It's important to filter data types and allow only what you can actually use. Bots always search for files like .zip or .sql that could contain private or security information. For this, we identify first that it's a URI path with a dot (http.request.uri.path contains ".") and then by exclusion we define what we want to allow, by adding a negative match.
With this approach, it's very important to check often if you might use any data type that is not on the list and firewall will block false positives.
I don't include on allow list .txt and .xml, why? Because .txt is the main source of information for hackers on what version of theme/plugin you're using, therefore they can detect vulnerabilities and exploit them. Robots.txt, ads.txt and similar should be whitelisted if you don't set in Allow rulest known bot to get unrestricted access.
XML as well is very often used to identify pages that you can't crawl into and provides information for a hacker or malicious crawlers. Therefore I never allow unknown bots to access it, and I recommend making sure that for known bots you whitelist access by adding the path to Allow ruleset.
Data type .html in WordPress is not used, and accessing it will only required linke for Google or Pinterest for domain authorization purposes. ".html" should be whitelisted for known bots
(http.request.uri.path contains "." and not ends_with(http.request.uri.path, ".php") and not ends_with(http.request.uri.path, ".aac") and not ends_with(http.request.uri.path, ".css") and not ends_with(http.request.uri.path, ".eot") and not ends_with(http.request.uri.path, ".gif") and not ends_with(http.request.uri.path, ".jpeg") and not ends_with(http.request.uri.path, ".jpg") and not ends_with(http.request.uri.path, ".js") and not ends_with(http.request.uri.path, ".less") and not ends_with(http.request.uri.path, ".mp3") and not ends_with(http.request.uri.path, ".mp4") and not ends_with(http.request.uri.path, ".ogg") and not ends_with(http.request.uri.path, ".otf") and not ends_with(http.request.uri.path, ".pdf") and not ends_with(http.request.uri.path, ".png") and not ends_with(http.request.uri.path, ".svg") and not ends_with(http.request.uri.path, ".ico") and not ends_with(http.request.uri.path, ".ttf") and not ends_with(http.request.uri.path, ".webp") and not ends_with(http.request.uri.path, ".woff") and not ends_with(http.request.uri.path, ".woff2"))