Forum Discussion

Takayuki_Kurosawa's avatar
Aug 09, 2026

F5 Rules for AWS WAF - does F5 have any access to the request data inspected by the rule groups?

I'm reviewing the data handling characteristics of the F5 Rules for AWS WAF managed rule groups (purchased through AWS Marketplace) and would like to confirm my understanding with the community.

 

K21015971 describes the procedure for reporting a suspected false positive. As I read it, the customer is asked to log the blocked HTTP requests along with the names of the rules that matched, mask any sensitive information with ****, and then submit a question with the F5 rules for AWS WAF tag and attach those requests.

 

My reading of that procedure is that F5 has no independent access to the requests inspected by the rule groups. If F5 could see them, there would be no need for the customer to extract, mask and attach them manually. Is that reading correct?

 

More specifically, could someone confirm whether the following are accurate?

 

1. HTTP request data inspected by the rule groups (source IP addresses, headers, request bodies, query strings, cookies) is never transmitted to F5.

 

2. AWS WAF logs, sampled requests, CloudWatch metrics, and the labels generated by rule matches remain entirely within the subscriber's own AWS account, with no access path available to F5.

 

3. The only information F5 receives in connection with a subscription is AWS Marketplace billing and metering data.

 

One related question. Section 5 of the F5 End User License Agreement (Collection and Use of Product Information) notes that, depending on the product and the licensed pricing tier, a customer may be able to opt out of the collection and use of such information by configuring the product to disable those features.

 

Is there any such configuration available for these rule groups? Or does the question simply not arise because no collection takes place for this product?

 

Thanks in advance.

No RepliesBe the first to reply