waf_top_rules
Identify dominant attack patterns by retrieving the most frequently triggered WAF rules with severity and descriptions.
Instructions
Most frequently triggered WAF rules with severity and description. Use to identify dominant attack patterns.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| count | No | Number of top rules to return (default 10) | |
| since | No | Time window for log search (e.g. '1h', '24h', '7d'). Default: 24h | 24h |