For the complete documentation index, see llms.txt. This page is also available as Markdown.

Mark a Log as Benign

If Check Point WAF flags a legitimate request as an attack, you can mark that log as benign. The WAF then learns that the request is safe and stops blocking or flagging matching traffic — without reducing protection for genuinely malicious requests.

Use this to resolve a false positive on a specific request, instead of waiting for the WAF's automatic learning to adapt or writing a broad exception.

Prerequisites

  • The asset's WAF practice is set to Detect or Prevent mode.

  • You have permissions to manage the asset's policy in the Infinity Portal.

Steps

  1. In the Infinity Portal, go to Check Point WAF > Events and filter to your asset.

  2. Locate the log for the request you want to allow. Use the URL, parameter, and timestamp to confirm it is the legitimate request being flagged.

  3. Open the log to review its details — matched indicators, location, and parameter.

  4. Right-click the log and select Mark as benign.

  5. Optionally, add a short reason or comment.

  6. Confirm. The log is marked and its request pattern is recorded as benign.

Once the action is recorded, the log shows a Learned badge.

When it takes effect

Allow up to 2 hours for the change to reach the enforcing WAF agents.

To verify, re-send the request that was previously flagged and confirm it is no longer blocked (in Prevent mode) or no longer raised as an attack (in Detect mode).

If you need it resolved immediately

Marking a log as benign is the recommended way to clear a false positive, but it is not immediate. If the request must be unblocked right away, add an Exception for it instead.

You want…
Use
Takes effect

The WAF to learn that this request is safe (recommended)

Mark as benign

Up to 2 hours

The request unblocked immediately

Immediately, on the next policy update

How to revert

If you marked the wrong log, or the request should be prevented again:

  1. Open the same log it shows the Learned badge.

  2. Right-click the log and select Revert.

  3. Allow the same 2-hour propagation window.

After propagation, matching traffic is protected again.

  • Marking a log as benign applies to the specific request pattern derived from that log, not to a broad URL pattern. To allow a whole URL or parameter pattern, use an exception instead.

  • If you are unsure whether a request is genuinely benign, investigate before marking it. Marking a real attack as benign reduces protection for that pattern.

  • If the same request pattern keeps arriving at high volume from many sources, the WAF's automatic learning may re-learn it after you revert. If a reverted request keeps coming back, investigate the underlying traffic or open a case with Check Point Support.

Setup Custom Rules and ExceptionsTrack Learning and Move from Learn/Detect to Prevent

Last updated

Was this helpful?