You use Amazon CloudFront in front of a private content S3 origin. To mitigate an OWASP Top 10 issue, you created a WAF web ACL and associated it to the CloudFront distribution, but attacks are still reaching the origin.
CloudWatch logs show the web ACL rules never match for the CloudFront requests.
What is the most likely configuration mistake?