Tuning and the count window

Tuning is where you see the count window, Promote Copilot, virtual-patch cards, and the controls that change a rule. The timeline explains the wait. It does not flip a rule.

One rollup

Analytics and Promote Copilot read the same WAF traffic rollup. Ranges on Analytics are 24 hours, 7 days, and 30 days. The default is 24 hours. A missing CloudWatch series is “not confirmed,” not zero, on the timeline, the report, and Copilot.

Sampled breakdowns (paths, countries, and similar) are samples. The product does not turn those samples into exact totals. A fuller log pipeline for exact geography and longer retention is not part of this version.

The timeline

The track runs through the first week. The decision itself stays 24 hours.

Marks on the timeline
MarkWhat it means
StartRules enter count.
12hA CloudWatch series shorter than this, on a closed clock, stays Hold.
24hCopilot can say Promote only after this watch window closes, and only when the evidence is complete.
7dA full week in count does not flip a rule. You still click Promote, and only for a rule whose evidence is complete.

The first-day line says managed rules stay in count and that a missing series is not a reason to block. The first-week line says Promote still uses the latest 24-hour rollup, the same numbers as Analytics and Copilot.

For a Hold or Needs allowlist row, the timeline and the card share one “what would change this” sentence. Promote rows do not get that line.

What you can change here

You can set a managed group to count or block, add a group in count from a virtual-patch card, save or remove an allowlist, and undo a promote. Custom allow, block, and rate rules sit in the same editor, beside the managed groups.

The WAF capacity budget shown in the dashboard is 1,500 WCU. Saves prefer a capacity check on the full rule list.

Related guides

More in this section