Tuning and the count window
Tuning is where you see the count window, Promote Copilot, virtual-patch cards, and the controls that change a rule. The timeline explains the wait. It does not flip a rule.
One rollup
Analytics and Promote Copilot read the same WAF traffic rollup. Ranges on Analytics are 24 hours, 7 days, and 30 days. The default is 24 hours. A missing CloudWatch series is “not confirmed,” not zero, on the timeline, the report, and Copilot.
Sampled breakdowns (paths, countries, and similar) are samples. The product does not turn those samples into exact totals. A fuller log pipeline for exact geography and longer retention is not part of this version.
The timeline
The track runs through the first week. The decision itself stays 24 hours.
| Mark | What it means |
|---|---|
| Start | Rules enter count. |
| 12h | A CloudWatch series shorter than this, on a closed clock, stays Hold. |
| 24h | Copilot can say Promote only after this watch window closes, and only when the evidence is complete. |
| 7d | A full week in count does not flip a rule. You still click Promote, and only for a rule whose evidence is complete. |
The first-day line says managed rules stay in count and that a missing series is not a reason to block. The first-week line says Promote still uses the latest 24-hour rollup, the same numbers as Analytics and Copilot.
For a Hold or Needs allowlist row, the timeline and the card share one “what would change this” sentence. Promote rows do not get that line.
What you can change here
You can set a managed group to count or block, add a group in count from a virtual-patch card, save or remove an allowlist, and undo a promote. Custom allow, block, and rate rules sit in the same editor, beside the managed groups.
The WAF capacity budget shown in the dashboard is 1,500 WCU. Saves prefer a capacity check on the full rule list.