Skip to main content
jkoay
Staff & Editor
Staff & Editor
November 9, 2020

Technical Tip: View WAF signature details with WAF’s event ID

  • November 9, 2020
  • 0 replies
  • 19530 views

Description


This article describes the procedure to identify the reason why traffic to specific URLs was blocked by WAF signatures when there is an event ID shown in Web Application Firewall logs as below and how to View WAF signature details with WAF’s event ID.

 

Scope

 

FortiGate.

 

Solution

 


The command below can be executed in CLI to check on signature details based on Web Application Firewall Event ID:

 

diag waf dump | grep –f 90300017

 

 

Note:

The CLI command 'diagnose waf dump' lists all the WAF signatures in FortiOS. It is only visible in CLI using this command, and not in the GUI.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!