Observe
Security events
Connect firewall and access-control decisions to request activity.
Security events explain why Easel allowed, blocked, logged, or challenged a request.
For the full security product model, see Firewall observability.
Where security shows up
- Request detail Firewall badge on Logs
- Project overview firewall action snapshots
- Observability charts that group by firewall action when the field is present
- Response headers such as
X-Easel-Firewall-ActionandX-Easel-Firewall-Rule-Idon some denials
Actions
Customer-facing action values you may see include:
Platform protections may also surface actions such as ban or throttle.
Decision sources
Prefer product concepts when describing a decision:
- Platform protection
- Custom rule
- Attack Mode
- Deployment protection
See Attack Mode and Custom firewall rules.
Debugging workflow
- Reproduce the request and capture the request ID.
- Open Logs for that ID or time window.
- Check the Firewall badge and status code.
- Confirm rule configuration in Project settings → Custom WAF rules.
- Confirm whether Attack Mode or deployment protection is enabled.
When a challenge interstitial appears, verification outcomes may show as
challenge pass or fail around /.well-known/easel-challenge/verify.