Azure WAF bot protection ruleset. Meaning of log ID 300700

eenchev 0 Reputation points
2025-03-12T14:29:21.1666667+00:00

I have enabled bot protection ruleset for a waf policy. The DRS ruleset normally has a detailed message in the logs but for the bot protection I am finding it hard to identify the reason for a match for 300700 id Other bots (group Unknownbots).

User's image

We have thousands of such logs. I know default action is log and using allow is not recommended which will stop further ruleset checks.

In general I want to finetune the ruleid so I decrease the noise from these log messages and add 1-2 exclusions. Details_data field is not very helpful. What does it see in REQUEST_HEADERS:

Azure Web Application Firewall
{count} votes

1 answer

Sort by: Most helpful
  1. eenchev 0 Reputation points
    2025-03-13T07:29:24.7766667+00:00

    Hi,

    Thank you for you comments.

    Here are some recent timestamps. As for other details there is nothing useful related to the match condition. details_data_s is "{ found within [REQUEST_HEADERS:]}" and Message : "Other bots"User's image

    User's image

    Traffic is mostly internal and is false positive but I want to be able to understand the reason for triggering which should normally be found in the logs.

    User's image

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.