Introducing the New WAF Rules Interface
Your WAF rules just got a lot easier to read. Same rules, same enforcement, new interface.
There's nothing to install and nothing to migrate. Your existing rules carry over exactly as they are, and the new interface shows up in your dashboard automatically.
Rules are where Wallarm's detection depth becomes yours to direct. A rule can target any part of a request, including a value buried deep inside a nested payload. The problem was never what rules could do. It was seeing what they covered without opening them one at a time. That's what we fixed.
What's new
Every rule type in one view
Browse all of your rule types from a single panel instead of clicking through a tree of hosts and paths. Pick a type to narrow the list, or look at everything at once. Each view has its own address, so you can bookmark a filtered list or send it to a teammate.
Every rule type, right from the start.
Visible request targeting
You can now see the exact part of the request each rule applies to, right in the list. A rule might point at a value several layers deep: a field inside a JSON object, inside a Base64 segment, inside a JWT, inside a request header. The full path shows up on the row. So the next time someone asks which of your parameters a rule covers, you can just look.
Filters for applications and scope
Narrow the list to specific applications, or separate the rules Wallarm creates and manages for you (marked Default, and not editable) from the ones your team built. Filters live in the address bar, so your view survives a reload.
Rule management in the list
Enable or disable a rule without deleting it, duplicate one as a starting point for the next, and clear out the ones you don't need anymore. All from the list, with endpoints, applications, and last updated on every row.
Creating a rule works the same way. You build the target one step at a time, choosing from the options that are valid at each step.
Cookie → JWT → Base64 → JSON → sub, built one step at a time.
Your rules and the way they're enforced haven't changed. What's changed is how fast you can find, read, and manage them.