waf_events_by_ip
Query WAF events filtered by IP address, returning timestamps, HTTP methods, URIs, status codes, and triggered rules.
Instructions
Drill into events from a specific IP address. Shows timestamps, methods, URIs, HTTP codes, and triggered rules.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ip | Yes | IP address to filter events by | |
| count | No | Number of events to return (default 20) | |
| verbose | No | Include full matched data in rules (default: truncated) | |
| since | No | Time window for log search (e.g. '1h', '24h', '7d'). Default: 24h | 24h |