RateBasedRule
Note
AWS WAF Classic support will end on September 30, 2025.
This is AWS WAF Classic documentation. For more information, see AWS WAF Classic in the developer guide.
For the latest version of AWS WAF , use the AWS WAFV2 API and see the AWS WAF Developer Guide. With the latest version, AWS WAF has a single set of endpoints for regional and global use.
A RateBasedRule is identical to a regular Rule, with
one addition: a RateBasedRule counts the number of requests that arrive from a
specified IP address every five minutes. For example, based on recent requests that you've
seen from an attacker, you might create a RateBasedRule that includes the
following conditions:
-
The requests come from 192.0.2.44.
-
They contain the value
BadBotin theUser-Agentheader.
In the rule, you also define the rate limit as 1,000.
Requests that meet both of these conditions and exceed 1,000 requests every five minutes trigger the rule's action (block or count), which is defined in the web ACL.
Contents
- MetricName
-
A friendly name or description for the metrics for a
RateBasedRule. The name can contain only alphanumeric characters (A-Z, a-z, 0-9), with maximum length 128 and minimum length one. It can't contain whitespace or metric names reserved for AWS WAF, including "All" and "Default_Action." You can't change the name of the metric after you create theRateBasedRule.Type: String
Length Constraints: Minimum length of 1. Maximum length of 128.
Pattern:
.*\S.*Required: Yes
- Name
-
A friendly name or description for a
RateBasedRule. You can't change the name of aRateBasedRuleafter you create it.Type: String
Length Constraints: Minimum length of 1. Maximum length of 128.
Pattern:
.*\S.*Required: Yes
- RateKey
-
The field that AWS WAF uses to determine if requests are likely arriving from single source and thus subject to rate monitoring. The only valid value for
RateKeyisIP.IPindicates that requests arriving from the same IP address are subject to theRateLimitthat is specified in theRateBasedRule.Type: String
Valid Values:
IPRequired: Yes
- RateLimit
-
The maximum number of requests, which have an identical value in the field specified by the
RateKey, allowed in a five-minute period. If the number of requests exceeds theRateLimitand the other predicates specified in the rule are also met, AWS WAF triggers the action that is specified for this rule.Type: Long
Valid Range: Minimum value of 100. Maximum value of 2000000000.
Required: Yes
- RuleId
-
A unique identifier for a
RateBasedRule. You useRuleIdto get more information about aRateBasedRule(see GetRateBasedRule), update aRateBasedRule(see UpdateRateBasedRule), insert aRateBasedRuleinto aWebACLor delete one from aWebACL(see UpdateWebACL), or delete aRateBasedRulefrom AWS WAF (see DeleteRateBasedRule).Type: String
Length Constraints: Minimum length of 1. Maximum length of 128.
Pattern:
.*\S.*Required: Yes
- MatchPredicates
-
The
Predicatesobject contains onePredicateelement for each ByteMatchSet, IPSet, or SqlInjectionMatchSet object that you want to include in aRateBasedRule.Type: Array of Predicate objects
Required: No
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following: