About text expressions
-
Determine that a particular HTTP header exists.For example, you may want to identify HTTP requests that contains a particular Accept-Language header for the purpose of directing the request to a particular server.
-
Determine that a particular HTTP URL contains a particular string.For example, you may want to block requests for particular URLs. Note that the string can occur at the beginning, middle, or end of another string.
-
Identify a POST request that is directed to a particular application.For example, you may want to identify all POST requests that are directed to a database application for the purpose of refreshing cached application data.
About operations on text
http.req.header("myHeader").contains("some-text")
http.req.url.suffix.contains("jpeg")
http.req.url.suffix.eq("jpeg")
Compounding and precedence in text expressions
http.req.hostname + http.req.url
http.req.method.eq(post) && http.req.body(1024).startswith("destination=")
Categories of text expressions
-
Information in HTTP headers, HTTP URLs, and the POST body in HTTP requests.For more information, see Expression prefixes for text in HTTP requests and responses.
-
Information regarding a VPN or a clientless VPN.For more information, see Expression prefixes for VPNs and clientless VPNs.
-
TCP payload information.For more information about TCP payload expressions, see Advanced policy expressions: Parsing HTTP, TCP, and UDP data.
-
Text in a Secure Sockets Layer (SSL) certificate.For information about text expressions for SSL and SSL certificate data, see Advanced policy expressions: Parsing SSL certificates and Expressions for SSL certificate dates.
Guidelines for text expressions
HTTP.REQ.URL.QUERY
HTTP.REQ.URL.AFTER_STR("?")
HTTP.REQ.HEADER("Example").TYPECAST_LIST_T(',').GET(1)
HTTP.REQ.HEADER("Example").AFTER_STR(",").BEFORE_STR(",")
HTTP.REQ.HEADER("Example").AFTER_STR("more")
HTTP.REQ.HEADER("Example").AFTER_REGEX(re/more/)