Solved
Forum Discussion
samstep
Cirrocumulus
ASM truncates requests when logging them, so it is possible that the attack signature was found in the part of the payload which was not logged.
https://support.f5.com/csp/article/K11048172
Ahmed_Galal
Sep 14, 2021Cirrostratus
Good Morning Sam,
hope that you are doing well.
thank you for your assistance, i am now in middle of increase max log size and face memory issue that might happen or convince developer with this part of request 😂 😂
- samstepSep 14, 2021Cirrocumulus
if they payload is really big (is the developer uploading a file?) this might be a false positive. You could also intercept the request using intercepting proxy such as Fiddler, OWASP ZAP or Burp Suite.
In your screenshot the signature 200000107 is detecting symbols &{