Override expressions
Set an override expression for the HTTP DDoS Attack Protection managed ruleset to define a specific scope for sensitivity level or action adjustments.
For example, you can set different sensitivity levels for different request URI paths: a medium sensitivity level for URI path A and a low sensitivity level for URI path B.
You can use the following fields in override expressions:
cf.client.botcf.threat_scorehttp.cookiehttp.hosthttp.refererhttp.request.urihttp.request.uri.pathhttp.request.uri.queryhttp.request.full_urihttp.request.methodhttp.request.versionhttp.request.cookieshttp.user_agenthttp.x_forwarded_forip.srcip.src.asnumip.src.continentip.src.countryip.src.is_in_european_unionsslcf.tls_client_auth.cert_verified
Refer to the Fields reference in the Rules language documentation for more information.
Was this helpful?
- Resources
- API
- New to Cloudflare?
- Products
- Sponsorships
- Open Source
- Support
- Help Center
- System Status
- Compliance
- GDPR
- Company
- cloudflare.com
- Our team
- Careers
- 2025 Cloudflare, Inc.
- Privacy Policy
- Terms of Use
- Report Security Issues
- Trademark