Skip to content
Myra Online Help Updated · 21 Aug 2026

Abbreviations in the WAF log

If you have configured a log format that includes the $myra_status variable, a three-digit code in the log indicates how Myra's protection mechanisms handled the request.

The individual status codes have the following meanings:

Blocked requests

Name Definition
BAI Blocked AI Bot The request was identified as an AI bot and blocked.
BBB Blocked Bad Bot The request came from known bad bots and was blocked.
BBL Blocked Blind Link The request was detected as a crawler via a blind link and blocked.
BBS Blocked Bad Signature The request was blocked due to an invalid signed URL signature.
BCT Blocked Content Type Length The request was blocked because the Content Type Length header was too long.
BDB Bad Database The request was blocked because it has a known malicious fingerprint.
BEL Blocked Expensive Limit The request was blocked by the Request Limiter on specific URLs from Myra.
BIB Blocked IP Blocklist The request was blocked using the IP blocklist.
BJS Blocked Java Spring The request was identified as a Spring4Shell attack and blocked.
BMP Blocked Myra Page The Myra page for blocked requests was delivered.
BNL Blocked Network Layer The request was blocked at the network level.
BPP Blocked Protected Page The Myra page for an unknown host header was delivered.
BRF Blocked Request Fingerprint The requester was blocked due to high fingerprint activity.
BRL Blocked Request Limiter The request was blocked by Myra’s Request Limiter.
BSM Blocked sqlmap The request came from the sqlmap SQL injection tool and was blocked.
BSS Blocked Shellshock The request targeted the Shellshock security vulnerability and was blocked.
BTI Blocked Threat Intelligence The request was blocked by Myra Threat Intelligence.
BTN Blocked TOR Network The request came from the Tor network and was blocked.
BVH Blocked Verify Human The request was answered with a CAPTCHA query that was triggered by a WAF rule stored with Myra.
BW Blocked WAF The request was blocked by a WAF rule stored with Myra.
BWL Blocked Rate Limit WAF The request was blocked by a Request Limiter in the WAF.
BWP Blocked WordPress Bot The request came from a malicious WordPress bot and was blocked.
FAB Failed Antibot The client failed verification by the Antibot mechanism.
PAB Passed Antibot The requester passed verification by the Antibot mechanism.
VAB Verifying Antibot The requester is undergoing Antibot verification by Myra.

Allowed requests

Name Definition
ACC Allowed Captcha Cookie The request was approved based on a valid CAPTCHA cookie.
ACS Allowed Captcha Success The request was approved because the CAPTCHA was successfully solved.
AW Allowed WAF The request was allowed by the Web Application Firewall (WAF).
AWL Allowed allowlist The request was allowed due to an existing entry on the Allowed list.

Informative

Name Definition
BWR WAF Redirect The request was redirected by a WAF rule
DPE Detected Pcore Bot A request was classified as a Pcore bot.
DRL Detected Request Limiter A request is in the Request Limiter area but below the burst limit.
DWP Detected WordPress Bot A request was classified as a WordPress bot.
LW Logged WAF A request matches a WAF rule stored with Myra and was logged.