This is normally a reverse-proxy to tomcat. If you see this, the @tomcat_path_traversal_exploit is not applied. http.request.orig_uri.path: /