[ Web Proxy ]
URL:
Viewing: https://developers.cloudflare.com/waf/managed-rules/check-for-exposed-credentials/monitor-events/ [Back]  [Original]

Monitor exposed credentials events Cloudflare Web Application Firewall (WAF) docsSkip to content
SearchCtrlKLog in
  1. Home
  2. /WAF
  3. /
  4. /Check for exposed credentials
  5. /Monitor exposed credentials events

Monitor exposed credentials events

Last updated Apr 16, 2026Copy as MarkdownView as MarkdownAgent setup
OverviewImportant notes

Deprecation notice

Exposed credentials check has been deprecated.

Switch from exposed credentials check to leaked credentials detection for improved security. To upgrade your current configuration, refer to the upgrade guide.

Sampled logs in Security Events shows entries for requests with exposed credentials identified by rules with the Log action.

Check for exposed credentials events in the Security Events dashboard, filtering by a specific rule ID. For more information on filtering events, refer to Adjust displayed data.

Important notes

Exposed credentials events are only logged after you activate the Exposed Credentials Check Managed Ruleset or create a custom rule checking for exposed credentials.

The log entries will not contain the values of the exposed credentials (username, email, or password). However, if matched payload logging is enabled, the log entries will contain the values of the fields in the rule expression that triggered the rule. These values might be the values of credential fields, depending on your rule configuration.

PreviousTest your configurationNextUpgrade to leaked credentials detection

Was this helpful?

YesNo
Edit pageReport issue
[]

Web Proxy Viewer  |  New URL  |  Original Page