Bot Detection Action

Monitor and analyze possible bot behavior within your network environment, rather than directly blocking the connection, you can specify whether to “Block” or “Monitor” an action when a bot detection rule has been matched.

HTTP > Advanced Threat Protection > Policies | Policy List | Bot Detection Rules

Set the action IWSVA will take when detecting bot activity. Choose between blocking or monitoring the bot and click Save. The typical behavior would be to Block the bot. You should only choose to Monitor a bot when you want to analyze or monitor it's behavior.

As with all Web Reputation policies, you have the ability to Add, Delete, Modify, or Deploy a Bot/C&C Callback Attempt Detection policy.