Is this a false positive firewall event?

After I updated the firewall of my Pro domain to Cloudflare’s new managed rule sets occasionally users email me saying they are blocked.

When I locate their requests in Cloudflare’s firewall events, I’m not always sure if (1) they are legitimate requests and (2) what to do about them.

Take this request for instance:

Does this appear as a legitimate request? If yes, what’s a good way to handle users getting blocked because of these rules?

Hey there!

Check our developer documentation here:

I’m not always sure if (1) they are legitimate requests and (2) what to do about them.

If you are not able to distinguish if it’s a legitimate or not, it’s better to not soften the existing level of security. Only change if you know that is a false positive.

Take Care!

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.