In some cases, Microsoft Exchange Autodiscover service requests can be "noisy", triggering large numbers of HTTP 404 (Not found) errors.
This example custom rule blocks requests for autodiscover.xml and autodiscover.src:
-
When incoming requests match:
Use the expression editor:
(ends_with(http.request.uri.path, "/autodiscover.xml") or ends_with(http.request.uri.path, "/autodiscover.src")) -
Then take action: Block
Alternatively, customers on a Business or Enterprise plan can use the matches comparison operator for the same purpose. For this example, the expression would be the following:
(http.request.uri.path matches "/autodiscover.(xml|src)$")