All glossary terms
Glossary

Log mode vs. block mode

In log mode (also called count, detect or simulate mode) a WAF rule only records matching requests; in block mode it stops them.

Teams use log mode to test new rules on real traffic before enforcing them. The problem is that many rules never leave log mode: the test period ends, nobody reviews the results, and the application stays unprotected while the dashboard shows the rule as "on".

The opposite failure also happens. A configuration change or vendor update can switch rules meant to log into blocking, which is what happened in a real Cloudflare incident Huskeys documented.

Where Huskeys fits

Huskeys tracks every rule's actual mode per application and flags rules stuck in log mode or blocking unexpectedly.

Related terms

Further reading