Changing the action used for automatic application layer DDoS mitigation
You can change the action that Shield Advanced uses for its application layer automatic response in multiple locations in the console:
Automatic mitigation configuration – Change the action when you configure automatic mitigation for your resource. For the procedure, see the preceding section Enabling and disabling automatic application layer DDoS mitigation.
Event details page – Change the action in the event details page, when you're viewing the event information in the console. For information, see Viewing AWS Shield Advanced event details.
If you have two protected resources that share a web ACL, and you set the action to
Count for one and Block for the other, Shield Advanced sets the action
for the rule group's rate-based rule
ShieldKnownOffenderIPRateBasedRule
to Block.