To conclude - I give up. It's obvious that you do not understand or that I express myself in a way that you do not comprehend. My first and original question was how to form a rule to get Ninja Forms to work, to be allowed to run. I just wanted to know how such a rule should be written in order to let ajax-admin.php go be executed without interference from the firewall in Nginx.
I was then asked to provide you with the the information in the "interception log" and although I have asked numerous of times where to find that information - as in where in the firewall that log file is to be found (the free firewall) I still have not gotten an answer of my first question or where to find the "Interception log".
For anyone that might run into the same problem I have asked for help elsewhere and gotten the tip to change the rule :
select.+(from|limit)
to:
\bselect\b(?=.*\b(from|limit)\b)
I have not yet tried that solution but it is a suggestion for a solution. My question, and not for you this time, is if anyone else can verify that this might work?
I am not, as I have said several times, not the most technical skilled person but I do find my way around computers. This a rule for the free firewall, in Nginx, in Appanel.