Skip to content

cf.waf.content_scan.truncated

cf.waf.content_scan.truncatedBoolean

Indicates whether the request body exceeded the size limit for content scanning and was truncated before scanning.

Requires a Cloudflare Enterprise plan with malicious uploads detection.

When this field is true, the scan results may be incomplete. Refer to Size limit.

Example usage:

# Block requests to a specific endpoint whose content was not fully scanned
cf.waf.content_scan.truncated and http.request.uri.path eq "/upload"
Categories:
  • Request

Was this helpful?