* Organizational parameters for the Rule (*Category*, *Subcategory*, *Risk level*)
* *Tags* to apply to requests that match this Rule
* *Log message* for requests that match this Rule (this field is not currently used, but will be in a pending release)
* General parameters for administration (*Name*, *Description*)

## Parameters

### Name

A name for this Rule, to be used within the interface. A [system tag](/how-link11-waap-works/tagging#system-tags) (shown below the *Tags* field) will include it as well.&#x20;

For the default Rules included with L11WAAP, the Names are numeric identifiers. (A production deployment will include a large number of Rules; therefore, they are usually organized/administered by their categories and subcategories.)

### Description

Information about this Rule, for use within the interface.

### Category

A general category for this Rule. It will be the basis for a system tag.

### Subcategory

A subcategory for this Rule, within the general Category. It will be the basis for a system tag.

### Risk level

A number ranging from 1 (lowest threat) to 5 (highest threat). It will be the basis for a system tag.

### Tags

A list of one or more tags, separated by spaces. Whenever this Content Filter Rule's *Match* condition matches a request, these tags will be attached.

In addition to these admin-defined tags, the system also shows some system tags that will be attached as well.

The tags are the basis for the decisions made when the applicable [Content Filter Profile](/console-walkthrough/security/content-filter/profiles) is evaluated for a request. They will also appear in the traffic logs.

### Log Message

(This field is not currently used, but will be in a pending release.) A message that will appear in the traffic logs when a request matches the *Match* condition.&#x20;

### Match

The criteria against which incoming requests will be compared. For Content Filter rules only, regexps are of the hyperscan flavor ([syntax](https://intel.github.io/hyperscan/dev-reference/compilation.html#supported-constructs)).


# Sites

This section of the console contains the following options:

* [Server Groups](/console-walkthrough/sites/server-groups): properties of server(s) for sites(s).
* [Backend Services](/console-walkthrough/sites/backend-services): the services that L11WAAP is protecting.
* [Edge Functions](/console-walkthrough/sites/edge-functions): for running custom Lua code.
* [DNS Records](/console-walkthrough/sites/dns-records): information about DNS configuration.
* [Load Balancers](/console-walkthrough/sites/ssl/load-balancers): managing SSL associated with load balancers.
* [Certificates](/console-walkthrough/sites/ssl/certificates): for managing SSL certificates.


# Server Groups

<figure><img src="/files/hbmgFbeUJMYaff2d3VQk" alt=""><figcaption></figcaption></figure>

## Overview

This section defines Server Groups: the highest level of organization within Link11 WAAP. A Server Group is based on a [Proxy Template](/console-walkthrough/sites/proxy-templates), and contains at least one [SSL Certificate](/console-walkthrough/sites/ssl/certificates) and at least one [Security Policy](/console-walkthrough/security/security-policies).

<figure><img src="/files/uiNsn3RqCbtNQUDLvZnM" alt=""><figcaption></figcaption></figure>

## Usage&#x20;

The usage of Server Groups is explained in detail here: [Policy Mapping and Traffic Routing](/how-link11-waap-works/policy-mapping-and-traffic-routing).

Typically, a Server Group represents a single domain.

## Administration

The main window (shown above) lists all currently defined Server Groups.

The administration (addition/deletion/editing/versioning) of these Groups follows the conventions described [here](/how-link11-waap-works/ui-overview-and-common-elements#configuration-and-administration).

## Parameters

<figure><img src="/files/aw16FHrIyitWl3VvhxPk" alt=""><figcaption></figcaption></figure>

### Name

A name for this Server Group, to be used within the interface.

### Challenge's cookie domain

The domain to use when [bot challenges](/reference-information/hostile-bot-detection-lwcsi) are issued.

### Description

Information about this Server Group, to be used within the interface.

### Match Host/Authority Headers

The scope for this Server Group (typically this is a list of domains), specified as a regex. If this list is edited, the edits must be saved before [a new SSL Certificate can be generated](#server-certificate).

### Server Certificate

The [SSL certificate](/console-walkthrough/sites/ssl/certificates) for this Server Group. The **Generate** button will generate a new certificate.&#x20;

{% hint style="info" %}
To avoid errors, the Server Certificate **Generate** button will be disabled if the *Match host/authority headers* field has been edited and the edits have not yet been saved.
{% endhint %}

### CA Certificate

The CA Certificate to use when enforcing mTLS for the domain ([read more about this](/using-the-product/how-do-i.../enable-mtls-mutual-tls)). The available certificates are those defined in the **CA Certificates** tab of the [Certificates](/console-walkthrough/sites/ssl/certificates) page.

In use, CA certificates are verified against the CRLs in the [CRL Distribution Points](#crl-distribution-points) list.

{% hint style="warning" %}
CA Certificate features will only be available if both of the following are true:

* An AWS NLB (Network Load Balancer is being used. (When using a Link11 Load Balancer, contact support.)
* CA Certificates have been [enabled within the System DB](/console-walkthrough/system/system-db#enabling-certificates-for-mtls).
  {% endhint %}

### Mode

Specifies how clients (i.e., end users) should present CA certificates for mTLS validation. Options are:

* \[Off] **Client authentication is disabled**. The system will not request CA certificates from clients.
* \[On] **CA certificate is required for authentication**. The system will request and validate CA certificates from clients.
* \[Optional] **CA certificate is requested but not required for authentication**. The system will not require clients to provide CA certificates. However, if a client does provide a certificate, it must be valid in order for its request to be accepted. If the client provides an invalid certificate (e.g., expired, revoked, or forged), the request will be blocked.

#### Sending CA data to the origin

When CA Certificates are enabled, Link11 WAAP will add headers to requests before passing them to the backend.

If a CA Certificate is provided, Link11 WAAP will add it to the request header, along with these additional headers:

| Header                   | Description                                    | Example Value                      |
| ------------------------ | ---------------------------------------------- | ---------------------------------- |
| SSL\_CLIENT\_VERIFY      | Client certificate verification status         | SUCCESS (valid) / FAILED (invalid) |
| SSL\_CLIENT\_CERT        | Full client certificate in URL encoded         | -----BEGIN CERTIFICATE----- ...    |
| SSL\_CLIENT\_S\_DN       | Client's Subject Distinguished Name (DN)       | CN=John Doe, O=ExampleCorp, C=US   |
| SSL\_CLIENT\_I\_DN       | Issuer (CA) Distinguished Name (DN)            | CN=Example CA, O=ExampleCorp, C=US |
| SSL\_CLIENT\_SERIAL      | Unique serial number of the client certificate | 1234567890ABCDEF                   |
| SSL\_CLIENT\_FINGERPRINT | SHA-1 fingerprint of the client certificate    | 5F:7C:1E:2B:...                    |

If no certificate is provided, the following headers will be passed:

| Header                   | Description                                   | Example Value |
| ------------------------ | --------------------------------------------- | ------------- |
| SSL\_CLIENT\_VERIFY      | Indicates no client certificate was provided  | NONE          |
| SSL\_CLIENT\_CERT        | Empty (not passed or -)                       | -             |
| SSL\_CLIENT\_S\_DN       | Empty (no subject DN since no cert exists)    | -             |
| SSL\_CLIENT\_I\_DN       | Empty (no issuer DN since no cert exists)     | -             |
| SSL\_CLIENT\_SERIAL      | Empty (no serial number since no cert exists) | -             |
| SSL\_CLIENT\_FINGERPRINT | Empty (no fingerprint since no cert exists)   | -             |

### CRL Distribution Points

Link11 supports CRLs (Certificate Revocation Lists). Admins can revoke client certificates that were previously allowed for mTLS authentication, so that unauthorized or compromised clients will be rejected without waiting for certificate expiration.

CRL Distribution Points (CDPs) are URLs where a CRL has been published. When **Enable CRL validation** is enabled, admins can add entries to the *CRL Distribution Points* list.&#x20;

This list shows the current CDPs/CRLs, and for each one, shows whether and when the CRL was successfully obtained and verified.

During mTLS negotiation, if a CA certificate has been specified, the client certificate is validated against the specified CRL(s).&#x20;

* If the certificate is **revoked**, the connection is rejected with a status code of 496. The Events Log will contain an entry with a *Block reason* of  “General: Client certificate revoked.”
* If the certificate is **signed by another CA,** the connection is rejected with a status code of 495. The Events Log will contain an entry with a *Block reason* of  “General: Client certificate could not be verified.”
* If the certificate is **not in the CRL**, the connection succeeds (assuming other validation checks pass).

{% hint style="info" %}
If the *CRL Distribution Points* list is populated, Link11 WAAP will fetch CRL data from the specified URL(s) every eight hours.
{% endhint %}

### Security policy

The [Security Policy](/console-walkthrough/security/security-policies) for this Server Group, with its parameters displayed for convenience.

### Proxy template

The [Proxy Template](/console-walkthrough/sites/proxy-templates) that this Server Group is based upon.

### Mobile Application Group

The [Mobile Application Group](/console-walkthrough/sites/mobile-application-groups) for this Server Group, if any.


# Proxy Templates

<figure><img src="/files/bmWcLVlNYAJmmAPVrN1b" alt=""><figcaption></figcaption></figure>

## Overview

Link11 WAAP acts as a reverse proxy; it receives requests from clients (web visitors, API clients, etc.), blocks hostile traffic, and passes legitimate requests to the backend.

Proxy Templates define L11WAAP's behavior as a proxy. They are templates for creating new sites (i.e., [Server Groups](/console-walkthrough/sites/server-groups)) within Link11 WAAP.&#x20;

{% hint style="info" %}
When new sites are created, they remain linked to their underlying templates. Revising a Proxy Template will automatically update all sites that are based upon it.
{% endhint %}

## Components

<figure><img src="/files/8vrvmopKGdFJRXQ4bhcT" alt=""><figcaption></figcaption></figure>

A Proxy Template consists of the following:

* General parameters for administration
* Frontend settings, defining L11WAAP's interaction with clients
* Backend settings, defining L11WAAP's interaction with backend servers
* Trusted Sources, defining trusted sources of traffic (e.g., load balancers and CDNs)
* Advanced Configuration, defining additional customization&#x20;

## General Parameters

### Name

A name to be used within the interface.

### Description

Information about this Template, to be used within the interface.

## Frontend Settings

### General frontend settings

#### Client IP header name

Defines one or more header fields within which L11WAAP can find the client's IP address. This field accepts up to five header names; their priority is determined by their order of entry here.

When the system receives an incoming request from a client, the request will have passed through a load balancer on its way to L11WAAP. This means that the header will contain the client's IP and the load-balancer IP. These two IPs are usually found within the `X-Forwarded-For` field (which is the default entry here). In this situation, L11WAAP knows how to extract the client IP from this field. In other situations, a different field name might be necessary. For example, if the customer is using Akamai CDN, the incoming request will have the client IP in a field named `True-Client-IP` instead.

### Size Limits

You can place limits on the amount of data that users can upload to the system. The defaults usually work well; however, if your application accepts user-generated content or other large files, then changes to these settings might be necessary.

{% hint style="info" %}
Please note that if you increase these settings within L11WAAP, then the upstream server should also be configured to accept and store the quantity of data that L11WAAP will (potentially) pass through.
{% endhint %}

#### Client max body size

Specifies the maximum accepted body size of a client request, as indicated by the request header Content-Length. Size in MBs.&#x20;

### Application IP Rate Limits

These settings allow you to limit the amount of resources consumed by an IP address. The system can limit consumption by the **average** number of requests per second, while also allowing temporary **bursts** at a higher rate.&#x20;

When a requestor exceeds any of these thresholds, subsequent requests will be answered with error code `503 (Service Unavailable)`.

{% hint style="info" %}
Note that this rate limiting applies across the entire application. For example, if one IP address is submitting requests to multiple URLs within a web application, all the requests are combined when determining if rate limits have been violated.\
\
If you need more flexibility, consider using [Rate Limit Rules](/console-walkthrough/security/rate-limit-rules) instead.
{% endhint %}

#### Requests per second per IP address

Sets the allowable request rate per IP, per second: i.e., the allowable per-second average of incoming requests, enforced on an incremental basis (where "increment" refers to the number of milliseconds allowed for one request).

**Example:** This is set to 100. Thus, 100 requests are allowed per second. However, the system does not enforce rate limits on a per-second basis; it used a granularity of milliseconds. Therefore, it will allow one request every 10 milliseconds. (100 r/s, divided by 1000 ms/s, equals 1r/10ms.)

#### Burst of requests per second per IP address

Sets the allowable additional burst rate per IP, per second. The additional requests are accepted and placed into a queue.

**Example:** Let's say that the previous field (*Requests per second per IP address*) is set to 100. Without burst limits—i.e., if this field were set to zero—the system will reject every request that was received less than 10ms after the previous one. However, the burst limit is set to 20 instead. This means that L11WAAP will accept 21 requests (1 original plus 20 additional) per 10 milliseconds. In other words, when a request is received, up to 20 more can be received and accepted within the following 10 ms. If instead 25 total requests are received during that time, the last four requests will be denied with a 503 error.

### Timeouts

The Timeout settings allow the system to monitor the time required to serve resources to each client. Any connection that exceeds the specific limits will be dropped.&#x20;

{% hint style="info" %}
**Why timeouts are important**

Some DDoS tools (e.g., R-U-Dead-Yet, or RUDY) send a relatively small quantity of traffic requests, but do so as slowly as possible (often with each byte sent separately). While a legitimate request can be resolved in milliseconds, a single RUDY client can tie up server resources for several minutes. Even a few hundred of these machines attacking a server can be very destructive.
{% endhint %}

The Timeout settings allow L11WAAP to block unresponsive requestors, whether their unresponsiveness is malicious or not. For most deployments, the default timeout settings work well. They are sufficient to filter out hostile traffic, while still accommodating even those users with low bandwidth.

All times are specified in seconds.

#### Client body timeout

If the body is not obtained in one read-step, this timeout begins. If the timeout expires and the client has still sent nothing, the L11WAAP Gateway returns error `Request time out (408)`.

#### Keepalive Timeout

The timeout for keep-alive connections with the client. The L11WAAP Gateway will close connections after this time. This setting increases server efficiency; it allows the server to re-use browser connections and save resources. When changing this value, special care should be taken; in some cases, it depends on specific cloud vendor and load balancer settings.&#x20;

#### Client header timeout

How long to wait for the client to send a request header. If the header is not received within this time, L11WAAP returns error `408 (Request Timeout)`.

#### Send timeout

Specifies the response timeout to the client. This timeout does not apply to the entire transfer but, rather, only between two subsequent client-read operations. Thus, if the client has not read any data for this amount of time, the L11WAAP Gateway shuts down the connection.

### Header Sizes

For more info on the header size settings below, see [this](https://nginx.org/en/docs/http/ngx_http_core_module.html#large_client_header_buffers) and [this](https://nginx.org/en/docs/http/ngx_http_core_module.html#client_header_buffer_size).

{% hint style="info" %}
The multiple of **Large header size** and **Large header buffers** should not exceed load balancer limitations.
{% endhint %}

#### Large header size

The maximum buffer size for accepting client request headers.&#x20;

#### Header buffer size

The default buffer size for accepting client request headers.

#### Large header buffers

The maximum number of buffers for accepting client request headers.

### Body Size

#### Client body buffer size

The maximum buffer size for accepting the client body.

## Backend Settings

### Proxy Connect Timeout

The time (in seconds) for L11WAAP to wait, before treating a connection with the backend as having failed.

### Proxy Send Timeout

The time (in seconds) for L11WAAP to wait, before treating a data transfer attempt to the backend as having failed.

### Proxy Read Timeout

The time (in seconds) for L11WAAP to wait, before treating a downstream (toward Link11) data transfer attempt as having failed.

### Backend Service Host Header

Defines the value of the Host header passed to the backend. The default value (`$host`) sets it equal to the Host header in the incoming request (in other words, the Host header is passed upstream unchanged).

### Real IP Header Name

Defines the field name that contains the client's IP address. L11WAAP is a proxy, and it passes incoming client requests to the upstream server. This means that the server will receive request headers which contain L11WAAP's cloud IP address as the "client" IP. Usually, this is not useful; almost always, the server will need the IP of the actual client instead. To facilitate server logging, analytics, and so on, L11WAAP adds the IP address of the originating client to the headers that it sends to the server. The *Real IP Header Name* defines the name of the field within which this information is passed.

## Trusted Sources

This list defines the ranges of IP addresses which are trusted for providing forwarded IPs: for example, the load balancers in front of L11WAAP, or a CDN.

Each entry in the list can be specified as either:

* A range of IPs
* The name of a [Global Filter](/console-walkthrough/security/global-filters). The Trusted Sources list will link to that Filter, and include its list of IPs; whenever the Filter's IPs are updated, the Trusted Sources list will be dynamically updated as well.&#x20;

Selecting the **+ New** button will display a new entry for editing. Multiple entries can be added.

For each entry, fill in the **Source** field to specify the type (*IP Address* or *Global Filter*), and the **Source value** (the IP range or Global Filter name). The **Comment** field is optional.

## Advanced Configuration

Internally, L11WAAP uses [Nginx](https://nginx.org/en/). A Proxy Template contains a number of commonly-used settings that define Nginx's parameters and behavior. However, there are many other possible configuration changes that an admin might want to make.

The Advanced Configuration section allows admins to define custom code for this purpose.&#x20;

### How it works

Nginx uses configuration files to define its settings. When a Link11 WAAP admin adds Custom Configuration Code to a Proxy Template, and then [publishes](/console-walkthrough/system/publish-changes) the changes, this code is inserted into an individual per-site configuration file. (In other words, each server group can have its own code.) It is then imported into the main nginx.conf file.

During this process, nginx.conf's other contents are not overwritten. L11WAAP extends this file with its various per-site settings.

{% hint style="warning" %}
Be extremely cautious when using the capability. The system will perform some basic validation on custom code (for syntax and so on), but this is not exhaustive; therefore, admins are ultimately responsible to ensure that the code is correct. If incorrect code is executed, this can result in unpredictable system behavior.
{% endhint %}

Some examples are below.

### Parameters

#### Advanced Configuration Name

A name to be used within the interface.

#### Description

A description to be used within the interface.

#### Protocol

Requests with this protocol will trigger the execution of the Custom Configuration Code.

#### Custom Configuration Code

The code which will be executed when requests have the specified Protocol.

{% hint style="info" %}
Custom code can use the directives and variables from [ngx\_http\_upstream\_module](https://nginx.org/en/docs/http/ngx_http_upstream_module.html).
{% endhint %}

In the examples below, there are sections of code delimited by `-----BEGIN SERVER-----` / `-----END SERVER-----`. and `-----BEGIN LOCATION-----` / `-----END LOCATION-----`. These delimiters are not included in the final file; they merely tell L11WAAP where to insert the code.

* Code inside the SERVER delimiters will be placed into a `server {}` block. (This code can include one or more nginx `location {}` blocks.)
* Code inside the LOCATION delimiters will be placed within a `location / {}` block for the specific server group.
* Code without any delimiters will be placed into the `server {}` block.

Below are some examples.

#### Example 1

```
-----BEGIN SERVER-----
ssl_client_certificate /etc/zzzz-client-cert-mydomain.crt;
ssl_verify_client on;
ssl_verify_depth 3;
-----END SERVER-----
-----BEGIN LOCATION-----
-----END LOCATION-----

```

#### **Example 1 discussion**

This snippet configures SSL client certificate authentication on the Nginx server, requiring clients to present valid certificates. The server uses the certificate authority file at /etc/zzzz-client-cert-mydomain.crt to validate the client's certificate, allowing up to 3 levels of intermediate certificates in the validation chain. There are no specific configurations for any URL locations.

Here is a detailed explanation.

```
ssl_client_certificate /etc/zzzz-client-cert-mydomain.crt;
```

Specifies the path to the client certificate authority (CA) file. This file contains the trusted CA certificates (in this case, zzzz-client-cert-mydomain.crt) that are used to verify the client's SSL certificate.

```
ssl_verify_client on;
```

This turns on SSL client verification, meaning the server will require and verify client certificates. Any client trying to connect to this server must present a valid SSL certificate signed by a trusted authority specified in the ssl\_client\_certificate file.

```
ssl_verify_depth 3;
```

Defines the maximum verification depth for the client certificate chain, meaning that Nginx will verify up to 3 levels of intermediate certificates. This ensures that the certificate chain presented by the client is valid up to the root certificate authority.

```
-----BEGIN LOCATION-----
-----END LOCATION-----
```

This section is empty, indicating that no specific configurations are defined for any particular location in this part of the file. However, in the broader context of Nginx configurations, this would be where you define behavior for specific paths or endpoints on the server, such as /api or /login.

#### Example 2

```
-----BEGIN SERVER-----
location ^~ /.well-known/acme-challenge/ {
  proxy_set_header rbz-letsencrypt 931f5de197188ad0ab3e2de3efeb4d60b15767dff448fbd0;
  proxy_set_header Host myplanet.app.reblaze.io;
  proxy_pass https://myplanet.app.reblaze.io;
  add_header Cache-Control "max-age=0, no-cache, no-store";
  add_header expires "Thu, 01 Jan 1970 00:00:01 GMT";
  add_header Pragma no-cache;
}
-----END SERVER-----
-----BEGIN LOCATION-----
-----END LOCATION-----

```

#### Example 2 discussion

By default, Let's Encrypt is supported only on port 80 (the http protocol). If for some reason the request is received over HTTPS (note that on Cloudfront there is a redirect from HTTP to HTTPS), it needs to be allowed. The code above adds validation on HTTPS.

#### Example 3

```
location / {
  proxy_http_version  1.1;
  proxy_pass $active_upstream;
  proxy_set_header Upgrade $http_upgrade;
  proxy_set_header Connection $connection_upgrade;
  proxy_set_header Host $host:$proxy_port;
  proxy_set_header X-Real-IP $remote_addr;
  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  proxy_set_header X-Forwarded-Proto $scheme;
  proxy_pass_request_headers on;
  access_by_lua_block {
    local hooks  = require "hooks"
    hooks.trigger_access()
  }
  header_filter_by_lua_block {
    local hooks  = require "hooks"
    hooks.trigger_header()
  }
  add_header X-Cache-Status $upstream_cache_status;
}
```

#### Example 3 discussion

This configuration proxies requests for a certain location (the root) to an upstream server, handling WebSocket connections and forwarding various headers like real client IP and protocol. Lua scripting is used to inject custom logic during the request and response phases, and the caching status of the upstream is also added to the response headers.

```
proxy_http_version  1.1;
```

Configures Nginx to use HTTP/1.1 when communicating with the upstream server.

```
proxy_pass $active_upstream;
```

Passes the request to the upstream server, which is dynamically defined by the $active\_upstream variable.

```
proxy_set_header Upgrade $http_upgrade;
```

Sets the Upgrade header to the value of $http\_upgrade, typically used for WebSocket connections or other HTTP protocol upgrades.

```
proxy_set_header Connection $connection_upgrade;
```

Sets the Connection header to the value of $connection\_upgrade. This also relates to keeping WebSocket or other persistent connections alive.

```
proxy_set_header Host $host:$proxy_port;
```

Modifies the Host header that is passed to the upstream server to include the requested host and port.

```
proxy_set_header X-Real-IP $remote_addr;
```

Adds a header to pass the client’s real IP address (from $remote\_addr).

```
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
```

Sets the X-Forwarded-For header, which includes the original IP address of the client, useful for tracking traffic through multiple proxies.

```
proxy_set_header X-Forwarded-Proto $scheme;
```

Sets the protocol used for the request (HTTP or HTTPS) in the X-Forwarded-Proto header.

```
proxy_pass_request_headers on;
```

Ensures that the request headers are forwarded to the upstream server.

```
access_by_lua_block {
  local hooks = require "hooks"
  hooks.trigger_access()
}
```

Lua blocks now customize how requests and responses are processed. First, a script is run at the access phase of the request. This script requires a Lua module called hooks and calls the trigger\_access() function. This can be used to run custom logic like authentication, logging, or modifying requests.

```
header_filter_by_lua_block {
  local hooks  = require "hooks"
  hooks.trigger_header()
}
```

Next, a Lua script is run during the header filter phase (typically after the response headers are received from the upstream server but before they are sent to the client). The trigger\_header() function can modify or inspect response headers.

```
add_header X-Cache-Status $upstream_cache_status;
```

Adds a custom header (X-Cache-Status) to the response, reflecting the caching status of the upstream server.

#### Example 4

```
location = /public/notification {
  access_by_lua_block {
    local session = require "session"
    local metadict = require "metadict"
    local metadict_set = metadict.metadict_set
    
    metadict_set("profiler", ngx.now(), 'rbz_start_req_proc')
    session.process_request()
    metadict_set("profiler", ngx.now(), 'rbz_done_req_proc')
  }
  header_filter_by_lua_block {
    local metadict = require "metadict"
    local metadict_set = metadict.metadict_set
    metadict_set("profiler", ngx.now(), 'rbz_start_response')       
  }
  proxy_cache_bypass 1;
  proxy_no_cache 1;
  add_header X-Cache-Status $upstream_cache_status;
  proxy_buffering off;
  proxy_pass https://mydomain_ssl;
}
```

#### Example 4 discussion

This Nginx configuration block handles requests for the path /public/notification, forwarding them to an upstream HTTPS server. Lua scripts are used to log profiling data for request and response processing times. Caching is disabled, and the response is sent directly without buffering. The use of session handling (session.process\_request()) suggests some form of user/session validation or similar logic.

```
location = /public/notification {
```

Specifies that this block handles requests to the exact URL /public/notification.

```
access_by_lua_block {
```

Begins Lua scripting for request handling.

```
 local session = require "session"
```

Loads a Lua module named "session". This module is likely responsible for session management or processing the request in some way.

```
local metadict = require "metadict"
```

Loads a Lua module called metadict, likely for logging or profiling purposes.

```
local metadict_set = metadict.metadict_set
```

Gets a function metadict\_set from the metadict module to set profiling data.

```
metadict_set("profiler", ngx.now(), 'rbz_start_req_proc')
```

Logs the start of request processing by calling metadict\_set with the current timestamp (ngx.now()), storing it under the key 'rbz\_start\_req\_proc' in a "profiler".

```
session.process_request()
```

Calls a function process\_request() from the session module, which processes the request, likely dealing with authentication, session validation, etc.

```
metadict_set("profiler", ngx.now(), 'rbz_done_req_proc')
```

Logs the end of the request processing by calling metadict\_set again, marking the completion of the request with the timestamp.

Next, there is Lua scripting for response handling.

```
header_filter_by_lua_block {
```

This block runs after the upstream server responds but before the response is sent to the client.

```
local metadict = require "metadict"
```

Loads the metadict module again.

```
local metadict_set = metadict.metadict_set
```

Retrieves the metadict\_set function.

```
metadict_set("profiler", ngx.now(), 'rbz_start_response')
```

Logs the start of the response phase by setting a timestamp for the key 'rbz\_start\_response' in the "profiler".

```
proxy_cache_bypass 1;
```

Instructs Nginx to bypass any caching mechanism for this specific request, meaning the response will not be served from cache.

```
proxy_no_cache 1;
```

Ensures that the response is not stored in the cache for future requests.

```
add_header X-Cache-Status $upstream_cache_status;
```

Adds a custom response header (X-Cache-Status) that contains the upstream cache status, indicating whether caching was used for this request.

```
proxy_buffering off;
```

Disables proxy buffering for this location, meaning that Nginx will not buffer the response and will immediately send it to the client as it receives it from the upstream server.

```
proxy_pass https://mydomain_ssl;
```

Forwards the request to the specified upstream server at <https://mydomain\\_ssl>. This could be a load balancer or an actual backend server, and it's handling the secure HTTPS protocol.&#x20;


# Mobile Application Groups

<figure><img src="/files/iXGCM17f4NzDUpEDyKgb" alt=""><figcaption></figcaption></figure>

## Overview

Link11 WAAP includes a Mobile SDK: a unique client certification mechanism for iOS and Android apps. Customers can publish their applications with the SDK embedded.

In use, the SDK signs the application, authenticates the device, and verifies user identity, adding a cryptographic HMAC signature to each request. The SDK provides a reliable and secure mechanism to confirm that the traffic is originating from a legitimate app user and not a bot or emulator.

### Acquiring the SDK

The latest version of the Mobile SDK, including instructions and code samples, is available here:

{% content-ref url="/spaces/G1lK8HrOf2KYcim5ESTg" %}
[Mobile SDK v2.3.0](https://waap.docs.link11.com/mobile-sdk-v2.3.0/)
{% endcontent-ref %}

Below, we discuss the parameters to configure within L11WAAP for receiving requests from mobile applications.&#x20;

## Usage&#x20;

A Mobile Application Group configures Mobile SDK parameters for a specific [Server Group](/console-walkthrough/sites/server-groups) (which usually represents a domain).

## Administration

The main window (shown above) lists all currently defined Mobile Application Groups.

The administration (addition/deletion/editing/versioning) of these Groups follows the conventions described [here](/how-link11-waap-works/ui-overview-and-common-elements#configuration-and-administration).

## Components

<figure><img src="/files/GbFk3DBntMu2iuZMjzdv" alt=""><figcaption></figcaption></figure>

### Name

The name of this Mobile Application Group, for use within the interface.

### Description

A description of this Mobile Application Group, for use within the interface.

### Token header name (optional)

The name of the header that contains the user authentication token. This can be left blank.

### Grace period

The allowable time between the timestamp of a request and the time that L11WAAP receives the request from the application. Requests with a longer delay will be rejected.

### App signatures

This list contains the SHA-256 digests of recognized certificates.

To find the signature for an iOS app, you can open the *Apple Development Certificate* in the Keychain app, and copy the **SHA-256 fingerprint**. Alternatively, you can [extract](https://stackoverflow.com/a/14885447) this fingerprint from the **ipa** bundle.

For Android app, you can get the SHA-256 fingerprint from the **keystore** or extract it from a signed APK with the **apksigner** tool (part of the Android SDK). See detailed instructions [here](https://security.stackexchange.com/questions/178936/how-to-verify-sha256-fingerprint-of-apk).

When uploading the fingerprint to the L11WAAP Console, make sure that it contains hexadecimal characters only, in lowercase, without spaces.

#### Active mode

Any number of signatures may be 'Active' at given time.&#x20;

{% hint style="info" %}
While debugging the app on an emulator, it will present a special signature: `abadbabe`. Make sure this is not activated on production.
{% endhint %}

### Profiles

This lists the remote profiles that can override the parameters of the SDK on all mobile clients.&#x20;

The **Default** profile is always empty. When it is active, the SDK parameters are fully determined by the app's local configuration. Only one remote profile may be active at a given time.


# Backend Services

<figure><img src="/files/9FoIklmJgPOEOkBo3A7D" alt=""><figcaption></figcaption></figure>

## Video Walkthrough (with an emphasis on Load Balancing) <a href="#video-walkthrough" id="video-walkthrough"></a>

{% embed url="<https://www.youtube.com/watch?v=8rsoUgLd17A>" %}

## Overview

This section defines the Backend Services that Link11 WAAP will protect. In other words, these are the destinations to which Link11 WAAP will send the (legitimate) traffic it receives.

A Service consists of one or more endpoints (defined in the [Endpoint List](#endpoint-list-not-labeled-in-the-ui), discussed below). Each Service can receive traffic for multiple web applications, and for multiple resources/locations within each web application.&#x20;

For a single Service, you can define multiple endpoints. Within them you can:

* Enable and configure load balancing, weighting and distributing traffic across your primary endpoints.&#x20;
* Define backups hosts, to which L11WAAP will failover your traffic when your primary hosts aren’t available.&#x20;
* Take hosts offline for maintenance by ticking a single box in the interface.&#x20;

## Usage within applications and APIs

Backend Services are designated to receive traffic for specific destination URLs in [Server Groups](/console-walkthrough/sites/server-groups).

## Administration

The main window (shown above) lists all currently defined Backend Services.

The administration (addition/deletion/editing/versioning) of these Services follows the conventions described [here](/how-link11-waap-works/ui-overview-and-common-elements#configuration-and-administration).

## Parameters

<figure><img src="/files/085UfdCSFisdWE1VLnFE" alt=""><figcaption></figcaption></figure>

### Name

A name for this Service, to be used within the interface.

### Use HTTP/1.1

Enables HTTP 1.1, which can increase performance due to multiplexing.

### Description

Information about this Service, for use within the interface.

### Transport Protocol

This configures the communication between L11WAAP and the backend.

| Option               | Value                                                                                                                                                                                                                   |
| -------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Per Request**      | This is the default mode. Incoming HTTP requests will go over HTTP, and incoming HTTPS requests will go over HTTPS.                                                                                                     |
| **HTTP Always**      | All communication between L11WAAP and the backend will be over HTTP. (This mode should not be used unless L11WAAP runs within the same cloud as the backend.)                                                           |
| **HTTPS Always**     | All communication between L11WAAP and the backend will be over HTTPS.                                                                                                                                                   |
| **Port Bridge Mode** | Link11 WAAP will use the same port as the incoming request. This is not limited to ports 80 and 443; L11WAAP will use whatever port was specified. Note: this mode is not available when more than one host is defined. |

### Load Balancing Stickiness Model

Sometimes an application requires a user to be connected to the same instance and backend endpoint throughout the session. L11WAAP can ensure that this occurs, and can do so using a variety of methods.

| Setting              | Behavior                                                                                                                                                              |
| -------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **None**             | This is the default. Requests will be distributed across the endpoints in a round-robin fashion, according to the Weights assigned to them (described below in the ). |
| **Auto Cookie**      | L11WAAP will automatically generate a cookie to maintain the session on the same endpoint.                                                                            |
| **Custom Cookie**    | You can provide the name of the cookie that L11WAAP will use to track the session, e.g. one generated by an AWS or GCP load balancer.                                 |
| **IP Hash**          | Routing will be determined from a hash of the client and destination IP addresses.                                                                                    |
| **Least Connection** | Requests will be sent to the endpoint with the fewest number of connections.                                                                                          |

### Server-to-Backend mTLS Certificate

The certificate to use for mTLS communication between Link11 WAAP and the customer origin.&#x20;

* The available certificates are those defined in the *Server-to-Backend mTLS Certificates* tab of the [Certificates](/console-walkthrough/sites/ssl/certificates#overview) page.&#x20;
* To use this feature, it must first be [enabled in the System DB](/console-walkthrough/system/system-db#enabling-certificates-for-mtls).

### Endpoint List (not labeled in the UI)

<figure><img src="/files/HBR7Cn2T2KvCdHzJvfF9" alt=""><figcaption></figcaption></figure>

This is a list of one or more endpoints. The settings for each endpoint in the list are as follows.

| **Attribute**    | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ---------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Host**         | <p>The name or IP address for each endpoint that L11WAAP protects. (Do not enter self-referential values such as 127.0.0.0/8, 0.0.0.0, ::1/128, ::0/128 or “localhost”.)<br><br>The host can be a normal web server, or it can be a load-balancer. Note that L11WAAP also provides load-balancing capabilities in its own right, as discussed below.<br><br>In <em>Port Bridge Mode</em>, it is possible to specify more than one host, separated by commas (as in the screenshot above).</p> |
| **HTTP Port**    | The HTTP port(s) for the server. To add a port, click in the field, and enter the port number into the "Search" field.                                                                                                                                                                                                                                                                                                                                                                        |
| **HTTPS Port**   | The HTTPS port(s) for the server. To add a port, click in the field, and enter the port number into the "Search" field.                                                                                                                                                                                                                                                                                                                                                                       |
| **Weight**       | The relative weight of each server for load-balancing purposes. L11WAAP distributes traffic with a round-robin sequence, according to these weights. For example, if two servers are both set to 'weight=1', they will receive equal amounts of traffic. If the first is set to 'weight=3' while the second is set to 'weight=1', the first server will receive three visitors for every single visitor that the second server receives.                                                      |
| **Max Fails**    | The maximum number of failed communication attempts that are allowed for this server. Once this number of failures occurs, L11WAAP will consider the server to be inactive. If other servers are available, L11WAAP will failover the traffic to them. If this was the only server available, the system will return an error to the client (either 504 Timeout, or 502 Bad Gateway).                                                                                                         |
| **Fail Timeout** | When a server fails, this is the length of time in seconds that L11WAAP will wait before trying to send traffic to it again.                                                                                                                                                                                                                                                                                                                                                                  |
| **Is Down?**     | When this box is checked, L11WAAP will not attempt to communicate with this server. This allows you to take a server offline for temporary maintenance or some other purpose.                                                                                                                                                                                                                                                                                                                 |

{% hint style="info" %}
There is currently a bug when adding a new endpoint to a list of existing endpoints. The second one will have its *Is Down?* checkbox disabled. \
\
Workaround: if you wish to add a "down" endpoint, begin by defining and adding it in "up" mode. Then, edit it; the *Is Down?* checkbox will be available.
{% endhint %}


# Edge Functions

Running custom code during traffic processing

<figure><img src="/files/SjgsGiWS1s6oKvXIL6LD" alt=""><figcaption></figcaption></figure>

## Overview

An Edge Function (EF) allow you to extend Link11 WAAP's tools and functionality. An EF consists of Lua code that can be run at different points in L11WAAP's traffic processing.

An EF can be configured to execute before any other processing occurs. Therefore, it can override or preempt other configured settings within L11WAAP.&#x20;

Or, it can be run after traffic filtering has been completed. An example use case is [custom logic based on the tags that Link11 WAAP attached to the request](#custom-function-for-accessing-tag-data).

{% hint style="warning" %}
When an admin creates an Edge Function, L11WAAP validates the code with a Lua compiler. If any syntax errors are found, an error message will be shown. However, Link11 does not validate the code beyond this. **Please ensure that the code is valid and tested before adding it.** If the code has errors, undefined behavior can occur when L11WAAP attempts to execute it.
{% endhint %}

Edge Functions are a very powerful tool. If you need assistance with this feature, please feel free to [contact support](/support).

## Usage within applications and APIs

Edge Functions are assigned to destination paths/URLs within [Security Policies](/console-walkthrough/security/security-policies).&#x20;

{% hint style="info" %}
Out of the box, L11WAAP includes a number of Edge Functions. Initially, they are not assigned to any Security Policies, and thus, are inactive by default.
{% endhint %}

## Administration

The main window (shown above) lists all current Edge Functions.

The administration (addition/deletion/editing/versioning) of EFs follows the conventions described [here](/how-link11-waap-works/ui-overview-and-common-elements#configuration-and-administration).

## Parameters

<figure><img src="/files/UedTVSeY35mKOmPm7E2t" alt=""><figcaption></figcaption></figure>

### Name

A name for this EF, to be used within the interface.&#x20;

### Description

Information about this EF, for use within the interface.

### Phase

This specifies when the Edge Function code will be executed.&#x20;

<table><thead><tr><th width="237.90185546875" valign="top">Phase</th><th valign="top">Description</th></tr></thead><tbody><tr><td valign="top"><strong>Request Pre Processing</strong></td><td valign="top"><p>Executes immediately when L11WAAP receives an incoming request, before any other processing occurs.</p><ul><li>Runs <strong>before</strong> the security logic.</li><li><strong>Cannot be preempted/prevented</strong> by the security logic, since it executes beforehand.</li><li>A request might only be blocked here if NGINX itself blocks it (e.g., due to malformed headers or connection limits).</li></ul></td></tr><tr><td valign="top"><strong>Request Post Processing</strong></td><td valign="top"><p>Executes after L11WAAP has finished processing the request, and before it sends the request to the backend server.</p><ul><li>Runs <strong>after</strong> the security logic.</li><li>Will <strong>only be reached if the request is allowed</strong> by the security logic.</li><li>If the request is blocked, this stage will not be executed.</li></ul></td></tr><tr><td valign="top"><strong>Response Pre Processing</strong></td><td valign="top"><p>Executes when L11WAAP receives the response from the backend.</p><ul><li>Runs on the <strong>response coming back from the origin</strong>, before any potential processing.</li><li>The response cannot be blocked here, as L11WAAP does not evaluate or filter responses from the origin at this stage (unless NGINX does it for some reason).</li></ul></td></tr><tr><td valign="top"><strong>Response Post Processing</strong></td><td valign="top"><p>Executes as the last action before L11WAAP sends the response to the client.</p><ul><li>Runs <strong>after</strong> the response has been processed (e.g., the addition of the <code>upstream-status</code> tag) and just <strong>before it is sent to the client</strong>.</li><li>Similar to the previous stage, since there is no security logic evaluating responses, this function cannot be blocked and will execute as normal.</li></ul></td></tr></tbody></table>

### Code

The Lua code for the Edge Function.

### Connections to Security Policies

The list of Security Policies that include this Edge Function. Each Security Policy defines the scope (i.e., the paths within Backend Services) for which the Function will be active.&#x20;

For a discussion of how to use this control, see [Connections to Security Policies](/how-link11-waap-works/ui-overview-and-common-elements#connections-to-security-policies).

## Examples

Out of the box, Link11 WAAP includes multiple Edge Functions. These can be studied as good illustrations of how to create and use Edge Functions.

Typically, an Edge Function will leverage built-in capabilities of nginx. Link11 WAAP also includes some custom capabilities, described below with examples.

## Custom Capabilities

### Accessing geolocation and ASN/org data

Sometimes customers need certain metadata to be sent to their origin servers, such as the request's country code, country name, ASN, or organization.

Edge Functions can access this information using these variables:

```
ngx.var.geo_country_code
ngx.var.geo_country_name
ngx.var.geo_asn
ngx.var.geo_org
```

If data is not available, the variable will contain this string: `-`.

Here's a usage example of inserting this information into request headers :

```
ngx.req.set_header("x-waap-geo-country-code", string.upper(ngx.var.geo_country_code))
ngx.req.set_header("x-waap-geo-country", ngx.var.geo_country_name)
ngx.req.set_header("x-waap-geo-asn", ngx.var.geo_asn)
ngx.req.set_header("x-waap-geo-org", ngx.var.geo_org)
```

### Accessing Tag data

Sometimes customers need to access the [Tags](/how-link11-waap-works/tagging) attached to the request during L11WAAP's processing, for case-specific purposes (business logic, customized responses, etc.)

This can be done in the [Request Post Processing phase](#phase)**,** with a custom function \[`ngx.tag_exist`] that returns a boolean. Its usage is as follows:

```
// returns true if tag1 was attached to the request, false otherwise
ngx.tag_exist("tag1")

// returns true if tag1 AND tag2 were attached to the request, false otherwise
ngx.tag_exist("tag1","tag2")

// returns true if tag1 OR tag2 were attached to the request, false otherwise
ngx.tag_exist("tag1") || ngx.tag_exist("tag2")
```

For example, L11WAAP includes a default Global Filter that adds a tag (`cloudfront`) to all requests bearing an AWS CloudFront IP. An Edge Function can pass this information to the origin in a header named "is-cloudfront", like this:

```
ngx.header["is-cloudfront"] = ngx.tag_exist("cloudfront")
```

### Adding custom messages to log events

An Edge Function can inject custom messages into events. This can be useful for increasing visibility into traffic logs, debugging, etc.

The syntax is as follows:

```
ngx.ctx.additional_messages = {"$MESSAGE"};
```

So, this Edge Function code:

```
ngx.ctx.additional_messages = {"Hello world"};
```

...will add `Hello world` to the event. This message will appear in:

* the Event Log's Messages section (shown below)&#x20;
* and the `messages` field when [retrieving traffic data from the API](/reference-information/api/api-access-to-traffic-data), or when downloading data from the Events Log.

<figure><img src="/files/AHJkvV8PCN5OHBmJk2mf" alt=""><figcaption></figcaption></figure>


# DNS Records

An optional feature

<figure><img src="/files/wB5lKk8MB0VsOKGyCY3j" alt=""><figcaption></figcaption></figure>

DNS Management is an optional capability. Your DNS records do not need to be maintained within Link11, but they can be.&#x20;

The user interface displays the records that are currently defined within Link11 WAAP. These records are not editable within the UI; they are configured outside of the UI, and are displayed here for informational purposes only.

For assistance in changing or configuring DNS records, within L11WAAP, [contact support](/support).


# SSL

This section is for SSL settings.

{% content-ref url="/pages/3Zbkuc2sdKwHrd7a9t4N" %}
[Load Balancers](/console-walkthrough/sites/ssl/load-balancers)
{% endcontent-ref %}

{% content-ref url="/pages/-LuXgqGbXTCeQw0wX9OO" %}
[Certificates](/console-walkthrough/sites/ssl/certificates)
{% endcontent-ref %}


# Load Balancers

<figure><img src="/files/ACwAdvJLlW7Htljnho7k" alt=""><figcaption></figcaption></figure>

## Overview

This page lists the load balancers currently set up within Link11 WAAP.&#x20;

Load balancers are added and managed outside of the UI; for assistance in changing or configuring load balancers, [contact support](/support).

Load balancer administration involves two primary activities:

* [Attachment](#attaching-certificates) of one or more security certificates.&#x20;
* For Link11 load balancers supporting a multi-regional or multi-cluster planet, [configuring the preferred traffic routing](#configuring-traffic-routing) (optional).

## Attaching certificates

You can select or change the SSL certificate attached to a load balancer. Selecting the **Attach Certificate** button displays this dialog:

<figure><img src="/files/ZNkJJtO64EVcKoJ8YXT6" alt=""><figcaption></figcaption></figure>

The certificates available for selection are those defined within the [SSL Certificate](/console-walkthrough/sites/ssl/certificates) list.

## Configuring traffic routing

When a public-cloud load balancer is used, Link11 automatically routes traffic to the customer planet for processing.

When Link11 cloud load balancing is used, and the customer planet has multiple clusters or spans geographic regions, admins have additional control over traffic routing.&#x20;

{% hint style="info" %}
**Note**: in this discussion, "one" load balancer is a conceptual representation. Physically, it represent multiple load balancing instances, running simultaneously in multiple locations.&#x20;
{% endhint %}

For each load balancer, admins can specify the preferred datacenter, i.e. the preferred regional instance of Link11 WAAP to scrub the traffic.

* The UI offers the selection of one *Preferred datacenter*; this will be the destination for traffic from all locations where that load balancer is running.
* If more granularity is needed, the API can be used to set a different preference for each location.

### How traffic is routed

When traffic is received, the system will route the traffic as follows:

* If a *Preferred datacenter* was selected, and that datacenter is up, it receives the traffic.
* If a *Preferred datacenter* was selected, but that datacenter is currently down, traffic is balanced across all available datacenters.
* If a *Preferred datacenter* was not selected, traffic is sent to the datacenter closest to the load balancer.

{% hint style="info" %}
In the above, *Preferred datacenter* refers to any preference, whether specified via the UI or API. See [this discussion](/reference-information/api/namespace-reference/load-balancers) about using the API correctly.
{% endhint %}

### Multiple datacenters processing a client session

In certain situations, a single client session might be processed in more than one datacenter.

This can occur when Frankfurt is the destination for traffic. In the interface, "Frankfurt" represents two physical datacenters in the Frankfurt region. The system can send traffic to either one.

This can also occur when a preferred datacenter is, or becomes, unavailable. The system will route its traffic elsewhere, as described above, but will continue monitoring the preferred datacenter. Once it becomes available, traffic will be routed there again.

When a client session is processed by multiple datacenters, this has no impact on analytics or most traffic scrubbing. However, it can delay enforcement of Rate Limit Rules, because each datacenter will only have processed a subset of the client's requests.


# Certificates

Administration of SSL certificates

<figure><img src="/files/UruwwG4W56ZEzPjeGvML" alt=""><figcaption></figcaption></figure>

## Overview

This section allows admins to manage SSL Certificates. There are four kinds of certificates, each with its own tab:

* **Server Certificates**, so that clients (end users) can communicate with Link11 WAAP using HTTPS.
* **CA Certificates**, so that Link11 WAAP can validate clients for mTLS communication.
* **Server-to-Backend mTLS Certificates**, so that customer origins can validate Link11 WAAP for mTLS communication.
* **Server-to-Backend CA Certificates**, so that Link11 WAAP can validate customer origins for mTLS communication.

Server Certificates are necessary for end users to communicate securely with Link11 WAAP. The other types of certificates are optional, and are only necessary for using mTLS (mutual TLS).&#x20;

Here is a diagram of the different types of certificates:

<figure><img src="/files/sML8VW5gUXNLj3GPcIFA" alt=""><figcaption></figcaption></figure>

Out of the box, Link11 offers management of Server Certificates.&#x20;

**To enable management of the other types of certificates** so that their tabs appear in the interface, follow the instructions here:  [How do I enable mTLS](/using-the-product/how-do-i.../enable-mtls-mutual-tls).

## Usage within applications and APIs

Server Certificates can be attached to [Load Balancers](/console-walkthrough/sites/ssl/load-balancers), or to domains via [Server Groups](/console-walkthrough/sites/server-groups).

Similarly, CA Certificates are also used in Server Groups. However, they are only available in the interface when using AWS NLB (Network Load Balancing). When using a Link11 load balancer, please contact support.

Server-to-Backend mTLS/CA Certificates are used in [Backend Services](/console-walkthrough/sites/backend-services#server-to-backend-mtls-certificate).

## Administration&#x20;

The list of currently defined Certificates is displayed in each tab. From here, new certificates can be generated, or existing ones can be edited.

{% hint style="info" %}
When adding new certificates, publishing your changes is necessary to make the new certificates available for use in the system.
{% endhint %}

All four types of certificates are administered using the same procedures, described below.

### Securing private keys

By default, Link11 WAAP offers admins the ability to auto-replace certificates using Let's Encrypt, and to download certificates in PFX format. To remove these features from the web console and API, [contact support](/support).

## Generating a Certificate

Selecting the **+ New button** displays the *Upload Certificate* dialog:

<figure><img src="/files/oNJhRq3onzYqSnLmh3cb" alt=""><figcaption></figcaption></figure>

When adding a certificate, a name for use within the interface can be specified. If this field is left blank, the system will generate a name automatically.

Certificates can be added manually, or L11WAAP can parse a PFX file.

{% hint style="info" %}
When using a GCP load balancer, the certificate must meet these requirements:

* It must be in [PEM format](http://ospkibook.sourceforge.net/docs/OSPKI-2.4.7/OSPKI-html/sample-ca-cert.htm).
* It cannot be protected by a passphrase. Google Cloud stores the private key in its own encrypted format.
* Its encryption algorithm must be either RSA-2048 or ECDSA P-256.

To create a new private key, use one of the following [OpenSSL](https://www.openssl.org/docs/) commands.

* Create an RSA-2048 private key:

  ```
  openssl genrsa -out $PRIVATE_KEY_FILE 2048
  ```
* Create an ECDSA P-256 private key:

  ```
  openssl ecparam -name prime256v1 -genkey -noout -out $PRIVATE_KEY_FILE
  ```

...where $PRIVATE\_KEY\_FILE is the path and filename for the new private key file.
{% endhint %}

## Editing/Configuring a Certificate

When an existing Certificate is edited, the *Edit Certificate* dialog appears:

<figure><img src="/files/6oO00tLpyjifz4oqABBP" alt=""><figcaption></figcaption></figure>

### Editable parameters and controls

#### **Certificate Name**

The certificate's current name within the interface can be edited.

#### **Auto Replacement by Let's Encrypt**

Let's Encrypt is a free certificate authority service. L11WAAP integrates with it, and offers this service by default.&#x20;

Once a day, L11WAAP will check each application it protects. If that application's certificate is going to expire in the coming week, and its *Auto Replacement by Let's Encrypt* option for that certificate is enabled, L11WAAP will generate a new certificate using Let's Encrypt, and will attach all of its sites to the new certificate.

{% hint style="info" %}
This feature can be disabled in the web console and API if desired. Contact support to do this.
{% endhint %}

#### Attach To Application

This tab includes a list of Server Groups. Selecting one will connect this Certificate to it.

#### Replace Existing Certificate

This tab includes a list of Certificates defined within the system. Selecting one and then clicking **Save** will result in all sites/applications being transferred from the selected Certificate over to the Certificate you're currently editing.

#### **Download PFX**

This will download the certificate information as a file in PFX format.

{% hint style="info" %}
This feature can be disabled in the web console and API if desired. Contact support to do this.
{% endhint %}


# System

This section of the console is for system-wide configuration.

* [Interactive Challenge](/console-walkthrough/system/interactive-challenge): one of Link11 WAAP's mechanisms for human verification.
* [SSO Configuration](/console-walkthrough/system/sso-configuration): for managing Single Sign-On for L11WAAP
* [Purge CDN Cache](/console-walkthrough/system/purge-cdn-cache): for clearing the cache(s) of Content Delivery Network nodes
* [Users Management](/console-walkthrough/system/users-management): for administering users of L11WAAP
* [Security Alerts](/console-walkthrough/system/security-alerts): for configuring email alerts, sent when Dynamic Rules are triggered
* [Log Exporters](/console-walkthrough/system/log-exporters): for exporting traffic event data, e.g. to a SIEM solution
* [Version Control](/console-walkthrough/system/version-control): for rolling forward/back to a different configuration
* [System DB](/console-walkthrough/system/system-db): for accessing system settings
* [Publish Changes](/console-walkthrough/system/publish-changes): for publishing configuration changes to proxies


# Interactive Challenge

<figure><img src="/files/ng7dadMX9tYMMqEgTK5u" alt=""><figcaption></figcaption></figure>

## Overview

Link11 WAAP contains several mechanisms for detecting bots within web traffic, including [Active Challenges](/how-link11-waap-works/traffic-reporting-and-analytics#the-challenge-process) and [Passive Challenges](/using-the-product/best-practices/enabling-passive-challenges).&#x20;

This page allows admins to configure the third mechanism: the L11WAAP **Interactive Challenge**, which is a form of CAPTCHA ("Completely Automated Public Turing test to tell Computers and Humans Apart").

The Interactive Challenge is more stringent than the other mechanisms. Therefore, when an Interactive Challenge is triggered, the user must pass it before being allowed to continue, even if the user had previously passed an Active Challenge or Passive Challenge.

## Usage within applications

The Interactive Challenge defined on this page can be used at various places within a web application. Create one or more [Actions](/console-walkthrough/security/actions) with the *Type* parameter set to *Interactive Challenge*, and then use the Action(s) within the appropriate security rulesets (within [Global Filters](/console-walkthrough/security/global-filters), [Rate Limit Rules](/console-walkthrough/security/rate-limit-rules), [ACL Profiles](/console-walkthrough/security/acl-policies), and [Content Filter Profiles](/console-walkthrough/security/content-filter/profiles)).

{% hint style="warning" %}
Admins should ensure that rulesets which can trigger Interactive Challenges are not applied to API endpoints. Interactive Challenges require user interaction, and therefore, API clients cannot pass them.
{% endhint %}

## Parameters

The parameters described below will determine how the Interactive Challenge page is displayed to the user.

### Direction

The direction of the text displayed to the user. For example, English should be set to `Left to right`, while for Hebrew, this should be set to `Right to left`.

### Style

This specifies how to display the image configured in the *Image/IMG* settings within the Languages section. When set to `Logo`, the image will be shown on the page once. When set to `Wallpaper`, the image will be tiled to fill the page.

### Palette

The colors used in the challenge.

### Languages

Admins can configure Interactive Challenges in different languages. A default L11WAAP deployment will contain English; to add additional languages for configuration, select **New language**. (This appears below the *Languages* section; you can collapse the section to make it more accessible.)

Each configured language will include the options below.

#### Title

The title that will be shown on the page.

#### Buttons text

During the Interactive Challenge, two buttons are shown to the user. The top field specifies the text for the first button that appears, and the bottom field specifies the text for the second button.

#### Image Element Source

This is the source for the image that will be shown on the Interactive Challenge page. It will be shown according to the *Style* setting.

#### IMG Element Preview

This displays a preview of the image specified in the *Image Element Source*.

## Testing an Interactive Challenge

To see how an interactive challenge will appear to a user, you can select it as the Action for a dedicated [Global Filter](/console-walkthrough/security/global-filters): one with a Rule list that will only match a test request (e.g., a specific IP that you will use to test the challenge).


# SSO Configuration

<figure><img src="/files/lgHSIFvZNcZtKJNLZ5NT" alt=""><figcaption></figcaption></figure>

Link11 WAAP provides the ability to log in using SSO (single sign-on). Configuration varies depending on the type of SSO: Okta, Microsoft, or Google.

## Set up Okta SSO

### **Step 1: register on** [**Okta**](https://www.okta.com/)**, and create an application**

Go to `https://{YOUR ACCOUNT}-admin.okta.com/admin/apps/active`

Click `Create App Integration` → `Create New App`

<figure><img src="/files/lqWp11D0WV5vxPf6pbof" alt=""><figcaption></figcaption></figure>

#### **Set this attribute:**

*Sign-in redirect URI*:&#x20;

`https://<planet-name>.app.reblaze.io/auth/okta-oauth2-<planet-name>/authorization-code/callback`

<figure><img src="/files/p0BV9bCPeubzDSe4v5Eu" alt=""><figcaption></figcaption></figure>

### **Step 2: Create group**

<figure><img src="/files/HLwRtq0qxSQaAJgC6Bhv" alt=""><figcaption></figcaption></figure>

#### Example configs:

For planet URL: `https://rbzdevexample.dev.app.reblaze.io/prod/sso-configuration`

Redirect URI like:\
`https://rbzdevexample.dev.app.reblaze.io/auth/okta-oauth2-rbzdevexample.dev /authorization-code/callback`

### **Step 3: Add parameters to Link11**

On the WAAP SSO page (**System** -> **SSO Configuration**):

<figure><img src="/files/RmvIN2cXqF27LTNNpd5b" alt=""><figcaption></figcaption></figure>

Fill in the requested values. For `Issuer`, use your Okta account. For `IDP Group Claim`, use the group you created above in Step 2.

## Set up Microsoft Entra ID SSO

### **Step 1: Go to** [**Azure Portal**](https://azure.microsoft.com/en-us/account/) **→** `Enterprise applications`

### **Step 2. Create the application**

Choose `+ New Application` → `+ Create your own application`**:**

![](/files/avGmSwmZUgrUiGTItxnE)

### **Step 3: Create the SSO app**

Select `Integrate any other application you don't find in the gallery (Non-gallery)`&#x20;

![](/files/23MATEN6Nm813N9Ziogb)

### **Step 4: Select SAML method**

Go to `Single sign-on` section and choose `SAML`**:**

![](/files/lQoBTEluP35Ska7YLPSF)

### **Step 5: Set up appropriate links**

Edit the `Basic SAML Configuration`:

* Set Azure's `Identifier (Entity ID)` to `<planet-name>.app.reblaze.io.` Alternately, a unique identifier can be entered (e.g., `customer_domain.com?sso=123`), without any "https\://" prefix. In either case, save a copy of this value somewhere; it will be needed again later.
* Set Azure's `Reply URL` to `https://<planet-name>.app.reblaze.io/auth/azure-saml2-<planet-name>/authorization-code/callback`

<figure><img src="/files/1PHgg9R5TJedvYMSJtzu" alt=""><figcaption></figcaption></figure>

### Step 6: Add a user group claim

Edit `user.groups`:&#x20;

<figure><img src="/files/NJ41SNiiwk5lqaP2Y71y" alt=""><figcaption></figcaption></figure>

Click on **`+`**`Add a group claim`, and choose:

* `All groups`
* Source attribute: `Group ID`

![](/files/wcjcp11m2K8ll0VoMHDK)

![](/files/guG4xes0XLg8i87dW53p)

### **Step 7: Add a user as a member of the application:**

![](/files/DxsD5Clgx7yrcss2IUYg)

### **Step 8: Get admin group ID**

Go to `Azure Active Directory` → `Groups`, and create a group.

![](/files/P7oxmmbbsmamecDhopjB)

And assign a user to the group:

<figure><img src="/files/xCRvJBjuT9NgOw40pg8l" alt=""><figcaption></figcaption></figure>

### Step 9: Get SAML 2 data for Reblaze

From Azure's `Single sign-on` section, copy the `Entity ID` (entered during a previous step) and `Login URL`:

<figure><img src="/files/2jB37sr0obod6iooVCfE" alt=""><figcaption></figcaption></figure>

And from the Groups `Overview` section, copy the `Object Id`. This should be the same ID from Step 8.)

<figure><img src="/files/dfQRkC86C9Pwq8Vf9avY" alt=""><figcaption></figcaption></figure>

Add these parameters to the Reblaze SSO page. For Reblaze's `IDP group claim`, use Azure's `Object Id`.

<figure><img src="/files/nPjYFolTsSIpKrDbSbfY" alt=""><figcaption></figcaption></figure>

## Set up Google SSO

### Step 1: Generate new OAuth credentials

1. Go to Google APIs & Services Credentials: <https://console.cloud.google.com/apis/credentials>
2. Click **Create Credentials** (shown below) -> **OAuth client ID**

<figure><img src="/files/FsPnt3gZOPpUsE3KAw3X" alt=""><figcaption></figcaption></figure>

### Step 2: Configure the new OAuth client ID

1. For **Application type**, select *Web application*
2. Specify a **Name** for this client ID. (This name is only shown in the Google Cloud console.)

### Step 3: Add authorized URIs

Define the domains and endpoints used by your planet to communicate with the OAuth 2.0 server:

* **Authorized JavaScript origins**: `https://<planet-name>.app.reblaze.io`
* **Authorized redirect URIs**: `https://<planet-name>.app.reblaze.io/auth/google-oauth2-<planet-name>/authorization-code/callback`

<figure><img src="/files/TUVhSxDtq7nsl3dZi7x3" alt=""><figcaption></figcaption></figure>

### Step 4: Create and get credentials

1. When you are done with the above steps, select **Create**. The new client ID will be created and displayed to you.
2. Copy the credentials (client id + client secret) for use in the following steps below.

### Step 5: Enable the Admin SDK API

1. Navigate to [https://console.developers.google.com](https://console.developers.google.com/)
2. In the **APIs & Services** menu, select **Library**
3. Search for "Admin SDK API", and select the result. The Admin SDK page will appear.
4. Select **ENABLE** if it isn't already enabled.

<figure><img src="/files/hzreLnWSxZyGpQ6xI1JJ" alt=""><figcaption></figcaption></figure>

### Step 6: Authorize the API client

1. Navigate to [admin.google.com](http://admin.google.com/)
2. Select **Security** -> **Settings**
3. At the bottom of the page, select **API access control**
4. Select **Domain wide delegation** -> **Manage domain wide delegation**
5. In the API Client section, select **Add New**
6. In the **Client Name** field, enter the client ID from Step 4 above.
7. In the **One or More API Scopes** field, enter this: `https://www.googleapis.com/auth/admin.directory.group.readonly`
8. Select **Authorize**

<figure><img src="/files/8oaUpNi6gHcwvV4CnN4V" alt=""><figcaption></figcaption></figure>

### Step 7: Configure Reblaze SSO

Within the Reblaze console, go to the SSO page (**System** -> **SSO Configuration**).

* **Enabled**: if not already "on", toggle it
* **SSO login name**: choose a name for display within the console
* **Provider:** select `google`
* **OAuth2 Client id**: enter the client id obtained in Step 4
* **OAuth2 Client secret**: enter the client secret obtained in Step 4
* **Protocol**: select `oauth2`
* **JWT token group property name**: select `email`

### Step 8: Map groups

Every Reblaze user account has a role, with an Access Level that defines permissions. There are [four Access Levels](/console-walkthrough/system/users-management#user-parameters) available, with varying capabilities.&#x20;

When a user logs in via Google SSO, the system uses their Google Groups to determine which role they will have within Reblaze.

In this step, you will define (if necessary) and connect Google groups to Reblaze roles.

1. Determine how many roles are being used within your planet. (Some organizations will use all four, while others might not.)
2. Navigate to <https://groups.google.com/my-groups>. Consider the Groups that currently exist; would  any map well to a Reblaze role? For each role that does not currently have an appropriate Google Group, select **Create Group** and define one.
3. Return to the Reblaze SSO Configuration page. For each role being used, create a group map with:
   * An **IDP Group Claim** containing the email associated with the corresponding Google Group
   * The **Reblaze role**
4. SSO configuration within Reblaze is now complete. User management now consists of ensuring that each user is a member of the appropriate Google Group. For example: a Google Group has been created for `editors@reblaze.com`, and within Reblaze, this email address is mapped to the role of `Editor`.  Every user who should have Editor permissions can receive them merely by being added to the `editors@reblaze.com` Google Group.

<figure><img src="/files/L3g4jTNeueJxWgC1CvXE" alt=""><figcaption></figcaption></figure>

<br>

&#x20;


# Purge CDN Cache

<figure><img src="/files/GcNYsNRLjkKxnuRGHj3a" alt=""><figcaption></figcaption></figure>

This feature allows admins to purge CDN caches at various scopes:

* The entire planet
* Specific domain(s) within the planet
* Specific paths within domain(s)&#x20;

A history of current and past activity is provided.

## Prerequisites

This feature is available when at least one CDN has been set up in the system. (To do this, contact customer support.) If no CDN is currently configured, an error message will be shown.

## **Three-Step Purging Process**&#x20;

Purging requires these steps:

1. Select the cache(s)
2. Initiate the purge
3. (Optional) monitor the results

## **Step 1: Select the cache(s) to purge**&#x20;

Cache selection varies, depending on the CDN being used.

### **To purge caches for an entire planet**&#x20;

For non-AWS CDNs, at the top left of the page, ensure that **All domains in the planet** is selected, then skip the remainder of Step 1, and continue to Step 2 below.

### **To purge one or more domains within the planet**&#x20;

AWS Cloudfront users will see the controls described below. For non-AWS CDNs, at the top left of the page, ensure that **Specific domains** is selected to display them.

* **Select CDN**: If there are multiple AWS load balancers, this control will appear. Select the AWS CDN provider for each domain/path where the cache has to be purged. \
  \
  In other situations (e.g., the planet uses the Google Cloud or Link11 CDN, or has only one AWS load balancer) this control is unnecessary and will not appear.
* **Alternative domain names**: For non-AWS CDNs, specify a domain configured within the planet. AWS Cloudfront does not support individual purges, so Cloudfront users will see a non-editable list (for informational purposes only) of all the domains for which caches will be purged.
* **Add a specific path**:
  * When this control is untoggled, caches for the entire domain will be purged.
  * When this control is toggled, the **Path** field will appear. Enter the path for which the cache should be purged.

**Adding more domains/paths**\
Multiple domains and/or paths can be specified for a purge.

After appropriate values have been entered into the controls described above, if another domain or path purge needs to be defined, select the **New Host** button and populate the new entry in the purge list. Repeat this process until all desired purges have been specified.

## Step 2: Initiate the purge

Select the **Purge CDN cache** button. The specified purge(s) will appear in the **Results** list at the bottom of the page.

## Step 3: (Optional) monitor the results

The **Results** list shows a history of purge commands submitted during the previous week. The list shows the date and time when each was submitted.

Within the list, the **Status** field shows the result of each purge during the most recent status update. Updates occur when the page is loaded or reloaded, and also each time the **Refresh Status** button is selected.

The possible statuses are:

* **In progress**: as of the most recent status update, the purge was still being processed. (Note that depending on how recently the list was updated, the actual current status might be different.)
* **Done**. The purge completed successfully.
* **Failed**. The purge was attempted but was not successful. To try again, a new purge command must be submitted.
* **Not available**. The purge was unsuccessful because the CDN was unavailable. To try again, a new purge command must be submitted.


# Users Management

<figure><img src="/files/Q6lCtCWMRVkWqSnDZz2M" alt=""><figcaption></figcaption></figure>

## Overview

This page allows admins to manage users of the Link11 WAAP system.

{% hint style="info" %}
This page is available only to users with an *Access level* of `WAAP manager` or higher.&#x20;
{% endhint %}

## Administration

User administration follows the List/Editor UI conventions described [here](/how-link11-waap-works/ui-overview-and-common-elements#configuration-and-administration).

### Add a new user

Select the **+ New** button, and the **New User** dialog will appear:

<figure><img src="/files/AcM6ILX5eUdEmDZH6og3" alt=""><figcaption></figcaption></figure>

Note that once a user is created, the email and organization values cannot be edited later. To change these, the user should be deleted and

## User Parameters

| Field        | Comment                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Contact Name | The user's name                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Email        | The user's email address. Note: after a user is created, this value is read-only and cannot be edited.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Mobile       | The user's mobile number, for sending OTP (one-time passwords) via SMS. This is an optional entry, because L11WAAP also provides other options for multi-factor authentication (which are configured on the [Account](/console-walkthrough/account) page). The number should begin with a "+" symbol and the country code. Example: a US number should appear in the format `+12223334567`.                                                                                                                                                                                                                                        |
| Access Level | <p>There are four Access Levels within L11WAAP:</p><ul><li><em>WAAP Viewer</em>: can see the <a href="/pages/l3dMd7u1EV7zSSzEhdIH">Analytics</a> section, i.e. the Dashboard and Events Log.</li><li><em>WAAP Editor</em>: has all WAAP Viewer permissions, and can also configure security rulesets and policies.</li><li><em>WAAP Manager</em>: has all WAAP Editor permissions, and can also manage users.</li><li><em>Admin</em>: has all WAAP Manager permissions, and can also manage the organization. Note that this Access Level is not available through User Management; these Admins must be added manually.</li></ul> |
| Organization | The organizations within the planet. The list of organizations is obtained during system bootup.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |


# Security Alerts

<figure><img src="/files/N5S9eOu9Mzn4oLvzTYuw" alt=""><figcaption></figcaption></figure>

## Overview

Security Alerts allow admins to configure email alerts to be sent when [Dynamic Rules](/console-walkthrough/security/dynamic-rules) are triggered.

## Usage within applications and APIs

Security Alerts operate at the system level. They can be defined for individual [Server Groups](/console-walkthrough/sites/server-groups), or for multiple Server Groups simultaneously. When any of the specified Dynamic Rules is triggered for any of the specified Server Groups, an email alert will be sent to the designated recipient(s).

Each email alert includes:

* The Dynamic Rule that was triggered: its name, description, "Limit" (a combination of the Rule's *Number of events* and *Time frame)*, and "Type" (which corresponds to the Rule's [*Target*](/console-walkthrough/security/dynamic-rules#target) setting)
* A list of the violators of that Rule

{% hint style="info" %}
In the email alerts, a Dynamic Rule enforcing limits on IP addresses will not be described as *Type: IP*; rather, the email body will say *Type: remote\_addr*.&#x20;
{% endhint %}

## Administration <a href="#administration" id="administration"></a>

The main window (shown above) lists all currently defined Security Alerts.

The administration (addition/deletion/editing/versioning) of these Alerts follows the conventions described [here](/how-link11-waap-works/ui-overview-and-common-elements#configuration-and-administration).

## Parameters

<figure><img src="/files/pWIBbwzl34VgsWL0isof" alt=""><figcaption></figcaption></figure>

### Name

The name of this Security Alert, for use within the interface.

### Server Groups

The Server Group(s) for which this Security Alert will be active.

* Individual Security Groups can be chosen.
* `Select all` will select all currently-defined Server Groups, i.e. all sites in the planet.
* `All Server Groups` will select all currently-defined Server Groups, and will include all Server Groups that are created in the future.

### Alert recipients

One or more recipients (specified as email addresses, separated by commas) to receive alerts when any of the listed Dynamic Rules are triggered.

### Dynamic Rules

One or more Dynamic Rules which will, when violated, trigger the sending of email alerts to the specified recipients.

{% hint style="info" %}
When adding Dynamic Rules to a Security Alert, ensure that each Rule is in "[active mode](/console-walkthrough/security/dynamic-rules#active-mode)".  Rules that are inactive will not trigger Security Alerts.
{% endhint %}


# Log Exporters

<figure><img src="/files/G0wyHBpTBkp26SnAipNn" alt=""><figcaption></figcaption></figure>

## Overview

Log Exporters allow admins to stream event data to an outside destination, e.g. a SIEM solution. Every few seconds, Link11 WAAP bundles and exports the most recent traffic events from its internal logs.

If desired, data values can be truncated according to settings in the [System DB](/console-walkthrough/system/system-db#limiting-log-exporter-data-lengths).

{% hint style="info" %}
For details of the protocols and format of the event data, see [Log Exporter Output](/reference-information/log-exporter-output).
{% endhint %}

{% hint style="warning" %}
There is a known issue when attempting to create a new Log Exporter. [More info](/known-issues#log-exporters)
{% endhint %}

Below is a discussion of the console interface for configuring Log Exporters.&#x20;

## Usage within applications and APIs

Log Exporters operate at the system level. Admins can configure them for specific [server groups](/console-walkthrough/sites/server-groups), or for the entire planet.&#x20;

## Administration <a href="#administration" id="administration"></a>

The main Log Exporter window lists all currently defined Log Exporters.

The administration (addition/deletion/editing/versioning) of Log Exporters follows the conventions described [here](/how-link11-waap-works/ui-overview-and-common-elements#configuration-and-administration).

## Parameters

<figure><img src="/files/0JfeAuGMR5SwCrHBwKWQ" alt=""><figcaption></figcaption></figure>

### Name

A unique name for use within L11WAAP.

### Status

Whether or not this Log Exporter is currently active.

### Destination IP

The destination IP to which event data will be sent.

### Port

The port to which event data will be sent.

### Server Groups

The specific server groups for which event data will be sent.

### Include encoded request data

When this is enabled, exported data will include a Base64-encoded representation of the HTTP request: its headers, cookies, and query arguments. This enables customer admins to extract and inspect the auth token and other metadata required for customer identification and security analysis.

Request data will be truncated (if necessary) to the [maximum lengths and parameter limits configured in the System DB](/console-walkthrough/system/system-db#limiting-log-exporter-data-lengths), then encoded for export.

### Transport protocol

The protocol to use while streaming the event data.

* **TCP:** Event data will be streamed over TCP.
* **TCP + TLS (Trusted)**: Event data will be streamed over HTTPS. When this is selected, an additional control will appear for uploading a PEM file containing the TLS certificate for the data's destination. The system will validate the certificate upon upload.
* **TCP + TLS (Untrusted)**: Event data will be streamed over HTTPS, but the system will not use a certificate.

### Requests to export

* **Blocked**: Export only the requests blocked by L11WAAP.&#x20;
* **All**: Export all the requests blocked or passed by L11WAAP.

{% hint style="info" %}
Note that currently, Log Exporters can not include requests challenged by L11WAAP, or blocked by the origin.
{% endhint %}

## Troubleshooting

If a Log Exporter has been configured but is not streaming data:

1. Verify that it is in [Active mode](#status).
2. If its [Protocol](#transport-protocol) is **TCP + TLS (Trusted)**, verify that the certificate is valid and has not expired.

If a Log Exporter is streaming truncated data, verify the data-length limits set in the [System DB](/console-walkthrough/system/system-db#limiting-log-exporter-data-lengths).


# Version Control

<figure><img src="/files/iHpbq45kdZpiSRExCfsb" alt=""><figcaption></figcaption></figure>

Link11 WAAP maintains Git versions of data and configurations.

This page displays previous versions of configurations, and allows admins to:

* Download a version by using the **"Download"** button at the top
* Revert/restore the system to any saved configuration.&#x20;

To revert/restore, hover the cursor over the desired configuration. The **"Restore"** icon will appear at the end of the entry. Select this icon.&#x20;

Once the restoration process is complete, [publish](/console-walkthrough/system/publish-changes). L11WAAP will push the selected configuration out to the proxy.


# System DB

<figure><img src="/files/tVNnRbfMQgU5YFpAenVI" alt=""><figcaption></figcaption></figure>

This page within the L11WAAP console displays the current System Database. The parameters contained here are used throughout the system.

Most of these settings are displayed for informational purposes only. In some cases, they can reflect features of the system not currently in use.&#x20;

The following features are available for configuration by customer admins:

* [Enabling certificates for mTLS](#enabling-certificates-for-mtls)
* [Limiting Log Exporter data lengths](#limiting-log-exporter-data-lengths)

Except for these, it is not recommended that admins attempt to edit settings within System DB. If you would like assistance, [contact support](/support).

## Enabling certificates for mTLS

By default, the Link11 WAAP interface does not offer management of certificates for mTLS. These features can be enabled through the System DB.

<figure><img src="/files/IKhP8uDvzZxUw8HzXLO9" alt=""><figcaption></figcaption></figure>

To do this, begin by selecting the `system` namespace for editing, then select `feature-toggle`.

As shown above, this contains three parameters:

* `ssl-client-to-v5-client-ca-certificate`, for mTLS between Link11 WAAP and end users.
* `ssl-server-to-backend-mtls-certificate`, for mTLS between Link11 WAAP and the customer origin (a certificate for customer origins to validate L11WAAP).
* `ssl-server-to-backend-ca-certificate`, for mTLS between Link11 WAAP and the customer origin (a certificate for L11WAAP to validate customer origins).

Set the appropriate parameter(s) to `true`, save the changes, and then [publish](/console-walkthrough/system/publish-changes).

* If `ssl-client-to-v5-client-ca-certificate`was activated, the *CA Certificates* tab will appear on the [Certificates](/console-walkthrough/sites/ssl/certificates) page. After being added there, certificates will be available for use in [Server Groups](/console-walkthrough/sites/server-groups#ca-certificate).
* If `ssl-server-to-backend-mtls-certificate`was activated, the *Server-to-Backend mTLS Certificates* tab will appear on the [Certificates](/console-walkthrough/sites/ssl/certificates) page. After being added there, certificates will be available for use in [Backend Services](/console-walkthrough/sites/backend-services).
* If `ssl-server-to-backend-ca-certificate` was activated, the *Server-to-Backend CA Certificates* tab will appear on the [Certificates](/console-walkthrough/sites/ssl/certificates) page. After being added there, certificates will be available for use in [Backend Services](/console-walkthrough/sites/backend-services).

The following can be helpful in understanding the names and usage of the various certificates:

<figure><img src="/files/sML8VW5gUXNLj3GPcIFA" alt=""><figcaption></figcaption></figure>

## Limiting Log Exporter data lengths

[Log Exporters](/console-walkthrough/system/log-exporters) stream traffic data to external destinations. Using the System DB, admins can limit the maximum lengths of various data included in the messages.

<figure><img src="/files/tAQjYS2WZXJq7fMd6TX8" alt=""><figcaption></figcaption></figure>

This is done by selecting the `system` namespace for editing, then selecting `log-exporter`. The values shown above will be available for editing.

After editing any of these parameters, save the changes and then publish.

The `max_characters` settings are the allowable lengths for the various data fields.

* Each setting is specified as the maximum number of characters. Data exceeding those lengths will be truncated.&#x20;
* The `encoded_fields` limit applies to all fields within [encoded requests](/console-walkthrough/system/log-exporters#include-encoded-request-data), i.e. to each header, cookie, and argument.

The `request_data_max_parameters_num` limit defines the maximum number of parameters in the encoded data. For example, when this is set to `100`, then the following limits are enforced:

1. The maximum number of POST data parameters is 100
2. The maximum number of GET data parameters is 100
3. The maximum number of header data parameters is 100

{% hint style="info" %}
The numbers shown in the screenshot above are the default values. If for some reason the `log-exporter` settings are deleted from System DB, these values will be used.
{% endhint %}


# Publish Changes

<figure><img src="/files/FlnhtwcaZVQ9tszwm0fR" alt=""><figcaption></figcaption></figure>

This page pushes a selected system configuration to the proxy, and makes it active. This is necessary when:

* Edits were recently made to the current configuration
* Changing to a different system configuration on the [Version Control](/console-walkthrough/system/version-control) page: either reverting to a previous version, or rolling forward to one that's different than the currently active one.

## Publishing recent edits to the current configuration

**Whenever you change the configuration of the Link11 WAAP platform, you must save your changes.** This is done with the **"Save"** button, available at the top of many pages within the UI.

{% hint style="warning" %}
If you do not save your changes, they will be lost when you go to a different page within the user interface. You will not be prompted or asked to confirm the abandonment of your changes.
{% endhint %}

After saving the changes, **you must publish them as well**, to push the changes out to the cloud. This is done by coming to this page and selecting the **"Publish"** button.

When you first arrive on this page, the most recent commit is automatically selected, so it is the one that is published when the button is selected. The most recent commit will include all of the changes that were made and saved.

## Publishing a version after working with Version Control

After working with Version Control, you must come to this page, select the desired *Commit* entry (hovering the cursor over an entry will show the **Select** button), and select the "**Publish"** button on the top right.

## Changing to a different commit

To set the system to a different commit, follow these steps:

1. In the pulldown at the top left of the sidebar menu, ensure that the appropriate *Target Bucket*(s) are selected. (The list of buckets is maintained in the [System DB](/console-walkthrough/system/system-db).)
2. The *Commit* list is a list of configurations, with the most recently edited version at the top. If you wish to publish your most recent edits, ensure that the top entry is selected. If instead you wish to revert to a previous entry, find it in the list and select it.
3. Select the "**Publish"** button on the top right.

{% hint style="info" %}
In version 5, the UI does not show which commit is the current published version. We plan to add this in a future version.
{% endhint %}


# Account

## Overview

If the user is logged into the planet directly (i.e., without using SSO), then selecting the user icon (![](/files/R0DifPBkiKyfJebeB25k)) at the top right of the UI will display a menu, including an option for opening the **Account Details** page.&#x20;

This page displays the account details of the current user, allows configuration of MFA (multi-factor authentication), and provides keys for using the API. Its sections are described below.

## Account Details

The name, email address, phone number, and organization of the current user are shown here.

For most users, their account details on this page are read-only. Editing is available through the [Users Management](/console-walkthrough/system/users-management) page.

## User Authentication

This section provides for setup of MFA (multi-factor authentication). It contains a QR code that can be scanned, to obtain an OTP (one-time password) via Google Authenticator, Authy, or other authentication platforms.&#x20;

At the bottom of this section, there are links to authentication apps for iOS and Android.

{% hint style="info" %}
Sending OTPs via SMS is still supported on the login page. However, other forms of authentication are generally preferable, as they are more secure.
{% endhint %}

## API Keys

This section displays the current API Keys. Multiple keys can be defined.

{% hint style="info" %}
API keys are required when [directly accessing](/using-the-product/the-link11-waap-api/using-curl) the [Link11 WAAP API](/using-the-product/the-link11-waap-api). (When [using Swagger](/using-the-product/the-link11-waap-api/using-swagger-ui) to access the API, a key is provided automatically.)
{% endhint %}

To add a key, select **+ New**. Specify a title for the new key.

To revoke an existing key, hover the cursor over it and select the trash can icon.


# Best Practices

This section describes best practices for some common tasks.

{% content-ref url="/pages/-LuXia2stuEeOoAkqlDp" %}
[Saving and Publishing Your Changes](/using-the-product/best-practices/publish-your-changes)
{% endcontent-ref %}

{% content-ref url="/pages/-LxqKQs8Up5CU7X62yOl" %}
[Enabling Passive Challenges](/using-the-product/best-practices/enabling-passive-challenges)
{% endcontent-ref %}

{% content-ref url="/pages/-Lub7az79ZjYJRLlNLFG" %}
[Understanding and Diagnosing Traffic Issues](/using-the-product/best-practices/dealing-with-false-positive)
{% endcontent-ref %}


# Saving and Publishing Your Changes

Whenever you change the configuration of the Link11 WAAP platform within the UI, **you must save your changes**, and **you must publish them to the cloud as well**.

{% hint style="warning" %}
If you do not save your changes, they will be lost when you go to a different page within the user interface. You will not be prompted or asked to confirm the abandonment of your changes.
{% endhint %}

{% hint style="info" %}
The Publishing process checks the saved changes for errors. If no errors are found, they are pushed to the cloud.
{% endhint %}

## Saving Changes

The various Editor pages within the UI have **"Save"** buttons in the top row of controls. Select this button to save whatever changes have been ma.de

Note that the **"Save"** button only saves your changes within your local session. To push them to your planet in the cloud, you must publish the changes as well.&#x20;

## Publishing Your Changes

Follow the process described here: [Publish Changes](/console-walkthrough/system/publish-changes).


# Enabling Passive Challenges

As described [here](/how-link11-waap-works/traffic-reporting-and-analytics#the-challenge-process), out of the box Link11 WAAP includes an **Active Challenge** process. This is very useful in distinguishing humans from bots.

Active Challenges work well, but an even better option is **Passive Challenges**.&#x20;

* Active Challenges temporarily redirect the user's browser. This can affect site metrics gathered by products such as Google Analytics. (Specifically, the initial referrer information is lost.) Passive Challenges are simple pieces of Javascript. They do not redirect the user's browser; they merely ask it to solve a challenge, and then insert the L11WAAP cookies.
* Active Challenges will not occur when site content is served from a CDN. Passive Challenges can still detect bots in this situation.

Most importantly, Passive Challenges allow L11WAAP to use **Biometric Bot Detection**—an advanced and sophisticated means of distinguishing humans from automated traffic sources.

## Biometric Bot Detection

With Biometric Bot Detection, L11WAAP continually gathers and analyzes stats such as client-side I/O events, triggered by the user’s keyboard, mouse, scroll, touch, zoom, device orientation, movements, and more. Based on these metrics, the platform constructs and maintains behavioral profiles of legitimate human visitors. L11WAAP learns and understands how actual humans interact with the web apps it is protecting. Continuous multivariate analysis verifies that each user is indeed conforming to expected behavioral patterns, and is thus a human user with legitimate intentions. [More information about this.](/reference-information/hostile-bot-detection-lwcsi/biometric-behavioral-verification)

{% hint style="info" %}
**We recommend that all customers enable Passive Challenges** if it is possible to do so. Biometric Bot Detection provides much more robust detection of automated traffic than is possible without it.
{% endhint %}

## Implementation

Implementing Passive Challenges is simple. Place this Javascript code within the pages of your web applications:

```
<script src="/c3650cdf-216a-4ba2-80b0-9d6c540b105e58d2670b-ea0f-484e-b88c-0e2c1499ec9bd71e4b42-8570-44e3-89b6-845326fa43b6" type="text/javascript"></script>
```

{% hint style="info" %}
The code snippet can go into the header or at the end of the page. **The best practice is to place it within the header.** This ensures that subsequent calls contain authenticating cookies.

(This matters for the first page served to a visitor. Subsequent pages will already have the authenticating cookies to include with their requests.)
{% endhint %}

{% hint style="info" %}
**Most customers set up the code snippet as a tag within their tag manager.** This makes it simple to install it instantly across their entire site/application.
{% endhint %}

If desired, the script code can include `async` and/or `defer` attributes:

```
<script async src="/c3650cdf-216a-4ba2-80b0-9d6c540b105e58d2670b-ea0f-484e-b88c-0e2c1499ec9bd71e4b42-8570-44e3-89b6-845326fa43b6" type="text/javascript"></script>
```

```
<script defer src="/c3650cdf-216a-4ba2-80b0-9d6c540b105e58d2670b-ea0f-484e-b88c-0e2c1499ec9bd71e4b42-8570-44e3-89b6-845326fa43b6" type="text/javascript"></script>
```

These usually are not necessary, and their effect will depend on the placement of the script within the page. Their use is left to your discretion.

## Testing

To test the implementation, use a browser to visit a page containing the Javascript snippet. Once it runs, the browser should have a cookie named **waap\_id**.

## Disabling Active Challenges (Optional)

There are two primary situations where customers sometimes want to disable Active Challenges:

* **When a customer needs site analytics** to correctly reflect all referrers. (Active Challenges can interfere with this.)
* **For API endpoints**. Active Challenges are designed to verify the client's browser environment; for most API calls, there is no browser environment to verify. (For users of our [Mobile SDK](/console-walkthrough/sites/mobile-application-groups), this is not a problem. They can still use active challenges for these endpoints.)

Other than those situations, Active Challenges can be very beneficial.

{% hint style="info" %}
**We recommend that you keep Active Challenges enabled if possible.** They automatically eliminate almost all DDoS traffic, scanning tools, and other hostile bot traffic.
{% endhint %}

If you wish to turn off Active Challenges, do the following.&#x20;

* Decide which paths/URLs should have Active Challenges disabled.
* Make a list of the [Security Policies](/console-walkthrough/security/security-policies) that are enforced upon those paths/URLs.&#x20;
* Ensure that this combined list of Security Policies does not apply to any paths/URLs where you wish to keep Active Challenges enabled. If there are some undesired paths/URLs included, split them off into separate Security Policies that are not part of the list. When you are done, the list of Policies should include all desired paths/URLs, and only those paths/URLs.
* For each Security Policy in the list:
  * To completely disable Active Challenges, ensure that its [ACL Profile](/console-walkthrough/security/acl-policies) does not include any tags in the *Bot Challenge / Apply* column.&#x20;
  * To partially disable Active Challenges, ensure that its ACL Profile has the proper combination of tags in the *Bot Challenge / Skip* and *Bot Challenge / Apply* columns.

{% hint style="info" %}
Note that the `acl-deny-bot` ACL Profile includes the `all` tag in its *Bot Challenge / Apply* column. As described above, for all Security Policies that use this Profile, you could exempt some traffic sources from Active Challenges by adding tags to the *Bot Challenge / Skip* column, or all traffic sources by removing the `all` tag.

However, if this were done, then this Profile would not behave in the way that its name implies. This can cause confusion later: not only during administration, but also when viewing events in the Dashboard and Events Log. \
\
To avoid this situation, we recommend that this default Profile should not be edited. Instead, admins should create a separate one for use in the relevant Security Policies.&#x20;
{% endhint %}

{% hint style="info" %}
Turning off Active Challenges will disable the direct blocking of bots (where a requestor is blocked merely for being identified as a bot). However, automated traffic will still be excluded via all other relevant means.&#x20;
{% endhint %}

{% hint style="danger" %}
**If you have not enabled Passive Challenges** (and successfully tested them), disabling Active Challenges is not recommended.
{% endhint %}


# Understanding and Diagnosing Traffic Issues

Leveraging Link11 WAAP's traffic data

## Introduction

Many security solutions provide information only about the traffic that they block. Contrary to this, Link11 WAAP shows *all* of the traffic that it receives.

This provides you with a powerful ability to dig into your traffic data and gain deep understanding about the nature and disposition of incoming requests.&#x20;

Metrics about blocked requests are useful, but their usefulness is multiplied when you can compare them to passed requests. By showing all requests, L11WAAP allows you to understand what "normal" requests look like. This gives you more insights into abnormal traffic.

{% hint style="info" %}
**The discussion below assumes you are already familiar with** [**Query Filter Syntax and Best Practices**](/reference-information/query-filter-syntax-and-best-practices)**.**
{% endhint %}

## Gaining General Insights

L11WAAP provides multiple ways to view your traffic. The discussion below will focus on the [Events Log](/console-walkthrough/analytics/events-log). Similar tactics can be applied when viewing different parts of the [Dashboard](/console-walkthrough/analytics/dashboard).

Sometimes the Events Log is used to answer a specific question about a request or a traffic source. At other times, it might be a more general exploration; for example, a beginning-of-the-day review of what happened over the last 24 hours.

Let's discuss the latter scenario (a general exploration). Because the Events Log shows all requests, it can be overwhelming. It's helpful to start by excluding requests that aren't as relevant to your current purpose. Examples:

* **Exclude passed requests**: `result!="Passed"`
* **Exclude requests being rejected by the origin** (i.e., the upstream server): `result!="Blocked by origin"`
* **Exclude requests from a banned IP**: `tags!="ip:192-168-2-3"`.&#x20;
* **Exclude requests that are obviously invalid**. For example, exclude those with unrecognized host headers: `reason~"unrecognized"`.

Eventually, you can filter the display down to a list of challenges or blocked requests that might produce some insights.

From this point, you are looking for possible patterns, or unusual outliers, and considering possible actions to take. For example:

* **Are there a lot of requests for a Wordpress file, but your site does not use Wordpress?** These are coming from malicious traffic sources. It might be useful to set up a [Dynamic Rule](/console-walkthrough/security/dynamic-rules), e.g. to Ban requestors who submit more than one request for that file in a three-minute period.
* **Is the same IP failing multiple challenges?** It might be interesting to filter on that IP only, and go through all of its activity, to see what that traffic source was trying to do. (You can see that a challenge is being failed when the challenge itself appears in the logs, but it is not followed by a successful request by the IP for the same URI.)
* **Are there many blocked requests for the same URI, but from different traffic sources?** This might be a False Positive alarm. See below for more on this.

There is no set procedure for this process. Essentially, you are browsing the list of challenges or blocked requests, thinking about why you are seeing the entries there, and asking further questions.

## Translating Encoding in Requests

Sometimes, request data will be encoded. Here's an example of an XSS attempt:

`default.site/api/?a==`\
`%3c%73%63%72%69%70%74%3e%77%69%6e%64%6f%77%2e%6f%6e%6c%6f%61%64%20%3d%20%66%75%6e%63%74%69%6f%6e%28%29%20%7b%76%61%72%20%6c%69%6e%6b%3d%64%6f%63%75%6d%65%6e%74%2e%67%65%74%45%6c%65%6d%65%6e%74%73%42%79%54%61%67%4e%61%6d%65%28%22%61%22%29%3b%6c%69%6e%6b%5b%30%5d%2e%68%72%65%66%3d%22%68%74%74%70%3a%2f%2f%61%74%74%61%63%6b%65%72%2d%73%69%74%65%2e%63%6f%6d%2f%22%3b%7d%3c%2f%73%63%72%69%70%74%3e`

In plain text, this is:

`default.site/api/?a==window.onload = function() {var link=document.getElementsByTagName("a");link[0].href="http://attacker-site.com/";}]`

L11WAAP will decode many requests, but not necessarily all. For example, double-encoded requests will only have their first level of encoding undone.

In these cases, you can right-click on the string in the UI (for example, the *Block Reason* field), select **Copy Value To Clipboard**, and run it through decoding tools. (For example, <http://0xcc.net/jsescape/>.)

## False Positive Alarms

A “False Positive” (FP) alarm occurs when a security system misinterprets a non-malicious activity as an attack. These errors are a critical issue for cybersecurity.

Although it might seem that FP errors do not necessarily have serious consequences, incorrect security alerts can lead to significant monetary losses. For example, an e-commerce site might incorrectly exclude real online shoppers. Or, it might reject "good" web crawlers, which would reduce its Internet visibility.

FP diagnosis is often done when L11WAAP is first deployed, before it has been fine-tuned for the customer's applications. It can also be done later, when you discover that certain requests are being blocked, but you do not understand why.&#x20;

## **Determining if a block is a FP**

When examining blocked request(s), it can be helpful to ask questions such as the following.

#### **Is the configuration appropriate for the application?**

Sometimes an application will expect and accept inputs that L11WAAP blocks by default. Example: the site might use a CMS which accepts HTML/Javascript POST requests. However, out of the box, the system is often configured to block requests containing POST. Thus, L11WAAP would need to be re-configured to match the application it is protecting.

#### **Has the web application been updated, without** L11WAAP **being updated as well?**

If the range of valid inputs has changed, but L11WAAP was not re-configured, then FP errors can result.

**Is the block happening to multiple users?**

If a single IP is being blocked, but other requestors for the same URI are being allowed through, the block is more likely to be the correct response to this IP's request. This is especially true when the single IP has attempted other questionable activities.

Conversely, if multiple requestors are being blocked, and they seem to be innocuous otherwise, this indicates the problem might be a FP.

#### Is the block being done by L11WAAP, or is it coming from elsewhere?

There are some situations where a request is blocked even though the system has no obvious reason to be blocking it. This can occur when L11WAAP is not actually the entity making the decision.

* **The upstream server can reject requests**. These requests can be displayed in the Events Log with `result~"origin"` as the filter.&#x20;
* **L11WAAP can use external sources of information**. Out of the box, L11WAAP includes a number of [Global Filters](/console-walkthrough/security/global-filters) based on threat intelligence feeds. Although a given traffic source might not be triggering any of L11WAAP's explicitly-configured security settings, it can still be blocked based on factors such as these.

#### Is this a FP that resulted from incorrect user actions?

Example: a web user visited a landing page, entered contact details into a form, and then tried to proceed to the next page. However, the request to proceed was blocked.&#x20;

This could be a FP due to "junk input." Perhaps the user entered a phone number of "1111111111" and it was rejected by the upstream application. Or perhaps the page itself autocompleted a field and inadvertently created junk input on its own.

#### Is this a FP that resulted from faulty or too-restrictive parameters within L11WAAP?

If requestors are being blocked for violating rate limits, and the rate limits are very stringent, then perhaps the limits are too tight, and they need to be relaxed.

Or, perhaps the block is the result of content filtering. This feature is powerful, and it is possible to mistakenly configure it to be too restrictive.

**Example:** requests are being blocked because of a [Content Filter Rule](/console-walkthrough/security/content-filter/rules) that contains this *Match* condition:

`(?i)(select|create|drop|\<|>|alert)\W`

The admin wrote this regex in order to identify SQL injection attempts (i.e, SELECT, CREATE, and DROP commands. Normally SQL and code injection attempts are blocked automatically by L11WAAP, but occasionally customers choose to disable this).

Now let's examine one of the blocked requests in the Events Log. It contains this:

`https://www.pinterest.com/pin/create/button/?url=https%3A%2F%2Fexample.com%2Fpitbull-2012%3Frt%3Dstorefront%26rp%3Dpitbull%26rn%3DPitbull%26s%3Dhanes-S04V%26c%3DBlack%26p%3DFRONT&amp;media=&amp;description=`

This can be decoded with a tool such as <http://0xcc.net/jsescape/>. It now becomes this:

`https://www.pinterest.com/pin/create/button/?url=https://example.com/pitbull-2012?rt=storefront&rp=pitbull&rn=Pitbull&s=hanes-S04V&c=Black&p=FRONT&amp;media=&amp;description=`

Now let's see why the regex condition matched the request. On <https://www.debuggex.com/>, it's possible to paste in regex and a string, and see if/where a match occurs.

![The result from deguggex.com](/files/-Lxq7P8RNmKoCNX8KS1O)

Notice the highlighted (in yellow) part of the string in the bottom textbox. This shows which part of the bottom string matches with the regex in the box above it.

We see that the expression that was meant to identify an SQL command of CREATE, is also matching with the URL generated by a user who was trying to feature this site's product on Pinterest.

This indicates that the regex should probably be modified, so that it only accomplishes its intended purpose. In this example, it could be modified as follows:

`(?i)(\sselect|\screate|\sdrop|\<|>|alert)\W`

This would require a space to be found before each potential SQL command, thus eliminating matches when those words are found in a URL.

## Summary of FP Detection

As mentioned earlier, there is no set procedure for the process of identifying the underlying reasons why requests are blocked. It requires digging into the requests, gathering data, and asking questions.

Hopefully the examples above are helpful in illustrating the necessary thought process, and some of the tools that are available.


# How Do I...

A task-based FAQ

This section answers questions that often arise about using Link11 WAAP.

{% content-ref url="/pages/nhgdghBPF5nJ4G4OLKfD" %}
[Authenticate mobile app users](/using-the-product/how-do-i.../authenticate-mobile-app-users)
{% endcontent-ref %}

{% content-ref url="/pages/-Lxamt6zmoUxDQIpxbFv" %}
[Ban, unban, and allowlist traffic sources](/using-the-product/how-do-i.../ban-unban-and-whitelist-traffic-sources)
{% endcontent-ref %}

{% content-ref url="/pages/-LwriIfFgFJ\_qqg3TokC" %}
[Bypass Link11 WAAP for loadtesting or other purposes](/using-the-product/how-do-i.../bypassing-rate-limits-for-loadtesting)
{% endcontent-ref %}

{% content-ref url="/pages/cAX7fv8XsvoSfZ0B2jEV" %}
[Configure a new path/section of a site](/using-the-product/how-do-i.../configure-a-new-path-section-of-a-site)
{% endcontent-ref %}

{% content-ref url="/pages/-LugLIqqfh20zIuInKy1" %}
[Control caching behavior](/using-the-product/how-do-i.../cache-modes)
{% endcontent-ref %}

{% content-ref url="/pages/4MZJ0KvXDyUTtcKz3RAB" %}
[Enable GraphQL traffic](/using-the-product/how-do-i.../enable-graphql-traffic)
{% endcontent-ref %}

{% content-ref url="/pages/5FTkTLQ8M5xI6qw2ZVR3" %}
[Enable mTLS (mutual TLS)](/using-the-product/how-do-i.../enable-mtls-mutual-tls)
{% endcontent-ref %}

{% content-ref url="/pages/lCDDqYzuRmcz9Y21Ud53" %}
[Protect sensitive information in logs and analytics](/using-the-product/how-do-i.../protect-sensitive-information-in-logs-and-analytics)
{% endcontent-ref %}

{% content-ref url="/pages/-LwrkzZ3vV0nUZCCkvwh" %}
[Quickly block an attacker](/using-the-product/how-do-i.../quickly-blocking-an-attacker)
{% endcontent-ref %}

{% content-ref url="/pages/9x7rMDZp5vsuPIbl97va" %}
[Redirect or block HTTP traffic](/using-the-product/how-do-i.../redirect-or-block-http-traffic)
{% endcontent-ref %}

{% content-ref url="/pages/-LxWLKy41mqYwvokPj-k" %}
[Set rate limits and exemptions](/using-the-product/how-do-i.../set-rate-limits)
{% endcontent-ref %}

{% content-ref url="/pages/1N66wVxUwQjhuzTvw331" %}
[Stream event data to a SIEM solution or other destination](/using-the-product/how-do-i.../stream-event-data-to-a-siem-solution-or-other-destination)
{% endcontent-ref %}


# Add custom messages to events

Sometimes it is desirable to add custom annotations to events in the traffic logs: perhaps for monitoring, visibility, or other purposes.

This can be done with [Edge Functions](/console-walkthrough/sites/edge-functions#adding-custom-messages-to-log-events).


# Authenticate mobile app users

Link11 WAAP includes a Mobile SDK for authenticating mobile application clients. For more information, see [Mobile Application Groups](/console-walkthrough/sites/mobile-application-groups).


# Ban, unban, and allowlist traffic sources

The [Quarantine](/console-walkthrough/security/quarantined) section shows a list of traffic sources (i.e., sources of incoming requests) that are currently banned, blocklisted, and allowlisted.&#x20;

## How to ban a requestor

A traffic source is banned automatically when it violates a [Dynamic Rule](/console-walkthrough/security/dynamic-rules).&#x20;

You cannot manually move a traffic source into quarantine. Instead, you can create a Dynamic Rule to do it for you. The Dynamic Rule's parameters should be as follows:

* It should be active (in other words, the *Inactive* toggle should not be selected).
* *Target* should be set to `IP`
* *Number of events* should be 0
* *Action* should be a blocking action (e.g., `Dynamic-rule block`)
* *Quarantine Time* should be the length of time you wish the ban to last
* The *Exclude* list should be empty
* The *Include* list should not contain `all`
* The *Include* list should contain the tag(s) that will uniquely identify requests coming from the traffic source.

## How to unban a requestor

Manually removing a requestor from quarantine is discussed here: [Cancelling quarantines and preventing False Positives](/console-walkthrough/security/quarantined#cancelling-quarantines-and-preventing-false-positives).

## How to allowlist a requestor

To exempt a traffic sources from potential quarantine, add identifying tags to the [**Exclude** list in the active Dynamic Rules](/console-walkthrough/security/dynamic-rules#include-and-exclude).

To exempt a traffic source from other stages of filtering, do one of the following:

* To bypass all stages of filtering, follow the steps described here: [Bypass Link11 WAAP for Loadtesting or Other Purposes](/using-the-product/how-do-i.../bypassing-rate-limits-for-loadtesting).
* To exempt requests only from bot challenges or content filtering, configure an [ACL Profile](/console-walkthrough/security/acl-policies) with appropriate tag(s) in the *Bypass* list, then use a [Security Policy](/console-walkthrough/security/security-policies) to assign that ACL Profile to the desired paths/URLs.
* To exempt requests only from bot challenges, configure an [ACL Profile](/console-walkthrough/security/acl-policies) with appropriate tag(s) in the *Bot Challenge / Skip* list, then use a [Security Policy](/console-walkthrough/security/security-policies) to assign that ACL Profile to the desired paths/URLs.


# Bypass Link11 WAAP for loadtesting or other purposes

Sometimes an admin needs to bypass the WAAP's traffic filtering, for example when "attacking" an application or server as part of a loadtest. Under normal circumstances, L11WAAP would prevent this, because it would enforce rate limits and block the excessive requests from reaching the backend.

Specific requests can be exempted from L11WAAP's traffic filtering (including rate limiting) by:

* Creating a [Global Filter](/console-walkthrough/security/global-filters) with narrowly-defined [*Rules*](/console-walkthrough/security/global-filters#rule-list) (which will only match those specific requests, and no others)
* Selecting the Global Filter's *Action* to be one of type *Skip*
* And ideally, defining a unique [tag](/console-walkthrough/security/global-filters#tags) to assign to those requests, so they will be identifiable in the traffic logs.

Incoming requests that meet the criteria for the Global Filter will not subjected to filtering. They will be passed directly through to the backend.


# Configure a new path/section of a site

**Scenario**: An admin has recently created a new section within an existing domain. (In this context, "section" means a path, or set of paths, that can be described in a single regex.) For example, perhaps a new API version is being exposed at `/apiv3`, which is a URL that did not previously exist.

How can the admin configure Link11 WAAP's security settings for the new path(s)?&#x20;

As shown in the diagram below, the association between security settings and paths is done within a [Security Policy](/console-walkthrough/security/security-policies).&#x20;

<figure><img src="/files/uiNsn3RqCbtNQUDLvZnM" alt=""><figcaption></figcaption></figure>

Specifically, each Security Policy contains a Path Map: a list of paths, and the security settings assigned to each.

Thus, the process for configuring new paths within L11WAAP is as follows:

1. Determine the Security Policy currently in place for the domain
2. Within that Security Policy, clone an existing Path Map
3. Configure the new Path Map as appropriate, to contain the new settings.

These steps are described below.

## Determining the Security Policy

1. Navigate to **Sites** -> **Server Groups**.
2. In the list that appears, select the [Server Group](/console-walkthrough/sites/server-groups) for the domain in question.
3. On the Server Group Editor page, note the current selection in the **Security Policy** pulldown list.

## Cloning an existing Path Map

1. Navigate to **Security** -> **Security Policies**
2. Select the Security Policy that is (as noted above) currently assigned to the domain's Server Group.
3. At the bottom of the Security Policies Editor page is the **Path Mapping** section. Expand one of the entries in this list.
4. Within the expanded display of the Path Map, at the bottom right, select the **Fork Path Mapping** button. This will create a clone of the original entry.

## Configuring the new Path Map

Ensure that the new Path Map is displayed for editing, and then:

1. Edit its **Name** to something appropriate
2. Define the **Match path** with an expression that will match all the new path(s) being configured
3. Verify that the other security settings in this Path Map are appropriate. If not, existing security rulesets (such as Rate Limit Rules, Content Filter Profiles, etc.) are available for selection. If it is necessary to create one or more new rulesets, you will need to leave this page (be sure to select **Save** first!), create the new settings, and return here to select them.&#x20;
4. When the new Path Map is correctly defined, select **Save.** Then [publish](/console-walkthrough/system/publish-changes) the changes.


# Configure TCP passthrough

Sometimes end-to-end encryption is necessary, and client traffic must be kept encrypted until it reaches the backend server.

For this purpose, Link11 supports TCP passthroug&#x68;**.** When this is configured, neither the Link11 load balancer nor L11WAAP will terminate or decrypt the TCP connection. The specified traffic will be passed through to the backend as-is.

{% hint style="warning" %}
**Caution**: If TCP passthrough is enabled, we recommend using it with the narrowest possible scope. This traffic is not decrypted, and therefore, cannot be inspected by Link11.&#x20;

Passed-through requests are not filtered for hostile content, rate limit violations, ACL enforcement, etc. They also are not logged by Link11.
{% endhint %}

To enable TCP passthrough, [contact support](/support).


# Control caching behavior

Web clients can cache resources from a server. Afterwards, a client can access its local cache, which reduces the number of requests sent to the server.&#x20;

Servers can instruct clients to implement caching in certain ways. Servers can also set separate caching policies for any intermediary proxies in-between the server and the client.

Link11 WAAP is a proxy between the clients and the backend. When the backend responds to clients, the outgoing responses pass through L11WAAP. You can instruct the system to preserve or alter the caching instructions in those responses.

This can be done through [Edge Functions](/console-walkthrough/sites/edge-functions). Out of the box, L11WAAP includes several cache policy Edge Functions for this purpose. If you need additional assistance in customizing L11WAAP's caching behavior, [contact support](/support).&#x20;


# Customize responses to clients

Blocked requests can receive customized [response headers](/console-walkthrough/security/actions#response-headers-only-available-for-block-actions), [status codes](/console-walkthrough/security/actions#status-code-only-available-for-block-actions), and [content](/console-walkthrough/security/actions#content-only-available-for-block-actions), by configuring the appropriate Actions.

Admins can also run custom Lua code via [Edge Functions](/console-walkthrough/sites/edge-functions). Edge Functions with a [phase](/console-walkthrough/sites/edge-functions#phase) of `Response Pre Processing` or `Response Post Processing` will be run after the backend has responded to the request, but before the response is sent to the client.


# Enable GraphQL traffic

## Motivation

By default, Link11 WAAP will block GraphQL traffic, for two reasons:

1. The size of the argument
2. [Content Filter Rule](/console-walkthrough/security/content-filter/rules) number **600110**, which contains this *Match* string: `([$@{}()\[\]].*){8,})`

## Enabling GraphQL traffic

To allow GraphQL traffic, create a [Content Filter Profile](/console-walkthrough/security/content-filter/profiles) with:

1. An *Argument Max Length* that will accommodate the maximum size of the queries
2. This tag in the *Ignore Content Filter Tags* list: `cf-rule-name:600110`

Then assign this Content Filter Profile to the location (i.e., the site or path) of the GraphQL queries via an appropriate [Security Policy](/console-walkthrough/security/security-policies).


# Enable mTLS (mutual TLS)

## Overview

Link11 WAAP supports mTLS encryption. This is optional, and can be enabled separately for:&#x20;

* Communication between Link11 WAAP and customer backends, for one or both ends of the pipeline.&#x20;
* Communication between clients (end users) and L11WAAP.

To enable mTLS for an end of a pipeline, the appropriate certificate must be supplied. Their names within the system are as follows:

<figure><img src="/files/sML8VW5gUXNLj3GPcIFA" alt=""><figcaption></figcaption></figure>

## How it works

### L11WAAP-to-customer-backend mTLS

Configuring mTLS to the customer backend is straightforward. After enabling this feature (as described below), admins add certificate(s) and assign them to [Backend Service(s)](/console-walkthrough/sites/backend-services). Once configured, L11WAAP will use mTLS when communicating with customer origins.

### Client-to-L11WAAP mTLS

Configuring mTLS to clients also requires feature enablement. Then, admins add CA Certificates and assign them to [Server Groups](/console-walkthrough/sites/server-groups#ca-certificate).&#x20;

Once client-to-L11WAAP mTLS is configured, end users will be required to present a client certificate at the beginning of each session during the TLS handshake. L11WAAP will validate the certificate, including the date, issuer, and verification against the [Client Revocation List](/console-walkthrough/sites/server-groups#using-crls-to-revoke-client-certificates). If validation fails, the user will receive an error, and will not be permitted to connect to the protected system.

Two additional notes about this type of mTLS:

* In the user interface, mTLS is only available when using an AWS [NLB](https://docs.aws.amazon.com/elasticloadbalancing/latest/network/introduction.html) (Network Load Balancer). To enable mTLS when using a Link11 load balancer, contact support.
* mTLS verification does not exempt a client from other types of traffic filtering. Even if a client  successfully establishes an mTLS connection with L11WAAP, its requests will still be blocked if they originate from a banned source, or exceed rate limits, or match a content filtering signature, etc.

## How to configure mTLS for communication with the backend(s)

Follow this process:

* [Enable the desired type(s) of server-to-backend certificates within the system](/console-walkthrough/system/system-db#enabling-certificates-for-mtls).
* Upload the certificate(s) in the *Server-to-Backend mTLS Certificates* tab and/or *Server-to-Backend CA Certificates* tab(s) of the [Certificates](/console-walkthrough/sites/ssl/certificates) page.
* [Publish](/console-walkthrough/system/publish-changes) your changes.
* Assign the appropriate certificate(s) to each Backend Service:
  * Open the Backend Service in the [Backend Service Editor](/console-walkthrough/sites/backend-services) page.&#x20;
  * Select the appropriate certificate(s) in the dropdown list(s).
* Save and publish your changes.

## How to configure mTLS for communication with clients

Follow this process:

* [Enable CA Certificates within the system](/console-walkthrough/system/system-db#enabling-certificates-for-mtls).
* Upload the CA Certificate(s) in the *CA Certificates* tab of the [Certificates](/console-walkthrough/sites/ssl/certificates) page.
* [Publish](/console-walkthrough/system/publish-changes) your changes.
* Assign the appropriate certificate to each Server Group:
  * Open the Server Group in the [Server Group Editor](/console-walkthrough/sites/server-groups#overview) page.&#x20;
  * Select the appropriate CA certificate in the [dropdown list](/console-walkthrough/sites/server-groups#ca-certificate).
  * Select the desired [mode](/console-walkthrough/sites/server-groups#mode).
  * Configure [CRLs](/console-walkthrough/sites/server-groups#using-crls-to-revoke-client-certificates) (Client Revocation Lists), if desired
* Save and publish your changes.


# Generate or renew my own SSL certificates

By default, Link11 supports communication between customer backends and [Let's Encrypt](https://letsencrypt.org/).&#x20;

When a backend system requests a new or renewed certificate from LE, Let's Encrypt responds initially with a challenge. Because Link11 WAAP is a proxy for the backend, this challenge will be sent to L11WAAP.&#x20;

Under normal circumstances, L11WAAP will forward this to the customer system. If this is not occurring, something in L11WAAP's default configuration might have been changed.&#x20;

To correct this, perform the following two-step process.

## Step 1: Verify the necessary Global Filter

1. Confirm that there is a [Global Filter](/console-walkthrough/security/global-filters) named *Let's Encrypt Requests*.
2. Confirm that this Filter:
   1. is in [Active mode](/console-walkthrough/security/global-filters#general-parameters)
   2. will add a tag of `let-s-encrypt`
   3. has an [Action](/console-walkthrough/security/global-filters#action) of `monitor (tag only)`
   4. contains a single [Rule](/console-walkthrough/security/global-filters#rule-list) entry, with *Category* set to `URI` and *Match* set to `^/\.well-known/(acme-challenge|rbz-traffic)/[A-Za-z0-9_-]+$`
3. If any edits were performed as a result of the above, save them and [publish](/console-walkthrough/system/publish-changes).

{% hint style="info" %}
If your planet was created before May 2025, the Global Filter described above should have been added during the upgrade to v5.3.17. Therefore, it should be restorable from the Version History at the bottom of the Global Filter Editor. Alternately, the settings described above can be edited manually.
{% endhint %}

## Step 2: Verify the passthrough of Let's Encrypt traffic

The Global Filter described above will add a tag of `let-s-encrypt` to challenges from LE.&#x20;

To ensure that this traffic is passed through L11WAAP to the customer backend:

1. Ensure that this tag is in the [Ignore field](/console-walkthrough/security/content-filter/profiles#step-3-allowlisting) in every Content Filter Profile. During this process, if a Profile is edited, ensure that the changes are saved.
2. After all Profiles have been checked, publish the changes (if any were made).

## Troubleshooting

If the process above is followed, and Let's Encrypt traffic is still being blocked by L11 WAAP, check the LE requests in the Events Log to discover the reason(s) for this.

Note that the passthrough of Let's Encrypt requests does not occur until the Content Filtering stage of the [traffic filtering process](/how-link11-waap-works/traffic-filtering-process). This means that several stages of filtering are still performed before the passthrough can occur. If legitimate requests from Let's Encrypt are tagged with `let-s-encrypt` but are still being blocked, use the Events Log entries to determine the source of the blocking action, and then correct the security settings that are responsible for this.

## Getting assistance

Feel free to [contact support](/mobile-sdk-v2.3.0/support) for assistance with any part of the process described above.


# Improve Events Log performance for large argument volumes

When a web application or API frequently receives incoming requests with excessively large arguments, or a large number of arguments, this can adversely impact the performance of the Events Log.

To address this, Link11 WAAP can defer the retrieval of arguments until an admin specifically requests it. More info on this feature is [here](/console-walkthrough/analytics/events-log#improving-performance-by-deferring-argument-retrieval).


# Load balance traffic across my origin servers

Link11 WAAP provides inherent capabilities for load-balancing across origin/backend servers.&#x20;

This is configured in [Backend Services](/console-walkthrough/sites/backend-services).


# Protect sensitive information in logs and analytics

Sometimes, incoming requests contain sensitive or Personally Identifiable Information that should not be included in logs and other forms of analytics.

Link11 WAAP provides the ability to mask specific types of information. This is configured using the *Masking Seed* and *Mask?* fields within [Content Filter Profiles](/console-walkthrough/security/content-filter/profiles).&#x20;

Note that you should ensure that [the relevant requests are always subjected to the Content Filtering process](/console-walkthrough/security/content-filter/profiles#circumstances-where-content-filtering-will-not-occur).&#x20;


# Quickly block an attacker

Sometimes situations will arise where an attacker needs to be blocked temporarily, while the security posture is being reconfigured. Since the hostile traffic is not being filtered, admins recognize that their security posture needs to be strengthened, but they need some time to analyze the situation. Meanwhile, the attacker should be blocked.

It might seem that admins should merely add the [system tag](/how-link11-waap-works/tagging#system-tags) for the attacker's IP (e.g., `ip:82-64-131-193`) to the *Enforce Deny* column in the applicable [ACL Profile](/console-walkthrough/security/acl-policies). This can work (as long as the attacker is consistently using the same IP), but it's not necessarily the best approach.

## Using a Global Filter

The better approach is usually to create a [Global Filter](/console-walkthrough/security/global-filters), based upon criteria that will match the attacker (but will not match any other traffic source), with an [Action](/console-walkthrough/security/actions) to block the matching requests.

Here's why this is usually the optimal choice:

* While both approaches can be done when the attacker is using a single IP (or a set of IPs), the second one also supports situations where the attacker is rotating IPs, and therefore needs to be identified with a combination of characteristics.
* The ACL Profile will limit the blocking to specific paths/URLs (those defined in the [Security Policies](/console-walkthrough/security/security-policies) associated with it, and used within one or more [Server Groups](/console-walkthrough/sites/server-groups)). The Global Filter will block the attacker's activity globally, which is usually more desirable.&#x20;
* The Global Filter is more efficient during processing, because the hostile requests are blocked earlier in the [traffic filtering process](/how-link11-waap-works/traffic-filtering-process).
* The ACL Profile approach can result in the long-term accumulation of "special cases" within the Profiles, if admins are not diligent about cleaning them up when they're no longer needed. This situation is not ideal, because it can be messy and difficult to manage. The Global Filter approach makes it easier to also consists in creating special cases, but they are more visible and thus, easier to find and purge when no longer necessary.

## Consider a dedicated Global Filter for long-term management

Instead of creating and discarding one-off Global Filters, it's often better to maintain a dedicated Global Filter for manually blocking attackers. As traffic sources need to be blocked (or unblocked), admins can just add (or remove) matching criteria.

This creates a single location for administering these special cases. Admins can easily monitor the current list of manual interventions, and purge them as they become obsolete.


# Redirect or block HTTP traffic

Under most circumstances, a session over unencrypted HTTP should not be accepted. Using Link11 WAAP, admins can refuse HTTP requests by either:

* Redirecting them to HTTPS
* Or simply blocking them.

Admins must also choose whether to refuse HTTP traffic:

* Globally, throughout the entire planet, or
* Selectively, to certain paths within the planet.

This can all be done with a single [Global Filter](/console-walkthrough/security/global-filters).&#x20;

## Initial Configuration

Create a Global Filter with these parameters:

* *Name* and *Description*: as desired
* *Active mode*: enabled
* *Source*: `self-managed`
* *Tags*: as desired, perhaps something descriptive such as `http-received`

## Configuring the Action

The  Global Filter's *Action* setting determines what will happen to the request.

To block the request completely, choose a blocking Action (perhaps the default `Global filter block` Action).

To redirect the HTTP request to HTTPS, you can select the default `https redirect` Action (shown below). If you choose to edit this Action or use a different one, ensure that the selected Action has the same *Status code,* and the same setting for the `location` header.

<figure><img src="/files/SsVfgcnG5JlTMYlkhSMC" alt=""><figcaption></figcaption></figure>

## Configuring the Rule list&#x20;

Within the *Rule* list, select **+New Entry**. Populate the new entry with:

* *Category* set to`Tag`
* *Match* set to `scheme:http`
* Whatever *Annotation* you wish.

At this point, the Global Filter should look something like this:

<figure><img src="/files/n2b9KNHNPSIeQ2MoGrkX" alt=""><figcaption></figcaption></figure>

## Configuring the Scope

By following the steps above, you have a Global Filter that will block or redirect HTTP traffic globally, throughout the entire planet.

If this was your goal, skip down to the [Saving and Publishing](/using-the-product/how-do-i.../redirect-or-block-http-traffic#saving-and-publishing) steps below.

If instead you only want to apply this Global Filter to certain paths within the planet, you must create one or more additional entries in the *Rule* list. Each should have:

* *Category* set to`Path`
* *Match* set to a regex describing the path
* Whatever *Annotation* you wish.

Create as many entries as necessary to include all the desired paths.

Note that these entries should all be within the same section as the first `Tag` entry. (If instead you selected +**New section**, and the entries are now in separate sections, ensure that the relation between them is set to **Relation: AND**.)

## Saving and Publishing

When you have completed the steps above, the Global Filter has been created.

Select **Save**, and then [publish the changes](/console-walkthrough/system/publish-changes).


# Run custom code

To run custom Lua code before or after Link11 WAAP processes a request, use an [Edge Function](/console-walkthrough/sites/edge-functions).

To define code for customizing nginx's behavior or parameters, use [Proxy Templates / Advanced Configuration](/console-walkthrough/sites/proxy-templates#advanced-configuration).


# Set rate limits and exemptions

Restricting consumption of resources and rate of requests

Different types of rate limits are defined in different parts of the Link11 WAAP interface.

**Static rate limits for entire sites/applications:** A static rate limiting capability is available via the [Application IP Rate Limits settings](/console-walkthrough/sites/proxy-templates#application-ip-rate-limits) within [Proxy Templates](/console-walkthrough/sites/proxy-templates). This is simple, IP-based rate limiting that applies globally to every site/application based upon that Proxy Template.

**Granular rate limiting:** More powerful capabilities are available through [Rate Limit Rules](/console-walkthrough/security/rate-limit-rules), including variable scope, multiple criteria for tracking requestors, actions, and more. These Rules are then associated with specific locations/URLs through [Security Policies](/console-walkthrough/security/security-policies).&#x20;

**Global enforcement by traffic source:** Requestors who submit excessive requests across the planet can be banned for configured lengths of time. This can be done via [Dynamic Rules](/console-walkthrough/security/dynamic-rules).&#x20;

## Creating Rate Limiting Exemptions

To exempt one or more traffic sources from all filtering, follow the instructions here: [Bypass Link11 WAAP for Loadtesting or Other Purposes](/using-the-product/how-do-i.../bypassing-rate-limits-for-loadtesting).

To exempt a traffic source from rate limiting only, do the following:

1. Determine a unique tag that will identify the traffic source(s).&#x20;
   * There might already be one in use by the system. For example, to exempt an entire ASN, the [system tag](/how-link11-waap-works/tagging#system-tags) for that ASN can be used.&#x20;
   * If not, then create a [Global Filter](/console-walkthrough/security/global-filters) that will assign a unique tag to requests from the traffic source(s) in question.
2. Add the tag to the *Exclude* filter list in the applicable [Rate Limit Rules](/console-walkthrough/security/rate-limit-rules) and [Dynamic Rules](/console-walkthrough/security/dynamic-rules).


# Stream event data to a SIEM solution or other destination

Link11 WAAP integrates with a wide range of SIEM \[Security Information and Events Management] solutions. Most of our enterprise clients stream L11WAAP events to ArcSight, RSA, IBM, Splunk, and other solutions.

To stream traffic event data to one or more of these destinations, create one or more [**Log Exporters**](/console-walkthrough/system/log-exporters).&#x20;

The lengths of Log Exporter data values can be controlled using the [System DB](/console-walkthrough/system/system-db#limiting-log-exporter-data-lengths).


# Use Terraform with Link11 WAAP

Link11 WAAP infrastructure can be managed using Terraform. The provider is [here](https://github.com/link11dev/terraform-provider-link11waap), along with its [documentation](https://registry.terraform.io/providers/link11dev/link11waap/latest/docs).

If you're unfamiliar with L11WAAP (especially the API), the information below is recommended reading. Resources are described below in two ways:

* [According to traffic flow](#resources-according-to-traffic-flow) through the system, to understand the resources' roles.
* [According to internal relationships](#resources-according-to-internal-relationships), to understand dependencies and configuration.

For each resource, a link is provided to an in-depth description of that feature in the UI. Sometimes the UI will provide more configuration options than the resource does, but the links should be helpful in understanding the purpose and use of each resource.&#x20;

{% hint style="warning" %}
When Link11 WAAP is updated via the provider, **the updates must be published** before they will take effect.&#x20;

This can be done through the [UI](/console-walkthrough/system/publish-changes), [API](https://waap.docs.link11.com/using-the-product/how-do-i.../pages/8c4fZjD3vu6AWariZrzK#put-api-v4.3-tools-publish-config), or the *link11waap\_publish* resource.
{% endhint %}

## Resources according to traffic flow

Consider a request originating at a client, and destined for the origin server. Here are the Terraform resources (shown in bold) that are involved as the request flows through the system.

<figure><img src="/files/93yojsTHY4yGrRcuVLaW" alt=""><figcaption><p>click to enlarge</p></figcaption></figure>

### Client connection to Link11 WAAP

#### Certificates and Load Balancers

These are necessary for the connection between the client and Link11. More info: [Certificates](/console-walkthrough/sites/ssl/certificates) and [Load Balancers](/console-walkthrough/sites/ssl/load-balancers).

### Traffic Source Verification

#### Trusted Networks

Link11 WAAP will only accept traffic from the trusted sources listed in [Planet Trusted Networks](/console-walkthrough/sites/proxy-templates#trusted-sources). These can be:

* Specific IP addresses, e.g. of load balancers
* Or the traffic sources specified in one or more Global Filters, e.g., a CDN.

#### Mobile Application Group (optional)

Link11 customers who publish native iOS or Android applications for their clients can include the Link11 WAAP Mobile SDK: a unique client certification mechanism for iOS and Android apps.

If the client is using an SDK-enabled app, then a [Mobile Application Group](/console-walkthrough/sites/mobile-application-groups) will define the necessary parameters for Link11 WAAP to authenticate the client.&#x20;

### Policy Mapping and Traffic Routing

#### Server Group

Within Link11 WAAP, the request's destination domain parameters are defined as a [Server Group](/console-walkthrough/sites/server-groups).

#### Proxy Template

Link11 WAAP acts as a proxy. The [Proxy Template](/console-walkthrough/sites/proxy-templates) defines its characteristics in this role; the Server Group is based upon this template.

#### Security Policy

A [Security Policy](/console-walkthrough/security/security-policies) assigns security rulesets (those that will be enforced in the next stage) to destination paths within the Server Group.&#x20;

They also determine the Edge Functions and Backend Service (see below) that will be used for the request.

### Traffic Processing

#### Global Filters

[Global Filters](/console-walkthrough/security/global-filters) analyze incoming requests and attach a variety of tags, according to the request's characteristics. They can also be configured to block certain requests.

As the name implies, Global Filters apply to all requests, regardless of their destination paths.

#### Rate Limits

[Rate Limit Rules](/console-walkthrough/security/rate-limit-rules) block traffic sources that send an excessive number of requests within a defined time period.

#### ACL Profile

Depending on a request's tags, an [ACL Profile](/console-walkthrough/security/acl-policies) can block it, exempt it from further processing, or perform other actions.

#### Edge Functions (optional)

[Edge Functions](/console-walkthrough/sites/edge-functions) are custom Lua code that can be run at various points during traffic processing, to extend Link11 WAAP's capabilities.

### Forward Legitimate Requests

#### Backend Service

Link11 WAAP will pass legitimate traffic through to the server(s) specified in the [Backend Service](/console-walkthrough/sites/backend-services).

The Backend Service definition that will be used is specified in the Security Policy.

### Config, Publishing, and Users

These resources are necessary for administering Link11 WAAP.

* [Config](/using-the-product/the-link11-waap-api/internal-data-structures#the-fundamental-data-structure-configuration): Most resources include a *config\_id* parameter. A configuration is a complete definition of L11WAAP's behavior for a specific environment; a customer can maintain multiple configurations (e.g., development, staging, and production). The default value for *config\_id* is `prod`.
* [Publishing](/using-the-product/best-practices/publish-your-changes): When L11WAAP's configuration is updated, the updates must be published before they will take effect.
* [Users](/console-walkthrough/system/users-management): This resource is for administering users of the Link11 WAAP system.

## Resources according to internal relationships

This diagram illustrates the relationships among some of the infrastructure resources.

<figure><img src="/files/uiNsn3RqCbtNQUDLvZnM" alt=""><figcaption></figcaption></figure>

The foundational resource is a Server Group, which usually represents a domain. Each Server Group is based upon a Proxy Template, has one or more certificates associated with it, and can incorporate an optional Mobile Application Group.&#x20;

Each Server Group contains at least one Security Policy, or (more commonly) contains a set of Security Policies defined for different paths within the Server Group.&#x20;

Each Security Policy associates a destination path with several types of security rulesets and other settings.

{% hint style="info" %}
The current Terraform version does not provide a resource for [Content Filter Profiles](/console-walkthrough/security/content-filter/profiles) (which define how requests are filtered according to threat signatures). The system will use a default Profile.
{% endhint %}

## More information

L11WAAP's Terraform provider is primarily a wrapper around the API. If there are questions about resource parameters or other issues, it can be helpful to read the reference guide for the equivalent API operation, which can be found in the [list of API namespaces](/reference-information/api/namespace-reference).


# The Link11 WAAP API

This section explains the usage of L11WAAP's API.

{% content-ref url="/pages/mOhw7dHrEN2DxgDlR3st" %}
[Overview](/using-the-product/the-link11-waap-api/overview)
{% endcontent-ref %}

{% content-ref url="/pages/umWs4xAEYBIe3iON1pZk" %}
[Internal data structures](/using-the-product/the-link11-waap-api/internal-data-structures)
{% endcontent-ref %}

{% content-ref url="/pages/mYB4UtgBhsxn7BTeZ6zK" %}
[Using Swagger UI](/using-the-product/the-link11-waap-api/using-swagger-ui)
{% endcontent-ref %}

{% content-ref url="/pages/ZeNMK1hdgY6jcOZAZZrh" %}
[Using curl](/using-the-product/the-link11-waap-api/using-curl)
{% endcontent-ref %}


# Overview

Link11 WAAP includes an API that provides full coverage of the system's capabilities.

Using the API will require familiarity with the following:

* L11WAAP's [internal data structures](/using-the-product/the-link11-waap-api/internal-data-structures)
* The API's namespaces and endpoints, which are documented in two locations:
  * In the reference section of this manual [here](/reference-information/api).
  * In Swagger UI. Along with documenting the API, this also includes the ability to submit API calls directly to your planet. ([more info](/using-the-product/the-link11-waap-api/using-swagger-ui))
* (Optional) the process for [accessing the API using curl](/using-the-product/the-link11-waap-api/using-curl).


# Internal data structures

## Overview

Link11 WAAP maintains most of its security parameters as Entries, which are contained in Documents, which are contained in Configurations.

A Configuration is a complete definition of L11WAAP's behavior for a specific environment. An organization can maintain multiple Configurations (e.g., development, staging, and production).

<figure><img src="/files/DPVj8k9n8EgqtzOm5orv" alt=""><figcaption></figcaption></figure>

Each Configuration contains multiple Documents of various types (Global Filters, ACL Profiles, etc.) Each Document contains at least one Entry, i.e., an individual security rule or definition.

A Configuration also includes data blobs, which currently are used to store the geolocation database. This is where L11WAAP obtains its geolocation data and ASN for each request it processes.

All of these data structures can be edited via API:

* A Document is a file treated as a JSON list of entries.
* An Entry is a JSON dictionary with a unique identifier. This field value must be unique inside the Document, and must be a valid part of an URL. Often, this field is labeled `id` (for example, configurations). At other times, it has a specific name (for example, Routing Profiles use the field `planet_name`.)
* A blob is a file treated as binary data.

## The fundamental data structure: Configuration

The Configuration is the atomic unit for all of L11WAAP's parameters. Any edits to a Configuration result in a new Configuration being created. Configurations are versioned, and can be reverted at any time.

### Default configuration

Most API calls require a parameter for the configuration (typically listed as *{config}*), representing the configuration id.&#x20;

{% hint style="info" %}
**Out of the box, the default value for this parameter is** `prod`**.**
{% endhint %}

### Modifying a configuration

When a Configuration is created or modified (whether by the UI console or an API call), the admin must push the changes out to the planet. This is the [publishing process](/console-walkthrough/system/publish-changes).


# Using Swagger UI

The Link11 WAAP API is available in [Swagger UI](https://swagger.io/). This tool provides design documentation, and can also be used to submit API calls directly to your planet.

## Location

By default, the API is available in Swagger UI at:

`{your planet name}/api/v4.0/openapi`.&#x20;

## Access

Using Swagger UI will require the user to be logged into the planet with a sufficient [Access Level](/console-walkthrough/system/users-management#user-parameters).&#x20;

{% hint style="info" %}
Swagger will display the entire API. However, the availability of individual routes is dependent upon the user's Access Level. A request sent with insufficient permissions for the route will fail.
{% endhint %}

{% hint style="warning" %}
If Swagger UI receives a request and the response is an HTML document, the most likely cause is the user is not logged in, or is logged in with insufficient permissions.&#x20;
{% endhint %}

## Namespaces

The Swagger interface shows the namespaces and data models for the API. Often, each one is initially collapsed, as in this example:

<figure><img src="/files/htF2YEYOXcWNM9LZBpsn" alt=""><figcaption></figcaption></figure>

Expanding a namespace reveals the endpoints within it:

<figure><img src="/files/rvvjORuQNPBCubHLl2oQ" alt=""><figcaption></figcaption></figure>

Expanding an endpoint reveals more information about required inputs (if any) and the information that will be returned in the response.

<figure><img src="/files/hPN6yWwZmZqugbi3Wvrn" alt=""><figcaption></figcaption></figure>

Some endpoints, as in the example above, do not require any inputs. Others require specific parameters:

<figure><img src="/files/la2AeMrY6yjp6JX4Z79H" alt=""><figcaption></figcaption></figure>

... or other inputs, such as a request body.

<figure><img src="/files/mxO7Gn2klV89clWg5bxy" alt=""><figcaption></figcaption></figure>

## Running API calls

Selecting the **Try it out** button will enable the editing of the required inputs, if any. Once the required inputs have been completed, the system will:

* display a command that can be submitted via curl (as explained [here](/using-the-product/the-link11-waap-api/using-curl)), and
* display an **Execute** button, which if selected will submit the command to the system and display the results.

Swagger allows you to interact with the API, try different commands, and see what responses will be generated.


# Using curl

While Swagger UI provides a visual interface into the API, it is often desirable to send API calls via the command line. For this, [curl](https://curl.se/) can be used.

## Required information

To send a curl request to the API, two things are required:

* An API key
* The curl command string

## Obtaining an API key

If an API key is not already available from previous API usage, the following steps should be followed.

1. Log into the planet console using a Link11 WAAP account (i.e., **without using SSO**). The account must have an [Access Level](/console-walkthrough/system/users-management#user-parameters) of *Editor* or higher.&#x20;
2. Navigate to [**Account**](/console-walkthrough/account) by selecting the user icon on the top right of the page
3. Navigate to **Account Details** -> **API Keys**. (If Account Details is not displayed in the Account menu, verify that the login was done directly into the planet using an L11WAAP account. If SSO is used, Account Details will not be available in the interface.)
4. Select "New" -> Enter a name for the key -> "Confirm"
5. Copy the value of that key for use within curl. (Note: this is the string that the system generated, not the name you supplied.)

## Using Swagger UI to construct the curl command string

Sending an API request via Swagger UI will also construct and display its curl command string:

1. Navigate to [the planet's instance of Swagger UI](/using-the-product/the-link11-waap-api/using-swagger-ui).&#x20;
2. Expand the desired namespace, and then the desired route within the namespace.
3. Select the "**Try it Now**" button
4. Edit the input fields (if any), providing all required inputs
5. Select the **"Execute"** button
6. After sending the request, Swagger UI will display the curl command string. Copy this.

To send this request using curl, edit the command string to include an additional header (`Authorization:Basic`) for the API key obtained earlier.

### Example

When Swagger UI is used to get a list of configurations via `GET /api/v4/conf/configs`, it will also display this curl command:

```bash
curl -X 'GET' \
  'https://www.mysite.com/api/v4/conf/configs' \
  -H 'accept: application/json'
```

To submit this command directly via curl, the following header must be added:

```bash
-H 'Authorization:Basic <api-key-obtained-earlier>'
```

...without the `<>`, and where `api-key-obtained-earlier` is the string obtained [above](#obtaining-an-api-key).

## Manually constructing the curl command string

API calls using curl are constructed according to these requirements:

* The API key is included, as explained above
* Input parameters defined as *query* are encoded into the URL
* Input parameters defined as *header* are included as headers
* Input parameters defined as **Request body** are included via curl's `-d` option

### Example: query and header parameters

A route to retrieve traffic data has this definition:

<figure><img src="/files/N2GsU42YlCpCniv0xZC1" alt=""><figcaption></figcaption></figure>

Note that `limit`, `offset`, `filters`, and `debug` are marked as *query* parameters, and therefore, will be encoded into the URL. However, `syntax` and `provider` are marked as *header* parameters.

The resulting curl command will look like this:

```bash
curl -X 'GET' \
  'https://mysite.com/api/v4.0/data/logs?limit=100&offset=0&filters=%7B%22AND%22%3A%5B%7B%22field%22%3A%20%22timestamp%22%2C%20%22value%22%3A%20%5B%222024-06-02T00%3A00%3A00%22%2C%20%222024-06-03T00%3A00%3A00%22%5D%2C%22op%22%3A%20%22between%22%7D%20%5D%7D&debug=false' \
  -H 'accept: application/json' \
  -H 'syntax: json' \
  -H 'provider: bigquery' \
  -H 'Authorization:Basic kFiudeEIOSd18dDineS2wn98sIO'
```

### Example: request body&#x20;

The POST */api/v4.0/data/timeline/parse* call includes this input:

<figure><img src="/files/eet0mGFmLyZbQJM8vM4Q" alt=""><figcaption></figcaption></figure>

Let's say that an admin wants to submit the string `timestamp between 2024-06-06 09:31:00 and 2024-06-06 09:36:00, status=301`. The curl command would look like this:

```bash
curl -X 'POST' \
  'https://mysite.com/api/v4.0/data/timeline/parse' \
  -H 'accept: application/json' \
  -H 'Content-Type: application/json' \
  -H 'Authorization:Basic kFiudeEIOSd18dDineS2wn98sIO' \
  -d '{
  "query": "timestamp between 2024-06-06 09:31:00 and 2024-06-06 09:36:00, status=301"
}'
```


# Acronyms

Used in this Product Manual

| Acronym  | Meaning                                    |
| -------- | ------------------------------------------ |
| **ACL**  | Access Control List                        |
| **API**  | Application Programming Interface          |
| **ASN**  | Autonomous System Number                   |
| **AWS**  | Amazon Web Services                        |
| **BL**   | Blocklist                                  |
| **BQ**   | BigQuery                                   |
| **BQML** | BigQuery Machine Learning                  |
| **CA**   | Cloud Armor                                |
| **CDN**  | Content Delivery Network                   |
| **FP**   | False Positive                             |
| **GCP**  | Google Cloud Platform                      |
| **IPS**  | Intrusion Prevention System                |
| **LB**   | Load Balancer                              |
| **ML**   | Machine Learning                           |
| **RFC**  | Request for Comments                       |
| **SIEM** | Security Information and Events Management |
| **SOC**  | Security Operation Center                  |
| **TTL**  | Time to Live                               |
| **VPC**  | Virtual Private Cloud                      |
| **WAAP** | Web Application and API Protection         |
| **WAF**  | Web Application Firewall                   |


# API

{% content-ref url="/pages/33Pol5fTYtEc45X8Hxj5" %}
[API access to traffic data](/reference-information/api/api-access-to-traffic-data)
{% endcontent-ref %}

{% content-ref url="/pages/7aVLvuczP46NYYJLaiE6" %}
[Types of namespaces](/reference-information/api/types-of-namespaces)
{% endcontent-ref %}

{% content-ref url="/pages/SldVWh1KEIgcM7LYuAwI" %}
[Namespace reference](/reference-information/api/namespace-reference)
{% endcontent-ref %}


# API access to traffic data

The page below describes how to retrieve traffic data via the API. It contains these main sections:

* [Introduction](#introduction)
* [The filters parameter](#the-filters-parameter) (which specifies the traffic data that will be retrieved)
* [The four API routes that retrieve traffic data](#api-access-to-traffic-data), and how to use them

## Introduction

The [**Data queries** API namespace](/reference-information/api/namespace-reference/data-queries) provides access to traffic data, via these four routes:

* *GET /api/v4.0/data/topx*
* *GET /api/v4.0/data/stats*
* *GET /api/v4.0/data/timeline*
* *GET /api/v4.0/data/logs*

Each includes an input parameter named `filters`. **This parameter specifies the traffic data that will be retrieved.**&#x20;

Below, we begin by discussing this parameter's usage, syntax, and construction. Then we discuss the four API routes that require it, and the different types of data they return.

## The filters parameter

`filters` is a string that specifies one or more conditions. A database query is constructed from those conditions, and the results are returned to the user.

Usage of the `filters` parameter depends on the context:

* When using Swagger UI, this value is supplied directly in the `filters` input field.&#x20;
* When using curl to call the Link11 WAAP API, this value is encoded into the destination URL, preceded by "filters=". See [this explanation](/using-the-product/the-link11-waap-api/using-curl#manually-constructing-the-curl-command-string) for more information.&#x20;

### A short example

Here is an example of a `filters` specification in JSON format:

```bash
{
  "AND": [
    {
      "field": "timestamp",
      "op": "between",
      "value": [
        "2024-06-06 09:31:00",
        "2024-06-06 09:36:00"
      ]
    },
    {
      "field": "tags",
      "op": "regex",
      "value": "unrecognized"
    }
  ]
}
```

This will return requests which:

* were received in a five-minute time period (from 2024-06-06 09:31:00 to 2024-06-06 09:36:00), and...
* have a [Tag](/how-link11-waap-works/tagging) containing the string `unrecognized` . (In this example, the admin wanted to retrieve requests tagged with `unrecognized-host-header`.)

## Format

The `filters` parameter can be supplied as a query string, or as JSON.

### Query string format

This format is used in the first [Query Specification](/console-walkthrough/analytics/dashboard#query-specification) input field in the UI's [Dashboard](/console-walkthrough/analytics/dashboard) and [Events Log](/console-walkthrough/analytics/events-log). For example, this query string will display all requests with a 301 response code within a certain time period:

`status=301, timestamp between 2024-06-06 09:31:00 and 2024-06-06 09:36:00`

For more information on this format, see [Query filter syntax and best practices](/reference-information/query-filter-syntax-and-best-practices).

### JSON format

The JSON equivalent of the query string above is:

<pre class="language-bash"><code class="lang-bash"><strong>{
</strong>  "AND": [
    {
      "field": "timestamp",
      "op": "between",
      "value": [
        "2024-06-06 09:31:00",
        "2024-06-06 09:36:00"
      ]
    },
    {
      "field": "status",
      "op": "eq",
      "value": 301
    }
  ]
}
</code></pre>

(This is provided as an example only. A full discussion of JSON syntax is below.)

### Converting from query string to JSON

The POST */api/v4.0/data/timeline/parse* API route accepts query strings and returns the same query in JSON format.

## JSON structure

{% hint style="info" %}
The discussion below will focus on building the `filters` parameter in JSON format, for two reasons. First, text query strings are discussed elsewhere (in the links given above). Second, for complex queries, JSON is more powerful.&#x20;
{% endhint %}

A JSON filters parameter is structured as follows:

```bash
{
  "AND": [
    $CONDITION1,
    $CONDITION2,
    ...
    $CONDITIONn
  ]
}
```

### The first condition: a range of dates/times

The first condition must be included, and must be a range of dates/times. It is structured as follows:

```bash
{
  "field": "timestamp",
  "op": "between",
  "value": [
    "$TIMESTAMP1",
    "$TIMESTAMP2"
  ]
}
```

where $TIMESTAMP1 and $TIMESTAMP2 are timestamps: specifications of date and time.

For timestamps, any ISO format is supported. Nevertheless, both timestamps must include year, month, and day.&#x20;

If hours, minutes, or seconds are not included in a timestamp, the time will be rendered as the beginning of the day/hour/minute, respectively. Examples: `"2022-07-14"` -> `"2022-07-14 00:00:00"`, `"2022-07-14 06:52"` -> `"2022-07-14 06:52:00"`, etc.

### Subsequent conditions

After the first condition, additional conditions can be specified if desired. They are structured as follows:

```bash
{
  "field": "$FIELD_NAME",
  "op": "$OPERATOR",
  "key": "$KEY",
  "value": $VALUE
}
```

They must meet these requirements:

* Multiple conditions are combined with a logical AND. (A logical OR is not supported, as this could potentially retrieve unexpectedly large amounts of data.)
* When multiple conditions are provided, all are followed by commas, except for the final one.
* The "key" line is optional; see discussion [below](#key).

{% hint style="info" %}
Here in the documentation, spaces and carriage returns are included in JSON filter examples for clarity. In usage, they are optional.&#x20;

Also, the order of a condition's components (its `field`/`op`/`key`/`value`) does not matter.
{% endhint %}

### Field names

Available fields include those inherent to HTTP requests, along with additional data added by L11WAAP during processing.

* Some of the added information consists of internal IDs for the security settings that are relevant to the request.&#x20;
* Some requests will not contain all possible information. When L11WAAP blocks a request, processing usually stops immediately, and later stages in the [traffic filtering process](/how-link11-waap-works/traffic-filtering-process) do not occur. &#x20;

<table><thead><tr><th width="202">Field name</th><th>Comments</th><th data-hidden>Description</th></tr></thead><tbody><tr><td>acl_triggers</td><td><p>Populated during evaluation of the active ACL Profile. Contains keys:<br>   acl_action</p><p>   action (the type of Action that was triggered)</p><p>   extra (currently unused)</p><p>   tags</p><p>   trigger_id</p><p>   trigger_name <br>All are strings, except for tags, which is an array of strings. </p></td><td></td></tr><tr><td>arguments</td><td><p>Arguments of the request, if any. Query string and JSON examples for <em>mysite.com/page?foo=1</em> :</p><p>     arguments["foo"]="1" </p><p>     {"field": "arguments", "key": "^foo$", "op": "eq", "value": "1"}</p></td><td></td></tr><tr><td>asn</td><td>string</td><td></td></tr><tr><td>authority</td><td>string</td><td></td></tr><tr><td>biometric</td><td>array</td><td></td></tr><tr><td>blocked</td><td>boolean</td><td></td></tr><tr><td>bot</td><td>boolean</td><td></td></tr><tr><td>branch</td><td>string</td><td></td></tr><tr><td>bytes_sent</td><td>integer</td><td></td></tr><tr><td>challenge</td><td>boolean</td><td></td></tr><tr><td>challenge_type</td><td>string</td><td></td></tr><tr><td>cf_restrict_triggers</td><td>array</td><td></td></tr><tr><td>cf_triggers</td><td>Populated if the request triggered a Content Filter Rule. Contains keys: action, extra, name, risk_level, ruleid, section, trigger_id, trigger_name, value. All have string values, except for risk_level, which is an integer.</td><td></td></tr><tr><td>challenge</td><td>boolean</td><td></td></tr><tr><td>challenge_type</td><td>string</td><td></td></tr><tr><td>cookies</td><td>Can inspect specific cookies or all cookies. See <a href="#json-filter-examples">JSON filter examples</a>.</td><td></td></tr><tr><td>country</td><td>string</td><td></td></tr><tr><td>dr_triggers</td><td>array</td><td></td></tr><tr><td>geo_region</td><td>string</td><td></td></tr><tr><td>gf_triggers</td><td>An array of entries, one for each Global Filter that matched the request. Each entry contains these keys: action, extra, name, section, trigger_id, trigger_name, value</td><td></td></tr><tr><td>headers</td><td>Can inspect specific headers or all headers. See <a href="#json-filter-examples">JSON filter examples</a>.</td><td></td></tr><tr><td>host</td><td>string</td><td></td></tr><tr><td>hostname</td><td>string</td><td></td></tr><tr><td>human</td><td>boolean</td><td></td></tr><tr><td>ichallenge</td><td>boolean</td><td></td></tr><tr><td>ip</td><td>string</td><td></td></tr><tr><td>logs</td><td>array</td><td></td></tr><tr><td>messages</td><td>An array of strings, containing messages added to the event by the system. These can include <a href="/pages/9UkxgPs6j4Obbt0sGDrH#adding-custom-messages-to-log-events">messages injected into events by Edge Functions.</a></td><td></td></tr><tr><td>method</td><td>string</td><td></td></tr><tr><td>monitor</td><td>boolean: whether or not the request triggered a Monitor action.</td><td></td></tr><tr><td>monitor_reasons</td><td>array of strings; the various reasons (if any) that the request triggered Monitor actions.</td><td></td></tr><tr><td>organization</td><td>string</td><td></td></tr><tr><td>path</td><td>string. The path excluding the TLD and excluding arguments; the string begins with "/". </td><td></td></tr><tr><td>path_parts</td><td><p>string. Contents for <em>mysite.com/abc/123/home.html?foo=true</em>: <br>"path_parts": {</p><p>     "part1": "abc", </p><p>     "part2": "123", </p><p>     "part3": "home.html", </p><p>     "path": "/abc/123/home.html" </p><p>}<br>To match the second part of this example:<br>     path_parts["part2"]="123"<br>     {"field": "path_parts", "key": "^part2$", "op": "eq", "value": "123"}<br></p></td><td></td></tr><tr><td>port</td><td>string</td><td></td></tr><tr><td>processing_stage</td><td>integer: the furthest stage of <a href="/pages/Tai9ex56CGarkEL6QpbC">traffic filtering</a> that was reached.<br>     0: Initialization<br>     2: Global Filtering<br>     3. Flow Control<br>     4. Global Rate Limits<br>     5. Rate Limits<br>     6. ACL Profile<br>     7. Content Filtering</td><td></td></tr><tr><td>profiling</td><td>array of items containing the security settings relevant to this request. Each item contains:<br>     a name (secpol, mapping, flow, limit, acl, content_filter)<br>     and value (the internal ID of that setting). </td><td></td></tr><tr><td>protocol</td><td>string</td><td></td></tr><tr><td>proxy</td><td>array of items containing proxy-related data. Each item contains a name and value. The names are: additional_tags, bytes_sent, container, geo_as_domain, geo_as_name, geo_as_type, geo_company_country, geo_company_domain, geo_company_type, geo_lat, geo_long, geo_mobile_carrier, geo_mobile_country, geo_mobile_mcc, geo_mobile_mnc, realip, request_id, request_length, request_time, ssl_cipher, ssl_protocol, status.</td><td></td></tr><tr><td>query</td><td>string. Example: for <em>mysite.com/page?code=117</em>, this is <code>?code=117</code>.</td><td></td></tr><tr><td>rbz_latency</td><td>integer</td><td></td></tr><tr><td>rbzsessionid</td><td>Cookie set by L11WAAP. Example query string and JSON:<br>    cookies["rbzsessionid"]="57870178706cb50db6d41aab"<br>    {"field": "cookies", "key": "^rbzsessionid$", "op": "eq", "value": "578701713f70dcd8706cb50db6d41aab"}</td><td></td></tr><tr><td>reason</td><td>string. The reason, if any, the request was blocked.</td><td></td></tr><tr><td>referer</td><td>string</td><td></td></tr><tr><td>request_id</td><td>string</td><td></td></tr><tr><td>request_length</td><td>integer</td><td></td></tr><tr><td>request_time</td><td>float</td><td></td></tr><tr><td>result</td><td>string; the disposition of the request. A way to quickly see anomalies is to search for {"field": "result", "op": "not eq", "value": "Passed"}</td><td></td></tr><tr><td>rl_triggers</td><td>array; the reasons (if any) that rate limits were triggered.</td><td></td></tr><tr><td>security_config</td><td><p>The configuration of security settings when this request was processed. Keys and data types are:<br>     acl_active (boolean)</p><p>     cf_active (boolean)</p><p>     cf_rules (integer)</p><p>     gf_rules (integer)</p><p>     revision (string)</p><p>     rl_rules (integer)</p><p>     secpolentryid (string)</p><p>     secpolid (string)</p></td><td></td></tr><tr><td>session</td><td>string</td><td></td></tr><tr><td>session_ids</td><td>array</td><td></td></tr><tr><td>status</td><td>integer</td><td></td></tr><tr><td>tags</td><td>array of strings: all the tags attached to the request</td><td></td></tr><tr><td>time_period</td><td>integer; the Epoch Unix timestamp of the request</td><td></td></tr><tr><td>timestamp</td><td>string; date and time </td><td></td></tr><tr><td>trigger_counters</td><td>The number of times an Action was triggered, and the source of the triggers (ACL Profile, Content Filtering, Global Filters, or Rate Limits). This is a collection of keys (counters) and values (integers with the value of each counter). Counter names are strings: acl, cf, cf_restrict, dr, gf, rl. Sample filter condition: {"field": "trigger_counters", "key": "acl", "value": 0, "op": "gt"} </td><td></td></tr><tr><td>upstream_addr</td><td>array of strings</td><td></td></tr><tr><td>upstream_data</td><td>array of elements: {addr (string), response_time (float), status (integer)}</td><td></td></tr><tr><td>upstream_response_time</td><td>float or null</td><td></td></tr><tr><td>upstream_status</td><td>array of integers</td><td></td></tr><tr><td>url</td><td>string</td><td></td></tr><tr><td>user_agent</td><td>string</td><td></td></tr><tr><td>version</td><td>string</td><td></td></tr><tr><td>waap_id</td><td>Cookie set by L11WAAP. Example query string and JSON:<br>  cookies["waap_id"]="Jc491eLWqTBOfDnJwNk"<br>      {"field": "cookies", "key": "^waap_id$", "op": "eq", "value": "Jc491eLWqTBOfDnJwNk"}</td><td></td></tr></tbody></table>

### Key

For some types of data, it might not be enough to specify the *field*, because there could be multiple parameters in the request that match it. For example, a field name of "cookies" or "headers" does not tell the system **which** cookie or header to inspect.

The *key* field supplies this information; it is the name of the specific parameter to evaluate. If this parameter is not defined, the system will inspect all instances of the specified field (all cookies, all headers, etc.).

Some examples are in the [JSON filters examples](#json-filter-examples) below.

### Values&#x20;

Values should be specified in the appropriate data type: strings as quote-delimited strings, integers as numbers, etc. Arrays of values can be supplied.

### Operators

| Operator | Data Type                   | Description                                                                |
| -------- | --------------------------- | -------------------------------------------------------------------------- |
| is       | boolean                     | checks if value is True or False                                           |
| eq       | integer / float / string    | checks exact match for numeric/string value                                |
| gt/ lt   | integer / float             | checks if value is greater/less than                                       |
| gte/ lte | integer / float             | checks if value is greater/less than or equal                              |
| in       | integer / float / string    | checks if numeric/string value is in a list of values                      |
| regex    | string                      | checks if string has a match with a regex                                  |
| between  | integer / float / timestamp | checks if value between two numbers/ timestamps. Does not depend on order. |

### Negative operators

Operators can be inverted by adding `not`. For example, `not eq` means "does not equal".

### Inverting a condition

It's possible to invert an entire condition by adding NOT, like this:

<pre class="language-bash"><code class="lang-bash"><strong>{
</strong><strong>  "NOT": {
</strong>    "field": "$FIELD_NAME",
    "op": "$OPERATOR",
    "key": "$KEY",
    "value": $VALUE
  }
}
</code></pre>

## JSON filter examples

Retrieve PUT and POST requests:

```bash
{
    "AND": [
        {"field": "timestamp", "op": "between", "value": ["2022-07-14 06:52:37", "2022-07-12 06:52:37"]},
        {"field": "method", "value":"^P.*T$", "op":"regex"}
    ]
}
```

Retrieve requests containing a tag that matches "geo" or "location":

```bash
{
    "AND": [
        {"field": "timestamp", "value": ["2022-07-14 06:52:37", "2022-07-12 06:52:37"], "op": "between"},
        {"field": "tags", "value": ["geo", "location"], "op": "in"}
    ]
}
```

Retrieve requests where **certain** cookies' values match a regex:

```bash
{
    "AND": [
        {"field": "timestamp", "value": ["2022-07-14 06:52:37", "2022-07-12 06:52:37"], "op": "between"},
        {"field": "cookies", "key": "analytics_.*", "value": "gcp_.*", "op": "regex"}
    ]
}
```

Retrieve requests where **any** cookie's value matches a regex:

```bash
{
    "AND": [
        {"field": "timestamp", "value": ["2022-07-14 06:52:37", "2022-07-12 06:52:37"], "op": "between"},
        {"field": "cookies", "value": "gcp_.*", "op": "regex"}
    ]
}
```

Retrieve requests according to a subfield (the *acl\_active* subfield of *security\_config* must be greater than 11).&#x20;

```bash
{
    "AND": [
        {"field": "timestamp", "value": ["2022-07-14 06:52:37", "2022-07-12 06:52:37"], "op": "between"},
        {"field": "security_config", "key": "acl_active", "value": 11, "op": "gt"}
  ]
}
```

Retrieve requests according to an array of subfields:

```bash
{
    "AND": [
        {"field": "timestamp", "value": ["2022-07-14 06:52:37", "2022-07-12 06:52:37"], "op": "between"},
        {
            "field": "cf_triggers",
            "conditions": [
                {"field": "risk_level", "value": 2, "op": "gt"},
                {"field": "ruleid", "value": "100037", "op": "eq"}
            ]
        }
    ]
}
```

Retrieve requests according to a combination of conditions (there is no limit on the number of conditions):

```bash
{
    "AND": [
        {"field": "timestamp", "value": ["2022-08-08 01:15:25", "2022-08-08 01:52:28"], "op": "between"},
        {"field": "tags", "value":"geo-continent-name:north-america", "op": "eq"},
        {"field": "agent", "key": "ephemeral_id", "value": "029ab6f-6d15-4290-b44f-9133", "op": "regex"},
        {"field": "trigger_counters", "key": "acl","value": 2,"op": "not gt"},
        {"field": "headers", "key": "x-forwarded.*", "value": "3.65.14.177", "op": "regex"},
        {"field": "path_parts", "key": "^part3$", "value": "^-1&", "op": "regex"},
        {"field": "security_config", "key": "cf_active", "value": true, "op": "not eq"},
        {"field": "ip", "value": ["2.55.96.231", "23.65.14.177", "3.1.92.15", "8.206.254.196"], "op": "in"}
    ]
}
```

## API access to traffic data

As noted previously, there are four API routes that use the `filters` parameter to retrieve traffic data:

* *GET /api/v4.0/data/topx*
* *GET /api/v4.0/data/stats*
* *GET /api/v4.0/data/timeline*
* *GET /api/v4.0/data/logs*

Their typical uses are as follows.

**Quickly discover the most important factors** in the traffic stream (e.g., the countries sending the most blocked requests, the URLs receiving the most bot traffic, etc.): use the *topx* route.

**Get a summary of traffic statistics** (total requests, bandwidth, and latency): use the *stats* route.

**Get a summary of security metrics** (total requests, blocked requests, status codes returned, number of human clients, activity of the origin, etc.): use the *timeline* route.

**Get complete data** for all requests matching certain criteria (often used for drilling down into trends discovered from the other routes): use the *logs* route.

Below, we discuss each route in detail.

## GET /api/v4.0/data/topx

This route provides API access to the same [Top Metrics](/console-walkthrough/analytics/dashboard#top-metrics) available in the Dashboard. Here's an example of Top Countries in the Dashboard:

<figure><img src="/files/EFjmeF9qtj3ZBWquyDDZ" alt=""><figcaption></figcaption></figure>

Calling this route returns all metrics of data: all results for "top applications", all results for "top countries", all items for "top sources", and so on. They are combined into a single continuous list:

```bash
{
  "data": {
    "results": [
        $RESULT1,
        $RESULT2,
        $RESULT3,
        ...
        $RESULTn
    ],
    "statistics": {
      "bytes_billed": null,
      "bytes_processed": null,
      "elapsed_ms": 0
    }
  },
  "status": 200
}
```

...where the list of $RESULTs looks something like this (incomplete) example:

```bash
"results": [
  {
    "key": "China",
    "label": "country"
  },
  {
    "key": "United States",
    "label": "country"
  },
  {
    "key": "161.1.50.2",
    "label": "ip"
  },
  {
    "key": "101.6.123.53",
    "label": "ip"
  },
  {
    "key": "161.1.50.5",
    "label": "ip"
  },
  {
    "key": "mysite.com/login",
    "label": "url"
  }
]

```

We see that in the time period specified in the `filters` parameter, there were three IP addresses in two countries that sent requests to a single URL.&#x20;

Some points to note:

* The results are organized and grouped together in the list according to their *label*.
* Labels are ordered alphabetically.
* Labels can differ in their number of results.
* The route returns the "top" results for each label (for example, results with the "ip" label show the IPs that sent the most blocked requests). When there are only a few results for a given label, all are retrieved. When there are many, only the "top" results are retrieved.

#### Actual usage

The example above is oversimplified. In actual use, the *topx* route:

* Returns much more data per result, not just *key* and *label* (see the list of fields below)
* Returns more categories than just *country*, *ip*, and *url* (see the discussion of the *label* field below)

A detailed discussion of *topx* follows.

### Contents of each result

Each result contains the fields listed below.&#x20;

{% hint style="info" %}
The \_time fields are in seconds. These are floats, but can appear at various precisions: zero decimal places, several decimal places, or scientific notation (e.g., 1.6210818451802098e-9).
{% endhint %}

<table><thead><tr><th width="285">Result field name</th><th width="130">Type</th><th>Comments</th></tr></thead><tbody><tr><td>avg_origin_time</td><td>float</td><td>The average amount of processing time by the origin for these requests. If no requests reached the origin, this will be null. </td></tr><tr><td>avg_rbz_time </td><td>float</td><td>The average amount of processing time by L11WAAP for these requests.</td></tr><tr><td>avg_total_time</td><td>float</td><td>The average total amount of processing time for these requests.</td></tr><tr><td>first_asn</td><td>string</td><td>First entry in the list of ASNs</td></tr><tr><td>first_geo_country</td><td>string</td><td>First entry in the list of countries</td></tr><tr><td>first_organization</td><td>string</td><td>First entry in the list of organizations</td></tr><tr><td>key</td><td>string</td><td>Content varies; see discussion below.</td></tr><tr><td>label</td><td>string</td><td>Category of result. See discussion below.</td></tr><tr><td>max_origin_time</td><td>float</td><td>The longest amount of processing time by the origin among these requests. If no requests reached the origin, this will be null. </td></tr><tr><td>max_rbz_time</td><td>float</td><td>The longest amount of processing time by L11WAAP among these requests.</td></tr><tr><td>max_total_time</td><td>float</td><td>The longest amount of total processing time among these requests.</td></tr><tr><td>min_origin_time</td><td>float</td><td>The shortest amount of processing time by the origin among these requests. If no requests reached the origin, this will be null. </td></tr><tr><td>min_rbz_time</td><td>float</td><td>The shortest amount of processing time by L11WAAP among these requests.</td></tr><tr><td>min_total_time</td><td>float</td><td>The shortest amount of total processing time among these requests.</td></tr><tr><td>num_of_blocked_requests</td><td>integer</td><td></td></tr><tr><td>num_of_bot_requests</td><td>integer</td><td></td></tr><tr><td>num_of_challenges</td><td>integer</td><td></td></tr><tr><td>num_of_human_requests</td><td>integer</td><td></td></tr><tr><td>num_of_monitored_requests</td><td>integer</td><td>Includes all requests that triggered a "monitor" action, even if they were blocked as well.</td></tr><tr><td>num_of_requests</td><td>integer</td><td></td></tr><tr><td>sum_of_bytes_sent</td><td>integer</td><td></td></tr><tr><td>sum_of_request_length</td><td>integer</td><td></td></tr></tbody></table>

### Organization of results: the label and key fields

The *topx* route returns results in a specific order:

* Results are grouped together according to their *label* (i.e., their category).
* Labels are ordered alphabetically (see full list below)
* Within each label, results are ordered by **num\_of\_blocked\_requests**, in descending order.

{% hint style="info" %}
Notice that this is unlike the UI's Dashboard Top Metrics, where some types of results have other default orders.
{% endhint %}

The *topx* route returns twelve categories of results, each with its own label. The label determines the contents of the *key* field.

| Label        | 'Key' field contains                        |
| ------------ | ------------------------------------------- |
| country      | country name                                |
| host         | host name or IP                             |
| ip           | IP address                                  |
| organization | organization                                |
| origin\_time | target URL                                  |
| rbz\_time    | target URL                                  |
| reason       | reason the request was monitored or blocked |
| referer      | referer string                              |
| total\_time  | target URL                                  |
| url          | target URL                                  |
| user\_agent  | user agent string                           |
| waap\_id     | waap\_id cookie value                       |

## GET /api/v4.0/data/stats

This route returns traffic metrics for the requested time period, broken down into shorter segments of time.

### Data structures

The retrieved metrics are structured like this:

```bash
{
  "data": {
    "results": [
      $RESULTS-TIMESEGMENT-1,
      $RESULTS-TIMESEGMENT-2,
      ...
      $RESULTS-TIMESEGMENT-n
    ],
    "statistics": {
      "bytes_billed": null,
      "bytes_processed": null,
      "elapsed_ms": 0
    }
  },
  "status": 200
}
```

...where each $RESULTS-TIMESEGMENT-x has this structure:

```bash
{
   "avg_latency": float,
   "hostname": string,
   "num_of_requests": integer,
   "sum_of_bandwidth": integer,
   "time_period": integer,
   "timeperiod_string": string
}

```

### Contents of each result

| Field name         |                                                                        |
| ------------------ | ---------------------------------------------------------------------- |
| avg\_latency       | Average latency in seconds                                             |
| hostname           | Host                                                                   |
| num\_of\_requests  | Total requests received during the time period                         |
| sum\_of\_bandwidth | Total bytes sent and received                                          |
| time\_period       | Beginning of time segment, as an Epoch Unix integer (e.g., 1718186400) |
| timeperiod\_string | Beginning of time segment, as a string (e.g., "2024-06-12 10:00:00")   |

## GET /api/v4.0/data/timeline

This route returns security metrics for the requested time period, broken down into shorter segments of time.

### Data structures

The retrieved metrics are structured like this:

```bash
{
  "data": {
    "results": [
      $RESULTS-TIMESEGMENT-1,
      $RESULTS-TIMESEGMENT-2,
      ...
      $RESULTS-TIMESEGMENT-n
    ],
    "statistics": {
      "bytes_billed": null,
      "bytes_processed": null,
      "elapsed_ms": 0
    }
  },
  "status": 200
}
```

...where each $RESULTS-TIMESEGMENT-x has this structure:

```bash
{
  "array_origin_status_codes": [
    $STATUS-DATA-ORIGIN1,
    $STATUS-DATA-ORIGIN2,
    ...
    $STATUS-DATA-ORIGINn,    
  ],
  "array_status_codes": [
    $STATUS-DATA-L11WAAP1,
    $STATUS-DATA-L11WAAP2,
    ...
    $STATUS-DATA-L11WAAPn,    
  ],
  "num_of_blocked_requests": integer,
  "num_of_challenges": integer,
  "num_of_human_requests": integer,
  "num_of_ip": integer,
  "num_of_origin_blocked_requests": integer,
  "num_of_requests": integer,
  "num_of_sessions": integer,
  "sum_of_sent_bytes": integer,
  "time_period": integer,
  "timeperiod_string": string 
}
```

...and each $STATUS-DATA-x contains the number of responses with a specific status:

```bash
{
  "num_of_requests": integer,
  "status": integer [an HTTP status code]
}
```

### Contents of each result

| Field name                         |                                                                                                                                                                                                        |
| ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| array\_origin\_status\_codes       | An array: each element contains a status code and the number of responses from the origin with that code. If no requests reached the origin during the specified time period, the array will be empty. |
| array\_status\_codes               | An array: each element contains a status code and the number of responses from L11WAAP with that code.                                                                                                 |
| num\_of\_blocked\_requests         | Requests that were blocked                                                                                                                                                                             |
| num\_of\_challenges                | Number of times L11WAAP issued a bot challenge                                                                                                                                                         |
| num\_of\_human\_requests           | Requests from human (i.e., non-bot) clients                                                                                                                                                            |
| num\_of\_ip                        | Number of IPs used by clients                                                                                                                                                                          |
| num\_of\_origin\_blocked\_requests | Number of requests rejected by the origin                                                                                                                                                              |
| num\_of\_requests                  | Total requests received during the time period                                                                                                                                                         |
| num\_of\_sessions                  | Number of unique sessions                                                                                                                                                                              |
| sum\_of\_sent\_bytes               | Total bytes sent                                                                                                                                                                                       |
| time\_period                       | Beginning of time segment, as an Epoch Unix integer (e.g., 1718186400)                                                                                                                                 |
| timeperiod\_string                 | Beginning of time segment, as a string (e.g., "2024-06-12 10:00:00")                                                                                                                                   |

## GET /api/v4.0/data/logs&#x20;

This route returns **all** requests that match the filter parameters, up to the number of requests specified. The results are returned like this:

```bash
{
  "data": {
    "results": [
      {
            $REQUEST1
      },
      {
            $REQUEST2
      }, 
      {
            $REQUEST3
      },           
      ...
      {
            $REQUESTn
      }
    ],
    "statistics": {
      "bytes_billed": null,
      "bytes_processed": null,
      "elapsed_ms": 0
    }
  },
  "status": 200
}
```

Each $REQUEST has this structure:

```
$FIELD1: $VALUE1,
$FIELD2: $VALUE2,
...
$FIELDn: $VALUEn
```

...where the $FIELDs are the **Field names** listed [above](#field-names) in the `filters` discussion, and the $VALUEs are their values, if any. So a request looks like this:

```bash
"acl_triggers": [],
"arguments": {},
"asn": "AS4837",
...
"user_agent": "curl/7.74.0",
"version": null
```


# Types of namespaces

The Link11 WAAP API includes over a dozen namespaces, each containing a number of routes.&#x20;

Each namespace has its own page in the documentation, listing all its routes, their parameters, and so on. These pages can be accessed in the left sidebar, in the [Namespace reference section](/reference-information/api/namespace-reference).

{% hint style="info" %}
The namespace pages are intended to act as a reference. They assume that you're already familiar with how to use the API, which is explained here [Using the Product / The Link11 WAAP API](/using-the-product/the-link11-waap-api).

Also, by default, every L11WAAP planet includes a Swagger UI instance that offers this same namespace information. However, the Swagger instance also provides additional interactive features, such as automatically building curl commands, submitting API calls directly, and more. [Read more about this](/using-the-product/the-link11-waap-api/using-swagger-ui).
{% endhint %}

Below is a general guide to the namespaces, showing the type of functionality each one provides. The namespaces can be organized into three broad categories:

* Security settings
* Site-related settings
* Other capabilities

## Security settings

<table><thead><tr><th width="235">API namespace</th><th>Full discussion of these settings in the UI</th></tr></thead><tbody><tr><td><a href="/pages/sPEkPad0ZjZnZ3VwRElD">ACL Profiles</a></td><td><a href="/pages/-LuhQEFjNgaQAjC26gpP">More info</a></td></tr><tr><td><a href="/pages/lP1I7LHgd8wuoQZoWD3N">Actions</a></td><td><a href="/pages/-LuXXhe1s4OmWtTPsbdc">More info</a></td></tr><tr><td><a href="/pages/XMeU3SD2AQ5bZ1w633zo">Content Filter Profiles</a></td><td><a href="/pages/-LuhREt20YEkB4JdQWYa">More info</a></td></tr><tr><td><a href="/pages/U1nNFOnP3xfknC8O7SqU">Content Filter Rules</a></td><td><a href="/pages/-LuhRUcnzXG-FalaisNk">More info</a></td></tr><tr><td><a href="/pages/5w8IQELO7HOmaDZg04sh">Dynamic Rules</a></td><td><a href="/pages/-LuXXjXNdEmQujH3IQYd">More info</a></td></tr><tr><td><a href="/pages/VtnJ1g7Sib17kikZAgdl">Flow Control Policies</a></td><td><a href="/pages/B1RC8cPddfJ5s9u3OD19">More info</a></td></tr><tr><td><a href="/pages/74tPYT2QRiqfqtWsVDx0">Global Filters</a></td><td><a href="/pages/-MAZNdmS9yULnfU1YUrh">More info</a></td></tr><tr><td><a href="/pages/gKM7ZVI8XAlIMSyjljaQ">Rate Limit Rules</a></td><td><a href="/pages/-MAZNlZmyzUevj73EjRT">More info</a></td></tr><tr><td><a href="/pages/TmtgMy7U9mF8CjjK7niD">Security Alerts</a></td><td><a href="/pages/TmtgMy7U9mF8CjjK7niD">More info</a></td></tr><tr><td><a href="/pages/mPjO75u08FhEDGUA7cHo">Security Policies</a></td><td><a href="/pages/dBaKTDZDGz3v60xNfs2T">More info</a></td></tr></tbody></table>

## **Site-related settings**

<table><thead><tr><th width="265">API namespace</th><th>Comments</th></tr></thead><tbody><tr><td><a href="/pages/uU5ie3UZetxh0ObEMWtg">Backend Services</a></td><td>For managing the services L11WAAP is protecting. <a href="/pages/kZgCJ92ssDELlHa1WevV">More info</a></td></tr><tr><td><a href="/pages/moqEqA80ODk2YpyEwqMN">Certificates</a></td><td>For managing SSL certificates. <a href="/pages/-LuXgqGbXTCeQw0wX9OO">More info</a></td></tr><tr><td><a href="/pages/fzJNtYIv0WxKOrvjDoEX">Edge Functions</a></td><td>For running custom Lua code. <a href="/pages/9UkxgPs6j4Obbt0sGDrH">More info</a></td></tr><tr><td><a href="/pages/R49RitkTwOeXu9YhiflX">Load Balancers</a></td><td>For managing SSL associated with load balancers. <a href="/pages/3Zbkuc2sdKwHrd7a9t4N">More info</a></td></tr><tr><td><a href="/pages/AgIQvKJfEIsnaO0nKPmq">Mobile Application Groups</a></td><td>For configuring Mobile SDK parameters. <a href="/pages/ruObxYN9szlhKHdqD1hO">More info</a></td></tr><tr><td><a href="/pages/fIBqR9ukjK2MKHtPGlVZ">Proxy Templates</a></td><td>For managing architectural parameters. <a href="/pages/7iOKBuKZQgxllP38PrTz">More info</a></td></tr><tr><td><a href="/pages/RcMKiYL17T62UXZiayev">Server Groups</a></td><td>For managing site-level properties. <a href="/pages/RolOF6ooCwL3bQcmrXOU">More info</a></td></tr></tbody></table>

## **Other capabilities**

<table><thead><tr><th width="185">API namespace</th><th>Comments</th></tr></thead><tbody><tr><td><a href="/pages/4ll3Ux2utrQdIkG6SUIL">Configs</a></td><td>For managing <a href="/pages/umWs4xAEYBIe3iON1pZk">configurations</a>, the fundamental internal data structure</td></tr><tr><td><a href="/pages/2Ky3LS0Udl2zh1gzXtTf">Data queries</a></td><td>For <a href="/pages/33Pol5fTYtEc45X8Hxj5">API access to traffic data</a> and managing <a href="/pages/-LuXXjPJLp2iuHpNgqxM">quarantined traffic sources</a></td></tr><tr><td><a href="/pages/FNnxYX8Usr3YTQVbvHUf">Log Exporters</a></td><td>For <a href="/pages/1N66wVxUwQjhuzTvw331">streaming events to an external destination</a> such as a SIEM solution</td></tr><tr><td><a href="/pages/N3pNVffM0M4puswRyCMW">Planets</a></td><td>For planet-level settings such as <a href="/pages/eCzSXDQkjiKwy0J0Ub1c">interactive challenges</a></td></tr><tr><td><a href="/pages/rGYym60HOJZx5dYdUUbX">Tags</a></td><td>For retrieval of <a href="/pages/-MDBbCNQPZskuYjEmLgy">tag</a> data</td></tr><tr><td><a href="/pages/8c4fZjD3vu6AWariZrzK">Tools</a></td><td>For miscellaneous capabilities, including <a href="/pages/GLJUElMc6P8LwWL03NIB">publishing</a> </td></tr><tr><td><a href="/pages/O0bSwRd9Xrc9skfuuvAt">Users</a></td><td>For management of users and API keys</td></tr></tbody></table>


# Namespace reference

{% content-ref url="/pages/sPEkPad0ZjZnZ3VwRElD" %}
[ACL Profiles](/reference-information/api/namespace-reference/acl-profiles)
{% endcontent-ref %}

{% content-ref url="/pages/lP1I7LHgd8wuoQZoWD3N" %}
[Actions](/reference-information/api/namespace-reference/actions)
{% endcontent-ref %}

{% content-ref url="/pages/uU5ie3UZetxh0ObEMWtg" %}
[Backend Services](/reference-information/api/namespace-reference/backend-services)
{% endcontent-ref %}

{% content-ref url="/pages/moqEqA80ODk2YpyEwqMN" %}
[Certificates](/reference-information/api/namespace-reference/certificates)
{% endcontent-ref %}

{% content-ref url="/pages/4ll3Ux2utrQdIkG6SUIL" %}
[Configs](/reference-information/api/namespace-reference/configs)
{% endcontent-ref %}

{% content-ref url="/pages/XMeU3SD2AQ5bZ1w633zo" %}
[Content Filter Profiles](/reference-information/api/namespace-reference/content-filter-profiles)
{% endcontent-ref %}

{% content-ref url="/pages/U1nNFOnP3xfknC8O7SqU" %}
[Content Filter Rules](/reference-information/api/namespace-reference/content-filter-rules)
{% endcontent-ref %}

{% content-ref url="/pages/2Ky3LS0Udl2zh1gzXtTf" %}
[Data queries](/reference-information/api/namespace-reference/data-queries)
{% endcontent-ref %}

{% content-ref url="/pages/5w8IQELO7HOmaDZg04sh" %}
[Dynamic Rules](/reference-information/api/namespace-reference/dynamic-rules)
{% endcontent-ref %}

{% content-ref url="/pages/fzJNtYIv0WxKOrvjDoEX" %}
[Edge Functions](/reference-information/api/namespace-reference/edge-functions)
{% endcontent-ref %}

{% content-ref url="/pages/VtnJ1g7Sib17kikZAgdl" %}
[Flow Control Policies](/reference-information/api/namespace-reference/flow-control-policies)
{% endcontent-ref %}

{% content-ref url="/pages/74tPYT2QRiqfqtWsVDx0" %}
[Global Filters](/reference-information/api/namespace-reference/global-filters)
{% endcontent-ref %}

{% content-ref url="/pages/R49RitkTwOeXu9YhiflX" %}
[Load Balancers](/reference-information/api/namespace-reference/load-balancers)
{% endcontent-ref %}

{% content-ref url="/pages/FNnxYX8Usr3YTQVbvHUf" %}
[Log Exporters](/reference-information/api/namespace-reference/log-exporters)
{% endcontent-ref %}

{% content-ref url="/pages/AgIQvKJfEIsnaO0nKPmq" %}
[Mobile Application Groups](/reference-information/api/namespace-reference/mobile-application-groups)
{% endcontent-ref %}

{% content-ref url="/pages/N3pNVffM0M4puswRyCMW" %}
[Planets](/reference-information/api/namespace-reference/planets)
{% endcontent-ref %}

{% content-ref url="/pages/fIBqR9ukjK2MKHtPGlVZ" %}
[Proxy Templates](/reference-information/api/namespace-reference/proxy-templates)
{% endcontent-ref %}

{% content-ref url="/pages/gKM7ZVI8XAlIMSyjljaQ" %}
[Rate Limit Rules](/reference-information/api/namespace-reference/rate-limit-rules)
{% endcontent-ref %}

{% content-ref url="/pages/TmtgMy7U9mF8CjjK7niD" %}
[Security Alerts](/reference-information/api/namespace-reference/security-alerts)
{% endcontent-ref %}

{% content-ref url="/pages/mPjO75u08FhEDGUA7cHo" %}
[Security Policies](/reference-information/api/namespace-reference/security-policies)
{% endcontent-ref %}

{% content-ref url="/pages/RcMKiYL17T62UXZiayev" %}
[Server Groups](/reference-information/api/namespace-reference/server-groups)
{% endcontent-ref %}

{% content-ref url="/pages/rGYym60HOJZx5dYdUUbX" %}
[Tags](/reference-information/api/namespace-reference/tags)
{% endcontent-ref %}

{% content-ref url="/pages/8c4fZjD3vu6AWariZrzK" %}
[Tools](/reference-information/api/namespace-reference/tools)
{% endcontent-ref %}

{% content-ref url="/pages/O0bSwRd9Xrc9skfuuvAt" %}
[Users](/reference-information/api/namespace-reference/users)
{% endcontent-ref %}


# ACL Profiles

## Get ACL Profiles

> Get all ACL Profiles in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/acl-profiles":{"get":{"operationId":"document_resource_get_api_v3_configs__config__d__document___get_42880613531283184","summary":"Get ACL Profiles","description":"Get all ACL Profiles in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"description":"ACL Profiles retrieved successfully","content":{"application/json":{"schema":{"title":"ACL Profiles document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/ACLProfile"}}}}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"tags":["ACL Profiles"]}}},"components":{"schemas":{"ACLProfile":{"properties":{"action":{"title":"Action","type":"string"},"allow":{"items":{"type":"string"},"title":"Allow","type":"array"},"allow_bot":{"items":{"type":"string"},"title":"Allow Bot","type":"array"},"deny":{"items":{"type":"string"},"title":"Deny","type":"array"},"deny_bot":{"items":{"type":"string"},"title":"Deny Bot","type":"array"},"description":{"title":"Description","type":"string"},"force_deny":{"items":{"type":"string"},"title":"Force Deny","type":"array"},"id":{"title":"Id","type":"string"},"name":{"title":"Name","type":"string"},"passthrough":{"items":{"type":"string"},"title":"Passthrough","type":"array"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"}},"required":["id","name"],"title":"ACLProfile","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Modify ACL Profiles

> Updates an existing set of ACL Profiles for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/acl-profiles":{"put":{"operationId":"document_resource_put_api_v3_configs__config__d__document___put_42880613531283184","summary":"Modify ACL Profiles","description":"Updates an existing set of ACL Profiles for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"ACL Profiles document","type":"array","items":{"$ref":"#/components/schemas/ACLProfile"}}}}},"responses":{"200":{"description":"ACL Profiles updated successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"tags":["ACL Profiles"]}}},"components":{"schemas":{"ACLProfile":{"properties":{"action":{"title":"Action","type":"string"},"allow":{"items":{"type":"string"},"title":"Allow","type":"array"},"allow_bot":{"items":{"type":"string"},"title":"Allow Bot","type":"array"},"deny":{"items":{"type":"string"},"title":"Deny","type":"array"},"deny_bot":{"items":{"type":"string"},"title":"Deny Bot","type":"array"},"description":{"title":"Description","type":"string"},"force_deny":{"items":{"type":"string"},"title":"Force Deny","type":"array"},"id":{"title":"Id","type":"string"},"name":{"title":"Name","type":"string"},"passthrough":{"items":{"type":"string"},"title":"Passthrough","type":"array"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"}},"required":["id","name"],"title":"ACLProfile","type":"object"},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create ACL Profiles

> Create a complete set of ACL Profiles for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/acl-profiles":{"post":{"operationId":"document_resource_post_api_v3_configs__config__d__document___post_42880613531283184","summary":"Create ACL Profiles","description":"Create a complete set of ACL Profiles for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"ACL Profiles document","type":"array","items":{"$ref":"#/components/schemas/ACLProfile"}}}}},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"ACL Profiles created successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["ACL Profiles"]}}},"components":{"schemas":{"ACLProfile":{"properties":{"action":{"title":"Action","type":"string"},"allow":{"items":{"type":"string"},"title":"Allow","type":"array"},"allow_bot":{"items":{"type":"string"},"title":"Allow Bot","type":"array"},"deny":{"items":{"type":"string"},"title":"Deny","type":"array"},"deny_bot":{"items":{"type":"string"},"title":"Deny Bot","type":"array"},"description":{"title":"Description","type":"string"},"force_deny":{"items":{"type":"string"},"title":"Force Deny","type":"array"},"id":{"title":"Id","type":"string"},"name":{"title":"Name","type":"string"},"passthrough":{"items":{"type":"string"},"title":"Passthrough","type":"array"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"}},"required":["id","name"],"title":"ACLProfile","type":"object"},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete ACL Profiles

> Delete all ACL Profiles in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/acl-profiles":{"delete":{"operationId":"document_resource_delete_api_v3_configs__config__d__document___delete_42880613531283184","summary":"Delete ACL Profiles","description":"Delete all ACL Profiles in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"ACL Profiles deleted successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["ACL Profiles"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get single ACL Profile

> Get an individual ACL Profile (not the entire set) from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/acl-profiles/{entry_id}":{"get":{"operationId":"entry_resource_get_api_v3_configs__config__d__document__e__entry___get_1426591218887049935","summary":"Get single ACL Profile","description":"Get an individual ACL Profile (not the entire set) from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"responses":{"200":{"description":"ACL Profile retrieved successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ACLProfile"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"tags":["ACL Profiles"]}}},"components":{"schemas":{"ACLProfile":{"properties":{"action":{"title":"Action","type":"string"},"allow":{"items":{"type":"string"},"title":"Allow","type":"array"},"allow_bot":{"items":{"type":"string"},"title":"Allow Bot","type":"array"},"deny":{"items":{"type":"string"},"title":"Deny","type":"array"},"deny_bot":{"items":{"type":"string"},"title":"Deny Bot","type":"array"},"description":{"title":"Description","type":"string"},"force_deny":{"items":{"type":"string"},"title":"Force Deny","type":"array"},"id":{"title":"Id","type":"string"},"name":{"title":"Name","type":"string"},"passthrough":{"items":{"type":"string"},"title":"Passthrough","type":"array"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"}},"required":["id","name"],"title":"ACLProfile","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Modify a single ACL Profile

> Update an individual ACL Profile within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/acl-profiles/{entry_id}":{"put":{"operationId":"entry_resource_put_api_v3_configs__config__d__document__e__entry___put_1426591218887049935","summary":"Modify a single ACL Profile","description":"Update an individual ACL Profile within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"ACL Profiles entry","$ref":"#/components/schemas/ACLProfile"}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"ACL Profile updated successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["ACL Profiles"]}}},"components":{"schemas":{"ACLProfile":{"properties":{"action":{"title":"Action","type":"string"},"allow":{"items":{"type":"string"},"title":"Allow","type":"array"},"allow_bot":{"items":{"type":"string"},"title":"Allow Bot","type":"array"},"deny":{"items":{"type":"string"},"title":"Deny","type":"array"},"deny_bot":{"items":{"type":"string"},"title":"Deny Bot","type":"array"},"description":{"title":"Description","type":"string"},"force_deny":{"items":{"type":"string"},"title":"Force Deny","type":"array"},"id":{"title":"Id","type":"string"},"name":{"title":"Name","type":"string"},"passthrough":{"items":{"type":"string"},"title":"Passthrough","type":"array"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"}},"required":["id","name"],"title":"ACLProfile","type":"object"},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create single ACL Profile

> Create an individual ACL Profile within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/acl-profiles/{entry_id}":{"post":{"operationId":"entries_resource_post_api_v3_configs__config__d__document__e__post_1255482801995229754","summary":"Create single ACL Profile","description":"Create an individual ACL Profile within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ACLProfile"}}}},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"ACL Profile created successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["ACL Profiles"]}}},"components":{"schemas":{"ACLProfile":{"properties":{"action":{"title":"Action","type":"string"},"allow":{"items":{"type":"string"},"title":"Allow","type":"array"},"allow_bot":{"items":{"type":"string"},"title":"Allow Bot","type":"array"},"deny":{"items":{"type":"string"},"title":"Deny","type":"array"},"deny_bot":{"items":{"type":"string"},"title":"Deny Bot","type":"array"},"description":{"title":"Description","type":"string"},"force_deny":{"items":{"type":"string"},"title":"Force Deny","type":"array"},"id":{"title":"Id","type":"string"},"name":{"title":"Name","type":"string"},"passthrough":{"items":{"type":"string"},"title":"Passthrough","type":"array"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"}},"required":["id","name"],"title":"ACLProfile","type":"object"},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete single ACL Profile

> Delete an individual ACL Profile (not the entire set) from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/acl-profiles/{entry_id}":{"delete":{"operationId":"entry_resource_delete_api_v3_configs__config__d__document__e__entry___delete_1426591218887049935","summary":"Delete single ACL Profile","description":"Delete an individual ACL Profile (not the entire set) from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"ACL Profile deleted successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["ACL Profiles"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get ACL Profiles version list

> Get list of versions of ACL Profiles in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/acl-profiles/versions":{"get":{"operationId":"document_list_version_resource_get_api_v3_configs__config__d__document__v__get_1351684752804657893","summary":"Get ACL Profiles version list","description":"Get list of versions of ACL Profiles in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Versions list","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/VersionEntry"}}}}}},"description":"ACL Profiles version list retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["ACL Profiles"]}}},"components":{"schemas":{"VersionEntry":{"title":"VersionEntry","type":"object","properties":{"author":{"title":"Author","type":"string"},"email":{"title":"Email","format":"email","type":"string"},"message":{"title":"Message","type":"string"},"date":{"format":"date-time","title":"Date","type":"string"},"version":{"title":"Version","type":"string"},"parents":{"type":"array","items":{"type":"string"}}}},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get version of ACL Profile

> Get a specific version of an ACL Profile

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/acl-profiles/versions/{version}":{"get":{"operationId":"document_version_resource_get_api_v3_configs__config__d__document__v__version___get_1370409337361692727","summary":"Get version of ACL Profile","description":"Get a specific version of an ACL Profile","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"ACL Profiles document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/ACLProfile"}}}}}},"description":"ACL Profile retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["ACL Profiles"]}}},"components":{"schemas":{"ACLProfile":{"properties":{"action":{"title":"Action","type":"string"},"allow":{"items":{"type":"string"},"title":"Allow","type":"array"},"allow_bot":{"items":{"type":"string"},"title":"Allow Bot","type":"array"},"deny":{"items":{"type":"string"},"title":"Deny","type":"array"},"deny_bot":{"items":{"type":"string"},"title":"Deny Bot","type":"array"},"description":{"title":"Description","type":"string"},"force_deny":{"items":{"type":"string"},"title":"Force Deny","type":"array"},"id":{"title":"Id","type":"string"},"name":{"title":"Name","type":"string"},"passthrough":{"items":{"type":"string"},"title":"Passthrough","type":"array"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"}},"required":["id","name"],"title":"ACLProfile","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Revert an ACL Profile to the specified version

> Set a previous ACL Profile version to be the current one

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/acl-profiles/versions/{version}/revert":{"put":{"operationId":"document_revert_resource_put_api_v3_configs__config__d__document__v__version__revert__put_1894561016170609423","summary":"Revert an ACL Profile to the specified version","description":"Set a previous ACL Profile version to be the current one","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"ACL Profile reversion was successful"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["ACL Profiles"]}}},"components":{"schemas":{"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```


# Actions

## Get Actions

> Get all Actions in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/actions":{"get":{"operationId":"document_resource_get_api_v3_configs__config__d__document___get_920494197590131601","summary":"Get Actions","description":"Get all Actions in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"description":"Actions retrieved successfully","content":{"application/json":{"schema":{"title":"Actions document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/Action"}}}}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"tags":["Actions"]}}},"components":{"schemas":{"Action":{"additionalProperties":false,"properties":{"description":{"type":"string","title":"Description"},"id":{"title":"Id","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"params":{"anyOf":[{"$ref":"#/components/schemas/ActionParams"},{"type":"object"}],"default":{},"title":"Action param List"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"type":{"allOf":[{"$ref":"#/components/schemas/ActionTypeEnum"}],"description":"Need to be one of predefined strings","title":"Type"}},"required":["id","name","type"],"title":"Action","type":"object"},"ActionParams":{"properties":{"content":{"default":"","title":"Content","type":"string"},"headers":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"description":"An object where keys are header names, and values are header values","title":"Headers"},"status":{"anyOf":[{"type":"integer"},{"type":"null"}],"default":null,"description":"Http status","title":"Status"}},"title":"ActionParams","type":"object"},"ActionTypeEnum":{"enum":["skip","block","challenge","ichallenge","monitor"],"title":"ActionTypeEnum","type":"string"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Modify Actions

> Update an existing set of Actions for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/actions":{"put":{"operationId":"document_resource_put_api_v3_configs__config__d__document___put_920494197590131601","summary":"Modify Actions","description":"Update an existing set of Actions for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"Actions document","type":"array","items":{"$ref":"#/components/schemas/Action"}}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Actions updated successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Actions"]}}},"components":{"schemas":{"Action":{"additionalProperties":false,"properties":{"description":{"type":"string","title":"Description"},"id":{"title":"Id","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"params":{"anyOf":[{"$ref":"#/components/schemas/ActionParams"},{"type":"object"}],"default":{},"title":"Action param List"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"type":{"allOf":[{"$ref":"#/components/schemas/ActionTypeEnum"}],"description":"Need to be one of predefined strings","title":"Type"}},"required":["id","name","type"],"title":"Action","type":"object"},"ActionParams":{"properties":{"content":{"default":"","title":"Content","type":"string"},"headers":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"description":"An object where keys are header names, and values are header values","title":"Headers"},"status":{"anyOf":[{"type":"integer"},{"type":"null"}],"default":null,"description":"Http status","title":"Status"}},"title":"ActionParams","type":"object"},"ActionTypeEnum":{"enum":["skip","block","challenge","ichallenge","monitor"],"title":"ActionTypeEnum","type":"string"},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create Actions

> Create complete set of Actions for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/actions":{"post":{"operationId":"document_resource_post_api_v3_configs__config__d__document___post_920494197590131601","summary":"Create Actions","description":"Create complete set of Actions for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"Actions document","type":"array","items":{"$ref":"#/components/schemas/Action"}}}}},"responses":{"201":{"description":"Actions created successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"tags":["Actions"]}}},"components":{"schemas":{"Action":{"additionalProperties":false,"properties":{"description":{"type":"string","title":"Description"},"id":{"title":"Id","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"params":{"anyOf":[{"$ref":"#/components/schemas/ActionParams"},{"type":"object"}],"default":{},"title":"Action param List"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"type":{"allOf":[{"$ref":"#/components/schemas/ActionTypeEnum"}],"description":"Need to be one of predefined strings","title":"Type"}},"required":["id","name","type"],"title":"Action","type":"object"},"ActionParams":{"properties":{"content":{"default":"","title":"Content","type":"string"},"headers":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"description":"An object where keys are header names, and values are header values","title":"Headers"},"status":{"anyOf":[{"type":"integer"},{"type":"null"}],"default":null,"description":"Http status","title":"Status"}},"title":"ActionParams","type":"object"},"ActionTypeEnum":{"enum":["skip","block","challenge","ichallenge","monitor"],"title":"ActionTypeEnum","type":"string"},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete Actions

> Delete all Actions in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/actions":{"delete":{"operationId":"document_resource_delete_api_v3_configs__config__d__document___delete_920494197590131601","summary":"Delete Actions","description":"Delete all Actions in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Actions deleted successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Actions"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get single Action

> Get an individual Action from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/actions/{entry_id}":{"get":{"operationId":"entry_resource_get_api_v3_configs__config__d__document__e__entry___get_188924675493220040","summary":"Get single Action","description":"Get an individual Action from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"responses":{"200":{"description":"Action retrieved successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Action"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"tags":["Actions"]}}},"components":{"schemas":{"Action":{"additionalProperties":false,"properties":{"description":{"type":"string","title":"Description"},"id":{"title":"Id","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"params":{"anyOf":[{"$ref":"#/components/schemas/ActionParams"},{"type":"object"}],"default":{},"title":"Action param List"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"type":{"allOf":[{"$ref":"#/components/schemas/ActionTypeEnum"}],"description":"Need to be one of predefined strings","title":"Type"}},"required":["id","name","type"],"title":"Action","type":"object"},"ActionParams":{"properties":{"content":{"default":"","title":"Content","type":"string"},"headers":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"description":"An object where keys are header names, and values are header values","title":"Headers"},"status":{"anyOf":[{"type":"integer"},{"type":"null"}],"default":null,"description":"Http status","title":"Status"}},"title":"ActionParams","type":"object"},"ActionTypeEnum":{"enum":["skip","block","challenge","ichallenge","monitor"],"title":"ActionTypeEnum","type":"string"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Modify a single Action

> Update an individual Action within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/actions/{entry_id}":{"put":{"operationId":"entry_resource_put_api_v3_configs__config__d__document__e__entry___put_188924675493220040","summary":"Modify a single Action","description":"Update an individual Action within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Action"}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Action updated successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Actions"]}}},"components":{"schemas":{"Action":{"additionalProperties":false,"properties":{"description":{"type":"string","title":"Description"},"id":{"title":"Id","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"params":{"anyOf":[{"$ref":"#/components/schemas/ActionParams"},{"type":"object"}],"default":{},"title":"Action param List"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"type":{"allOf":[{"$ref":"#/components/schemas/ActionTypeEnum"}],"description":"Need to be one of predefined strings","title":"Type"}},"required":["id","name","type"],"title":"Action","type":"object"},"ActionParams":{"properties":{"content":{"default":"","title":"Content","type":"string"},"headers":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"description":"An object where keys are header names, and values are header values","title":"Headers"},"status":{"anyOf":[{"type":"integer"},{"type":"null"}],"default":null,"description":"Http status","title":"Status"}},"title":"ActionParams","type":"object"},"ActionTypeEnum":{"enum":["skip","block","challenge","ichallenge","monitor"],"title":"ActionTypeEnum","type":"string"},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create single Action

> Create an individual Action within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/actions/{entry_id}":{"post":{"description":"Create an individual Action within a configuration","operationId":"entries_resource_post_api_v3_configs__config__d__document__e__post_1233211825730707681","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Action"}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"Action created successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"summary":"Create single Action","tags":["Actions"]}}},"components":{"schemas":{"Action":{"additionalProperties":false,"properties":{"description":{"type":"string","title":"Description"},"id":{"title":"Id","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"params":{"anyOf":[{"$ref":"#/components/schemas/ActionParams"},{"type":"object"}],"default":{},"title":"Action param List"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"type":{"allOf":[{"$ref":"#/components/schemas/ActionTypeEnum"}],"description":"Need to be one of predefined strings","title":"Type"}},"required":["id","name","type"],"title":"Action","type":"object"},"ActionParams":{"properties":{"content":{"default":"","title":"Content","type":"string"},"headers":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"description":"An object where keys are header names, and values are header values","title":"Headers"},"status":{"anyOf":[{"type":"integer"},{"type":"null"}],"default":null,"description":"Http status","title":"Status"}},"title":"ActionParams","type":"object"},"ActionTypeEnum":{"enum":["skip","block","challenge","ichallenge","monitor"],"title":"ActionTypeEnum","type":"string"},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete single Action

> Delete an individual Action from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/actions/{entry_id}":{"delete":{"operationId":"entry_resource_delete_api_v3_configs__config__d__document__e__entry___delete_188924675493220040","summary":"Delete single Action","description":"Delete an individual Action from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Action deleted successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Actions"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get Actions version list

> Get list of versions of Actions in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/actions/versions":{"get":{"operationId":"document_list_version_resource_get_api_v3_configs__config__d__document__v__get_2192084746238710671","summary":"Get Actions version list","description":"Get list of versions of Actions in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Versions list","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/VersionEntry"}}}}}},"description":"Actions version list retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Actions"]}}},"components":{"schemas":{"VersionEntry":{"title":"VersionEntry","type":"object","properties":{"author":{"title":"Author","type":"string"},"email":{"title":"Email","format":"email","type":"string"},"message":{"title":"Message","type":"string"},"date":{"format":"date-time","title":"Date","type":"string"},"version":{"title":"Version","type":"string"},"parents":{"type":"array","items":{"type":"string"}}}},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get version of Actions

> Get a specific version of an Action

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/actions/versions/{version}":{"get":{"operationId":"document_version_resource_get_api_v3_configs__config__d__document__v__version___get_2213417477955538928","summary":"Get version of Actions","description":"Get a specific version of an Action","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Actions document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/Action"}}}}}},"description":"Action version retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Actions"]}}},"components":{"schemas":{"Action":{"additionalProperties":false,"properties":{"description":{"type":"string","title":"Description"},"id":{"title":"Id","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"params":{"anyOf":[{"$ref":"#/components/schemas/ActionParams"},{"type":"object"}],"default":{},"title":"Action param List"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"type":{"allOf":[{"$ref":"#/components/schemas/ActionTypeEnum"}],"description":"Need to be one of predefined strings","title":"Type"}},"required":["id","name","type"],"title":"Action","type":"object"},"ActionParams":{"properties":{"content":{"default":"","title":"Content","type":"string"},"headers":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"description":"An object where keys are header names, and values are header values","title":"Headers"},"status":{"anyOf":[{"type":"integer"},{"type":"null"}],"default":null,"description":"Http status","title":"Status"}},"title":"ActionParams","type":"object"},"ActionTypeEnum":{"enum":["skip","block","challenge","ichallenge","monitor"],"title":"ActionTypeEnum","type":"string"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Revert Actions to the specified version

> Set a previous Actions version to be the current one

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/actions/versions/{version}/revert":{"put":{"description":"Set a previous Actions version to be the current one","operationId":"document_revert_resource_put_api_v3_configs__config__d__document__v__version__revert__put_2219093287643266132","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Actions reversion was successful"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"summary":"Revert Actions to the specified version","tags":["Actions"]}}},"components":{"schemas":{"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```


# Backend Services

## Get Backend Services

> Get all Backend Services in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/backend-services":{"get":{"operationId":"document_resource_get_api_v3_configs__config__d__document___get_917981194030078625","summary":"Get Backend Services","description":"Get all Backend Services in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"description":"Backend Services retrieved successfully","content":{"application/json":{"schema":{"title":"Backend Services document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/BackendService"}}}}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"tags":["Backend Services"]}}},"components":{"schemas":{"BackendService":{"properties":{"back_hosts":{"items":{"$ref":"#/components/schemas/BackendHost"},"title":"Back Hosts","type":"array"},"description":{"anyOf":[{"type":"string"}],"default":"","title":"Description"},"http11":{"description":"Use HTTP/1.1","title":"Http11","type":"boolean"},"id":{"title":"Id","type":"string"},"least_conn":{"title":"Least Conn","type":"boolean"},"name":{"title":"Name","type":"string","minLength":1},"sticky":{"description":"Load Balancing stickiness model","enum":["none","autocookie","customcookie","iphash","least_conn"],"title":"Sticky","type":"string"},"sticky_cookie_name":{"anyOf":[{"type":"string"}],"default":"","description":"Custom cookie name","title":"Sticky Cookie Name"},"transport_mode":{"description":"Tranport protocol <br> Service connectivity might follow incoming requests, will always be HTTP, or always HTTPS. Port-bridge mode means that Reblaze will target port numbers identical to incoming requests' port numbers.","enum":["default","http","https","port_bridge"],"title":"Transport Mode","type":"string"},"mtls_certificate":{"type":"string","description":"ID of mTLS certificate attached to backend service","title":"mTLS Certificate"},"mtls_trusted_certificate":{"type":"string","description":"ID of CA certificate attached to backend service","title":"CA Certificate"}},"required":["id","name","http11","transport_mode","sticky","sticky_cookie_name","least_conn","back_hosts"],"title":"BackendService","type":"object"},"BackendHost":{"properties":{"backup":{"title":"Backup","type":"boolean"},"down":{"title":"Down","type":"boolean"},"fail_timeout":{"title":"Fail Timeout","type":"integer"},"host":{"description":"URI or IP of host","title":"Host","type":"string"},"http_ports":{"title":"Http Ports","type":"array","items":{"type":"integer"}},"https_ports":{"title":"Https Ports","type":"array","items":{"type":"integer"}},"max_fails":{"title":"Max Fails","type":"integer"},"monitor_state":{"title":"Monitor State","type":"string"},"weight":{"title":"Weight","type":"integer"}},"required":["host","http_ports","https_ports","weight","max_fails","fail_timeout","down","monitor_state","backup"],"title":"BackendHost","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Modify Backend Services

> Updates an existing set of Backend Services for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/backend-services":{"put":{"operationId":"document_resource_put_api_v3_configs__config__d__document___put_917981194030078625","summary":"Modify Backend Services","description":"Updates an existing set of Backend Services for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"Backend Services document","type":"array","items":{"$ref":"#/components/schemas/BackendService"}}}}},"responses":{"200":{"description":"Backend Services updated successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"tags":["Backend Services"]}}},"components":{"schemas":{"BackendService":{"properties":{"back_hosts":{"items":{"$ref":"#/components/schemas/BackendHost"},"title":"Back Hosts","type":"array"},"description":{"anyOf":[{"type":"string"}],"default":"","title":"Description"},"http11":{"description":"Use HTTP/1.1","title":"Http11","type":"boolean"},"id":{"title":"Id","type":"string"},"least_conn":{"title":"Least Conn","type":"boolean"},"name":{"title":"Name","type":"string","minLength":1},"sticky":{"description":"Load Balancing stickiness model","enum":["none","autocookie","customcookie","iphash","least_conn"],"title":"Sticky","type":"string"},"sticky_cookie_name":{"anyOf":[{"type":"string"}],"default":"","description":"Custom cookie name","title":"Sticky Cookie Name"},"transport_mode":{"description":"Tranport protocol <br> Service connectivity might follow incoming requests, will always be HTTP, or always HTTPS. Port-bridge mode means that Reblaze will target port numbers identical to incoming requests' port numbers.","enum":["default","http","https","port_bridge"],"title":"Transport Mode","type":"string"},"mtls_certificate":{"type":"string","description":"ID of mTLS certificate attached to backend service","title":"mTLS Certificate"},"mtls_trusted_certificate":{"type":"string","description":"ID of CA certificate attached to backend service","title":"CA Certificate"}},"required":["id","name","http11","transport_mode","sticky","sticky_cookie_name","least_conn","back_hosts"],"title":"BackendService","type":"object"},"BackendHost":{"properties":{"backup":{"title":"Backup","type":"boolean"},"down":{"title":"Down","type":"boolean"},"fail_timeout":{"title":"Fail Timeout","type":"integer"},"host":{"description":"URI or IP of host","title":"Host","type":"string"},"http_ports":{"title":"Http Ports","type":"array","items":{"type":"integer"}},"https_ports":{"title":"Https Ports","type":"array","items":{"type":"integer"}},"max_fails":{"title":"Max Fails","type":"integer"},"monitor_state":{"title":"Monitor State","type":"string"},"weight":{"title":"Weight","type":"integer"}},"required":["host","http_ports","https_ports","weight","max_fails","fail_timeout","down","monitor_state","backup"],"title":"BackendHost","type":"object"},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create Backend Services

> Create a complete set of Backend Services for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/backend-services":{"post":{"operationId":"document_resource_post_api_v3_configs__config__d__document___post_917981194030078625","summary":"Create Backend Services","description":"Create a complete set of Backend Services for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"Backend Services document","type":"array","items":{"$ref":"#/components/schemas/BackendService"}}}}},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"Backend Services created successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Backend Services"]}}},"components":{"schemas":{"BackendService":{"properties":{"back_hosts":{"items":{"$ref":"#/components/schemas/BackendHost"},"title":"Back Hosts","type":"array"},"description":{"anyOf":[{"type":"string"}],"default":"","title":"Description"},"http11":{"description":"Use HTTP/1.1","title":"Http11","type":"boolean"},"id":{"title":"Id","type":"string"},"least_conn":{"title":"Least Conn","type":"boolean"},"name":{"title":"Name","type":"string","minLength":1},"sticky":{"description":"Load Balancing stickiness model","enum":["none","autocookie","customcookie","iphash","least_conn"],"title":"Sticky","type":"string"},"sticky_cookie_name":{"anyOf":[{"type":"string"}],"default":"","description":"Custom cookie name","title":"Sticky Cookie Name"},"transport_mode":{"description":"Tranport protocol <br> Service connectivity might follow incoming requests, will always be HTTP, or always HTTPS. Port-bridge mode means that Reblaze will target port numbers identical to incoming requests' port numbers.","enum":["default","http","https","port_bridge"],"title":"Transport Mode","type":"string"},"mtls_certificate":{"type":"string","description":"ID of mTLS certificate attached to backend service","title":"mTLS Certificate"},"mtls_trusted_certificate":{"type":"string","description":"ID of CA certificate attached to backend service","title":"CA Certificate"}},"required":["id","name","http11","transport_mode","sticky","sticky_cookie_name","least_conn","back_hosts"],"title":"BackendService","type":"object"},"BackendHost":{"properties":{"backup":{"title":"Backup","type":"boolean"},"down":{"title":"Down","type":"boolean"},"fail_timeout":{"title":"Fail Timeout","type":"integer"},"host":{"description":"URI or IP of host","title":"Host","type":"string"},"http_ports":{"title":"Http Ports","type":"array","items":{"type":"integer"}},"https_ports":{"title":"Https Ports","type":"array","items":{"type":"integer"}},"max_fails":{"title":"Max Fails","type":"integer"},"monitor_state":{"title":"Monitor State","type":"string"},"weight":{"title":"Weight","type":"integer"}},"required":["host","http_ports","https_ports","weight","max_fails","fail_timeout","down","monitor_state","backup"],"title":"BackendHost","type":"object"},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete Backend Services

> Delete all Backend Services in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/backend-services":{"delete":{"operationId":"document_resource_delete_api_v3_configs__config__d__document___delete_917981194030078625","summary":"Delete Backend Services","description":"Delete all Backend Services in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Backend Services deleted successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Backend Services"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get single Backend Service

> Get an individual Backend Service from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/backend-services/{entry_id}":{"get":{"operationId":"entry_resource_get_api_v3_configs__config__d__document__e__entry___get_2039370200812113407","summary":"Get single Backend Service","description":"Get an individual Backend Service from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"responses":{"200":{"description":"Backend Service retrieved successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/BackendService"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"tags":["Backend Services"]}}},"components":{"schemas":{"BackendService":{"properties":{"back_hosts":{"items":{"$ref":"#/components/schemas/BackendHost"},"title":"Back Hosts","type":"array"},"description":{"anyOf":[{"type":"string"}],"default":"","title":"Description"},"http11":{"description":"Use HTTP/1.1","title":"Http11","type":"boolean"},"id":{"title":"Id","type":"string"},"least_conn":{"title":"Least Conn","type":"boolean"},"name":{"title":"Name","type":"string","minLength":1},"sticky":{"description":"Load Balancing stickiness model","enum":["none","autocookie","customcookie","iphash","least_conn"],"title":"Sticky","type":"string"},"sticky_cookie_name":{"anyOf":[{"type":"string"}],"default":"","description":"Custom cookie name","title":"Sticky Cookie Name"},"transport_mode":{"description":"Tranport protocol <br> Service connectivity might follow incoming requests, will always be HTTP, or always HTTPS. Port-bridge mode means that Reblaze will target port numbers identical to incoming requests' port numbers.","enum":["default","http","https","port_bridge"],"title":"Transport Mode","type":"string"},"mtls_certificate":{"type":"string","description":"ID of mTLS certificate attached to backend service","title":"mTLS Certificate"},"mtls_trusted_certificate":{"type":"string","description":"ID of CA certificate attached to backend service","title":"CA Certificate"}},"required":["id","name","http11","transport_mode","sticky","sticky_cookie_name","least_conn","back_hosts"],"title":"BackendService","type":"object"},"BackendHost":{"properties":{"backup":{"title":"Backup","type":"boolean"},"down":{"title":"Down","type":"boolean"},"fail_timeout":{"title":"Fail Timeout","type":"integer"},"host":{"description":"URI or IP of host","title":"Host","type":"string"},"http_ports":{"title":"Http Ports","type":"array","items":{"type":"integer"}},"https_ports":{"title":"Https Ports","type":"array","items":{"type":"integer"}},"max_fails":{"title":"Max Fails","type":"integer"},"monitor_state":{"title":"Monitor State","type":"string"},"weight":{"title":"Weight","type":"integer"}},"required":["host","http_ports","https_ports","weight","max_fails","fail_timeout","down","monitor_state","backup"],"title":"BackendHost","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Modify a single Backend Service

> Update an individual Backend Service within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/backend-services/{entry_id}":{"put":{"operationId":"entry_resource_put_api_v3_configs__config__d__document__e__entry___put_2039370200812113407","summary":"Modify a single Backend Service","description":"Update an individual Backend Service within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BackendService"}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Backend Service updated successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Backend Services"]}}},"components":{"schemas":{"BackendService":{"properties":{"back_hosts":{"items":{"$ref":"#/components/schemas/BackendHost"},"title":"Back Hosts","type":"array"},"description":{"anyOf":[{"type":"string"}],"default":"","title":"Description"},"http11":{"description":"Use HTTP/1.1","title":"Http11","type":"boolean"},"id":{"title":"Id","type":"string"},"least_conn":{"title":"Least Conn","type":"boolean"},"name":{"title":"Name","type":"string","minLength":1},"sticky":{"description":"Load Balancing stickiness model","enum":["none","autocookie","customcookie","iphash","least_conn"],"title":"Sticky","type":"string"},"sticky_cookie_name":{"anyOf":[{"type":"string"}],"default":"","description":"Custom cookie name","title":"Sticky Cookie Name"},"transport_mode":{"description":"Tranport protocol <br> Service connectivity might follow incoming requests, will always be HTTP, or always HTTPS. Port-bridge mode means that Reblaze will target port numbers identical to incoming requests' port numbers.","enum":["default","http","https","port_bridge"],"title":"Transport Mode","type":"string"},"mtls_certificate":{"type":"string","description":"ID of mTLS certificate attached to backend service","title":"mTLS Certificate"},"mtls_trusted_certificate":{"type":"string","description":"ID of CA certificate attached to backend service","title":"CA Certificate"}},"required":["id","name","http11","transport_mode","sticky","sticky_cookie_name","least_conn","back_hosts"],"title":"BackendService","type":"object"},"BackendHost":{"properties":{"backup":{"title":"Backup","type":"boolean"},"down":{"title":"Down","type":"boolean"},"fail_timeout":{"title":"Fail Timeout","type":"integer"},"host":{"description":"URI or IP of host","title":"Host","type":"string"},"http_ports":{"title":"Http Ports","type":"array","items":{"type":"integer"}},"https_ports":{"title":"Https Ports","type":"array","items":{"type":"integer"}},"max_fails":{"title":"Max Fails","type":"integer"},"monitor_state":{"title":"Monitor State","type":"string"},"weight":{"title":"Weight","type":"integer"}},"required":["host","http_ports","https_ports","weight","max_fails","fail_timeout","down","monitor_state","backup"],"title":"BackendHost","type":"object"},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create single Backend Service

> Create an individual Backend Service within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/backend-services/{entry_id}":{"post":{"operationId":"entries_resource_post_api_v3_configs__config__d__document__e__post_1682546273078263211","summary":"Create single Backend Service","description":"Create an individual Backend Service within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BackendService"}}}},"responses":{"201":{"description":"Backend Service created successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"tags":["Backend Services"]}}},"components":{"schemas":{"BackendService":{"properties":{"back_hosts":{"items":{"$ref":"#/components/schemas/BackendHost"},"title":"Back Hosts","type":"array"},"description":{"anyOf":[{"type":"string"}],"default":"","title":"Description"},"http11":{"description":"Use HTTP/1.1","title":"Http11","type":"boolean"},"id":{"title":"Id","type":"string"},"least_conn":{"title":"Least Conn","type":"boolean"},"name":{"title":"Name","type":"string","minLength":1},"sticky":{"description":"Load Balancing stickiness model","enum":["none","autocookie","customcookie","iphash","least_conn"],"title":"Sticky","type":"string"},"sticky_cookie_name":{"anyOf":[{"type":"string"}],"default":"","description":"Custom cookie name","title":"Sticky Cookie Name"},"transport_mode":{"description":"Tranport protocol <br> Service connectivity might follow incoming requests, will always be HTTP, or always HTTPS. Port-bridge mode means that Reblaze will target port numbers identical to incoming requests' port numbers.","enum":["default","http","https","port_bridge"],"title":"Transport Mode","type":"string"},"mtls_certificate":{"type":"string","description":"ID of mTLS certificate attached to backend service","title":"mTLS Certificate"},"mtls_trusted_certificate":{"type":"string","description":"ID of CA certificate attached to backend service","title":"CA Certificate"}},"required":["id","name","http11","transport_mode","sticky","sticky_cookie_name","least_conn","back_hosts"],"title":"BackendService","type":"object"},"BackendHost":{"properties":{"backup":{"title":"Backup","type":"boolean"},"down":{"title":"Down","type":"boolean"},"fail_timeout":{"title":"Fail Timeout","type":"integer"},"host":{"description":"URI or IP of host","title":"Host","type":"string"},"http_ports":{"title":"Http Ports","type":"array","items":{"type":"integer"}},"https_ports":{"title":"Https Ports","type":"array","items":{"type":"integer"}},"max_fails":{"title":"Max Fails","type":"integer"},"monitor_state":{"title":"Monitor State","type":"string"},"weight":{"title":"Weight","type":"integer"}},"required":["host","http_ports","https_ports","weight","max_fails","fail_timeout","down","monitor_state","backup"],"title":"BackendHost","type":"object"},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete single Backend Service

> Delete an individual Backend Service from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/backend-services/{entry_id}":{"delete":{"operationId":"entry_resource_delete_api_v3_configs__config__d__document__e__entry___delete_2039370200812113407","summary":"Delete single Backend Service","description":"Delete an individual Backend Service from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Backend Service deleted successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Backend Services"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get Backend Services version list

> Get list of versions of Backend Services in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/backend-services/versions":{"get":{"operationId":"document_list_version_resource_get_api_v3_configs__config__d__document__v__get_1064601299435648815","summary":"Get Backend Services version list","description":"Get list of versions of Backend Services in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Versions list","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/VersionEntry"}}}}}},"description":"Backend Services version list retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Backend Services"]}}},"components":{"schemas":{"VersionEntry":{"title":"VersionEntry","type":"object","properties":{"author":{"title":"Author","type":"string"},"email":{"title":"Email","format":"email","type":"string"},"message":{"title":"Message","type":"string"},"date":{"format":"date-time","title":"Date","type":"string"},"version":{"title":"Version","type":"string"},"parents":{"type":"array","items":{"type":"string"}}}},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get version of Backend Service

> Get a specific version of a Backend Service

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/backend-services/versions/{version}":{"get":{"operationId":"document_version_resource_get_api_v3_configs__config__d__document__v__version___get_1317216686524434426","summary":"Get version of Backend Service","description":"Get a specific version of a Backend Service","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Backend Services document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/BackendService"}}}}}},"description":"Backend Service retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Backend Services"]}}},"components":{"schemas":{"BackendService":{"properties":{"back_hosts":{"items":{"$ref":"#/components/schemas/BackendHost"},"title":"Back Hosts","type":"array"},"description":{"anyOf":[{"type":"string"}],"default":"","title":"Description"},"http11":{"description":"Use HTTP/1.1","title":"Http11","type":"boolean"},"id":{"title":"Id","type":"string"},"least_conn":{"title":"Least Conn","type":"boolean"},"name":{"title":"Name","type":"string","minLength":1},"sticky":{"description":"Load Balancing stickiness model","enum":["none","autocookie","customcookie","iphash","least_conn"],"title":"Sticky","type":"string"},"sticky_cookie_name":{"anyOf":[{"type":"string"}],"default":"","description":"Custom cookie name","title":"Sticky Cookie Name"},"transport_mode":{"description":"Tranport protocol <br> Service connectivity might follow incoming requests, will always be HTTP, or always HTTPS. Port-bridge mode means that Reblaze will target port numbers identical to incoming requests' port numbers.","enum":["default","http","https","port_bridge"],"title":"Transport Mode","type":"string"},"mtls_certificate":{"type":"string","description":"ID of mTLS certificate attached to backend service","title":"mTLS Certificate"},"mtls_trusted_certificate":{"type":"string","description":"ID of CA certificate attached to backend service","title":"CA Certificate"}},"required":["id","name","http11","transport_mode","sticky","sticky_cookie_name","least_conn","back_hosts"],"title":"BackendService","type":"object"},"BackendHost":{"properties":{"backup":{"title":"Backup","type":"boolean"},"down":{"title":"Down","type":"boolean"},"fail_timeout":{"title":"Fail Timeout","type":"integer"},"host":{"description":"URI or IP of host","title":"Host","type":"string"},"http_ports":{"title":"Http Ports","type":"array","items":{"type":"integer"}},"https_ports":{"title":"Https Ports","type":"array","items":{"type":"integer"}},"max_fails":{"title":"Max Fails","type":"integer"},"monitor_state":{"title":"Monitor State","type":"string"},"weight":{"title":"Weight","type":"integer"}},"required":["host","http_ports","https_ports","weight","max_fails","fail_timeout","down","monitor_state","backup"],"title":"BackendHost","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Revert a Backend Service to the specified version

> Set a previous Backend Service version to be the current one

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/backend-services/versions/{version}/revert":{"put":{"operationId":"document_revert_resource_put_api_v3_configs__config__d__document__v__version__revert__put_452516142452866822","summary":"Revert a Backend Service to the specified version","description":"Set a previous Backend Service version to be the current one","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Backend Service reversion was successful"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Backend Services"]}}},"components":{"schemas":{"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```


# Certificates

## List Certificates

> Get a list of the planet's certificates for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/certificates":{"get":{"operationId":"get_api_v3_reblaze_configs__config__d_certificates__get_1339581305765730668","summary":"List Certificates","description":"Get a list of the planet's certificates for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"description":"Certificates were retrieved successfully","content":{"application/json":{"schema":{"title":"Response Get Api V4 Reblaze Configs Certificates","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/CertificateResponse"}}}}}}},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Certificates"]}}},"components":{"schemas":{"CertificateResponse":{"title":"Certificate response","allOf":[{"$ref":"#/components/schemas/CertificateBase"}],"properties":{"links":{"default":[],"items":{"$ref":"#/components/schemas/ProviderLink"},"title":"Provider Links","type":"array"}}},"CertificateBase":{"properties":{"cert_body":{"title":"Cert Body","type":"string"},"exp_date":{"format":"date","title":"Exp Date","type":"string"},"id":{"description":"Unique id","pattern":"^[A-Za-z0-9\\-\\_]*$","title":"Id","type":"string"},"issuer":{"title":"Issuer","type":"string"},"le_auto_renew":{"default":true,"title":"Le Auto Renew","type":"boolean"},"le_auto_replace":{"default":true,"title":"Le Auto Replace","type":"boolean"},"le_hash":{"default":"","title":"Le Hash","type":"string"},"name":{"title":"Name","description":"Display name for the certificate. Can only contain letters, numbers, dashes, and underscores. If omitted, defaults to the certificate ID.","type":"string","pattern":"^[A-Za-z0-9\\-\\_]*$"},"private_key":{"title":"Private Key","type":"string"},"san":{"items":{"type":"string"},"title":"San","type":"array"},"subject":{"title":"Subject","type":"string"},"upload_time":{"format":"date-time","title":"Upload Time","type":"string"},"revoked":{"title":"Revoked","type":"boolean","default":false},"crl":{"title":"CRL","type":"array","default":[],"items":{"type":"string"},"description":"Certificate Revocation List"},"cdp":{"title":"CDP","type":"array","items":{"type":"string"},"default":[],"description":"Certificate Distribution Point"},"side":{"title":"Certificate Side","enum":["clientCA","server","serverToBackendMTLS","backendCA"],"type":"string","default":"server"}},"required":["id"],"title":"Base Certificate","type":"object"},"ProviderLink":{"properties":{"link":{"title":"Link","type":"string"},"provider":{"title":"Provider","type":"string"},"region":{"title":"Region","type":"string"}},"required":["provider","link","region"],"title":"ProviderLink","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Get Certificate

> Get a specific Certificate for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/certificates/{entry_id}":{"get":{"operationId":"get_one_api_v3_reblaze_configs__config__d_certificates_e__id___get_385040395977565767","summary":"Get Certificate","description":"Get a specific Certificate for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Id","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CertificateResponse"}}},"description":"Certificate was retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Certificates"]}}},"components":{"schemas":{"CertificateResponse":{"title":"Certificate response","allOf":[{"$ref":"#/components/schemas/CertificateBase"}],"properties":{"links":{"default":[],"items":{"$ref":"#/components/schemas/ProviderLink"},"title":"Provider Links","type":"array"}}},"CertificateBase":{"properties":{"cert_body":{"title":"Cert Body","type":"string"},"exp_date":{"format":"date","title":"Exp Date","type":"string"},"id":{"description":"Unique id","pattern":"^[A-Za-z0-9\\-\\_]*$","title":"Id","type":"string"},"issuer":{"title":"Issuer","type":"string"},"le_auto_renew":{"default":true,"title":"Le Auto Renew","type":"boolean"},"le_auto_replace":{"default":true,"title":"Le Auto Replace","type":"boolean"},"le_hash":{"default":"","title":"Le Hash","type":"string"},"name":{"title":"Name","description":"Display name for the certificate. Can only contain letters, numbers, dashes, and underscores. If omitted, defaults to the certificate ID.","type":"string","pattern":"^[A-Za-z0-9\\-\\_]*$"},"private_key":{"title":"Private Key","type":"string"},"san":{"items":{"type":"string"},"title":"San","type":"array"},"subject":{"title":"Subject","type":"string"},"upload_time":{"format":"date-time","title":"Upload Time","type":"string"},"revoked":{"title":"Revoked","type":"boolean","default":false},"crl":{"title":"CRL","type":"array","default":[],"items":{"type":"string"},"description":"Certificate Revocation List"},"cdp":{"title":"CDP","type":"array","items":{"type":"string"},"default":[],"description":"Certificate Distribution Point"},"side":{"title":"Certificate Side","enum":["clientCA","server","serverToBackendMTLS","backendCA"],"type":"string","default":"server"}},"required":["id"],"title":"Base Certificate","type":"object"},"ProviderLink":{"properties":{"link":{"title":"Link","type":"string"},"provider":{"title":"Provider","type":"string"},"region":{"title":"Region","type":"string"}},"required":["provider","link","region"],"title":"ProviderLink","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Modify Certificate

> Change settings for a specific certificate. ("le\_" parameters refer to Let's Encrypt.)

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/certificates/{entry_id}":{"put":{"operationId":"update_api_v3_reblaze_configs__config__d_certificates_e__id___put_385040395977565767","summary":"Modify Certificate","description":"Change settings for a specific certificate. (\"le_\" parameters refer to Let's Encrypt.)","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Id","type":"string"}},{"in":"query","name":"le_auto_renew","required":false,"schema":{"default":true,"title":"Le Auto Renew","type":"boolean"}},{"in":"query","name":"le_auto_replace","required":false,"schema":{"default":true,"title":"Le Auto Replace","type":"boolean"}},{"in":"query","name":"replace_cert_id","required":false,"schema":{"title":"Replace Cert Id","type":"string"}},{"in":"query","name":"name","required":false,"description":"Display name for the certificate. Can only contain letters, numbers, dashes, and underscores.","schema":{"title":"Name","type":"string","pattern":"^[A-Za-z0-9\\-\\_]*$"}}],"responses":{"200":{"description":"Certificate modified successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Certificates"]}}},"components":{"schemas":{"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Add Certificate

> Create new certificate for a specific list of domains. Generate new certificate or upload existing one based on input parameters. "le\_" parameters refer to Let's Encrypt.

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/certificates/{entry_id}":{"post":{"description":"Create new certificate for a specific list of domains. Generate new certificate or upload existing one based on input parameters. \"le_\" parameters refer to Let's Encrypt.","operationId":"add_api_v3_reblaze_configs__config__d_certificates_e__id___post_385040395977565767","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"pattern":"(?:[a-z](?:[-a-z0-9]{0,61}[a-z0-9])?)","title":"Id","type":"string"}},{"in":"query","name":"domains","required":false,"schema":{"default":[],"items":{"type":"string"},"title":"Domains","type":"array"}}],"requestBody":{"content":{"application/json":{"schema":{"allOf":[{"$ref":"#/components/schemas/Certificate"}],"default":{"id":"","name":"","le_auto_renew":true,"le_auto_replace":true,"le_hash":"","provider_links":[]},"title":"Body"}}}},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"Certificate created"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"summary":"Add Certificate","tags":["Certificates"]}}},"components":{"schemas":{"Certificate":{"title":"Certificate","allOf":[{"$ref":"#/components/schemas/CertificateBase"}],"properties":{"provider_links":{"default":[],"items":{"$ref":"#/components/schemas/ProviderLink"},"title":"Provider Links","type":"array"}}},"CertificateBase":{"properties":{"cert_body":{"title":"Cert Body","type":"string"},"exp_date":{"format":"date","title":"Exp Date","type":"string"},"id":{"description":"Unique id","pattern":"^[A-Za-z0-9\\-\\_]*$","title":"Id","type":"string"},"issuer":{"title":"Issuer","type":"string"},"le_auto_renew":{"default":true,"title":"Le Auto Renew","type":"boolean"},"le_auto_replace":{"default":true,"title":"Le Auto Replace","type":"boolean"},"le_hash":{"default":"","title":"Le Hash","type":"string"},"name":{"title":"Name","description":"Display name for the certificate. Can only contain letters, numbers, dashes, and underscores. If omitted, defaults to the certificate ID.","type":"string","pattern":"^[A-Za-z0-9\\-\\_]*$"},"private_key":{"title":"Private Key","type":"string"},"san":{"items":{"type":"string"},"title":"San","type":"array"},"subject":{"title":"Subject","type":"string"},"upload_time":{"format":"date-time","title":"Upload Time","type":"string"},"revoked":{"title":"Revoked","type":"boolean","default":false},"crl":{"title":"CRL","type":"array","default":[],"items":{"type":"string"},"description":"Certificate Revocation List"},"cdp":{"title":"CDP","type":"array","items":{"type":"string"},"default":[],"description":"Certificate Distribution Point"},"side":{"title":"Certificate Side","enum":["clientCA","server","serverToBackendMTLS","backendCA"],"type":"string","default":"server"}},"required":["id"],"title":"Base Certificate","type":"object"},"ProviderLink":{"properties":{"link":{"title":"Link","type":"string"},"provider":{"title":"Provider","type":"string"},"region":{"title":"Region","type":"string"}},"required":["provider","link","region"],"title":"ProviderLink","type":"object"},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete Certificate

> Delete an individual Certificate from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/certificates/{entry_id}":{"delete":{"operationId":"delete_api_v3_reblaze_configs__config__d_certificates_e__id___delete_385040395977565767","summary":"Delete Certificate","description":"Delete an individual Certificate from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Id","type":"string"}}],"responses":{"200":{"description":"Certificate deleted successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Certificates"]}}},"components":{"schemas":{"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## GET /api/v4.3/conf/{config}/certificates/{entry\_id}/pfx

> Get Certificate PFX

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/certificates/{entry_id}/pfx":{"get":{"operationId":"export_api_v3_reblaze_configs__config__d_certificates_e__id__pfx__get_775020538878279514","summary":"Get Certificate PFX","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Id","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"format":"binary","title":"Response Export Api Certificates PFX","type":"string"}}},"description":"Certificate's PFX retrieved successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Certificates"]}}},"components":{"schemas":{"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## GET /api/v4.3/conf/{config}/certificates/{entry\_id}/pem

> Get Certificate PEM

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/certificates/{entry_id}/pem":{"get":{"operationId":"certificates_pem_get_775020538878279514","summary":"Get Certificate PEM","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Id","type":"string"}}],"responses":{"200":{"content":{"application/x-pem-file":{"schema":{"format":"binary","title":"Response Certificates PEM","type":"string"}}},"description":"Certificate's PEM retrieved successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Certificates"]}}},"components":{"schemas":{"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```


# Configs

## Get Configurations

> Get detailed list of existing configurations

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/configs":{"get":{"operationId":"configs_get_api_v3_configs__get_1449941962472013169","summary":"Get Configurations","description":"Get detailed list of existing configurations","parameters":[],"responses":{"200":{"description":"List of configurations was retrieved successfully","content":{"application/json":{"schema":{"title":"Response Configs Get Api Configs","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/Meta"}}}}}}}},"tags":["Configs"]}}},"components":{"schemas":{"Meta":{"properties":{"date":{"format":"date-time","title":"Date","type":"string"},"description":{"title":"Description","type":"string"},"id":{"title":"Id","type":"string"},"logs":{"default":[],"items":{"$ref":"#/components/schemas/VersionLog"},"title":"Logs","type":"array"},"version":{"title":"Version","type":"string"}},"required":["id","description"],"title":"Meta","type":"object"},"VersionLog":{"properties":{"date":{"format":"date-time","title":"Date","type":"string"},"version":{"title":"Version","type":"string"}},"title":"VersionLog","type":"object"}}}}
```

## Get a Configuration

> Retrieve a complete configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/configs/{config}":{"get":{"operationId":"config_get_api_v3_configs__config___get_70818436946675179","summary":"Get a Configuration","description":"Retrieve a complete configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{}}},"description":"Configuration retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Configs"]}}},"components":{"schemas":{"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get Versions of a Config

> Get all versions of a given configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/configs/{config}/versions":{"get":{"operationId":"config_list_version_get_api_v3_configs__config__v__get_494180803762951086","summary":"Get Versions of a Config","description":"Get all versions of a given configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Versions list","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/VersionEntry"}}}}}},"description":"Config versions retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Configs"]}}},"components":{"schemas":{"VersionEntry":{"title":"VersionEntry","type":"object","properties":{"author":{"title":"Author","type":"string"},"email":{"title":"Email","format":"email","type":"string"},"message":{"title":"Message","type":"string"},"date":{"format":"date-time","title":"Date","type":"string"},"version":{"title":"Version","type":"string"},"parents":{"type":"array","items":{"type":"string"}}}},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Revert a Config to a Version

> Set a previous version of a configuration to be the current one

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/configs/{config}/versions/{version}/revert":{"put":{"operationId":"config_revert_put_api_v3_configs__config__v__version__revert__put_1739432878779982029","summary":"Revert a Config to a Version","description":"Set a previous version of a configuration to be the current one","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Configuration reversion was successful"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Configs"]}}},"components":{"schemas":{"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```


# Content Filter Profiles

## Get Content Filter Profiles

> Get all Content Filter Profiles in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-profiles":{"get":{"operationId":"document_resource_get_api_v3_configs__config__d__document___get_162176221706214370","summary":"Get Content Filter Profiles","description":"Get all Content Filter Profiles in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"description":"Content Filter Profiles retrieved successfully","content":{"application/json":{"schema":{"title":"Content Filter Profiles document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/ContentFilterProfile"}}}}}}},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Content Filter Profiles"]}}},"components":{"schemas":{"ContentFilterProfile":{"properties":{"action":{"anyOf":[{"type":"string"}],"default":"","title":"Action"},"active":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"allsections":{"anyOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"All sections"},"args":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Arguments"},"content_type":{"anyOf":[{"items":{"type":"string"},"type":"array"}],"default":[],"description":"List of content types","title":"Content Type"},"cookies":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Cookies"},"decoding":{"allOf":[{"$ref":"#/components/schemas/Decoding"}],"title":"Active / Inactive decoding"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"graphql_path":{"anyOf":[{"type":"string"}],"default":"","description":"A field in a JSON that contains GraphQL query that need to be parsed. The value should be passed in JSONPath format. It supports regex for values as well.","title":"GraphQL Property JSON path"},"headers":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Headers"},"id":{"title":"Id","type":"string"},"ignore":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"ignore_alphanum":{"description":"When true, arguments, headers or cookies, which contain only alpha numeric characters, will be ignored","title":"Ignore Alphanumeric","type":"boolean"},"ignore_body":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Ignore Body"},"masking_seed":{"description":"A seed which will be used in the masking process","title":"Masking Seed","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"path":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Path"},"report":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"url":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"URL"}},"required":["id","name","ignore_alphanum","args","headers","cookies","path","decoding","masking_seed"],"title":"ContentFilterProfile","type":"object"},"ContentFilterProfileSection":{"properties":{"enable_max_count":{"description":"Enable or disable max amount of items of the section type allowed in the request","title":"Enable Max Count","type":"boolean"},"enable_max_length":{"description":"Enable or disable max length of characters allowed for each item of the section type in the request","title":"Enable Max Length","type":"boolean"},"max_count":{"description":"Max amount of items of the section type allowed in the request","minimum":1,"title":"Max Count","type":"integer"},"max_length":{"description":"Max length of characters allowed for each item of the section type in the request","minimum":1,"title":"Max Length","type":"integer"},"names":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Names","type":"array"},"regex":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Regex","type":"array"},"text":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Text","type":"array"}},"required":["max_length","enable_max_length","max_count","enable_max_count"],"title":"ContentFilterProfileSection","type":"object"},"ContentFilterEntryMatch":{"properties":{"ignore_cf_rule_tags":{"anyOf":[{"items":{"type":"string"},"type":"array"}],"default":[],"description":"List of excluded Content Filter tags","title":"Excluded Tags"},"key":{"anyOf":[{"type":"string"}],"default":"","title":"Key"},"mask":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Mask"},"reg":{"anyOf":[{"type":"string"}],"default":"","title":"Reg"},"restrict":{"title":"Restrict","type":"boolean"},"domain":{"anyOf":[{"type":"string"}],"default":"","title":"Domain"},"path":{"anyOf":[{"type":"string"}],"default":"","title":"Path"},"case_insensitive":{"title":"Case insensitive","type":"boolean"},"active":{"title":"Active","type":"boolean"}},"title":"ContentFilterEntryMatch","type":"object"},"Decoding":{"properties":{"base64":{"anyOf":[{"type":"boolean"}],"default":true,"title":"Base64"},"dual":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Dual"},"html":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Html"},"unicode":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Unicode"}},"title":"Decoding","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Modify Content Filter Profiles

> Update an existing set of Content Filter Profiles for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-profiles":{"put":{"operationId":"document_resource_put_api_v3_configs__config__d__document___put_162176221706214370","summary":"Modify Content Filter Profiles","description":"Update an existing set of Content Filter Profiles for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"Content Filter Profiles document","type":"array","items":{"$ref":"#/components/schemas/ContentFilterProfile"}}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Content Filter Profiles updated successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Content Filter Profiles"]}}},"components":{"schemas":{"ContentFilterProfile":{"properties":{"action":{"anyOf":[{"type":"string"}],"default":"","title":"Action"},"active":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"allsections":{"anyOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"All sections"},"args":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Arguments"},"content_type":{"anyOf":[{"items":{"type":"string"},"type":"array"}],"default":[],"description":"List of content types","title":"Content Type"},"cookies":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Cookies"},"decoding":{"allOf":[{"$ref":"#/components/schemas/Decoding"}],"title":"Active / Inactive decoding"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"graphql_path":{"anyOf":[{"type":"string"}],"default":"","description":"A field in a JSON that contains GraphQL query that need to be parsed. The value should be passed in JSONPath format. It supports regex for values as well.","title":"GraphQL Property JSON path"},"headers":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Headers"},"id":{"title":"Id","type":"string"},"ignore":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"ignore_alphanum":{"description":"When true, arguments, headers or cookies, which contain only alpha numeric characters, will be ignored","title":"Ignore Alphanumeric","type":"boolean"},"ignore_body":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Ignore Body"},"masking_seed":{"description":"A seed which will be used in the masking process","title":"Masking Seed","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"path":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Path"},"report":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"url":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"URL"}},"required":["id","name","ignore_alphanum","args","headers","cookies","path","decoding","masking_seed"],"title":"ContentFilterProfile","type":"object"},"ContentFilterProfileSection":{"properties":{"enable_max_count":{"description":"Enable or disable max amount of items of the section type allowed in the request","title":"Enable Max Count","type":"boolean"},"enable_max_length":{"description":"Enable or disable max length of characters allowed for each item of the section type in the request","title":"Enable Max Length","type":"boolean"},"max_count":{"description":"Max amount of items of the section type allowed in the request","minimum":1,"title":"Max Count","type":"integer"},"max_length":{"description":"Max length of characters allowed for each item of the section type in the request","minimum":1,"title":"Max Length","type":"integer"},"names":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Names","type":"array"},"regex":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Regex","type":"array"},"text":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Text","type":"array"}},"required":["max_length","enable_max_length","max_count","enable_max_count"],"title":"ContentFilterProfileSection","type":"object"},"ContentFilterEntryMatch":{"properties":{"ignore_cf_rule_tags":{"anyOf":[{"items":{"type":"string"},"type":"array"}],"default":[],"description":"List of excluded Content Filter tags","title":"Excluded Tags"},"key":{"anyOf":[{"type":"string"}],"default":"","title":"Key"},"mask":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Mask"},"reg":{"anyOf":[{"type":"string"}],"default":"","title":"Reg"},"restrict":{"title":"Restrict","type":"boolean"},"domain":{"anyOf":[{"type":"string"}],"default":"","title":"Domain"},"path":{"anyOf":[{"type":"string"}],"default":"","title":"Path"},"case_insensitive":{"title":"Case insensitive","type":"boolean"},"active":{"title":"Active","type":"boolean"}},"title":"ContentFilterEntryMatch","type":"object"},"Decoding":{"properties":{"base64":{"anyOf":[{"type":"boolean"}],"default":true,"title":"Base64"},"dual":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Dual"},"html":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Html"},"unicode":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Unicode"}},"title":"Decoding","type":"object"},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create Content Filter Profiles

> Create a complete set of Content Filter Profiles for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-profiles":{"post":{"operationId":"document_resource_post_api_v3_configs__config__d__document___post_162176221706214370","summary":"Create Content Filter Profiles","description":"Create a complete set of Content Filter Profiles for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"Content Filter Profiles document","type":"array","items":{"$ref":"#/components/schemas/ContentFilterProfile"}}}}},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"Content Filter Profiles created successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Content Filter Profiles"]}}},"components":{"schemas":{"ContentFilterProfile":{"properties":{"action":{"anyOf":[{"type":"string"}],"default":"","title":"Action"},"active":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"allsections":{"anyOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"All sections"},"args":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Arguments"},"content_type":{"anyOf":[{"items":{"type":"string"},"type":"array"}],"default":[],"description":"List of content types","title":"Content Type"},"cookies":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Cookies"},"decoding":{"allOf":[{"$ref":"#/components/schemas/Decoding"}],"title":"Active / Inactive decoding"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"graphql_path":{"anyOf":[{"type":"string"}],"default":"","description":"A field in a JSON that contains GraphQL query that need to be parsed. The value should be passed in JSONPath format. It supports regex for values as well.","title":"GraphQL Property JSON path"},"headers":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Headers"},"id":{"title":"Id","type":"string"},"ignore":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"ignore_alphanum":{"description":"When true, arguments, headers or cookies, which contain only alpha numeric characters, will be ignored","title":"Ignore Alphanumeric","type":"boolean"},"ignore_body":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Ignore Body"},"masking_seed":{"description":"A seed which will be used in the masking process","title":"Masking Seed","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"path":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Path"},"report":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"url":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"URL"}},"required":["id","name","ignore_alphanum","args","headers","cookies","path","decoding","masking_seed"],"title":"ContentFilterProfile","type":"object"},"ContentFilterProfileSection":{"properties":{"enable_max_count":{"description":"Enable or disable max amount of items of the section type allowed in the request","title":"Enable Max Count","type":"boolean"},"enable_max_length":{"description":"Enable or disable max length of characters allowed for each item of the section type in the request","title":"Enable Max Length","type":"boolean"},"max_count":{"description":"Max amount of items of the section type allowed in the request","minimum":1,"title":"Max Count","type":"integer"},"max_length":{"description":"Max length of characters allowed for each item of the section type in the request","minimum":1,"title":"Max Length","type":"integer"},"names":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Names","type":"array"},"regex":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Regex","type":"array"},"text":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Text","type":"array"}},"required":["max_length","enable_max_length","max_count","enable_max_count"],"title":"ContentFilterProfileSection","type":"object"},"ContentFilterEntryMatch":{"properties":{"ignore_cf_rule_tags":{"anyOf":[{"items":{"type":"string"},"type":"array"}],"default":[],"description":"List of excluded Content Filter tags","title":"Excluded Tags"},"key":{"anyOf":[{"type":"string"}],"default":"","title":"Key"},"mask":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Mask"},"reg":{"anyOf":[{"type":"string"}],"default":"","title":"Reg"},"restrict":{"title":"Restrict","type":"boolean"},"domain":{"anyOf":[{"type":"string"}],"default":"","title":"Domain"},"path":{"anyOf":[{"type":"string"}],"default":"","title":"Path"},"case_insensitive":{"title":"Case insensitive","type":"boolean"},"active":{"title":"Active","type":"boolean"}},"title":"ContentFilterEntryMatch","type":"object"},"Decoding":{"properties":{"base64":{"anyOf":[{"type":"boolean"}],"default":true,"title":"Base64"},"dual":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Dual"},"html":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Html"},"unicode":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Unicode"}},"title":"Decoding","type":"object"},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete Content Filter Profiles

> Delete all Content Filter Profiles in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-profiles":{"delete":{"operationId":"document_resource_delete_api_v3_configs__config__d__document___delete_162176221706214370","summary":"Delete Content Filter Profiles","description":"Delete all Content Filter Profiles in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"description":"Content Filter Profiles deleted successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}}},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Content Filter Profiles"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get single Content Filter Profile

> Get a Content Filter Profile from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-profiles/{entry_id}":{"get":{"operationId":"entry_resource_get_api_v3_configs__config__d__document__e__entry___get_1097168093453778213","summary":"Get single Content Filter Profile","description":"Get a Content Filter Profile from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ContentFilterProfile"}}},"description":"Content Filter Profile retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Content Filter Profiles"]}}},"components":{"schemas":{"ContentFilterProfile":{"properties":{"action":{"anyOf":[{"type":"string"}],"default":"","title":"Action"},"active":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"allsections":{"anyOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"All sections"},"args":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Arguments"},"content_type":{"anyOf":[{"items":{"type":"string"},"type":"array"}],"default":[],"description":"List of content types","title":"Content Type"},"cookies":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Cookies"},"decoding":{"allOf":[{"$ref":"#/components/schemas/Decoding"}],"title":"Active / Inactive decoding"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"graphql_path":{"anyOf":[{"type":"string"}],"default":"","description":"A field in a JSON that contains GraphQL query that need to be parsed. The value should be passed in JSONPath format. It supports regex for values as well.","title":"GraphQL Property JSON path"},"headers":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Headers"},"id":{"title":"Id","type":"string"},"ignore":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"ignore_alphanum":{"description":"When true, arguments, headers or cookies, which contain only alpha numeric characters, will be ignored","title":"Ignore Alphanumeric","type":"boolean"},"ignore_body":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Ignore Body"},"masking_seed":{"description":"A seed which will be used in the masking process","title":"Masking Seed","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"path":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Path"},"report":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"url":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"URL"}},"required":["id","name","ignore_alphanum","args","headers","cookies","path","decoding","masking_seed"],"title":"ContentFilterProfile","type":"object"},"ContentFilterProfileSection":{"properties":{"enable_max_count":{"description":"Enable or disable max amount of items of the section type allowed in the request","title":"Enable Max Count","type":"boolean"},"enable_max_length":{"description":"Enable or disable max length of characters allowed for each item of the section type in the request","title":"Enable Max Length","type":"boolean"},"max_count":{"description":"Max amount of items of the section type allowed in the request","minimum":1,"title":"Max Count","type":"integer"},"max_length":{"description":"Max length of characters allowed for each item of the section type in the request","minimum":1,"title":"Max Length","type":"integer"},"names":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Names","type":"array"},"regex":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Regex","type":"array"},"text":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Text","type":"array"}},"required":["max_length","enable_max_length","max_count","enable_max_count"],"title":"ContentFilterProfileSection","type":"object"},"ContentFilterEntryMatch":{"properties":{"ignore_cf_rule_tags":{"anyOf":[{"items":{"type":"string"},"type":"array"}],"default":[],"description":"List of excluded Content Filter tags","title":"Excluded Tags"},"key":{"anyOf":[{"type":"string"}],"default":"","title":"Key"},"mask":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Mask"},"reg":{"anyOf":[{"type":"string"}],"default":"","title":"Reg"},"restrict":{"title":"Restrict","type":"boolean"},"domain":{"anyOf":[{"type":"string"}],"default":"","title":"Domain"},"path":{"anyOf":[{"type":"string"}],"default":"","title":"Path"},"case_insensitive":{"title":"Case insensitive","type":"boolean"},"active":{"title":"Active","type":"boolean"}},"title":"ContentFilterEntryMatch","type":"object"},"Decoding":{"properties":{"base64":{"anyOf":[{"type":"boolean"}],"default":true,"title":"Base64"},"dual":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Dual"},"html":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Html"},"unicode":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Unicode"}},"title":"Decoding","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Modify a single Content Filter Profile

> Update an individual Content Filter Profile within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-profiles/{entry_id}":{"put":{"operationId":"entry_resource_put_api_v3_configs__config__d__document__e__entry___put_1097168093453778213","summary":"Modify a single Content Filter Profile","description":"Update an individual Content Filter Profile within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ContentFilterProfile"}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Content Filter Profile updated successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Content Filter Profiles"]}}},"components":{"schemas":{"ContentFilterProfile":{"properties":{"action":{"anyOf":[{"type":"string"}],"default":"","title":"Action"},"active":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"allsections":{"anyOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"All sections"},"args":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Arguments"},"content_type":{"anyOf":[{"items":{"type":"string"},"type":"array"}],"default":[],"description":"List of content types","title":"Content Type"},"cookies":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Cookies"},"decoding":{"allOf":[{"$ref":"#/components/schemas/Decoding"}],"title":"Active / Inactive decoding"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"graphql_path":{"anyOf":[{"type":"string"}],"default":"","description":"A field in a JSON that contains GraphQL query that need to be parsed. The value should be passed in JSONPath format. It supports regex for values as well.","title":"GraphQL Property JSON path"},"headers":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Headers"},"id":{"title":"Id","type":"string"},"ignore":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"ignore_alphanum":{"description":"When true, arguments, headers or cookies, which contain only alpha numeric characters, will be ignored","title":"Ignore Alphanumeric","type":"boolean"},"ignore_body":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Ignore Body"},"masking_seed":{"description":"A seed which will be used in the masking process","title":"Masking Seed","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"path":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Path"},"report":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"url":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"URL"}},"required":["id","name","ignore_alphanum","args","headers","cookies","path","decoding","masking_seed"],"title":"ContentFilterProfile","type":"object"},"ContentFilterProfileSection":{"properties":{"enable_max_count":{"description":"Enable or disable max amount of items of the section type allowed in the request","title":"Enable Max Count","type":"boolean"},"enable_max_length":{"description":"Enable or disable max length of characters allowed for each item of the section type in the request","title":"Enable Max Length","type":"boolean"},"max_count":{"description":"Max amount of items of the section type allowed in the request","minimum":1,"title":"Max Count","type":"integer"},"max_length":{"description":"Max length of characters allowed for each item of the section type in the request","minimum":1,"title":"Max Length","type":"integer"},"names":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Names","type":"array"},"regex":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Regex","type":"array"},"text":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Text","type":"array"}},"required":["max_length","enable_max_length","max_count","enable_max_count"],"title":"ContentFilterProfileSection","type":"object"},"ContentFilterEntryMatch":{"properties":{"ignore_cf_rule_tags":{"anyOf":[{"items":{"type":"string"},"type":"array"}],"default":[],"description":"List of excluded Content Filter tags","title":"Excluded Tags"},"key":{"anyOf":[{"type":"string"}],"default":"","title":"Key"},"mask":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Mask"},"reg":{"anyOf":[{"type":"string"}],"default":"","title":"Reg"},"restrict":{"title":"Restrict","type":"boolean"},"domain":{"anyOf":[{"type":"string"}],"default":"","title":"Domain"},"path":{"anyOf":[{"type":"string"}],"default":"","title":"Path"},"case_insensitive":{"title":"Case insensitive","type":"boolean"},"active":{"title":"Active","type":"boolean"}},"title":"ContentFilterEntryMatch","type":"object"},"Decoding":{"properties":{"base64":{"anyOf":[{"type":"boolean"}],"default":true,"title":"Base64"},"dual":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Dual"},"html":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Html"},"unicode":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Unicode"}},"title":"Decoding","type":"object"},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create single Content Filter Profile

> Create an individual Content Filter Profile within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-profiles/{entry_id}":{"post":{"operationId":"entries_resource_post_api_v3_configs__config__d__document__e__post_1698823422282145218","summary":"Create single Content Filter Profile","description":"Create an individual Content Filter Profile within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ContentFilterProfile"}}}},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"Content Filter Profile created successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Content Filter Profiles"]}}},"components":{"schemas":{"ContentFilterProfile":{"properties":{"action":{"anyOf":[{"type":"string"}],"default":"","title":"Action"},"active":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"allsections":{"anyOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"All sections"},"args":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Arguments"},"content_type":{"anyOf":[{"items":{"type":"string"},"type":"array"}],"default":[],"description":"List of content types","title":"Content Type"},"cookies":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Cookies"},"decoding":{"allOf":[{"$ref":"#/components/schemas/Decoding"}],"title":"Active / Inactive decoding"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"graphql_path":{"anyOf":[{"type":"string"}],"default":"","description":"A field in a JSON that contains GraphQL query that need to be parsed. The value should be passed in JSONPath format. It supports regex for values as well.","title":"GraphQL Property JSON path"},"headers":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Headers"},"id":{"title":"Id","type":"string"},"ignore":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"ignore_alphanum":{"description":"When true, arguments, headers or cookies, which contain only alpha numeric characters, will be ignored","title":"Ignore Alphanumeric","type":"boolean"},"ignore_body":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Ignore Body"},"masking_seed":{"description":"A seed which will be used in the masking process","title":"Masking Seed","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"path":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Path"},"report":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"url":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"URL"}},"required":["id","name","ignore_alphanum","args","headers","cookies","path","decoding","masking_seed"],"title":"ContentFilterProfile","type":"object"},"ContentFilterProfileSection":{"properties":{"enable_max_count":{"description":"Enable or disable max amount of items of the section type allowed in the request","title":"Enable Max Count","type":"boolean"},"enable_max_length":{"description":"Enable or disable max length of characters allowed for each item of the section type in the request","title":"Enable Max Length","type":"boolean"},"max_count":{"description":"Max amount of items of the section type allowed in the request","minimum":1,"title":"Max Count","type":"integer"},"max_length":{"description":"Max length of characters allowed for each item of the section type in the request","minimum":1,"title":"Max Length","type":"integer"},"names":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Names","type":"array"},"regex":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Regex","type":"array"},"text":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Text","type":"array"}},"required":["max_length","enable_max_length","max_count","enable_max_count"],"title":"ContentFilterProfileSection","type":"object"},"ContentFilterEntryMatch":{"properties":{"ignore_cf_rule_tags":{"anyOf":[{"items":{"type":"string"},"type":"array"}],"default":[],"description":"List of excluded Content Filter tags","title":"Excluded Tags"},"key":{"anyOf":[{"type":"string"}],"default":"","title":"Key"},"mask":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Mask"},"reg":{"anyOf":[{"type":"string"}],"default":"","title":"Reg"},"restrict":{"title":"Restrict","type":"boolean"},"domain":{"anyOf":[{"type":"string"}],"default":"","title":"Domain"},"path":{"anyOf":[{"type":"string"}],"default":"","title":"Path"},"case_insensitive":{"title":"Case insensitive","type":"boolean"},"active":{"title":"Active","type":"boolean"}},"title":"ContentFilterEntryMatch","type":"object"},"Decoding":{"properties":{"base64":{"anyOf":[{"type":"boolean"}],"default":true,"title":"Base64"},"dual":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Dual"},"html":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Html"},"unicode":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Unicode"}},"title":"Decoding","type":"object"},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete single Content Filter Profile

> Delete an individual Content Filter Profile from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-profiles/{entry_id}":{"delete":{"operationId":"entry_resource_delete_api_v3_configs__config__d__document__e__entry___delete_1097168093453778213","summary":"Delete single Content Filter Profile","description":"Delete an individual Content Filter Profile from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry ID","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Content Filter Profile deleted successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Content Filter Profiles"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get Content Filter Profiles version list

> Get list of versions of Content Filter Profiles in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-profiles/versions":{"get":{"operationId":"document_list_version_resource_get_api_v3_configs__config__d__document__v__get_23287116275484050","summary":"Get Content Filter Profiles version list","description":"Get list of versions of Content Filter Profiles in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Versions list","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/VersionEntry"}}}}}},"description":"Content Filter Profiles version list retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Content Filter Profiles"]}}},"components":{"schemas":{"VersionEntry":{"title":"VersionEntry","type":"object","properties":{"author":{"title":"Author","type":"string"},"email":{"title":"Email","format":"email","type":"string"},"message":{"title":"Message","type":"string"},"date":{"format":"date-time","title":"Date","type":"string"},"version":{"title":"Version","type":"string"},"parents":{"type":"array","items":{"type":"string"}}}},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get version of Content Filter Profile

> Get a specific version of a Content Filter Profile

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-profiles/versions/{version}":{"get":{"operationId":"document_version_resource_get_api_v3_configs__config__d__document__v__version___get_2148044252366748675","summary":"Get version of Content Filter Profile","description":"Get a specific version of a Content Filter Profile","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Content Filter Profiles document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/ContentFilterProfile"}}}}}},"description":"Content Filter Profile retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Content Filter Profiles"]}}},"components":{"schemas":{"ContentFilterProfile":{"properties":{"action":{"anyOf":[{"type":"string"}],"default":"","title":"Action"},"active":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"allsections":{"anyOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"All sections"},"args":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Arguments"},"content_type":{"anyOf":[{"items":{"type":"string"},"type":"array"}],"default":[],"description":"List of content types","title":"Content Type"},"cookies":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Cookies"},"decoding":{"allOf":[{"$ref":"#/components/schemas/Decoding"}],"title":"Active / Inactive decoding"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"graphql_path":{"anyOf":[{"type":"string"}],"default":"","description":"A field in a JSON that contains GraphQL query that need to be parsed. The value should be passed in JSONPath format. It supports regex for values as well.","title":"GraphQL Property JSON path"},"headers":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Headers"},"id":{"title":"Id","type":"string"},"ignore":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"ignore_alphanum":{"description":"When true, arguments, headers or cookies, which contain only alpha numeric characters, will be ignored","title":"Ignore Alphanumeric","type":"boolean"},"ignore_body":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Ignore Body"},"masking_seed":{"description":"A seed which will be used in the masking process","title":"Masking Seed","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"path":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"Path"},"report":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"url":{"allOf":[{"$ref":"#/components/schemas/ContentFilterProfileSection"}],"title":"URL"}},"required":["id","name","ignore_alphanum","args","headers","cookies","path","decoding","masking_seed"],"title":"ContentFilterProfile","type":"object"},"ContentFilterProfileSection":{"properties":{"enable_max_count":{"description":"Enable or disable max amount of items of the section type allowed in the request","title":"Enable Max Count","type":"boolean"},"enable_max_length":{"description":"Enable or disable max length of characters allowed for each item of the section type in the request","title":"Enable Max Length","type":"boolean"},"max_count":{"description":"Max amount of items of the section type allowed in the request","minimum":1,"title":"Max Count","type":"integer"},"max_length":{"description":"Max length of characters allowed for each item of the section type in the request","minimum":1,"title":"Max Length","type":"integer"},"names":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Names","type":"array"},"regex":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Regex","type":"array"},"text":{"items":{"$ref":"#/components/schemas/ContentFilterEntryMatch"},"title":"Text","type":"array"}},"required":["max_length","enable_max_length","max_count","enable_max_count"],"title":"ContentFilterProfileSection","type":"object"},"ContentFilterEntryMatch":{"properties":{"ignore_cf_rule_tags":{"anyOf":[{"items":{"type":"string"},"type":"array"}],"default":[],"description":"List of excluded Content Filter tags","title":"Excluded Tags"},"key":{"anyOf":[{"type":"string"}],"default":"","title":"Key"},"mask":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Mask"},"reg":{"anyOf":[{"type":"string"}],"default":"","title":"Reg"},"restrict":{"title":"Restrict","type":"boolean"},"domain":{"anyOf":[{"type":"string"}],"default":"","title":"Domain"},"path":{"anyOf":[{"type":"string"}],"default":"","title":"Path"},"case_insensitive":{"title":"Case insensitive","type":"boolean"},"active":{"title":"Active","type":"boolean"}},"title":"ContentFilterEntryMatch","type":"object"},"Decoding":{"properties":{"base64":{"anyOf":[{"type":"boolean"}],"default":true,"title":"Base64"},"dual":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Dual"},"html":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Html"},"unicode":{"anyOf":[{"type":"boolean"}],"default":false,"title":"Unicode"}},"title":"Decoding","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Revert a Content Filter Profile to the specified version

> Set a previous Content Filter Profile version to be the current one

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-profiles/versions/{version}/revert":{"put":{"description":"Set a previous Content Filter Profile version to be the current one","operationId":"document_revert_resource_put_api_v3_configs__config__d__document__v__version__revert__put_703361524879250541","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Content Filter Profile reversion was successful"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"summary":"Revert a Content Filter Profile to the specified version","tags":["Content Filter Profiles"]}}},"components":{"schemas":{"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```


# Content Filter Rules

## Get Content Filter Rules

> Get all Content Filter Rules in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-rules":{"get":{"operationId":"document_resource_get_api_v3_configs__config__d__document___get_240525296325212383","summary":"Get Content Filter Rules","description":"Get all Content Filter Rules in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"description":"Content Filter Rules retrieved successfully","content":{"application/json":{"schema":{"title":"Content Filter Rules document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/ContentFilterRule"}}}}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"tags":["Content Filter Rules"]}}},"components":{"schemas":{"ContentFilterRule":{"additionalProperties":false,"properties":{"category":{"description":"Category of the rule","title":"Category","type":"string"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"id":{"title":"Id","type":"string"},"msg":{"description":"Log message for this rule","title":"Message","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"operand":{"description":"Matching domain(s) regex","minLength":1,"title":"Operand","type":"string"},"risk":{"description":"Risk level of this rule, between 1 (lowest risk) and 5 (highest risk)","maximum":5,"minimum":1,"title":"Risk Level","type":"integer"},"subcategory":{"description":"Subcategory of the rule","title":"Subcategory","type":"string"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"}},"required":["id","name","msg","operand","category","subcategory","risk"],"title":"ContentFilterRule","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Modify Content Filter Rules

> Update an existing set of Content Filter Rules for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-rules":{"put":{"operationId":"document_resource_put_api_v3_configs__config__d__document___put_240525296325212383","summary":"Modify Content Filter Rules","description":"Update an existing set of Content Filter Rules for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"Content Filter Rules document","type":"array","items":{"$ref":"#/components/schemas/ContentFilterRule"}}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Content Filter Rules updated successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Content Filter Rules"]}}},"components":{"schemas":{"ContentFilterRule":{"additionalProperties":false,"properties":{"category":{"description":"Category of the rule","title":"Category","type":"string"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"id":{"title":"Id","type":"string"},"msg":{"description":"Log message for this rule","title":"Message","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"operand":{"description":"Matching domain(s) regex","minLength":1,"title":"Operand","type":"string"},"risk":{"description":"Risk level of this rule, between 1 (lowest risk) and 5 (highest risk)","maximum":5,"minimum":1,"title":"Risk Level","type":"integer"},"subcategory":{"description":"Subcategory of the rule","title":"Subcategory","type":"string"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"}},"required":["id","name","msg","operand","category","subcategory","risk"],"title":"ContentFilterRule","type":"object"},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create Content Filter Rules

> Create a complete set of Content Filter Rules for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-rules":{"post":{"operationId":"document_resource_post_api_v3_configs__config__d__document___post_240525296325212383","summary":"Create Content Filter Rules","description":"Create a complete set of Content Filter Rules for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"Content Filter Rules document","type":"array","items":{"$ref":"#/components/schemas/ContentFilterRule"}}}}},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"Content Filter Rules created successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Content Filter Rules"]}}},"components":{"schemas":{"ContentFilterRule":{"additionalProperties":false,"properties":{"category":{"description":"Category of the rule","title":"Category","type":"string"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"id":{"title":"Id","type":"string"},"msg":{"description":"Log message for this rule","title":"Message","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"operand":{"description":"Matching domain(s) regex","minLength":1,"title":"Operand","type":"string"},"risk":{"description":"Risk level of this rule, between 1 (lowest risk) and 5 (highest risk)","maximum":5,"minimum":1,"title":"Risk Level","type":"integer"},"subcategory":{"description":"Subcategory of the rule","title":"Subcategory","type":"string"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"}},"required":["id","name","msg","operand","category","subcategory","risk"],"title":"ContentFilterRule","type":"object"},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete Content Filter Rules

> Delete all Content Filter Rules in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-rules":{"delete":{"operationId":"document_resource_delete_api_v3_configs__config__d__document___delete_240525296325212383","summary":"Delete Content Filter Rules","description":"Delete all Content Filter Rules in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Content Filter Rules deleted successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Content Filter Rules"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get single Content Filter Rule

> Get a Content Filter Rule from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-rules/{entry_id}":{"get":{"operationId":"entry_resource_get_api_v3_configs__config__d__document__e__entry___get_632074844295302070","summary":"Get single Content Filter Rule","description":"Get a Content Filter Rule from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"responses":{"200":{"description":"Content Filter Rule retrieved successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ContentFilterRule"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"tags":["Content Filter Rules"]}}},"components":{"schemas":{"ContentFilterRule":{"additionalProperties":false,"properties":{"category":{"description":"Category of the rule","title":"Category","type":"string"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"id":{"title":"Id","type":"string"},"msg":{"description":"Log message for this rule","title":"Message","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"operand":{"description":"Matching domain(s) regex","minLength":1,"title":"Operand","type":"string"},"risk":{"description":"Risk level of this rule, between 1 (lowest risk) and 5 (highest risk)","maximum":5,"minimum":1,"title":"Risk Level","type":"integer"},"subcategory":{"description":"Subcategory of the rule","title":"Subcategory","type":"string"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"}},"required":["id","name","msg","operand","category","subcategory","risk"],"title":"ContentFilterRule","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Modify a single Content Filter Rule

> Update an individual Content Filter Rule within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-rules/{entry_id}":{"put":{"operationId":"entry_resource_put_api_v3_configs__config__d__document__e__entry___put_632074844295302070","summary":"Modify a single Content Filter Rule","description":"Update an individual Content Filter Rule within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ContentFilterRule"}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Content Filter Rule updated successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Content Filter Rules"]}}},"components":{"schemas":{"ContentFilterRule":{"additionalProperties":false,"properties":{"category":{"description":"Category of the rule","title":"Category","type":"string"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"id":{"title":"Id","type":"string"},"msg":{"description":"Log message for this rule","title":"Message","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"operand":{"description":"Matching domain(s) regex","minLength":1,"title":"Operand","type":"string"},"risk":{"description":"Risk level of this rule, between 1 (lowest risk) and 5 (highest risk)","maximum":5,"minimum":1,"title":"Risk Level","type":"integer"},"subcategory":{"description":"Subcategory of the rule","title":"Subcategory","type":"string"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"}},"required":["id","name","msg","operand","category","subcategory","risk"],"title":"ContentFilterRule","type":"object"},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create single Content Filter Rule

> Create an individual Content Filter Rule within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-rules/{entry_id}":{"post":{"description":"Create an individual Content Filter Rule within a configuration","operationId":"entries_resource_post_api_v3_configs__config__d__document__e__post_341850698560955842","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ContentFilterRule"}}}},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"Content Filter Rule created successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"summary":"Create single Content Filter Rule","tags":["Content Filter Rules"]}}},"components":{"schemas":{"ContentFilterRule":{"additionalProperties":false,"properties":{"category":{"description":"Category of the rule","title":"Category","type":"string"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"id":{"title":"Id","type":"string"},"msg":{"description":"Log message for this rule","title":"Message","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"operand":{"description":"Matching domain(s) regex","minLength":1,"title":"Operand","type":"string"},"risk":{"description":"Risk level of this rule, between 1 (lowest risk) and 5 (highest risk)","maximum":5,"minimum":1,"title":"Risk Level","type":"integer"},"subcategory":{"description":"Subcategory of the rule","title":"Subcategory","type":"string"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"}},"required":["id","name","msg","operand","category","subcategory","risk"],"title":"ContentFilterRule","type":"object"},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete single Content Filter Rule

> Delete an individual Content Filter Rule from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-rules/{entry_id}":{"delete":{"description":"Delete an individual Content Filter Rule from the specified configuration","operationId":"entry_resource_delete_api_v3_configs__config__d__document__e__entry___delete_632074844295302070","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Content Filter Rule deleted successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"summary":"Delete single Content Filter Rule","tags":["Content Filter Rules"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get Content Filter Rules version list

> Get list of versions of Content Filter Rules in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-rules/versions":{"get":{"operationId":"document_list_version_resource_get_api_v3_configs__config__d__document__v__get_714503588836468709","summary":"Get Content Filter Rules version list","description":"Get list of versions of Content Filter Rules in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Versions list","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/VersionEntry"}}}}}},"description":"Content Filter Rules version list retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Content Filter Rules"]}}},"components":{"schemas":{"VersionEntry":{"title":"VersionEntry","type":"object","properties":{"author":{"title":"Author","type":"string"},"email":{"title":"Email","format":"email","type":"string"},"message":{"title":"Message","type":"string"},"date":{"format":"date-time","title":"Date","type":"string"},"version":{"title":"Version","type":"string"},"parents":{"type":"array","items":{"type":"string"}}}},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get version of Content Filter Rule set

> Get a specific version of a Content Filter Rule set

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-rules/versions/{version}":{"get":{"operationId":"document_version_resource_get_api_v3_configs__config__d__document__v__version___get_843713431888815403","summary":"Get version of Content Filter Rule set","description":"Get a specific version of a Content Filter Rule set","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Content Filter Rules document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/ContentFilterRule"}}}}}},"description":"Content Filter Rule set retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Content Filter Rules"]}}},"components":{"schemas":{"ContentFilterRule":{"additionalProperties":false,"properties":{"category":{"description":"Category of the rule","title":"Category","type":"string"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"id":{"title":"Id","type":"string"},"msg":{"description":"Log message for this rule","title":"Message","type":"string"},"name":{"minLength":1,"title":"Name","type":"string"},"operand":{"description":"Matching domain(s) regex","minLength":1,"title":"Operand","type":"string"},"risk":{"description":"Risk level of this rule, between 1 (lowest risk) and 5 (highest risk)","maximum":5,"minimum":1,"title":"Risk Level","type":"integer"},"subcategory":{"description":"Subcategory of the rule","title":"Subcategory","type":"string"},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"}},"required":["id","name","msg","operand","category","subcategory","risk"],"title":"ContentFilterRule","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Revert a Content Filter Rule to the specified version

> Set a previous Content Filter Rule version to be the current one

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/content-filter-rules/versions/{version}/revert":{"put":{"operationId":"document_revert_resource_put_api_v3_configs__config__d__document__v__version__revert__put_794361952230410099","summary":"Revert a Content Filter Rule to the specified version","description":"Set a previous Content Filter Rule version to be the current one","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Content Filter Rule reversion was successful"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Content Filter Rules"]}}},"components":{"schemas":{"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```


# Data queries

{% hint style="info" %}
Two of the **Data queries** routes below manage [quarantined traffic sources](/console-walkthrough/security/quarantined). The rest are for retrieving traffic data; for instructions on using them, see [API access to traffic data](/reference-information/api/api-access-to-traffic-data).
{% endhint %}

## Quarantine operations

## Get quarantined list

> Get quarantined list

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/data/quarantined":{"get":{"operationId":"api.quarantined.handler.get_quarantined","summary":"Get quarantined list","description":"Get quarantined list","parameters":[{"in":"query","name":"config","schema":{"type":"string"}},{"in":"query","name":"ids","schema":{"items":{"type":"string"},"type":"array"}},{"in":"query","name":"rule_ids","schema":{"items":{"type":"string"},"type":"array"}},{"description":"Database to get data from","in":"header","name":"provider","required":true,"schema":{"description":"Database to get data from","enum":["mongodb"],"type":"string"}},{"description":"Syntax of query","in":"header","name":"syntax","required":true,"schema":{"description":"Syntax of query","enum":["string_query"],"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"data":{"properties":{"results":{"type":"array"},"statistics":{"type":"object"}},"required":["statistics","results"],"type":"object"},"status":{"type":"integer"}},"required":["status","data"],"type":"object"}}},"description":"Query for quarantined has been run successfully"},"4XX":{"content":{"application/json":{"schema":{"properties":{"detail":{"type":"string"},"status":{"type":"integer"},"title":{"type":"string"}},"required":["status","detail","title"],"type":"object"}}},"description":"Misconfigured request"}},"tags":["Data queries"]}}}}
```

## Delete record(s) from quarantined list

> Delete record(s) from quarantined list

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/data/quarantined":{"delete":{"operationId":"api.quarantined.handler.delete_quarantined","summary":"Delete record(s) from quarantined list","description":"Delete record(s) from quarantined list","parameters":[{"description":"Database to get data from","in":"header","name":"provider","required":true,"schema":{"description":"Database to get data from","enum":["mongodb"],"type":"string"}},{"description":"Syntax of query","in":"header","name":"syntax","required":true,"schema":{"description":"Syntax of query","enum":["json"],"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"properties":{"config":{"type":"string"},"ids":{"items":{"type":"string"},"type":"array"},"rule_ids":{"items":{"type":"string"},"type":"array"}},"type":"object"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"data":{"properties":{"results":{"type":"array"},"statistics":{"type":"object"}},"required":["statistics","results"],"type":"object"},"status":{"type":"integer"}},"required":["status","data"],"type":"object"}}},"description":"Record(s) was/were successfully deleted"},"4XX":{"content":{"application/json":{"schema":{"properties":{"detail":{"type":"string"},"status":{"type":"integer"},"title":{"type":"string"}},"required":["status","detail","title"],"type":"object"}}},"description":"Misconfigured request"}},"tags":["Data queries"]}}}}
```

## Traffic data operations

## Get traffic data from logs

> Retrieve traffic data using 'filters' parameter, explained at \[<https://gb.docs.reblaze.com/reference-information/api/api-access-to-traffic-data]\\(https://gb.docs.reblaze.com/reference-information/api/api-access-to-traffic-data)>

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/data/logs":{"get":{"operationId":"api.logs.handler.get_loglines_860854857476889660","summary":"Get traffic data from logs","description":"Retrieve traffic data using 'filters' parameter, explained at [https://gb.docs.reblaze.com/reference-information/api/api-access-to-traffic-data](https://gb.docs.reblaze.com/reference-information/api/api-access-to-traffic-data)","parameters":[{"in":"query","name":"limit","schema":{"default":100,"maximum":2500,"minimum":1,"type":"integer"}},{"in":"query","name":"offset","schema":{"default":0,"minimum":0,"type":"integer"}},{"description":"Filters for request in format selected below (JSON or query string)","in":"query","name":"filters","schema":{"description":"Filters for request in format selected below (JSON or query string)","type":"string"},"style":"deepObject"},{"description":"if set to true the request will return rendered SQL without running it, for debug purposes","in":"query","name":"debug","required":false,"schema":{"description":"if set to true the request will return rendered SQL without running it, for debug purposes","type":"boolean"}},{"description":"if set to true the query will be saved in the query history","in":"query","name":"save_history","required":false,"schema":{"description":"if set to true the query will be saved in the query history","type":"boolean"}},{"description":"Syntax of query","in":"header","name":"syntax","required":false,"schema":{"description":"syntax of query","enum":["json","string_query"],"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"data":{"properties":{"results":{"type":"array"},"statistics":{"type":"object"}},"required":["statistics","results"],"type":"object"},"status":{"type":"integer"}},"required":["status","data"],"type":"object"}}},"description":"Logs has been received successfully"},"4XX":{"content":{"application/json":{"schema":{"properties":{"detail":{"type":"string"},"status":{"type":"integer"},"title":{"type":"string"}},"required":["status","detail","title"],"type":"object"}}},"description":"Misconfigured request"}},"tags":["Data queries"]}}}}
```

## Get traffic stats

> Get stats (time\_period, counter, hostname, bandwidth, latency) using 'filters' parameter, explained at \[<https://gb.docs.reblaze.com/reference-information/api/api-access-to-traffic-data]\\(https://gb.docs.reblaze.com/reference-information/api/api-access-to-traffic-data)>

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/data/stats":{"get":{"operationId":"api.dashboard.handler.get_stats_1179987213029942625","summary":"Get traffic stats","description":"Get stats (time_period, counter, hostname, bandwidth, latency) using 'filters' parameter, explained at [https://gb.docs.reblaze.com/reference-information/api/api-access-to-traffic-data](https://gb.docs.reblaze.com/reference-information/api/api-access-to-traffic-data)","parameters":[{"description":"Filters for request in format selected below (JSON or query string)","in":"query","name":"filters","schema":{"description":"Filters for request in format selected below (JSON or query string)","type":"string"},"style":"deepObject"},{"description":"if set to true the request will return rendered SQL without running it, for debug purposes","in":"query","name":"debug","required":false,"schema":{"description":"if set to true the request will return rendered SQL without running it, for debug purposes","type":"boolean"}},{"description":"Syntax of query","in":"header","name":"syntax","required":false,"schema":{"description":"syntax of query","enum":["json","string_query"],"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"data":{"properties":{"results":{"type":"array"},"statistics":{"type":"object"}},"required":["statistics","results"],"type":"object"},"status":{"type":"integer"}},"required":["status","data"],"type":"object"}}},"description":"Stats has been received successfully"},"4XX":{"content":{"application/json":{"schema":{"properties":{"detail":{"type":"string"},"status":{"type":"integer"},"title":{"type":"string"}},"required":["status","detail","title"],"type":"object"}}},"description":"Misconfigured request"}},"tags":["Data queries"]}}}}
```

## Get traffic timeline

> Get timeline (time\_period, sessions, remote\_addr, all\_hits, blocked, origin\_blocked, challenge, is\_human, statuses stats, origin statuses stats, bytes\_sent) using 'filters' parameter, explained at \[<https://gb.docs.reblaze.com/reference-information/api/api-access-to-traffic-data]\\(https://gb.docs.reblaze.com/reference-information/api/api-access-to-traffic-data)>

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/data/timeline":{"get":{"operationId":"api.dashboard.handler.get_timeline_185381998472123425","summary":"Get traffic timeline","description":"Get timeline (time_period, sessions, remote_addr, all_hits, blocked, origin_blocked, challenge, is_human, statuses stats, origin statuses stats, bytes_sent) using 'filters' parameter, explained at [https://gb.docs.reblaze.com/reference-information/api/api-access-to-traffic-data](https://gb.docs.reblaze.com/reference-information/api/api-access-to-traffic-data)","parameters":[{"description":"Filters for request in format selected below (JSON or query string)","in":"query","name":"filters","schema":{"description":"Filters for request in format selected below (JSON or query string)","type":"string"},"style":"deepObject"},{"description":"if set to true the request will return rendered SQL without running it, for debug purposes","in":"query","name":"debug","required":false,"schema":{"description":"if set to true the request will return rendered SQL without running it, for debug purposes","type":"boolean"}},{"description":"Syntax of query","in":"header","name":"syntax","required":false,"schema":{"description":"syntax of query","enum":["json","string_query"],"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"data":{"properties":{"results":{"type":"array"},"statistics":{"type":"object"}},"required":["statistics","results"],"type":"object"},"status":{"type":"integer"}},"required":["status","data"],"type":"object"}}},"description":"Timeline has been received successfully"},"4XX":{"content":{"application/json":{"schema":{"properties":{"detail":{"type":"string"},"status":{"type":"integer"},"title":{"type":"string"}},"required":["status","detail","title"],"type":"object"}}},"description":"Misconfigured request"}},"tags":["Data queries"]}}}}
```

## Convert 'filters' query string to JSON

> Convert a query string (as used in the UI Dashboard and Events Log) into JSON format.

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/data/timeline/parse":{"post":{"operationId":"api.dashboard.handler.post_parse_38303596745303976","summary":"Convert 'filters' query string to JSON","description":"Convert a query string (as used in the UI Dashboard and Events Log) into JSON format.","parameters":[],"requestBody":{"content":{"application/json":{"schema":{"properties":{"query":{"oneOf":[{"type":"string"},{"type":"object"}]}},"required":["query"],"type":"object"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"type":"object"}}},"description":"Filter string has been converted successfully"},"4XX":{"content":{"application/json":{"schema":{"properties":{"detail":{"type":"string"},"status":{"type":"integer"},"title":{"type":"string"}},"required":["status","detail","title"],"type":"object"}}},"description":"Misconfigured request"}},"tags":["Data queries"]}}}}
```

## Get "top" traffic data

> Get topx stats using 'filters' parameter, explained at \[<https://gb.docs.reblaze.com/reference-information/api/api-access-to-traffic-data]\\(https://gb.docs.reblaze.com/reference-information/api/api-access-to-traffic-data)>

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/data/topx":{"get":{"operationId":"api.dashboard.handler.get_topx_2280964647653779379","summary":"Get \"top\" traffic data","description":"Get topx stats using 'filters' parameter, explained at [https://gb.docs.reblaze.com/reference-information/api/api-access-to-traffic-data](https://gb.docs.reblaze.com/reference-information/api/api-access-to-traffic-data)","parameters":[{"description":"Filters for request in format selected below (JSON or query string)","in":"query","name":"filters","schema":{"description":"Filters for request in format selected below (JSON or query string)","type":"string"},"style":"deepObject"},{"description":"if set to true the request will return rendered SQL without running it, for debug purposes","in":"query","name":"debug","required":false,"schema":{"description":"if set to true the request will return rendered SQL without running it, for debug purposes","type":"boolean"}},{"description":"if set to true the query will be saved in the query history","in":"query","name":"save_history","required":false,"schema":{"description":"if set to true the query will be saved in the query history","type":"boolean"}},{"description":"Syntax of query","in":"header","name":"syntax","required":false,"schema":{"description":"syntax of query","enum":["json","string_query"],"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"properties":{"data":{"properties":{"results":{"type":"array"},"statistics":{"type":"object"}},"required":["statistics","results"],"type":"object"},"status":{"type":"integer"}},"required":["status","data"],"type":"object"}}},"description":"Topx has been received successfully"},"4XX":{"content":{"application/json":{"schema":{"properties":{"detail":{"type":"string"},"status":{"type":"integer"},"title":{"type":"string"}},"required":["status","detail","title"],"type":"object"}}},"description":"Misconfigured request"}},"tags":["Data queries"]}}}}
```


# Dynamic Rules

## Get Dynamic Rules

> Get all Dynamic Rules in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/dynamic-rules":{"get":{"operationId":"get_api_v3_reblaze_configs__config__d_dynamic_rules__get_130152134249177325","summary":"Get Dynamic Rules","description":"Get all Dynamic Rules in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Response Get Api Dynamic Rules","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/DynamicRule"}}}}}},"description":"Dynamic Rules retrieved successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Dynamic Rules"]}}},"components":{"schemas":{"DynamicRule":{"properties":{"action":{"title":"Action","type":"string"},"active":{"title":"Active","type":"boolean"},"description":{"default":"","title":"Description","type":"string"},"id":{"description":"Unique id","pattern":"^[A-Za-z0-9\\-\\_]*$","title":"Id","type":"string"},"include":{"title":"Include","type":"object","properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"title":"Tags","type":"array","items":{"type":"string"}}}},"exclude":{"title":"Exclude","type":"object","properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"title":"Tags","type":"array","items":{"type":"string"}}}},"name":{"title":"Name","type":"string"},"offload_ip_filtering":{"title":"OffloadIPFiltering","type":"boolean"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"},"target":{"title":"Target","type":"string"},"threshold":{"title":"Threshold","type":"integer"},"timeframe":{"title":"Timeframe","type":"integer"},"ttl":{"title":"Ttl","type":"integer"}},"required":["id","name","threshold","timeframe","ttl","active","offload_ip_filtering","target","action"],"title":"DynamicRule","type":"object"},"TagsRelationEnum":{"title":"TagsRelationEnum","description":"Relation between tags","type":"string","enum":["OR","AND"]},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Get specific Dynamic Rule

> Get a Dynamic Rule from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/dynamic-rules/{entry_id}":{"get":{"operationId":"get_one_api_v3_reblaze_configs__config__d_dynamic_rules_e__id___get_1148973984917593028","summary":"Get specific Dynamic Rule","description":"Get a Dynamic Rule from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry ID","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/DynamicRule"}}},"description":"Dynamic Rule retrieved successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Dynamic Rules"]}}},"components":{"schemas":{"DynamicRule":{"properties":{"action":{"title":"Action","type":"string"},"active":{"title":"Active","type":"boolean"},"description":{"default":"","title":"Description","type":"string"},"id":{"description":"Unique id","pattern":"^[A-Za-z0-9\\-\\_]*$","title":"Id","type":"string"},"include":{"title":"Include","type":"object","properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"title":"Tags","type":"array","items":{"type":"string"}}}},"exclude":{"title":"Exclude","type":"object","properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"title":"Tags","type":"array","items":{"type":"string"}}}},"name":{"title":"Name","type":"string"},"offload_ip_filtering":{"title":"OffloadIPFiltering","type":"boolean"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"},"target":{"title":"Target","type":"string"},"threshold":{"title":"Threshold","type":"integer"},"timeframe":{"title":"Timeframe","type":"integer"},"ttl":{"title":"Ttl","type":"integer"}},"required":["id","name","threshold","timeframe","ttl","active","offload_ip_filtering","target","action"],"title":"DynamicRule","type":"object"},"TagsRelationEnum":{"title":"TagsRelationEnum","description":"Relation between tags","type":"string","enum":["OR","AND"]},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Modify Dynamic Rule

> Update an individual Dynamic Rule within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/dynamic-rules/{entry_id}":{"put":{"operationId":"update_api_v3_reblaze_configs__config__d_dynamic_rules_e__id___put_1148973984917593028","summary":"Modify Dynamic Rule","description":"Update an individual Dynamic Rule within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Id","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/DynamicRule"}}},"required":true},"responses":{"200":{"description":"Dynamic Rule updated successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}}},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Dynamic Rules"]}}},"components":{"schemas":{"DynamicRule":{"properties":{"action":{"title":"Action","type":"string"},"active":{"title":"Active","type":"boolean"},"description":{"default":"","title":"Description","type":"string"},"id":{"description":"Unique id","pattern":"^[A-Za-z0-9\\-\\_]*$","title":"Id","type":"string"},"include":{"title":"Include","type":"object","properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"title":"Tags","type":"array","items":{"type":"string"}}}},"exclude":{"title":"Exclude","type":"object","properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"title":"Tags","type":"array","items":{"type":"string"}}}},"name":{"title":"Name","type":"string"},"offload_ip_filtering":{"title":"OffloadIPFiltering","type":"boolean"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"},"target":{"title":"Target","type":"string"},"threshold":{"title":"Threshold","type":"integer"},"timeframe":{"title":"Timeframe","type":"integer"},"ttl":{"title":"Ttl","type":"integer"}},"required":["id","name","threshold","timeframe","ttl","active","offload_ip_filtering","target","action"],"title":"DynamicRule","type":"object"},"TagsRelationEnum":{"title":"TagsRelationEnum","description":"Relation between tags","type":"string","enum":["OR","AND"]},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Create Dynamic Rule

> Create an individual Dynamic Rule within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/dynamic-rules/{entry_id}":{"post":{"operationId":"add_api_v3_reblaze_configs__config__d_dynamic_rules_e__id___post_1148973984917593028","summary":"Create Dynamic Rule","description":"Create an individual Dynamic Rule within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"pattern":"^[A-Za-z0-9\\-\\_]*$","title":"Id","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/DynamicRule"}}},"required":true},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"Dynamic Rule created successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Dynamic Rules"]}}},"components":{"schemas":{"DynamicRule":{"properties":{"action":{"title":"Action","type":"string"},"active":{"title":"Active","type":"boolean"},"description":{"default":"","title":"Description","type":"string"},"id":{"description":"Unique id","pattern":"^[A-Za-z0-9\\-\\_]*$","title":"Id","type":"string"},"include":{"title":"Include","type":"object","properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"title":"Tags","type":"array","items":{"type":"string"}}}},"exclude":{"title":"Exclude","type":"object","properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"title":"Tags","type":"array","items":{"type":"string"}}}},"name":{"title":"Name","type":"string"},"offload_ip_filtering":{"title":"OffloadIPFiltering","type":"boolean"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"},"target":{"title":"Target","type":"string"},"threshold":{"title":"Threshold","type":"integer"},"timeframe":{"title":"Timeframe","type":"integer"},"ttl":{"title":"Ttl","type":"integer"}},"required":["id","name","threshold","timeframe","ttl","active","offload_ip_filtering","target","action"],"title":"DynamicRule","type":"object"},"TagsRelationEnum":{"title":"TagsRelationEnum","description":"Relation between tags","type":"string","enum":["OR","AND"]},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Delete Dynamic Rule

> Delete an individual Dynamic Rule from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/dynamic-rules/{entry_id}":{"delete":{"operationId":"delete_api_v3_reblaze_configs__config__d_dynamic_rules_e__id___delete_1148973984917593028","summary":"Delete Dynamic Rule","description":"Delete an individual Dynamic Rule from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Id","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Dynamic Rule deleted successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Dynamic Rules"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```


# Edge Functions

## Get Edge Functions

> Get all Edge Functions in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/edge-functions":{"get":{"operationId":"document_resource_get_api_v3_configs__config__d__document___get_6879659801245559","summary":"Get Edge Functions","description":"Get all Edge Functions in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"description":"Edge Functions retrieved successfully","content":{"application/json":{"schema":{"title":"Edge Functions document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/EdgeFunction"}}}}}}}},"tags":["Edge Functions"]}}},"components":{"schemas":{"EdgeFunction":{"additionalProperties":false,"properties":{"code":{"description":"Edge Function Code","title":"Code","type":"string"},"description":{"anyOf":[{"type":"string"}],"default":"","title":"Description"},"id":{"description":"Unique id","pattern":"^[A-Za-z0-9_]*$","title":"Id","type":"string"},"name":{"title":"Name","type":"string"},"phase":{"enum":["request","response"],"title":"Phase","type":"string"}},"required":["id","name","code","phase"],"title":"EdgeFunction","type":"object"}}}}
```

## Modify Edge Functions

> Update an existing set of Edge Functions for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/edge-functions":{"put":{"description":"Update an existing set of Edge Functions for a configuration","operationId":"document_resource_put_api_v3_configs__config__d__document___put_6879659801245559","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"Edge Functions document","type":"array","items":{"$ref":"#/components/schemas/EdgeFunction"}}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Edge Functions updated successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"summary":"Modify Edge Functions","tags":["Edge Functions"]}}},"components":{"schemas":{"EdgeFunction":{"additionalProperties":false,"properties":{"code":{"description":"Edge Function Code","title":"Code","type":"string"},"description":{"anyOf":[{"type":"string"}],"default":"","title":"Description"},"id":{"description":"Unique id","pattern":"^[A-Za-z0-9_]*$","title":"Id","type":"string"},"name":{"title":"Name","type":"string"},"phase":{"enum":["request","response"],"title":"Phase","type":"string"}},"required":["id","name","code","phase"],"title":"EdgeFunction","type":"object"},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create Edge Functions

> Create a complete set of Edge Functions for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/edge-functions":{"post":{"operationId":"document_resource_post_api_v3_configs__config__d__document___post_6879659801245559","summary":"Create Edge Functions","description":"Create a complete set of Edge Functions for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"Edge Functions document","type":"array","items":{"$ref":"#/components/schemas/EdgeFunction"}}}}},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"Edge Functions created successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Edge Functions"]}}},"components":{"schemas":{"EdgeFunction":{"additionalProperties":false,"properties":{"code":{"description":"Edge Function Code","title":"Code","type":"string"},"description":{"anyOf":[{"type":"string"}],"default":"","title":"Description"},"id":{"description":"Unique id","pattern":"^[A-Za-z0-9_]*$","title":"Id","type":"string"},"name":{"title":"Name","type":"string"},"phase":{"enum":["request","response"],"title":"Phase","type":"string"}},"required":["id","name","code","phase"],"title":"EdgeFunction","type":"object"},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete Edge Functions

> Delete all Edge Functions in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/edge-functions":{"delete":{"operationId":"document_resource_delete_api_v3_configs__config__d__document___delete_6879659801245559","summary":"Delete Edge Functions","description":"Delete all Edge Functions in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Edge Functions deleted successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Edge Functions"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get specific Edge Function

> Get an Edge Function from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/edge-functions/{entry_id}":{"get":{"operationId":"entry_resource_get_api_v3_configs__config__d__document__e__entry___get_292002034326962409","summary":"Get specific Edge Function","description":"Get an Edge Function from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry ID","type":"string"}}],"responses":{"200":{"description":"Edge Function retrieved successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/EdgeFunction"}}}},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Edge Functions"]}}},"components":{"schemas":{"EdgeFunction":{"additionalProperties":false,"properties":{"code":{"description":"Edge Function Code","title":"Code","type":"string"},"description":{"anyOf":[{"type":"string"}],"default":"","title":"Description"},"id":{"description":"Unique id","pattern":"^[A-Za-z0-9_]*$","title":"Id","type":"string"},"name":{"title":"Name","type":"string"},"phase":{"enum":["request","response"],"title":"Phase","type":"string"}},"required":["id","name","code","phase"],"title":"EdgeFunction","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Modify a single Edge Function

> Update an individual Edge Function within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/edge-functions/{entry_id}":{"put":{"operationId":"entry_resource_put_api_v3_configs__config__d__document__e__entry___put_292002034326962409","summary":"Modify a single Edge Function","description":"Update an individual Edge Function within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/EdgeFunction"}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Edge Function updated successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Edge Functions"]}}},"components":{"schemas":{"EdgeFunction":{"additionalProperties":false,"properties":{"code":{"description":"Edge Function Code","title":"Code","type":"string"},"description":{"anyOf":[{"type":"string"}],"default":"","title":"Description"},"id":{"description":"Unique id","pattern":"^[A-Za-z0-9_]*$","title":"Id","type":"string"},"name":{"title":"Name","type":"string"},"phase":{"enum":["request","response"],"title":"Phase","type":"string"}},"required":["id","name","code","phase"],"title":"EdgeFunction","type":"object"},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create single Edge Function

> Create an individual Edge Function within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/edge-functions/{entry_id}":{"post":{"description":"Create an individual Edge Function within a configuration","operationId":"entries_resource_post_api_v3_configs__config__d__document__e__post_770839733381503437","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry ID","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/EdgeFunction"}}}},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"Edge Function created successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"summary":"Create single Edge Function","tags":["Edge Functions"]}}},"components":{"schemas":{"EdgeFunction":{"additionalProperties":false,"properties":{"code":{"description":"Edge Function Code","title":"Code","type":"string"},"description":{"anyOf":[{"type":"string"}],"default":"","title":"Description"},"id":{"description":"Unique id","pattern":"^[A-Za-z0-9_]*$","title":"Id","type":"string"},"name":{"title":"Name","type":"string"},"phase":{"enum":["request","response"],"title":"Phase","type":"string"}},"required":["id","name","code","phase"],"title":"EdgeFunction","type":"object"},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete single Edge Function

> Delete an individual Edge Function from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/edge-functions/{entry_id}":{"delete":{"description":"Delete an individual Edge Function from the specified configuration","operationId":"entry_resource_delete_api_v3_configs__config__d__document__e__entry___delete_292002034326962409","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Edge Function deleted successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"summary":"Delete single Edge Function","tags":["Edge Functions"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get Edge Functions version list

> Get list of versions of Edge Functions in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/edge-functions/versions":{"get":{"operationId":"document_list_version_resource_get_api_v3_configs__config__d__document__v__get_325157665928822156","summary":"Get Edge Functions version list","description":"Get list of versions of Edge Functions in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Versions list","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/VersionEntry"}}}}}},"description":"Edge Functions version list retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Edge Functions"]}}},"components":{"schemas":{"VersionEntry":{"title":"VersionEntry","type":"object","properties":{"author":{"title":"Author","type":"string"},"email":{"title":"Email","format":"email","type":"string"},"message":{"title":"Message","type":"string"},"date":{"format":"date-time","title":"Date","type":"string"},"version":{"title":"Version","type":"string"},"parents":{"type":"array","items":{"type":"string"}}}},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get version of Edge Function

> Get a specific version of an Edge Function

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/edge-functions/versions/{version}":{"get":{"operationId":"document_version_resource_get_api_v3_configs__config__d__document__v__version___get_2157733992678878348","summary":"Get version of Edge Function","description":"Get a specific version of an Edge Function","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Edge Functions document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/EdgeFunction"}}}}}},"description":"Edge Function retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Edge Functions"]}}},"components":{"schemas":{"EdgeFunction":{"additionalProperties":false,"properties":{"code":{"description":"Edge Function Code","title":"Code","type":"string"},"description":{"anyOf":[{"type":"string"}],"default":"","title":"Description"},"id":{"description":"Unique id","pattern":"^[A-Za-z0-9_]*$","title":"Id","type":"string"},"name":{"title":"Name","type":"string"},"phase":{"enum":["request","response"],"title":"Phase","type":"string"}},"required":["id","name","code","phase"],"title":"EdgeFunction","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Revert an Edge Function to the specified version

> Set a previous Edge Function version to be the current one

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/edge-functions/versions/{version}/revert":{"put":{"description":"Set a previous Edge Function version to be the current one","operationId":"document_revert_resource_put_api_v3_configs__config__d__document__v__version__revert__put_672753031115275799","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Edge Function reversion was successful"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"summary":"Revert an Edge Function to the specified version","tags":["Edge Functions"]}}},"components":{"schemas":{"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```


# Flow Control Policies

## Get Flow Control Policies

> Get all Flow Control Policies in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/flow-control-policies":{"get":{"operationId":"document_resource_get_api_v3_configs__config__d__document___get_18696332526555447","summary":"Get Flow Control Policies","description":"Get all Flow Control Policies in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"description":"Flow Control Policies retrieved successfully","content":{"application/json":{"schema":{"title":"Flow Control Policies document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/FlowControl"}}}}}}}},"tags":["Flow Control Policies"]}}},"components":{"schemas":{"FlowControl":{"additionalProperties":false,"properties":{"active":{"description":"This flow is active","title":"Active flag","type":"boolean"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"exclude":{"default":[],"description":"Tags describing requests to exclude from the flow control rule","items":{"type":"string"},"title":"Excluded tags","type":"array"},"id":{"title":"Id","type":"string"},"include":{"default":[],"description":"Tags describing requests to include in the flow control rule","items":{"type":"string"},"title":"Included tags","type":"array"},"key":{"items":{"$ref":"#/components/schemas/FlowControlKeyEntry"},"title":"Key","type":"array","default":[]},"name":{"minLength":1,"title":"Name","type":"string"},"steps":{"description":"Array of sections describing steps of restricted flow","items":{"$ref":"#/components/schemas/FlowStepItem"},"title":"Steps","type":"array","default":[]},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"timeframe":{"description":"The time in which to limit the requests according to the threshold","title":"Time To Limit","type":"number"}},"required":["id","name","timeframe","key","steps","active"],"title":"FlowControl","type":"object"},"FlowControlKeyEntry":{"additionalProperties":false,"properties":{"args":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Arguments"},"attrs":{"anyOf":[{"$ref":"#/components/schemas/AttributesEnum"},{"type":"null"}],"default":null,"title":"Attributes"},"cookies":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Cookies"},"headers":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Headers"},"plugins":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Plugins"}},"title":"KeyEntry","type":"object"},"AttributesEnum":{"enum":["asnFlowSef","authority","company","country","ip","method","network","path","query","region","secpolentryid","securitypolicyentryid","securitypolicyentry","secpolid","securitypolicyid","securitypolicy","secpolname","securitypolicyname","secpolentryname","securitypolicyentryname","session","subregion","tags","uri"],"title":"AttributesEnum","type":"string"},"FlowStepItem":{"properties":{"args":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Args"},"cookies":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Cookies"},"headers":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Headers"},"method":{"$ref":"#/components/schemas/HTTPMethodEnum"},"plugins":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Plugins"},"uri":{"title":"Uri","type":"string"}},"required":["method","uri"],"title":"FlowStepItem","type":"object"},"HTTPMethodEnum":{"enum":["GET","HEAD","POST","PUT","DELETE","CONNECT","TRACE","OPTIONS","PATCH"],"title":"HTTPMethodEnum","type":"string"}}}}
```

## Modify Flow Control Policies

> Update an existing set of Flow Control Policies for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/flow-control-policies":{"put":{"operationId":"document_resource_put_api_v3_configs__config__d__document___put_18696332526555447","summary":"Modify Flow Control Policies","description":"Update an existing set of Flow Control Policies for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"Flow Control Policies document","type":"array","items":{"$ref":"#/components/schemas/FlowControl"}}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Flow Control Policies updated successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Flow Control Policies"]}}},"components":{"schemas":{"FlowControl":{"additionalProperties":false,"properties":{"active":{"description":"This flow is active","title":"Active flag","type":"boolean"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"exclude":{"default":[],"description":"Tags describing requests to exclude from the flow control rule","items":{"type":"string"},"title":"Excluded tags","type":"array"},"id":{"title":"Id","type":"string"},"include":{"default":[],"description":"Tags describing requests to include in the flow control rule","items":{"type":"string"},"title":"Included tags","type":"array"},"key":{"items":{"$ref":"#/components/schemas/FlowControlKeyEntry"},"title":"Key","type":"array","default":[]},"name":{"minLength":1,"title":"Name","type":"string"},"steps":{"description":"Array of sections describing steps of restricted flow","items":{"$ref":"#/components/schemas/FlowStepItem"},"title":"Steps","type":"array","default":[]},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"timeframe":{"description":"The time in which to limit the requests according to the threshold","title":"Time To Limit","type":"number"}},"required":["id","name","timeframe","key","steps","active"],"title":"FlowControl","type":"object"},"FlowControlKeyEntry":{"additionalProperties":false,"properties":{"args":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Arguments"},"attrs":{"anyOf":[{"$ref":"#/components/schemas/AttributesEnum"},{"type":"null"}],"default":null,"title":"Attributes"},"cookies":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Cookies"},"headers":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Headers"},"plugins":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Plugins"}},"title":"KeyEntry","type":"object"},"AttributesEnum":{"enum":["asnFlowSef","authority","company","country","ip","method","network","path","query","region","secpolentryid","securitypolicyentryid","securitypolicyentry","secpolid","securitypolicyid","securitypolicy","secpolname","securitypolicyname","secpolentryname","securitypolicyentryname","session","subregion","tags","uri"],"title":"AttributesEnum","type":"string"},"FlowStepItem":{"properties":{"args":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Args"},"cookies":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Cookies"},"headers":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Headers"},"method":{"$ref":"#/components/schemas/HTTPMethodEnum"},"plugins":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Plugins"},"uri":{"title":"Uri","type":"string"}},"required":["method","uri"],"title":"FlowStepItem","type":"object"},"HTTPMethodEnum":{"enum":["GET","HEAD","POST","PUT","DELETE","CONNECT","TRACE","OPTIONS","PATCH"],"title":"HTTPMethodEnum","type":"string"},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create Flow Control Policies

> Create a complete set of Flow Control Policies for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/flow-control-policies":{"post":{"operationId":"document_resource_post_api_v3_configs__config__d__document___post_18696332526555447","summary":"Create Flow Control Policies","description":"Create a complete set of Flow Control Policies for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"Flow Control Policies document","type":"array","items":{"$ref":"#/components/schemas/FlowControl"}}}}},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"Flow Control Policies created successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Flow Control Policies"]}}},"components":{"schemas":{"FlowControl":{"additionalProperties":false,"properties":{"active":{"description":"This flow is active","title":"Active flag","type":"boolean"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"exclude":{"default":[],"description":"Tags describing requests to exclude from the flow control rule","items":{"type":"string"},"title":"Excluded tags","type":"array"},"id":{"title":"Id","type":"string"},"include":{"default":[],"description":"Tags describing requests to include in the flow control rule","items":{"type":"string"},"title":"Included tags","type":"array"},"key":{"items":{"$ref":"#/components/schemas/FlowControlKeyEntry"},"title":"Key","type":"array","default":[]},"name":{"minLength":1,"title":"Name","type":"string"},"steps":{"description":"Array of sections describing steps of restricted flow","items":{"$ref":"#/components/schemas/FlowStepItem"},"title":"Steps","type":"array","default":[]},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"timeframe":{"description":"The time in which to limit the requests according to the threshold","title":"Time To Limit","type":"number"}},"required":["id","name","timeframe","key","steps","active"],"title":"FlowControl","type":"object"},"FlowControlKeyEntry":{"additionalProperties":false,"properties":{"args":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Arguments"},"attrs":{"anyOf":[{"$ref":"#/components/schemas/AttributesEnum"},{"type":"null"}],"default":null,"title":"Attributes"},"cookies":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Cookies"},"headers":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Headers"},"plugins":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Plugins"}},"title":"KeyEntry","type":"object"},"AttributesEnum":{"enum":["asnFlowSef","authority","company","country","ip","method","network","path","query","region","secpolentryid","securitypolicyentryid","securitypolicyentry","secpolid","securitypolicyid","securitypolicy","secpolname","securitypolicyname","secpolentryname","securitypolicyentryname","session","subregion","tags","uri"],"title":"AttributesEnum","type":"string"},"FlowStepItem":{"properties":{"args":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Args"},"cookies":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Cookies"},"headers":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Headers"},"method":{"$ref":"#/components/schemas/HTTPMethodEnum"},"plugins":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Plugins"},"uri":{"title":"Uri","type":"string"}},"required":["method","uri"],"title":"FlowStepItem","type":"object"},"HTTPMethodEnum":{"enum":["GET","HEAD","POST","PUT","DELETE","CONNECT","TRACE","OPTIONS","PATCH"],"title":"HTTPMethodEnum","type":"string"},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete Flow Control Policies

> Delete all Flow Control Policies in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/flow-control-policies":{"delete":{"description":"Delete all Flow Control Policies in a configuration","operationId":"document_resource_delete_api_v3_configs__config__d__document___delete_18696332526555447","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Flow Control Policies deleted successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"summary":"Delete Flow Control Policies","tags":["Flow Control Policies"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get specific Flow Control Policy

> Get a Flow Control Policy from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/flow-control-policies/{entry_id}":{"get":{"operationId":"entry_resource_get_api_v3_configs__config__d__document__e__entry___get_1161522589225571987","summary":"Get specific Flow Control Policy","description":"Get a Flow Control Policy from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"responses":{"200":{"description":"Flow Control Policy retrieved successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/FlowControl"}}}},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Flow Control Policies"]}}},"components":{"schemas":{"FlowControl":{"additionalProperties":false,"properties":{"active":{"description":"This flow is active","title":"Active flag","type":"boolean"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"exclude":{"default":[],"description":"Tags describing requests to exclude from the flow control rule","items":{"type":"string"},"title":"Excluded tags","type":"array"},"id":{"title":"Id","type":"string"},"include":{"default":[],"description":"Tags describing requests to include in the flow control rule","items":{"type":"string"},"title":"Included tags","type":"array"},"key":{"items":{"$ref":"#/components/schemas/FlowControlKeyEntry"},"title":"Key","type":"array","default":[]},"name":{"minLength":1,"title":"Name","type":"string"},"steps":{"description":"Array of sections describing steps of restricted flow","items":{"$ref":"#/components/schemas/FlowStepItem"},"title":"Steps","type":"array","default":[]},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"timeframe":{"description":"The time in which to limit the requests according to the threshold","title":"Time To Limit","type":"number"}},"required":["id","name","timeframe","key","steps","active"],"title":"FlowControl","type":"object"},"FlowControlKeyEntry":{"additionalProperties":false,"properties":{"args":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Arguments"},"attrs":{"anyOf":[{"$ref":"#/components/schemas/AttributesEnum"},{"type":"null"}],"default":null,"title":"Attributes"},"cookies":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Cookies"},"headers":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Headers"},"plugins":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Plugins"}},"title":"KeyEntry","type":"object"},"AttributesEnum":{"enum":["asnFlowSef","authority","company","country","ip","method","network","path","query","region","secpolentryid","securitypolicyentryid","securitypolicyentry","secpolid","securitypolicyid","securitypolicy","secpolname","securitypolicyname","secpolentryname","securitypolicyentryname","session","subregion","tags","uri"],"title":"AttributesEnum","type":"string"},"FlowStepItem":{"properties":{"args":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Args"},"cookies":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Cookies"},"headers":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Headers"},"method":{"$ref":"#/components/schemas/HTTPMethodEnum"},"plugins":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Plugins"},"uri":{"title":"Uri","type":"string"}},"required":["method","uri"],"title":"FlowStepItem","type":"object"},"HTTPMethodEnum":{"enum":["GET","HEAD","POST","PUT","DELETE","CONNECT","TRACE","OPTIONS","PATCH"],"title":"HTTPMethodEnum","type":"string"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Modify a single Flow Control Policy

> Update an individual Flow Control Policy within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/flow-control-policies/{entry_id}":{"put":{"operationId":"entry_resource_put_api_v3_configs__config__d__document__e__entry___put_1161522589225571987","summary":"Modify a single Flow Control Policy","description":"Update an individual Flow Control Policy within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/FlowControl"}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Flow Control Policy updated successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Flow Control Policies"]}}},"components":{"schemas":{"FlowControl":{"additionalProperties":false,"properties":{"active":{"description":"This flow is active","title":"Active flag","type":"boolean"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"exclude":{"default":[],"description":"Tags describing requests to exclude from the flow control rule","items":{"type":"string"},"title":"Excluded tags","type":"array"},"id":{"title":"Id","type":"string"},"include":{"default":[],"description":"Tags describing requests to include in the flow control rule","items":{"type":"string"},"title":"Included tags","type":"array"},"key":{"items":{"$ref":"#/components/schemas/FlowControlKeyEntry"},"title":"Key","type":"array","default":[]},"name":{"minLength":1,"title":"Name","type":"string"},"steps":{"description":"Array of sections describing steps of restricted flow","items":{"$ref":"#/components/schemas/FlowStepItem"},"title":"Steps","type":"array","default":[]},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"timeframe":{"description":"The time in which to limit the requests according to the threshold","title":"Time To Limit","type":"number"}},"required":["id","name","timeframe","key","steps","active"],"title":"FlowControl","type":"object"},"FlowControlKeyEntry":{"additionalProperties":false,"properties":{"args":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Arguments"},"attrs":{"anyOf":[{"$ref":"#/components/schemas/AttributesEnum"},{"type":"null"}],"default":null,"title":"Attributes"},"cookies":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Cookies"},"headers":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Headers"},"plugins":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Plugins"}},"title":"KeyEntry","type":"object"},"AttributesEnum":{"enum":["asnFlowSef","authority","company","country","ip","method","network","path","query","region","secpolentryid","securitypolicyentryid","securitypolicyentry","secpolid","securitypolicyid","securitypolicy","secpolname","securitypolicyname","secpolentryname","securitypolicyentryname","session","subregion","tags","uri"],"title":"AttributesEnum","type":"string"},"FlowStepItem":{"properties":{"args":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Args"},"cookies":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Cookies"},"headers":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Headers"},"method":{"$ref":"#/components/schemas/HTTPMethodEnum"},"plugins":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Plugins"},"uri":{"title":"Uri","type":"string"}},"required":["method","uri"],"title":"FlowStepItem","type":"object"},"HTTPMethodEnum":{"enum":["GET","HEAD","POST","PUT","DELETE","CONNECT","TRACE","OPTIONS","PATCH"],"title":"HTTPMethodEnum","type":"string"},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create single Flow Control Policy

> Create an individual Flow Control Policy within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/flow-control-policies/{entry_id}":{"post":{"operationId":"entries_resource_post_api_v3_configs__config__d__document__e__post_2091894710826690054","summary":"Create single Flow Control Policy","description":"Create an individual Flow Control Policy within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/FlowControl"}}}},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"Flow Control Policy created successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Flow Control Policies"]}}},"components":{"schemas":{"FlowControl":{"additionalProperties":false,"properties":{"active":{"description":"This flow is active","title":"Active flag","type":"boolean"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"exclude":{"default":[],"description":"Tags describing requests to exclude from the flow control rule","items":{"type":"string"},"title":"Excluded tags","type":"array"},"id":{"title":"Id","type":"string"},"include":{"default":[],"description":"Tags describing requests to include in the flow control rule","items":{"type":"string"},"title":"Included tags","type":"array"},"key":{"items":{"$ref":"#/components/schemas/FlowControlKeyEntry"},"title":"Key","type":"array","default":[]},"name":{"minLength":1,"title":"Name","type":"string"},"steps":{"description":"Array of sections describing steps of restricted flow","items":{"$ref":"#/components/schemas/FlowStepItem"},"title":"Steps","type":"array","default":[]},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"timeframe":{"description":"The time in which to limit the requests according to the threshold","title":"Time To Limit","type":"number"}},"required":["id","name","timeframe","key","steps","active"],"title":"FlowControl","type":"object"},"FlowControlKeyEntry":{"additionalProperties":false,"properties":{"args":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Arguments"},"attrs":{"anyOf":[{"$ref":"#/components/schemas/AttributesEnum"},{"type":"null"}],"default":null,"title":"Attributes"},"cookies":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Cookies"},"headers":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Headers"},"plugins":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Plugins"}},"title":"KeyEntry","type":"object"},"AttributesEnum":{"enum":["asnFlowSef","authority","company","country","ip","method","network","path","query","region","secpolentryid","securitypolicyentryid","securitypolicyentry","secpolid","securitypolicyid","securitypolicy","secpolname","securitypolicyname","secpolentryname","securitypolicyentryname","session","subregion","tags","uri"],"title":"AttributesEnum","type":"string"},"FlowStepItem":{"properties":{"args":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Args"},"cookies":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Cookies"},"headers":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Headers"},"method":{"$ref":"#/components/schemas/HTTPMethodEnum"},"plugins":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Plugins"},"uri":{"title":"Uri","type":"string"}},"required":["method","uri"],"title":"FlowStepItem","type":"object"},"HTTPMethodEnum":{"enum":["GET","HEAD","POST","PUT","DELETE","CONNECT","TRACE","OPTIONS","PATCH"],"title":"HTTPMethodEnum","type":"string"},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete single Flow Control Policy

> Delete an individual Flow Control Policy from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/flow-control-policies/{entry_id}":{"delete":{"operationId":"entry_resource_delete_api_v3_configs__config__d__document__e__entry___delete_1161522589225571987","summary":"Delete single Flow Control Policy","description":"Delete an individual Flow Control Policy from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Flow Control Policy deleted successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Flow Control Policies"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get Flow Control Policies version list

> Get list of versions of Flow Control Policies in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/flow-control-policies/versions":{"get":{"operationId":"document_list_version_resource_get_api_v3_configs__config__d__document__v__get_243192244709770866","summary":"Get Flow Control Policies version list","description":"Get list of versions of Flow Control Policies in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Versions list","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/VersionEntry"}}}}}},"description":"Flow Control Policies version list retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Flow Control Policies"]}}},"components":{"schemas":{"VersionEntry":{"title":"VersionEntry","type":"object","properties":{"author":{"title":"Author","type":"string"},"email":{"title":"Email","format":"email","type":"string"},"message":{"title":"Message","type":"string"},"date":{"format":"date-time","title":"Date","type":"string"},"version":{"title":"Version","type":"string"},"parents":{"type":"array","items":{"type":"string"}}}},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get version of Flow Control Policy

> Get a specific version of a Flow Control Policy

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/flow-control-policies/versions/{version}":{"get":{"operationId":"document_version_resource_get_api_v3_configs__config__d__document__v__version___get_1332957339605358508","summary":"Get version of Flow Control Policy","description":"Get a specific version of a Flow Control Policy","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Flow Control Policies document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/FlowControl"}}}}}},"description":"Flow Control Policy retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Flow Control Policies"]}}},"components":{"schemas":{"FlowControl":{"additionalProperties":false,"properties":{"active":{"description":"This flow is active","title":"Active flag","type":"boolean"},"description":{"anyOf":[{"type":"string"},{"type":"null"}],"default":"","title":"Description"},"exclude":{"default":[],"description":"Tags describing requests to exclude from the flow control rule","items":{"type":"string"},"title":"Excluded tags","type":"array"},"id":{"title":"Id","type":"string"},"include":{"default":[],"description":"Tags describing requests to include in the flow control rule","items":{"type":"string"},"title":"Included tags","type":"array"},"key":{"items":{"$ref":"#/components/schemas/FlowControlKeyEntry"},"title":"Key","type":"array","default":[]},"name":{"minLength":1,"title":"Name","type":"string"},"steps":{"description":"Array of sections describing steps of restricted flow","items":{"$ref":"#/components/schemas/FlowStepItem"},"title":"Steps","type":"array","default":[]},"tags":{"default":[],"description":"List of tags to apply","items":{"type":"string"},"title":"Tags List","type":"array"},"timeframe":{"description":"The time in which to limit the requests according to the threshold","title":"Time To Limit","type":"number"}},"required":["id","name","timeframe","key","steps","active"],"title":"FlowControl","type":"object"},"FlowControlKeyEntry":{"additionalProperties":false,"properties":{"args":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Arguments"},"attrs":{"anyOf":[{"$ref":"#/components/schemas/AttributesEnum"},{"type":"null"}],"default":null,"title":"Attributes"},"cookies":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Cookies"},"headers":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Headers"},"plugins":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Plugins"}},"title":"KeyEntry","type":"object"},"AttributesEnum":{"enum":["asnFlowSef","authority","company","country","ip","method","network","path","query","region","secpolentryid","securitypolicyentryid","securitypolicyentry","secpolid","securitypolicyid","securitypolicy","secpolname","securitypolicyname","secpolentryname","securitypolicyentryname","session","subregion","tags","uri"],"title":"AttributesEnum","type":"string"},"FlowStepItem":{"properties":{"args":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Args"},"cookies":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Cookies"},"headers":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Headers"},"method":{"$ref":"#/components/schemas/HTTPMethodEnum"},"plugins":{"anyOf":[{"additionalProperties":{"type":"string"},"type":"object"},{"type":"null"}],"default":null,"title":"Plugins"},"uri":{"title":"Uri","type":"string"}},"required":["method","uri"],"title":"FlowStepItem","type":"object"},"HTTPMethodEnum":{"enum":["GET","HEAD","POST","PUT","DELETE","CONNECT","TRACE","OPTIONS","PATCH"],"title":"HTTPMethodEnum","type":"string"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Revert a Flow Control Policy to the specified version

> Set a previous Flow Control Policy version to be the current one

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/flow-control-policies/versions/{version}/revert":{"put":{"operationId":"document_revert_resource_put_api_v3_configs__config__d__document__v__version__revert__put_284329767158655723","summary":"Revert a Flow Control Policy to the specified version","description":"Set a previous Flow Control Policy version to be the current one","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Flow Control Policy reversion was successful"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Flow Control Policies"]}}},"components":{"schemas":{"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```


# Global Filters

## Get Global Filters

> Get all Global Filters in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/global-filters":{"get":{"operationId":"document_resource_get_api_v3_configs__config__d__document___get_1676856049316246245","summary":"Get Global Filters","description":"Get all Global Filters in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"description":"Global Filters retrieved successfully","content":{"application/json":{"schema":{"title":"Global Filters document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/GlobalFilter"}}}}}}}},"tags":["Global Filters"]}}},"components":{"schemas":{"GlobalFilter":{"properties":{"action":{"title":"Action"},"active":{"title":"Active","type":"boolean"},"description":{"title":"Description","type":"string"},"id":{"title":"Id","type":"string"},"mdate":{"title":"Mdate","type":"string"},"name":{"title":"Name","type":"string"},"rule":{"anyOf":[{},{"items":{},"type":"array"}],"title":"Rule","default":{}},"source":{"title":"Source","type":"string"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"}},"required":["id","name","source","mdate","active"],"title":"GlobalFilter","type":"object"}}}}
```

## Modify Global Filters

> Update an existing set of Global Filters for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/global-filters":{"put":{"operationId":"document_resource_put_api_v3_configs__config__d__document___put_1676856049316246245","summary":"Modify Global Filters","description":"Update an existing set of Global Filters for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"Global Filters document","type":"array","items":{"$ref":"#/components/schemas/GlobalFilter"}}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Global Filters updated successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Global Filters"]}}},"components":{"schemas":{"GlobalFilter":{"properties":{"action":{"title":"Action"},"active":{"title":"Active","type":"boolean"},"description":{"title":"Description","type":"string"},"id":{"title":"Id","type":"string"},"mdate":{"title":"Mdate","type":"string"},"name":{"title":"Name","type":"string"},"rule":{"anyOf":[{},{"items":{},"type":"array"}],"title":"Rule","default":{}},"source":{"title":"Source","type":"string"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"}},"required":["id","name","source","mdate","active"],"title":"GlobalFilter","type":"object"},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create Global Filters

> Create a complete set of Global Filters for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/global-filters":{"post":{"operationId":"document_resource_post_api_v3_configs__config__d__document___post_1676856049316246245","summary":"Create Global Filters","description":"Create a complete set of Global Filters for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"Global Filters document","type":"array","items":{"$ref":"#/components/schemas/GlobalFilter"}}}}},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"Global Filters created successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Global Filters"]}}},"components":{"schemas":{"GlobalFilter":{"properties":{"action":{"title":"Action"},"active":{"title":"Active","type":"boolean"},"description":{"title":"Description","type":"string"},"id":{"title":"Id","type":"string"},"mdate":{"title":"Mdate","type":"string"},"name":{"title":"Name","type":"string"},"rule":{"anyOf":[{},{"items":{},"type":"array"}],"title":"Rule","default":{}},"source":{"title":"Source","type":"string"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"}},"required":["id","name","source","mdate","active"],"title":"GlobalFilter","type":"object"},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete Global Filters

> Delete all Global Filters in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/global-filters":{"delete":{"operationId":"document_resource_delete_api_v3_configs__config__d__document___delete_1676856049316246245","summary":"Delete Global Filters","description":"Delete all Global Filters in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Global Filters deleted successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Global Filters"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get specific Global Filter

> Get a Global Filter from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/global-filters/{entry_id}":{"get":{"operationId":"entry_resource_get_api_v3_configs__config__d__document__e__entry___get_1003463473229020795","summary":"Get specific Global Filter","description":"Get a Global Filter from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"responses":{"200":{"description":"Global Filter retrieved successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/GlobalFilter"}}}},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Global Filters"]}}},"components":{"schemas":{"GlobalFilter":{"properties":{"action":{"title":"Action"},"active":{"title":"Active","type":"boolean"},"description":{"title":"Description","type":"string"},"id":{"title":"Id","type":"string"},"mdate":{"title":"Mdate","type":"string"},"name":{"title":"Name","type":"string"},"rule":{"anyOf":[{},{"items":{},"type":"array"}],"title":"Rule","default":{}},"source":{"title":"Source","type":"string"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"}},"required":["id","name","source","mdate","active"],"title":"GlobalFilter","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Modify a single Global Filter

> Update an individual Global Filter within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/global-filters/{entry_id}":{"put":{"operationId":"entry_resource_put_api_v3_configs__config__d__document__e__entry___put_1003463473229020795","summary":"Modify a single Global Filter","description":"Update an individual Global Filter within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/GlobalFilter"}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Global Filter updated successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Global Filters"]}}},"components":{"schemas":{"GlobalFilter":{"properties":{"action":{"title":"Action"},"active":{"title":"Active","type":"boolean"},"description":{"title":"Description","type":"string"},"id":{"title":"Id","type":"string"},"mdate":{"title":"Mdate","type":"string"},"name":{"title":"Name","type":"string"},"rule":{"anyOf":[{},{"items":{},"type":"array"}],"title":"Rule","default":{}},"source":{"title":"Source","type":"string"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"}},"required":["id","name","source","mdate","active"],"title":"GlobalFilter","type":"object"},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create single Global Filter

> Create an individual Global Filter within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/global-filters/{entry_id}":{"post":{"operationId":"entries_resource_post_api_v3_configs__config__d__document__e__post_1166386460330720479","summary":"Create single Global Filter","description":"Create an individual Global Filter within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/GlobalFilter"}}}},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"Global Filter created successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Global Filters"]}}},"components":{"schemas":{"GlobalFilter":{"properties":{"action":{"title":"Action"},"active":{"title":"Active","type":"boolean"},"description":{"title":"Description","type":"string"},"id":{"title":"Id","type":"string"},"mdate":{"title":"Mdate","type":"string"},"name":{"title":"Name","type":"string"},"rule":{"anyOf":[{},{"items":{},"type":"array"}],"title":"Rule","default":{}},"source":{"title":"Source","type":"string"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"}},"required":["id","name","source","mdate","active"],"title":"GlobalFilter","type":"object"},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete single Global Filter

> Delete an individual Global Filter from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/global-filters/{entry_id}":{"delete":{"operationId":"entry_resource_delete_api_v3_configs__config__d__document__e__entry___delete_1003463473229020795","summary":"Delete single Global Filter","description":"Delete an individual Global Filter from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Global Filter deleted successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Global Filters"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get Global Filters version list

> Get list of versions of Global Filters in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/global-filters/versions":{"get":{"operationId":"document_list_version_resource_get_api_v3_configs__config__d__document__v__get_2041886931480876971","summary":"Get Global Filters version list","description":"Get list of versions of Global Filters in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Versions list","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/VersionEntry"}}}}}},"description":"Global Filters version list retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Global Filters"]}}},"components":{"schemas":{"VersionEntry":{"title":"VersionEntry","type":"object","properties":{"author":{"title":"Author","type":"string"},"email":{"title":"Email","format":"email","type":"string"},"message":{"title":"Message","type":"string"},"date":{"format":"date-time","title":"Date","type":"string"},"version":{"title":"Version","type":"string"},"parents":{"type":"array","items":{"type":"string"}}}},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get version of Global Filter

> Get a specific version of a Global Filter

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/global-filters/versions/{version}":{"get":{"description":"Get a specific version of a Global Filter","operationId":"document_version_resource_get_api_v3_configs__config__d__document__v__version___get_102326504528354101","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Global Filters document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/GlobalFilter"}}}}}},"description":"Global Filter retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"summary":"Get version of Global Filter","tags":["Global Filters"]}}},"components":{"schemas":{"GlobalFilter":{"properties":{"action":{"title":"Action"},"active":{"title":"Active","type":"boolean"},"description":{"title":"Description","type":"string"},"id":{"title":"Id","type":"string"},"mdate":{"title":"Mdate","type":"string"},"name":{"title":"Name","type":"string"},"rule":{"anyOf":[{},{"items":{},"type":"array"}],"title":"Rule","default":{}},"source":{"title":"Source","type":"string"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"}},"required":["id","name","source","mdate","active"],"title":"GlobalFilter","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Revert a Global Filter to the specified version

> Set a previous Global Filter version to be the current one

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/global-filters/versions/{version}/revert":{"put":{"operationId":"document_revert_resource_put_api_v3_configs__config__d__document__v__version__revert__put_824028035654525829","summary":"Revert a Global Filter to the specified version","description":"Set a previous Global Filter version to be the current one","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Global Filter reversion was successful"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Global Filters"]}}},"components":{"schemas":{"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```


# Load Balancers

## Prerequisites

The *{config}* API parameter is discussed [here](/using-the-product/the-link11-waap-api/internal-data-structures#the-fundamental-data-structure-configuration).

Load balancer administration is discussed [here](/console-walkthrough/sites/ssl/load-balancers). The discussion below assumes familiarity with it.

## Special considerations when using the API

### Multi-regional configuration

As explained [here](/console-walkthrough/sites/ssl/load-balancers#configuring-traffic-routing), when a Link11 load balancer supports a multi-regional planet, admins can (if desired) configure traffic routing.

The API provides additional granularity beyond the configuration available in the web console:&#x20;

* In the UI, the load balancer is treated as a single instance. However, this "one" load balancer is conceptual: it represents multiple physical instances, running simultaneously in different cities. The API provides the ability to configure each city separately, if desired.
* In the UI, the *Preferred datacenter* control displays a list of datacenters where Link11 WAAP has been deployed. In the API, this list is provided in the `upstream_regions` parameter, which is returned when calling *GET /api/v4.3/conf/{config}/load-balancers/regions.*
* In the UI, one *Preferred datacenter* can be selected, which will be applied to all cities. In the API, different datacenters can be specified for different cities, by calling *POST /api/v4.3/conf/{config}/load-balancers/regions.*

{% hint style="info" %}
When calling *POST /api/v4.3/conf/{config}/load-balancers/regions*, all desired preferences should be specified. All unspecified regions will be set to the default preference of `automatic` .

If an incorrect preferred datacenter (one where L11WAAP is not running) is specified, this action will be rejected, and the previous selection will remain in effect.
{% endhint %}

## API overview

<table><thead><tr><th width="346.4755859375">Action</th><th>Operation</th></tr></thead><tbody><tr><td>To retrieve information about all load balancers</td><td>GET .../load-balancers</td></tr><tr><td>To add a certificate</td><td>PUT .../{entry_name}/certificates/{certificate_id}</td></tr><tr><td>To remove a certificate</td><td>DELETE .../{entry_name}/certificates</td></tr><tr><td>To get the list of Link11 WAAP datacenters, and each city's current preference</td><td>GET .../regions</td></tr><tr><td>To set preferred datacenters for each city</td><td>POST .../regions</td></tr></tbody></table>

## Operations

## Get Load Balancers

> Get all Load Balancers in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/load-balancers":{"get":{"operationId":"get_load_balancers_api_v3_reblaze_config_load_balancers__get_191271472328453064","summary":"Get Load Balancers","description":"Get all Load Balancers in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Response Get Load Balancers Api v4.3 Reblaze Load Balancers","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/LoadBalancer"}}}}}},"description":"Load Balancers retrieved successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Load Balancers"]}}},"components":{"schemas":{"LoadBalancer":{"properties":{"certificates":{"items":{"type":"string"},"title":"Certificates","type":"array"},"default_certificate":{"title":"Default Certificate","type":"string"},"dns_name":{"title":"Dns Name","type":"string"},"listener_name":{"title":"Listener Name","type":"string"},"listener_port":{"description":"Port in AWS or IP in GCP","title":"Listener Port","type":"integer"},"load_balancer_type":{"enum":["classic","application"],"title":"Load Balancer Type","type":"string"},"max_certificates":{"title":"Max Certificates","type":"integer"},"name":{"title":"Name","type":"string"},"provider":{"$ref":"#/components/schemas/CloudProviderEnum"},"region":{"title":"Region","type":"string"}},"required":["provider","name","listener_name","listener_port","dns_name","region","load_balancer_type","max_certificates","default_certificate","certificates"],"title":"LoadBalancer","type":"object"},"CloudProviderEnum":{"description":"An enumeration.","enum":["aws","gcp","link11"],"title":"CloudProviderEnum","type":"string"},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Add Certificate

> Add a certificate to a Load Balancer

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/load-balancers/{entry_name}/certificates/{certificate_id}":{"put":{"operationId":"add_certificate_to_load_balancer_api_v3_reblaze_config__config__load_balancers__load_balancer_name__certificates__certificate_id___put_162012920830018407","summary":"Add Certificate","description":"Add a certificate to a Load Balancer","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_name","required":true,"schema":{"title":"Load Balancer Name","type":"string"}},{"in":"path","name":"certificate_id","required":true,"schema":{"title":"Certificate ID","type":"string"}},{"in":"query","name":"provider","required":true,"schema":{"$ref":"#/components/schemas/CloudProviderEnum"}},{"in":"query","name":"region","required":true,"schema":{"title":"Region","type":"string"}},{"in":"query","name":"default","required":false,"schema":{"default":false,"title":"Default","type":"boolean"}},{"in":"query","name":"elbv2","required":false,"schema":{"default":true,"title":"ELB v2","type":"boolean"}},{"in":"query","name":"listener","required":true,"schema":{"title":"Listener","type":"string"}},{"in":"query","name":"listener-port","required":true,"schema":{"title":"Listener Port","type":"integer"}}],"responses":{"200":{"description":"Successfully added certificate to Load Balancer"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Load Balancers"]}}},"components":{"schemas":{"CloudProviderEnum":{"description":"An enumeration.","enum":["aws","gcp","link11"],"title":"CloudProviderEnum","type":"string"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Detach certificate

> Detach a non-default certificate from the Load Balancer

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/load-balancers/{entry_name}/certificates":{"delete":{"operationId":"remove_certificate_from_load_balancer_api_v3_reblaze_config__config__load_balancers__load_balancer_name__certificates__delete_1218194429487707258","summary":"Detach certificate","description":"Detach a non-default certificate from the Load Balancer","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_name","required":true,"schema":{"title":"Load Balancer Name","type":"string"}},{"in":"query","name":"provider","required":true,"schema":{"title":"Provider","type":"string"}},{"in":"query","name":"region","required":true,"schema":{"title":"Region","type":"string"}},{"in":"query","name":"certificate-id","required":false,"schema":{"title":"Certificate ID","type":"string"}},{"in":"query","name":"elbv2","required":false,"schema":{"default":true,"title":"ELB v2","type":"boolean"}},{"in":"query","name":"listener","required":false,"schema":{"title":"Listener","type":"string"}},{"in":"query","name":"listener-port","required":false,"schema":{"title":"Listener Port","type":"string"}}],"responses":{"200":{"description":"Successfully detached certificate from Load Balancer"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Load Balancers"]}}},"components":{"schemas":{"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Get available datacenters per region and Load Balancer

> Get regions with available datacenters for each Load Balancer.

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/load-balancers/regions":{"get":{"operationId":"get_load_balancers_regions_api_v4_config_load_balancers__get","summary":"Get available datacenters per region and Load Balancer","description":"Get regions with available datacenters for each Load Balancer.","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Response Get Datacenters Regions Api v4.3 Reblaze Load Balancers","$ref":"#/components/schemas/LoadBalancerRegions"}}},"description":"Load Balancers retrieved successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Load Balancers"]}}},"components":{"schemas":{"LoadBalancerRegions":{"properties":{"city_codes":{"items":{"type":"string"},"title":"City Names","type":"object"},"lbs":{"title":"Load Balancers","type":"array","items":{"$ref":"#/components/schemas/LoadBalancerRegion"}}},"required":["provider","name"],"type":"object"},"LoadBalancerRegion":{"properties":{"id":{"type":"integer","title":"LoadBalancer ID"},"regions":{"type":"object","title":"Current LoadBalancer Settings","items":{"type":"string"}},"name":{"type":"string","title":"LoadBalancer Name"},"upstream_regions":{"type":"array","title":"Available Datacenter Regions","items":{"type":"string"}}}},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Set preferred datacenters for each Load Balancer

> Set preferred datacenters for each Load Balancer. "automatic" will choose the best route depending on the load balancer location.

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/load-balancers/regions":{"post":{"operationId":"set_load_balancers_regions_api_v4_config_load_balancers__set","summary":"Set preferred datacenters for each Load Balancer","description":"Set preferred datacenters for each Load Balancer. \"automatic\" will choose the best route depending on the load balancer location.","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"LoadBalancers by ID, with LoadBalancer Region to Datacenter Region","properties":{"lbs":{"title":"LoadBalancers by ID","type":"array","items":{"type":"object","title":"LoadBalancer Region to Datacenter Region"}}},"required":["lbs"]}}}},"responses":{"200":{"content":{"application/json":{"schema":{"title":"Set Preferred Datacenters for each Load Balancers v4.3 Reblaze Load Balancers","properties":{"message":{"type":"string","title":"Message"}}}}},"description":"Load Balancers retrieved successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Load Balancers"]}}},"components":{"schemas":{"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```


# Log Exporters

## Get Log Exporters

> Get all Log Exporters in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/log-exporters":{"get":{"operationId":"document_resource_get_api_v3_configs__config__d__document___get_920494197590142712","summary":"Get Log Exporters","description":"Get all Log Exporters in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"description":"Log Exporters retrieved successfully","content":{"application/json":{"schema":{"title":"Log Exporters document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/LogExporterOut"}}}}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"tags":["Log Exporters"]}}},"components":{"schemas":{"LogExporterOut":{"type":"object","properties":{"id":{"type":"string"},"name":{"type":"string","description":"Name field"},"active":{"type":"boolean","description":"This configuration will only take effect when the flag is set to true","title":"Configuration active","default":false},"filter":{"type":"string","enum":["all","blocked"]},"format":{"type":"string","enum":["custom_syslog"],"description":"Format of the log row that will be exported"},"server_groups":{"title":"Server Groups","description":"List of attached Server Group IDs or all","type":"object","properties":{"all":{"type":"boolean","description":"Log for all Server Groups existing now and in the future will be sent.","default":true},"ids":{"type":"array","description":"List of Server Group IDs in case 'all' is False","items":{"type":"string"}}}},"connection":{"type":"object","properties":{"host":{"anyOf":[{"type":"string","format":"uri"},{"type":"string","format":"ipv4"},{"type":"string","format":"ipv6"}]},"port":{"type":"integer"},"protocol":{"type":"string","description":"Protocol (e.g., TCP, UDP, etc.)"},"tls_mode":{"type":"string","default":"no_tls","enum":["no_tls","tls_no_verify","tls"]},"certificate":{"type":"object","properties":{"chain_data":{"type":"array","items":{"cn":"string","exp_date":"string"}},"cert_body":{"type":"string","description":"Certificate body"}},"required":["cert_body"]}},"required":["host","port","protocol"],"additionalProperties":false}},"required":["id","name","format","connection","server_groups"],"additionalProperties":false},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get single Log Exporter configuration

> Get an individual Log Exporter configuration from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/log-exporters/{entry_id}":{"get":{"operationId":"entry_resource_get_api_v3_configs__config__d__document__e__entry___get_188924675193220040","summary":"Get single Log Exporter configuration","description":"Get an individual Log Exporter configuration from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"responses":{"200":{"description":"Log Exporter configuration retrieved successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/LogExporterOut"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"tags":["Log Exporters"]}}},"components":{"schemas":{"LogExporterOut":{"type":"object","properties":{"id":{"type":"string"},"name":{"type":"string","description":"Name field"},"active":{"type":"boolean","description":"This configuration will only take effect when the flag is set to true","title":"Configuration active","default":false},"filter":{"type":"string","enum":["all","blocked"]},"format":{"type":"string","enum":["custom_syslog"],"description":"Format of the log row that will be exported"},"server_groups":{"title":"Server Groups","description":"List of attached Server Group IDs or all","type":"object","properties":{"all":{"type":"boolean","description":"Log for all Server Groups existing now and in the future will be sent.","default":true},"ids":{"type":"array","description":"List of Server Group IDs in case 'all' is False","items":{"type":"string"}}}},"connection":{"type":"object","properties":{"host":{"anyOf":[{"type":"string","format":"uri"},{"type":"string","format":"ipv4"},{"type":"string","format":"ipv6"}]},"port":{"type":"integer"},"protocol":{"type":"string","description":"Protocol (e.g., TCP, UDP, etc.)"},"tls_mode":{"type":"string","default":"no_tls","enum":["no_tls","tls_no_verify","tls"]},"certificate":{"type":"object","properties":{"chain_data":{"type":"array","items":{"cn":"string","exp_date":"string"}},"cert_body":{"type":"string","description":"Certificate body"}},"required":["cert_body"]}},"required":["host","port","protocol"],"additionalProperties":false}},"required":["id","name","format","connection","server_groups"],"additionalProperties":false},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Modify a single Log Exporter configuration

> Update an individual Log Exporter configuration within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/log-exporters/{entry_id}":{"put":{"operationId":"entry_resource_put_api_v3_configs__config__d__document__e__entry___put_188924675193220040","summary":"Modify a single Log Exporter configuration","description":"Update an individual Log Exporter configuration within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/LogExporter"}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Log Exporter configuration updated successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Log Exporters"]}}},"components":{"schemas":{"LogExporter":{"type":"object","properties":{"id":{"type":"string"},"name":{"type":"string","description":"Name field"},"active":{"type":"boolean","description":"This configuration will only take effect when the flag is set to true","title":"Configuration active","default":false},"filter":{"type":"string","enum":["all","blocked"]},"format":{"type":"string","enum":["custom_syslog"],"description":"Format of the log row that will be exported"},"include_request_data":{"type":"boolean","description":"Include base64 encoded request into exported data","default":false,"title":"Include Request Data"},"server_groups":{"title":"Server Groups","description":"List of attached Server Group IDs or all","type":"object","properties":{"all":{"type":"boolean","description":"Log for all Server Groups existing now and in the future will be sent.","default":true},"ids":{"type":"array","description":"List of Server Group IDs in case 'all' is False","items":{"type":"string"}}}},"connection":{"type":"object","properties":{"host":{"anyOf":[{"type":"string","format":"uri"},{"type":"string","format":"ipv4"},{"type":"string","format":"ipv6"}]},"port":{"type":"integer"},"protocol":{"type":"string","description":"Protocol (e.g., TCP, UDP, etc.)"},"tls_mode":{"type":"string","default":"no_tls","enum":["no_tls","tls_no_verify","tls"]},"certificate":{"type":"object","properties":{"cert_body":{"type":"string","description":"Certificate body"}},"required":["cert_body"]}},"required":["host","port","protocol"],"additionalProperties":false}},"required":["id","name","format","connection","server_groups"],"additionalProperties":false},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create single Log Exporter configuration

> Create an individual Log Exporter configuration within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/log-exporters/{entry_id}":{"post":{"description":"Create an individual Log Exporter configuration within a configuration","operationId":"entries_resource_post_api_v3_configs__config__d__document__e__post_1233211825730707681","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/LogExporter"}}}},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"Log Exporter configuration created successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"summary":"Create single Log Exporter configuration","tags":["Log Exporters"]}}},"components":{"schemas":{"LogExporter":{"type":"object","properties":{"id":{"type":"string"},"name":{"type":"string","description":"Name field"},"active":{"type":"boolean","description":"This configuration will only take effect when the flag is set to true","title":"Configuration active","default":false},"filter":{"type":"string","enum":["all","blocked"]},"format":{"type":"string","enum":["custom_syslog"],"description":"Format of the log row that will be exported"},"include_request_data":{"type":"boolean","description":"Include base64 encoded request into exported data","default":false,"title":"Include Request Data"},"server_groups":{"title":"Server Groups","description":"List of attached Server Group IDs or all","type":"object","properties":{"all":{"type":"boolean","description":"Log for all Server Groups existing now and in the future will be sent.","default":true},"ids":{"type":"array","description":"List of Server Group IDs in case 'all' is False","items":{"type":"string"}}}},"connection":{"type":"object","properties":{"host":{"anyOf":[{"type":"string","format":"uri"},{"type":"string","format":"ipv4"},{"type":"string","format":"ipv6"}]},"port":{"type":"integer"},"protocol":{"type":"string","description":"Protocol (e.g., TCP, UDP, etc.)"},"tls_mode":{"type":"string","default":"no_tls","enum":["no_tls","tls_no_verify","tls"]},"certificate":{"type":"object","properties":{"cert_body":{"type":"string","description":"Certificate body"}},"required":["cert_body"]}},"required":["host","port","protocol"],"additionalProperties":false}},"required":["id","name","format","connection","server_groups"],"additionalProperties":false},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete single Log Exporter configuration

> Delete an individual Log Exporter configuration from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/log-exporters/{entry_id}":{"delete":{"operationId":"entry_resource_delete_api_v3_configs__config__d__document__e__entry___delete_188924675193220040","summary":"Delete single Log Exporter configuration","description":"Delete an individual Log Exporter configuration from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Log Exporter configuration deleted successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Log Exporters"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get Log Exporters version list

> Get list of versions of Log Exporters in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/log-exporters/versions":{"get":{"operationId":"document_list_version_resource_get_api_v3_configs__config__d__document__v__get_2192084746238710671","summary":"Get Log Exporters version list","description":"Get list of versions of Log Exporters in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Versions list","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/VersionEntry"}}}}}},"description":"Log Exporters version list retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Log Exporters"]}}},"components":{"schemas":{"VersionEntry":{"title":"VersionEntry","type":"object","properties":{"author":{"title":"Author","type":"string"},"email":{"title":"Email","format":"email","type":"string"},"message":{"title":"Message","type":"string"},"date":{"format":"date-time","title":"Date","type":"string"},"version":{"title":"Version","type":"string"},"parents":{"type":"array","items":{"type":"string"}}}},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get version of Log Exporters

> Get a specific version of an Log Exporter configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/log-exporters/versions/{version}":{"get":{"operationId":"document_version_resource_get_api_v3_configs__config__d__document__v__version___get_2213417477955538928","summary":"Get version of Log Exporters","description":"Get a specific version of an Log Exporter configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Log Exporters document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/LogExporterOut"}}}}}},"description":"Log Exporter configuration version retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Log Exporters"]}}},"components":{"schemas":{"LogExporterOut":{"type":"object","properties":{"id":{"type":"string"},"name":{"type":"string","description":"Name field"},"active":{"type":"boolean","description":"This configuration will only take effect when the flag is set to true","title":"Configuration active","default":false},"filter":{"type":"string","enum":["all","blocked"]},"format":{"type":"string","enum":["custom_syslog"],"description":"Format of the log row that will be exported"},"server_groups":{"title":"Server Groups","description":"List of attached Server Group IDs or all","type":"object","properties":{"all":{"type":"boolean","description":"Log for all Server Groups existing now and in the future will be sent.","default":true},"ids":{"type":"array","description":"List of Server Group IDs in case 'all' is False","items":{"type":"string"}}}},"connection":{"type":"object","properties":{"host":{"anyOf":[{"type":"string","format":"uri"},{"type":"string","format":"ipv4"},{"type":"string","format":"ipv6"}]},"port":{"type":"integer"},"protocol":{"type":"string","description":"Protocol (e.g., TCP, UDP, etc.)"},"tls_mode":{"type":"string","default":"no_tls","enum":["no_tls","tls_no_verify","tls"]},"certificate":{"type":"object","properties":{"chain_data":{"type":"array","items":{"cn":"string","exp_date":"string"}},"cert_body":{"type":"string","description":"Certificate body"}},"required":["cert_body"]}},"required":["host","port","protocol"],"additionalProperties":false}},"required":["id","name","format","connection","server_groups"],"additionalProperties":false},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Revert Log Exporters to the specified version

> Set a previous Log Exporters version to be the current one

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/log-exporters/versions/{version}/revert":{"put":{"description":"Set a previous Log Exporters version to be the current one","operationId":"document_revert_resource_put_api_v3_configs__config__d__document__v__version__revert__put_2219093287643266132","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Log Exporters reversion was successful"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"summary":"Revert Log Exporters to the specified version","tags":["Log Exporters"]}}},"components":{"schemas":{"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```


# Mobile Application Groups

## Get Mobile Application Groups

> Get all Mobile Application Groups

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/mobile-application-groups":{"get":{"description":"Get all Mobile Application Groups","operationId":"get_api_v3_reblaze_configs__config__d_mobile_apps__get_2067933194781881224","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"description":"Mobile Application Groups retrieved successfully","content":{"application/json":{"schema":{"title":"Mobile Application Groups","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/MobileAppConfig"}}}}}}},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"summary":"Get Mobile Application Groups","tags":["Mobile Application Groups"]}}},"components":{"schemas":{"MobileAppConfig":{"properties":{"id":{"title":"Id","type":"string"},"name":{"title":"Name","type":"string"},"description":{"title":"Description","type":"string"},"uid_header":{"title":"Uid header","type":"string"},"grace":{"title":"Grace","type":"string"},"active_config":{"default":[],"items":{"$ref":"#/components/schemas/ActiveConfig"},"title":"ActiveConfig","type":"array"},"signatures":{"default":[],"items":{"$ref":"#/components/schemas/Signature"},"title":"Signature","type":"array"}}},"ActiveConfig":{"properties":{"active":{"title":"Active","type":"boolean"},"json_":{"title":"JSON","type":"string"},"name":{"title":"Name","type":"string"}}},"Signature":{"properties":{"active":{"title":"Active","type":"boolean"},"hash":{"title":"Hash","type":"string"},"name":{"title":"Name","type":"string"}},"required":["name","hash","active"],"title":"Signature","type":"object"},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Get Mobile Application Group

> Get a Mobile Application Group from the specified identifier

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/mobile-application-groups/{entry_id}":{"get":{"operationId":"get_one_api_v3_reblaze_configs__config__d_mobile_apps_e__id___get_579203461284956730","summary":"Get Mobile Application Group","description":"Get a Mobile Application Group from the specified identifier","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Id","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/MobileAppConfig"}}},"description":"Mobile Application Group retrieved successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Mobile Application Groups"]}}},"components":{"schemas":{"MobileAppConfig":{"properties":{"id":{"title":"Id","type":"string"},"name":{"title":"Name","type":"string"},"description":{"title":"Description","type":"string"},"uid_header":{"title":"Uid header","type":"string"},"grace":{"title":"Grace","type":"string"},"active_config":{"default":[],"items":{"$ref":"#/components/schemas/ActiveConfig"},"title":"ActiveConfig","type":"array"},"signatures":{"default":[],"items":{"$ref":"#/components/schemas/Signature"},"title":"Signature","type":"array"}}},"ActiveConfig":{"properties":{"active":{"title":"Active","type":"boolean"},"json_":{"title":"JSON","type":"string"},"name":{"title":"Name","type":"string"}}},"Signature":{"properties":{"active":{"title":"Active","type":"boolean"},"hash":{"title":"Hash","type":"string"},"name":{"title":"Name","type":"string"}},"required":["name","hash","active"],"title":"Signature","type":"object"},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Modify Mobile Application Group

> Update an individual Mobile Application Group within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/mobile-application-groups/{entry_id}":{"put":{"operationId":"update_api_v3_reblaze_configs__config__d_mobile_apps_e__id___put_579203461284956730","summary":"Modify Mobile Application Group","description":"Update an individual Mobile Application Group within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Id","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/MobileAppConfig"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Mobile Application Group updated successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Mobile Application Groups"]}}},"components":{"schemas":{"MobileAppConfig":{"properties":{"id":{"title":"Id","type":"string"},"name":{"title":"Name","type":"string"},"description":{"title":"Description","type":"string"},"uid_header":{"title":"Uid header","type":"string"},"grace":{"title":"Grace","type":"string"},"active_config":{"default":[],"items":{"$ref":"#/components/schemas/ActiveConfig"},"title":"ActiveConfig","type":"array"},"signatures":{"default":[],"items":{"$ref":"#/components/schemas/Signature"},"title":"Signature","type":"array"}}},"ActiveConfig":{"properties":{"active":{"title":"Active","type":"boolean"},"json_":{"title":"JSON","type":"string"},"name":{"title":"Name","type":"string"}}},"Signature":{"properties":{"active":{"title":"Active","type":"boolean"},"hash":{"title":"Hash","type":"string"},"name":{"title":"Name","type":"string"}},"required":["name","hash","active"],"title":"Signature","type":"object"},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Create Mobile Application Group

> Create an individual Mobile Application Group within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/mobile-application-groups/{entry_id}":{"post":{"operationId":"add_api_v3_reblaze_configs__config__d_mobile_apps_e__id___post_579203461284956730","summary":"Create Mobile Application Group","description":"Create an individual Mobile Application Group within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"pattern":"^[A-Za-z0-9\\-\\_]*$","title":"Id","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/MobileAppConfig"}}},"required":true},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"Mobile Application Group created successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Mobile Application Groups"]}}},"components":{"schemas":{"MobileAppConfig":{"properties":{"id":{"title":"Id","type":"string"},"name":{"title":"Name","type":"string"},"description":{"title":"Description","type":"string"},"uid_header":{"title":"Uid header","type":"string"},"grace":{"title":"Grace","type":"string"},"active_config":{"default":[],"items":{"$ref":"#/components/schemas/ActiveConfig"},"title":"ActiveConfig","type":"array"},"signatures":{"default":[],"items":{"$ref":"#/components/schemas/Signature"},"title":"Signature","type":"array"}}},"ActiveConfig":{"properties":{"active":{"title":"Active","type":"boolean"},"json_":{"title":"JSON","type":"string"},"name":{"title":"Name","type":"string"}}},"Signature":{"properties":{"active":{"title":"Active","type":"boolean"},"hash":{"title":"Hash","type":"string"},"name":{"title":"Name","type":"string"}},"required":["name","hash","active"],"title":"Signature","type":"object"},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Delete Mobile Application Group

> Delete an individual Mobile Applicaions Group from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/mobile-application-groups/{entry_id}":{"delete":{"operationId":"delete_api_v3_reblaze_configs__config__d_mobile_apps_e__id___delete_579203461284956730","summary":"Delete Mobile Application Group","description":"Delete an individual Mobile Applicaions Group from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Id","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Mobile Application Group deleted successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Bad Request"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Mobile Application Groups"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```


# Planets

## Get Planet

> Get planet-wide settings and values

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/planets":{"get":{"operationId":"get_one_api_v3_reblaze_configs__config__d_planet__get_1120641698848173491","summary":"Get Planet","description":"Get planet-wide settings and values","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Planet"}}},"description":"Planet info successfully retrieved"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Planets"]}}},"components":{"schemas":{"Planet":{"properties":{"ichallenge":{"$ref":"#/components/schemas/IChallenge"},"name":{"title":"Name","type":"string"},"trusted_nets":{"items":{"$ref":"#/components/schemas/TrustedNet"},"title":"Trusted Nets","type":"array"}},"required":["name","trusted_nets","ichallenge"],"title":"Planet","type":"object"},"IChallenge":{"properties":{"attrs":{"title":"Attrs","type":"object"},"lang":{"title":"Lang","type":"object"},"palette":{"items":{"type":"string"},"title":"Palette","type":"array"},"position":{"title":"Position","type":"object"}},"required":["attrs","palette","position","lang"],"title":"IChallenge","type":"object"},"TrustedNet":{"properties":{"address":{"title":"Address","type":"string"},"comment":{"title":"Comment","type":"string"}},"required":["address","comment"],"title":"TrustedNet","type":"object"},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Modify Planet

> Modify settings of a planet

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/planets/{entry_id}":{"put":{"operationId":"update_api_v3_reblaze_configs__config__d_planet__put_1918893960546327346","summary":"Modify Planet","description":"Modify settings of a planet","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","description":"Planet ID","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Planet"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Planet updated successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Planets"]}}},"components":{"schemas":{"Planet":{"properties":{"ichallenge":{"$ref":"#/components/schemas/IChallenge"},"name":{"title":"Name","type":"string"},"trusted_nets":{"items":{"$ref":"#/components/schemas/TrustedNet"},"title":"Trusted Nets","type":"array"}},"required":["name","trusted_nets","ichallenge"],"title":"Planet","type":"object"},"IChallenge":{"properties":{"attrs":{"title":"Attrs","type":"object"},"lang":{"title":"Lang","type":"object"},"palette":{"items":{"type":"string"},"title":"Palette","type":"array"},"position":{"title":"Position","type":"object"}},"required":["attrs","palette","position","lang"],"title":"IChallenge","type":"object"},"TrustedNet":{"properties":{"address":{"title":"Address","type":"string"},"comment":{"title":"Comment","type":"string"}},"required":["address","comment"],"title":"TrustedNet","type":"object"},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```


# Proxy Templates

## Get Proxy Templates

> Get all Proxy Templates in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/proxy-templates":{"get":{"description":"Get all Proxy Templates in a configuration","operationId":"get_api_v3_reblaze_configs__config__d_proxy_templates__get_2067933194781881224","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"description":"Proxy Templates retrieved successfully","content":{"application/json":{"schema":{"title":"Proxy Templates document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/ProxyTemplate"}}}}}}},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"summary":"Get Proxy Templates","tags":["Proxy Templates"]}}},"components":{"schemas":{"ProxyTemplate":{"properties":{"acao_header":{"title":"Acao Header","type":"boolean"},"client_body_buffer_size":{"title":"Client Body Buffer Size","type":"string"},"client_body_timeout":{"title":"Client Body Timeout","type":"string"},"client_header_buffer_size":{"title":"Client Header Buffer Size","type":"string"},"client_header_timeout":{"title":"Client Header Timeout","type":"string"},"client_max_body_size":{"title":"Client Max Body Size","type":"string"},"conf_specific":{"default":"","title":"Conf Specific","type":"string"},"custom_listener":{"title":"Custom Listener","type":"boolean"},"description":{"default":"","title":"Description","type":"string"},"keepalive_timeout":{"title":"Keepalive Timeout","type":"string"},"large_client_header_buffers_count":{"title":"Large Client Header Buffers Count","type":"string"},"large_client_header_buffers_size":{"title":"Large Client Header Buffers Size","type":"string"},"limit_req_burst":{"title":"Limit Req Burst","type":"string"},"limit_req_rate":{"title":"Limit Req Rate","type":"string"},"mask_headers":{"title":"Mask Headers","type":"string"},"name":{"title":"Name","type":"string"},"proxy_connect_timeout":{"title":"Proxy Connect Timeout","type":"string"},"proxy_read_timeout":{"title":"Proxy Read Timeout","type":"string"},"proxy_send_timeout":{"title":"Proxy Send Timeout","type":"string"},"send_timeout":{"title":"Send Timeout","type":"string"},"ssl_ciphers":{"title":"Ssl Ciphers","type":"string"},"ssl_conf_specific":{"default":"","title":"Ssl Conf Specific","type":"string"},"ssl_protocols":{"items":{"$ref":"#/components/schemas/SslProtocols"},"title":"Ssl Protocols","type":"array"},"upstream_host":{"title":"Upstream Host","type":"string"},"xff_header_name":{"title":"Xff Header Name","type":"array","items":{"type":"string"}},"xrealip_header_name":{"title":"Xrealip Header Name","type":"string"},"advanced_configuration":{"title":"Advanced nginx configuration","type":"array","items":{"$ref":"#/components/schemas/ProxyTemplateAdvancedConfig"},"default":[]}},"required":["name","acao_header","xff_header_name","proxy_connect_timeout","proxy_read_timeout","proxy_send_timeout","upstream_host","client_body_timeout","client_body_buffer_size","client_header_timeout","keepalive_timeout","send_timeout","client_max_body_size","limit_req_rate","limit_req_burst","mask_headers","xrealip_header_name","custom_listener","client_header_buffer_size","large_client_header_buffers_count","large_client_header_buffers_size"],"title":"ProxyTemplate","type":"object"},"SslProtocols":{"title":"SslProtocols","type":"string","enum":["SSLv2","SSLv3","TLSv1","TLSv1.1","TLSv1.2","TLSv1.3"]},"ProxyTemplateAdvancedConfig":{"title":"ProxyTemplateAdvancedConfig","type":"object","properties":{"configuration":{"description":"Custom nginx configuration lines","minLength":1,"title":"Configuration","type":"string"},"description":{"title":"Description","anyOf":[{"type":"string"},{"type":"null"}],"default":""},"name":{"title":"Name","minLength":1,"type":"string"},"protocol":{"title":"Protocols","description":"Protocols for which config should be applied","type":"array","minItems":1,"items":{"$ref":"#/components/schemas/HttpProtocols"}}},"required":["name","protocol","configuration"]},"HttpProtocols":{"title":"HttpProtocols","type":"string","enum":["http","https"]},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Get Proxy Template

> Get a Proxy Template from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/proxy-templates/{entry_id}":{"get":{"operationId":"get_one_api_v3_reblaze_configs__config__d_proxy_templates_e__id___get_502278317936005532","summary":"Get Proxy Template","description":"Get a Proxy Template from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Id","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProxyTemplate"}}},"description":"Proxy Template retrieved successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Proxy Templates"]}}},"components":{"schemas":{"ProxyTemplate":{"properties":{"acao_header":{"title":"Acao Header","type":"boolean"},"client_body_buffer_size":{"title":"Client Body Buffer Size","type":"string"},"client_body_timeout":{"title":"Client Body Timeout","type":"string"},"client_header_buffer_size":{"title":"Client Header Buffer Size","type":"string"},"client_header_timeout":{"title":"Client Header Timeout","type":"string"},"client_max_body_size":{"title":"Client Max Body Size","type":"string"},"conf_specific":{"default":"","title":"Conf Specific","type":"string"},"custom_listener":{"title":"Custom Listener","type":"boolean"},"description":{"default":"","title":"Description","type":"string"},"keepalive_timeout":{"title":"Keepalive Timeout","type":"string"},"large_client_header_buffers_count":{"title":"Large Client Header Buffers Count","type":"string"},"large_client_header_buffers_size":{"title":"Large Client Header Buffers Size","type":"string"},"limit_req_burst":{"title":"Limit Req Burst","type":"string"},"limit_req_rate":{"title":"Limit Req Rate","type":"string"},"mask_headers":{"title":"Mask Headers","type":"string"},"name":{"title":"Name","type":"string"},"proxy_connect_timeout":{"title":"Proxy Connect Timeout","type":"string"},"proxy_read_timeout":{"title":"Proxy Read Timeout","type":"string"},"proxy_send_timeout":{"title":"Proxy Send Timeout","type":"string"},"send_timeout":{"title":"Send Timeout","type":"string"},"ssl_ciphers":{"title":"Ssl Ciphers","type":"string"},"ssl_conf_specific":{"default":"","title":"Ssl Conf Specific","type":"string"},"ssl_protocols":{"items":{"$ref":"#/components/schemas/SslProtocols"},"title":"Ssl Protocols","type":"array"},"upstream_host":{"title":"Upstream Host","type":"string"},"xff_header_name":{"title":"Xff Header Name","type":"array","items":{"type":"string"}},"xrealip_header_name":{"title":"Xrealip Header Name","type":"string"},"advanced_configuration":{"title":"Advanced nginx configuration","type":"array","items":{"$ref":"#/components/schemas/ProxyTemplateAdvancedConfig"},"default":[]}},"required":["name","acao_header","xff_header_name","proxy_connect_timeout","proxy_read_timeout","proxy_send_timeout","upstream_host","client_body_timeout","client_body_buffer_size","client_header_timeout","keepalive_timeout","send_timeout","client_max_body_size","limit_req_rate","limit_req_burst","mask_headers","xrealip_header_name","custom_listener","client_header_buffer_size","large_client_header_buffers_count","large_client_header_buffers_size"],"title":"ProxyTemplate","type":"object"},"SslProtocols":{"title":"SslProtocols","type":"string","enum":["SSLv2","SSLv3","TLSv1","TLSv1.1","TLSv1.2","TLSv1.3"]},"ProxyTemplateAdvancedConfig":{"title":"ProxyTemplateAdvancedConfig","type":"object","properties":{"configuration":{"description":"Custom nginx configuration lines","minLength":1,"title":"Configuration","type":"string"},"description":{"title":"Description","anyOf":[{"type":"string"},{"type":"null"}],"default":""},"name":{"title":"Name","minLength":1,"type":"string"},"protocol":{"title":"Protocols","description":"Protocols for which config should be applied","type":"array","minItems":1,"items":{"$ref":"#/components/schemas/HttpProtocols"}}},"required":["name","protocol","configuration"]},"HttpProtocols":{"title":"HttpProtocols","type":"string","enum":["http","https"]},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Modify Proxy Template

> Update an individual Proxy Template within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/proxy-templates/{entry_id}":{"put":{"operationId":"update_api_v3_reblaze_configs__config__d_proxy_templates_e__id___put_502278317936005532","summary":"Modify Proxy Template","description":"Update an individual Proxy Template within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Id","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProxyTemplate"}}},"required":true},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Proxy Template updated successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Proxy Templates"]}}},"components":{"schemas":{"ProxyTemplate":{"properties":{"acao_header":{"title":"Acao Header","type":"boolean"},"client_body_buffer_size":{"title":"Client Body Buffer Size","type":"string"},"client_body_timeout":{"title":"Client Body Timeout","type":"string"},"client_header_buffer_size":{"title":"Client Header Buffer Size","type":"string"},"client_header_timeout":{"title":"Client Header Timeout","type":"string"},"client_max_body_size":{"title":"Client Max Body Size","type":"string"},"conf_specific":{"default":"","title":"Conf Specific","type":"string"},"custom_listener":{"title":"Custom Listener","type":"boolean"},"description":{"default":"","title":"Description","type":"string"},"keepalive_timeout":{"title":"Keepalive Timeout","type":"string"},"large_client_header_buffers_count":{"title":"Large Client Header Buffers Count","type":"string"},"large_client_header_buffers_size":{"title":"Large Client Header Buffers Size","type":"string"},"limit_req_burst":{"title":"Limit Req Burst","type":"string"},"limit_req_rate":{"title":"Limit Req Rate","type":"string"},"mask_headers":{"title":"Mask Headers","type":"string"},"name":{"title":"Name","type":"string"},"proxy_connect_timeout":{"title":"Proxy Connect Timeout","type":"string"},"proxy_read_timeout":{"title":"Proxy Read Timeout","type":"string"},"proxy_send_timeout":{"title":"Proxy Send Timeout","type":"string"},"send_timeout":{"title":"Send Timeout","type":"string"},"ssl_ciphers":{"title":"Ssl Ciphers","type":"string"},"ssl_conf_specific":{"default":"","title":"Ssl Conf Specific","type":"string"},"ssl_protocols":{"items":{"$ref":"#/components/schemas/SslProtocols"},"title":"Ssl Protocols","type":"array"},"upstream_host":{"title":"Upstream Host","type":"string"},"xff_header_name":{"title":"Xff Header Name","type":"array","items":{"type":"string"}},"xrealip_header_name":{"title":"Xrealip Header Name","type":"string"},"advanced_configuration":{"title":"Advanced nginx configuration","type":"array","items":{"$ref":"#/components/schemas/ProxyTemplateAdvancedConfig"},"default":[]}},"required":["name","acao_header","xff_header_name","proxy_connect_timeout","proxy_read_timeout","proxy_send_timeout","upstream_host","client_body_timeout","client_body_buffer_size","client_header_timeout","keepalive_timeout","send_timeout","client_max_body_size","limit_req_rate","limit_req_burst","mask_headers","xrealip_header_name","custom_listener","client_header_buffer_size","large_client_header_buffers_count","large_client_header_buffers_size"],"title":"ProxyTemplate","type":"object"},"SslProtocols":{"title":"SslProtocols","type":"string","enum":["SSLv2","SSLv3","TLSv1","TLSv1.1","TLSv1.2","TLSv1.3"]},"ProxyTemplateAdvancedConfig":{"title":"ProxyTemplateAdvancedConfig","type":"object","properties":{"configuration":{"description":"Custom nginx configuration lines","minLength":1,"title":"Configuration","type":"string"},"description":{"title":"Description","anyOf":[{"type":"string"},{"type":"null"}],"default":""},"name":{"title":"Name","minLength":1,"type":"string"},"protocol":{"title":"Protocols","description":"Protocols for which config should be applied","type":"array","minItems":1,"items":{"$ref":"#/components/schemas/HttpProtocols"}}},"required":["name","protocol","configuration"]},"HttpProtocols":{"title":"HttpProtocols","type":"string","enum":["http","https"]},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Create Proxy Template

> Create an individual Proxy Template within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/proxy-templates/{entry_id}":{"post":{"operationId":"add_api_v3_reblaze_configs__config__d_proxy_templates_e__id___post_502278317936005532","summary":"Create Proxy Template","description":"Create an individual Proxy Template within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"pattern":"^[A-Za-z0-9\\-\\_]*$","title":"Id","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProxyTemplate"}}},"required":true},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"Proxy Template created successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Proxy Templates"]}}},"components":{"schemas":{"ProxyTemplate":{"properties":{"acao_header":{"title":"Acao Header","type":"boolean"},"client_body_buffer_size":{"title":"Client Body Buffer Size","type":"string"},"client_body_timeout":{"title":"Client Body Timeout","type":"string"},"client_header_buffer_size":{"title":"Client Header Buffer Size","type":"string"},"client_header_timeout":{"title":"Client Header Timeout","type":"string"},"client_max_body_size":{"title":"Client Max Body Size","type":"string"},"conf_specific":{"default":"","title":"Conf Specific","type":"string"},"custom_listener":{"title":"Custom Listener","type":"boolean"},"description":{"default":"","title":"Description","type":"string"},"keepalive_timeout":{"title":"Keepalive Timeout","type":"string"},"large_client_header_buffers_count":{"title":"Large Client Header Buffers Count","type":"string"},"large_client_header_buffers_size":{"title":"Large Client Header Buffers Size","type":"string"},"limit_req_burst":{"title":"Limit Req Burst","type":"string"},"limit_req_rate":{"title":"Limit Req Rate","type":"string"},"mask_headers":{"title":"Mask Headers","type":"string"},"name":{"title":"Name","type":"string"},"proxy_connect_timeout":{"title":"Proxy Connect Timeout","type":"string"},"proxy_read_timeout":{"title":"Proxy Read Timeout","type":"string"},"proxy_send_timeout":{"title":"Proxy Send Timeout","type":"string"},"send_timeout":{"title":"Send Timeout","type":"string"},"ssl_ciphers":{"title":"Ssl Ciphers","type":"string"},"ssl_conf_specific":{"default":"","title":"Ssl Conf Specific","type":"string"},"ssl_protocols":{"items":{"$ref":"#/components/schemas/SslProtocols"},"title":"Ssl Protocols","type":"array"},"upstream_host":{"title":"Upstream Host","type":"string"},"xff_header_name":{"title":"Xff Header Name","type":"array","items":{"type":"string"}},"xrealip_header_name":{"title":"Xrealip Header Name","type":"string"},"advanced_configuration":{"title":"Advanced nginx configuration","type":"array","items":{"$ref":"#/components/schemas/ProxyTemplateAdvancedConfig"},"default":[]}},"required":["name","acao_header","xff_header_name","proxy_connect_timeout","proxy_read_timeout","proxy_send_timeout","upstream_host","client_body_timeout","client_body_buffer_size","client_header_timeout","keepalive_timeout","send_timeout","client_max_body_size","limit_req_rate","limit_req_burst","mask_headers","xrealip_header_name","custom_listener","client_header_buffer_size","large_client_header_buffers_count","large_client_header_buffers_size"],"title":"ProxyTemplate","type":"object"},"SslProtocols":{"title":"SslProtocols","type":"string","enum":["SSLv2","SSLv3","TLSv1","TLSv1.1","TLSv1.2","TLSv1.3"]},"ProxyTemplateAdvancedConfig":{"title":"ProxyTemplateAdvancedConfig","type":"object","properties":{"configuration":{"description":"Custom nginx configuration lines","minLength":1,"title":"Configuration","type":"string"},"description":{"title":"Description","anyOf":[{"type":"string"},{"type":"null"}],"default":""},"name":{"title":"Name","minLength":1,"type":"string"},"protocol":{"title":"Protocols","description":"Protocols for which config should be applied","type":"array","minItems":1,"items":{"$ref":"#/components/schemas/HttpProtocols"}}},"required":["name","protocol","configuration"]},"HttpProtocols":{"title":"HttpProtocols","type":"string","enum":["http","https"]},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```

## Delete Proxy Template

> Delete an individual Proxy Template from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/proxy-templates/{entry_id}":{"delete":{"operationId":"delete_api_v3_reblaze_configs__config__d_proxy_templates_e__id___delete_502278317936005532","summary":"Delete Proxy Template","description":"Delete an individual Proxy Template from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Id","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Proxy Template deleted successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Bad Request"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/Error"}}},"description":"Internal Server Error"}},"tags":["Proxy Templates"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"},"Error":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"Error","type":"object"}}}}
```


# Purge CDN Cache

## Get CDN providers

> Get all enabled CDN providers for the planet

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/purge-cdn-cache/providers":{"get":{"operationId":"get_enabled_cdn_providers_api_v3_reblaze_configs_cdn_providers_enabled__get_191271472328453069","summary":"Get CDN providers","description":"Get all enabled CDN providers for the planet","responses":{"200":{"content":{"application/json":{"schema":{"title":"Response Get CDN providers Api v4.3","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/CdnProviderUnion"}}}}}},"description":"Enabled CDN providers retrieved successfully"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/DetailedResponse"}}},"description":"Internal Server Error"}},"tags":["Purge CDN Cache"]}}},"components":{"schemas":{"CdnProviderUnion":{"type":"object","title":"CDN Provider Union","description":"Union of CDN Providers with specific fields based on the provider type.","discriminator":{"propertyName":"provider"},"oneOf":[{"title":"AWS CDN Provider","description":"Schema for AWS CDN Provider","properties":{"name":{"type":"string","minLength":1,"description":"Name of the CDN provider"},"provider":{"type":"string","enum":["aws"]},"distribution_id":{"type":"string","minLength":1,"description":"AWS-specific distribution ID"}},"required":["name","provider","distribution_id"],"additionalProperties":false},{"title":"GCP CDN Provider","description":"Schema for GCP CDN Provider","properties":{"provider":{"type":"string","enum":["gcp"]}},"required":["provider"],"additionalProperties":false},{"title":"Link11 CDN Provider","description":"Schema for Link11 CDN Provider","properties":{"provider":{"type":"string","enum":["link11"]}},"required":["provider"],"additionalProperties":false}]},"DetailedResponse":{"properties":{"message":{"title":"Message","type":"string"},"detail":{"title":"Detail","type":"string"},"data":{"type":"object","properties":{"message":{"title":"Message","type":"string"}}}},"required":["message","detail","data"],"title":"DetailedResponse","type":"object"}}}}
```

## Purge CDN Cache

> Purge CDN cache for a given list of CDN targets. All items in the list must be of the same type \
> (i.e., all AWS targets, all GCP targets, or all Link11 targets).<br>

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/purge-cdn-cache/purge":{"post":{"operationId":"purge_cdn_cache_api_v3_reblaze_configs_cdn_providers_purge__post_162012920830015407","summary":"Purge CDN Cache","description":"Purge CDN cache for a given list of CDN targets. All items in the list must be of the same type \n(i.e., all AWS targets, all GCP targets, or all Link11 targets).\n","requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/CdnTargetUnion"}}}}},"responses":{"200":{"description":"CDN cache purged successfully"},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/InputError"}}},"description":"Input Error"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/DetailedResponse"}}},"description":"Internal Server Error"}},"tags":["Purge CDN Cache"]}}},"components":{"schemas":{"CdnTargetUnion":{"type":"object","title":"CDN Target Union","description":"Union of CDN Providers Targets for cache purging with specific fields based on the provider type.","oneOf":[{"title":"AWS CDN Target","description":"Schema for AWS CDN Target","properties":{"host":{"type":"string","minLength":1,"description":"Host for purging. Must be \"all\"."},"path":{"type":"string","minLength":1,"description":"Path for purging. Should be \"all\" to purge all paths."},"distribution_id":{"minLength":1,"type":"string","description":"AWS-specific distribution ID"}},"required":["host","path","distribution_id"],"additionalProperties":false},{"title":"GCP CDN Target","description":"Schema for GCP CDN Target","properties":{"host":{"type":"string","minLength":1,"description":"Host for purging. Should be \"all\" to purge all hosts."},"path":{"type":"string","minLength":1,"description":"Path for purging. Should be \"all\" to purge all paths."}},"required":["host","path"],"additionalProperties":false},{"title":"Link11 CDN Target","description":"Schema for Link11 CDN Target","properties":{"host":{"type":"string","minLength":1,"description":"Host for purging. Should be \"all\" to purge all hosts."},"path":{"type":"string","minLength":1,"description":"Path for purging. Should be \"all\" to purge all paths."}},"required":["host","path"],"additionalProperties":false}]},"InputError":{"properties":{"code":{"title":"Code","type":"integer"},"message":{"title":"Message","type":"string"}},"required":["code","message"],"title":"InputError","type":"object"},"DetailedResponse":{"properties":{"message":{"title":"Message","type":"string"},"detail":{"title":"Detail","type":"string"},"data":{"type":"object","properties":{"message":{"title":"Message","type":"string"}}}},"required":["message","detail","data"],"title":"DetailedResponse","type":"object"}}}}
```

## Get CDN cache purge statuses

> Get all CDN cache purge statuses from the past week

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/purge-cdn-cache/purges":{"get":{"operationId":"get_purge_statuses_api_v3_reblaze_configs_cdn_purges__get_191271472328453089","summary":"Get CDN cache purge statuses","description":"Get all CDN cache purge statuses from the past week","responses":{"200":{"description":"CDN purge statuses retrieved successfully","content":{"application/json":{"schema":{"title":"Response Get CDN Purge Statuses Api v4.3","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"type":"object","properties":{"provider":{"type":"string","description":"CDN provider type","enum":["aws","gcp","link11"]},"target":{"oneOf":[{"$ref":"#/components/schemas/AwsCdnTarget"},{"$ref":"#/components/schemas/GcpCdnTarget"},{"$ref":"#/components/schemas/Link11CdnTarget"}],"description":"Target details for the specific CDN provider."},"status":{"type":"string","description":"The current status of the purge"},"timestamp":{"type":"string","format":"date-time","description":"The timestamp of the purge status"}}}}}}}}},"500":{"description":"Internal Server Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/DetailedResponse"}}}}},"tags":["Purge CDN Cache"]}}},"components":{"schemas":{"DetailedResponse":{"properties":{"message":{"title":"Message","type":"string"},"detail":{"title":"Detail","type":"string"},"data":{"type":"object","properties":{"message":{"title":"Message","type":"string"}}}},"required":["message","detail","data"],"title":"DetailedResponse","type":"object"}}}}
```


# Rate Limit Rules

## Get Rate Limit Rules

> Get all Rate Limit Rules in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/rate-limit-rules":{"get":{"operationId":"document_resource_get_api_v3_configs__config__d__document___get_835443798066274040","summary":"Get Rate Limit Rules","description":"Get all Rate Limit Rules in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"description":"Rate Limit Rules retrieved successfully","content":{"application/json":{"schema":{"title":"Rate Limit Rules document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/RateLimit"}}}}}}}},"tags":["Rate Limit Rules"]}}},"components":{"schemas":{"RateLimit":{"properties":{"action":{"title":"Action","type":"string"},"active":{"title":"Active","type":"boolean"},"description":{"title":"Description","type":"string"},"exclude":{"properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"items":{"type":"string","title":"Tags"},"type":"array"}},"title":"Exclude"},"global":{"title":"Global","type":"boolean"},"id":{"title":"Id","type":"string"},"include":{"type":"object","properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"items":{"type":"string","title":"Tags"},"type":"array","title":"Include"}}},"is_action_ban":{"title":"Is Action Ban","type":"boolean"},"key":{"anyOf":[{"type":"integer"},{"type":"number"},{"type":"boolean"},{},{"items":{},"type":"array"}],"title":"Key"},"last_activated":{"title":"Last Activated","type":"integer"},"name":{"title":"Name","type":"string"},"pairwith":{"title":"Pairwith"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"},"threshold":{"title":"Threshold","type":"integer"},"timeframe":{"title":"Timeframe","type":"integer"},"ttl":{"title":"Ttl","type":"integer"}},"required":["id","name","global","active","timeframe","threshold","action","exclude","include"],"title":"RateLimit","type":"object"},"TagsRelationEnum":{"title":"TagsRelationEnum","description":"Relation between tags","type":"string","enum":["OR","AND"]}}}}
```

## Modify Rate Limit Rules

> Update an existing set of Rate Limit Rules for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/rate-limit-rules":{"put":{"operationId":"document_resource_put_api_v3_configs__config__d__document___put_835443798066274040","summary":"Modify Rate Limit Rules","description":"Update an existing set of Rate Limit Rules for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"Rate Limit Rules document","type":"array","items":{"$ref":"#/components/schemas/RateLimit"}}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Rate Limit Rules updated successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Rate Limit Rules"]}}},"components":{"schemas":{"RateLimit":{"properties":{"action":{"title":"Action","type":"string"},"active":{"title":"Active","type":"boolean"},"description":{"title":"Description","type":"string"},"exclude":{"properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"items":{"type":"string","title":"Tags"},"type":"array"}},"title":"Exclude"},"global":{"title":"Global","type":"boolean"},"id":{"title":"Id","type":"string"},"include":{"type":"object","properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"items":{"type":"string","title":"Tags"},"type":"array","title":"Include"}}},"is_action_ban":{"title":"Is Action Ban","type":"boolean"},"key":{"anyOf":[{"type":"integer"},{"type":"number"},{"type":"boolean"},{},{"items":{},"type":"array"}],"title":"Key"},"last_activated":{"title":"Last Activated","type":"integer"},"name":{"title":"Name","type":"string"},"pairwith":{"title":"Pairwith"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"},"threshold":{"title":"Threshold","type":"integer"},"timeframe":{"title":"Timeframe","type":"integer"},"ttl":{"title":"Ttl","type":"integer"}},"required":["id","name","global","active","timeframe","threshold","action","exclude","include"],"title":"RateLimit","type":"object"},"TagsRelationEnum":{"title":"TagsRelationEnum","description":"Relation between tags","type":"string","enum":["OR","AND"]},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create Rate Limit Rules

> Create a complete set of Rate Limit Rules for a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/rate-limit-rules":{"post":{"operationId":"document_resource_post_api_v3_configs__config__d__document___post_835443798066274040","summary":"Create Rate Limit Rules","description":"Create a complete set of Rate Limit Rules for a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"title":"Rate Limit Rules document","type":"array","items":{"$ref":"#/components/schemas/RateLimit"}}}}},"responses":{"201":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}},"description":"Rate Limit Rules created successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Rate Limit Rules"]}}},"components":{"schemas":{"RateLimit":{"properties":{"action":{"title":"Action","type":"string"},"active":{"title":"Active","type":"boolean"},"description":{"title":"Description","type":"string"},"exclude":{"properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"items":{"type":"string","title":"Tags"},"type":"array"}},"title":"Exclude"},"global":{"title":"Global","type":"boolean"},"id":{"title":"Id","type":"string"},"include":{"type":"object","properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"items":{"type":"string","title":"Tags"},"type":"array","title":"Include"}}},"is_action_ban":{"title":"Is Action Ban","type":"boolean"},"key":{"anyOf":[{"type":"integer"},{"type":"number"},{"type":"boolean"},{},{"items":{},"type":"array"}],"title":"Key"},"last_activated":{"title":"Last Activated","type":"integer"},"name":{"title":"Name","type":"string"},"pairwith":{"title":"Pairwith"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"},"threshold":{"title":"Threshold","type":"integer"},"timeframe":{"title":"Timeframe","type":"integer"},"ttl":{"title":"Ttl","type":"integer"}},"required":["id","name","global","active","timeframe","threshold","action","exclude","include"],"title":"RateLimit","type":"object"},"TagsRelationEnum":{"title":"TagsRelationEnum","description":"Relation between tags","type":"string","enum":["OR","AND"]},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete Rate Limit Rules

> Delete all Rate Limit Rules in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/rate-limit-rules":{"delete":{"operationId":"document_resource_delete_api_v3_configs__config__d__document___delete_835443798066274040","summary":"Delete Rate Limit Rules","description":"Delete all Rate Limit Rules in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Rate Limit Rules deleted successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Rate Limit Rules"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get specific Rate Limit Rule

> Get a Rate Limit Rule from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/rate-limit-rules/{entry_id}":{"get":{"operationId":"entry_resource_get_api_v3_configs__config__d__document__e__entry___get_2024587963096661028","summary":"Get specific Rate Limit Rule","description":"Get a Rate Limit Rule from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"responses":{"200":{"description":"Rate Limit Rule retrieved successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/RateLimit"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"tags":["Rate Limit Rules"]}}},"components":{"schemas":{"RateLimit":{"properties":{"action":{"title":"Action","type":"string"},"active":{"title":"Active","type":"boolean"},"description":{"title":"Description","type":"string"},"exclude":{"properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"items":{"type":"string","title":"Tags"},"type":"array"}},"title":"Exclude"},"global":{"title":"Global","type":"boolean"},"id":{"title":"Id","type":"string"},"include":{"type":"object","properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"items":{"type":"string","title":"Tags"},"type":"array","title":"Include"}}},"is_action_ban":{"title":"Is Action Ban","type":"boolean"},"key":{"anyOf":[{"type":"integer"},{"type":"number"},{"type":"boolean"},{},{"items":{},"type":"array"}],"title":"Key"},"last_activated":{"title":"Last Activated","type":"integer"},"name":{"title":"Name","type":"string"},"pairwith":{"title":"Pairwith"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"},"threshold":{"title":"Threshold","type":"integer"},"timeframe":{"title":"Timeframe","type":"integer"},"ttl":{"title":"Ttl","type":"integer"}},"required":["id","name","global","active","timeframe","threshold","action","exclude","include"],"title":"RateLimit","type":"object"},"TagsRelationEnum":{"title":"TagsRelationEnum","description":"Relation between tags","type":"string","enum":["OR","AND"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Modify a single Rate Limit Rule

> Update an individual Rate Limit Rule within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/rate-limit-rules/{entry_id}":{"put":{"operationId":"entry_resource_put_api_v3_configs__config__d__document__e__entry___put_2024587963096661028","summary":"Modify a single Rate Limit Rule","description":"Update an individual Rate Limit Rule within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/RateLimit"}}}},"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Rate Limit Rule updated successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Rate Limit Rules"]}}},"components":{"schemas":{"RateLimit":{"properties":{"action":{"title":"Action","type":"string"},"active":{"title":"Active","type":"boolean"},"description":{"title":"Description","type":"string"},"exclude":{"properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"items":{"type":"string","title":"Tags"},"type":"array"}},"title":"Exclude"},"global":{"title":"Global","type":"boolean"},"id":{"title":"Id","type":"string"},"include":{"type":"object","properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"items":{"type":"string","title":"Tags"},"type":"array","title":"Include"}}},"is_action_ban":{"title":"Is Action Ban","type":"boolean"},"key":{"anyOf":[{"type":"integer"},{"type":"number"},{"type":"boolean"},{},{"items":{},"type":"array"}],"title":"Key"},"last_activated":{"title":"Last Activated","type":"integer"},"name":{"title":"Name","type":"string"},"pairwith":{"title":"Pairwith"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"},"threshold":{"title":"Threshold","type":"integer"},"timeframe":{"title":"Timeframe","type":"integer"},"ttl":{"title":"Ttl","type":"integer"}},"required":["id","name","global","active","timeframe","threshold","action","exclude","include"],"title":"RateLimit","type":"object"},"TagsRelationEnum":{"title":"TagsRelationEnum","description":"Relation between tags","type":"string","enum":["OR","AND"]},"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Create single Rate Limit Rule

> Create an individual Rate Limit Rule within a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/rate-limit-rules/{entry_id}":{"post":{"operationId":"entries_resource_post_api_v3_configs__config__d__document__e__post_338242239728621746","summary":"Create single Rate Limit Rule","description":"Create an individual Rate Limit Rule within a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/RateLimit"}}}},"responses":{"201":{"description":"Rate Limit Rule created successfully","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseCreate"}}}},"422":{"description":"Validation Error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}}}},"tags":["Rate Limit Rules"]}}},"components":{"schemas":{"RateLimit":{"properties":{"action":{"title":"Action","type":"string"},"active":{"title":"Active","type":"boolean"},"description":{"title":"Description","type":"string"},"exclude":{"properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"items":{"type":"string","title":"Tags"},"type":"array"}},"title":"Exclude"},"global":{"title":"Global","type":"boolean"},"id":{"title":"Id","type":"string"},"include":{"type":"object","properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"items":{"type":"string","title":"Tags"},"type":"array","title":"Include"}}},"is_action_ban":{"title":"Is Action Ban","type":"boolean"},"key":{"anyOf":[{"type":"integer"},{"type":"number"},{"type":"boolean"},{},{"items":{},"type":"array"}],"title":"Key"},"last_activated":{"title":"Last Activated","type":"integer"},"name":{"title":"Name","type":"string"},"pairwith":{"title":"Pairwith"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"},"threshold":{"title":"Threshold","type":"integer"},"timeframe":{"title":"Timeframe","type":"integer"},"ttl":{"title":"Ttl","type":"integer"}},"required":["id","name","global","active","timeframe","threshold","action","exclude","include"],"title":"RateLimit","type":"object"},"TagsRelationEnum":{"title":"TagsRelationEnum","description":"Relation between tags","type":"string","enum":["OR","AND"]},"ResponseCreate":{"title":"ResponseCreate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful create operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Delete single Rate Limit Rule

> Delete an individual Rate Limit Rule from the specified configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/rate-limit-rules/{entry_id}":{"delete":{"operationId":"entry_resource_delete_api_v3_configs__config__d__document__e__entry___delete_2024587963096661028","summary":"Delete single Rate Limit Rule","description":"Delete an individual Rate Limit Rule from the specified configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"entry_id","required":true,"schema":{"title":"Entry","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseDelete"}}},"description":"Rate Limit Rule deleted successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Rate Limit Rules"]}}},"components":{"schemas":{"ResponseDelete":{"title":"ResponseDelete","type":"object","properties":{"message":{"title":"Message","description":"Information about successful delete operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get Rate Limit Rules version list

> Get list of versions of Rate Limit Rules in a configuration

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/rate-limit-rules/versions":{"get":{"operationId":"document_list_version_resource_get_api_v3_configs__config__d__document__v__get_621303428617033970","summary":"Get Rate Limit Rules version list","description":"Get list of versions of Rate Limit Rules in a configuration","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Versions list","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/VersionEntry"}}}}}},"description":"Rate Limit Rules version list retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Rate Limit Rules"]}}},"components":{"schemas":{"VersionEntry":{"title":"VersionEntry","type":"object","properties":{"author":{"title":"Author","type":"string"},"email":{"title":"Email","format":"email","type":"string"},"message":{"title":"Message","type":"string"},"date":{"format":"date-time","title":"Date","type":"string"},"version":{"title":"Version","type":"string"},"parents":{"type":"array","items":{"type":"string"}}}},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Get version of Rate Limit Rule

> Get a specific version of a Rate Limit Rule

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/rate-limit-rules/versions/{version}":{"get":{"operationId":"document_version_resource_get_api_v3_configs__config__d__document__v__version___get_1267587814308377813","summary":"Get version of Rate Limit Rule","description":"Get a specific version of a Rate Limit Rule","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"title":"Rate Limit Rules document","properties":{"total":{"type":"integer"},"items":{"type":"array","items":{"$ref":"#/components/schemas/RateLimit"}}}}}},"description":"Rate Limit Rule retrieved successfully"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Rate Limit Rules"]}}},"components":{"schemas":{"RateLimit":{"properties":{"action":{"title":"Action","type":"string"},"active":{"title":"Active","type":"boolean"},"description":{"title":"Description","type":"string"},"exclude":{"properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"items":{"type":"string","title":"Tags"},"type":"array"}},"title":"Exclude"},"global":{"title":"Global","type":"boolean"},"id":{"title":"Id","type":"string"},"include":{"type":"object","properties":{"relation":{"$ref":"#/components/schemas/TagsRelationEnum"},"tags":{"items":{"type":"string","title":"Tags"},"type":"array","title":"Include"}}},"is_action_ban":{"title":"Is Action Ban","type":"boolean"},"key":{"anyOf":[{"type":"integer"},{"type":"number"},{"type":"boolean"},{},{"items":{},"type":"array"}],"title":"Key"},"last_activated":{"title":"Last Activated","type":"integer"},"name":{"title":"Name","type":"string"},"pairwith":{"title":"Pairwith"},"tags":{"items":{"type":"string"},"title":"Tags","type":"array"},"threshold":{"title":"Threshold","type":"integer"},"timeframe":{"title":"Timeframe","type":"integer"},"ttl":{"title":"Ttl","type":"integer"}},"required":["id","name","global","active","timeframe","threshold","action","exclude","include"],"title":"RateLimit","type":"object"},"TagsRelationEnum":{"title":"TagsRelationEnum","description":"Relation between tags","type":"string","enum":["OR","AND"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```

## Revert a Rate Limit Rule to the specified version

> Set a previous Rate Limit Rule version to be the current one

```json
{"openapi":"3.0.2","info":{"title":"Link11 WAAP","version":"v4.3"},"paths":{"/api/v4.3/conf/{config}/rate-limit-rules/versions/{version}/revert":{"put":{"operationId":"document_revert_resource_put_api_v3_configs__config__d__document__v__version__revert__put_1483098490404470532","summary":"Revert a Rate Limit Rule to the specified version","description":"Set a previous Rate Limit Rule version to be the current one","parameters":[{"in":"path","name":"config","required":true,"schema":{"title":"Config","type":"string"}},{"in":"path","name":"version","required":true,"schema":{"title":"Version","type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ResponseUpdate"}}},"description":"Rate Limit Rule reversion was successful"},"422":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/HTTPValidationError"}}},"description":"Validation Error"}},"tags":["Rate Limit Rules"]}}},"components":{"schemas":{"ResponseUpdate":{"title":"ResponseUpdate","type":"object","properties":{"message":{"title":"Message","description":"Information about successful update operation","type":"string"}},"required":["message"]},"HTTPValidationError":{"properties":{"detail":{"items":{"$ref":"#/components/schemas/ValidationError"},"title":"Detail","type":"array"}},"title":"HTTPValidationError","type":"object"},"ValidationError":{"properties":{"loc":{"items":{"anyOf":[{"type":"string"},{"type":"integer"}]},"title":"Location","type":"array"},"msg":{"title":"Message","type":"string"},"type":{"title":"Error Type","type":"string"}},"required":["loc","msg","type"],"title":"ValidationError","type":"object"}}}}
```




---

[Next Page](/llms-full.txt/1)

