Solved
Forum Discussion
samstep
Sep 13, 2021Cirrocumulus
ASM truncates requests when logging them, so it is possible that the attack signature was found in the part of the payload which was not logged.
https://support.f5.com/csp/article/K11048172
- Ahmed_GalalSep 14, 2021Cirrostratus
Good Morning Sam,
hope that you are doing well.
thank you for your assistance, i am now in middle of increase max log size and face memory issue that might happen or convince developer with this part of request 😂 😂
- samstepSep 14, 2021Cirrocumulus
if they payload is really big (is the developer uploading a file?) this might be a false positive. You could also intercept the request using intercepting proxy such as Fiddler, OWASP ZAP or Burp Suite.
In your screenshot the signature 200000107 is detecting symbols &{