Accessing WAF and CDN traffic filter event logs in Adobe Experience Manager as a Cloud Service

This article explains how to find and download logs for Web Application Firewall (WAF) and CDN traffic filter events in Adobe Experience Manager as a Cloud Service using Cloud Manager.

Description description

When investigating incidents where CDN traffic filter rules or Web Application Firewall (WAF) protections are triggered in Adobe Experience Manager as a Cloud Service, you may need to review event logs for further analysis. There is no dedicated WAF log interface; instead, these events are recorded within the standard CDN logs available through Cloud Manager.

Environment

Adobe Experience Manager as a Cloud Service (AEMaaCS)

Symptoms

  • Need to investigate incidents where CDN traffic filter or WAF rules were triggered
  • Uncertainty about where such events are recorded
  • No specific error codes or stack traces are present

Cause

WAF and CDN traffic filter events are logged within the standard CDN logs in Cloud Manager. There is no separate WAF log interface.

Resolution resolution

Follow the steps below to resolve the issue:

  1. Log in to Cloud Manager for your organization.
  2. Select the relevant Cloud Manager program and environment where the incident occurred.
  3. Navigate to the Logs section.
  4. Choose the log type CDN from the available options.
  5. Specify the time range that covers the incident or suspected WAF/traffic filter event.
  6. Download the logs for review.
  7. Search the downloaded logs for entries related to traffic filter or WAF rule triggers. These events are recorded within the CDN logs, not in a separate WAF log interface.

To verify, confirm that the expected traffic filter or WAF events appear in the CDN logs for the specified time range.

recommendation-more-help
experience-cloud-kcs-help-kbarticles