Skip to content

Troubleshoot with WAF WebACL log

0

Hi,

In our WebACL log, we keep seeing requests to our ALB from different countries but targeting the same host ip address in the request header. This ip seems to belong to AWS. Is there a way to find out what endpoint the requests are trying to reach? How did the spammers get the endpoints? And what can I do to protect our endpoints? Thanks.

  • Wich field of the WebACL log are you considering that tells you "targeting he same host" ?

1 Answer
0

Hello, Could you please clarify what do you mean by host IP address here? is it the IP address of the EC2 instance behind the load balancer or the IP of the load balancer node itself?

AWS
answered a year ago
  • Hi Prenesh, we're using ECS services on Fargate behind the ALB which is protected by WAF. We can close this question now. I can't find the sample log any more.

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.