Mark a Log as Benign
If Check Point WAF flags a legitimate request as an attack, you can mark that log as benign. The WAF then learns that the request is safe and stops blocking or flagging matching traffic — without reducing protection for genuinely malicious requests.
Use this to resolve a false positive on a specific request, instead of waiting for the WAF's automatic learning to adapt or writing a broad exception.
Prerequisites
The asset's WAF practice is set to Detect or Prevent mode.
You have permissions to manage the asset's policy in the Infinity Portal.
Steps
In the Infinity Portal, go to Check Point WAF > Events and filter to your asset.
Locate the log for the request you want to allow. Use the URL, parameter, and timestamp to confirm it is the legitimate request being flagged.
Open the log to review its details — matched indicators, location, and parameter.
Right-click the log and select Mark as benign.
Optionally, add a short reason or comment.
Confirm. The log is marked and its request pattern is recorded as benign.
Once the action is recorded, the log shows a Learned badge.
When it takes effect
Allow up to 2 hours for the change to reach the enforcing WAF agents.
To verify, re-send the request that was previously flagged and confirm it is no longer blocked (in Prevent mode) or no longer raised as an attack (in Detect mode).
If you need it resolved immediately
Marking a log as benign is the recommended way to clear a false positive, but it is not immediate. If the request must be unblocked right away, add an Exception for it instead.
The WAF to learn that this request is safe (recommended)
Mark as benign
Up to 2 hours
How to revert
If you marked the wrong log, or the request should be prevented again:
Open the same log it shows the Learned badge.
Right-click the log and select Revert.
Allow the same 2-hour propagation window.
After propagation, matching traffic is protected again.
Related
Setup Custom Rules and ExceptionsTrack Learning and Move from Learn/Detect to PreventLast updated
Was this helpful?