I do write a node.js script that check my website, if the total requests for the past 24 hours more than 2m requests then it will auto turn on managed challange to block some attack, but this isnt the best option so i need to find some rule that work best for my site. I do search the web for ‘setup rule anti ddos cloudflare‘ but it doesnt give me much info so if you know how to setup waf, please help me. Thanks.
In my experience, only enabling “I’m under attack” mode truly blocks HTTP attacks. Even though the traffic patterns are very abnormal, Cloudflare really doesn’t care and will just forward everything.
The guides that @Oxy shared can help. But maybe you also just need to realize that Cloudflare isn’t the be-all-end-all solution to stopping any and all attacks.