You can view the evasion technique violations logged by the BIG-IP ASM system:-
Log in to the Configuration utility.
Navigate to Security > Event Logs > Application > Requests.
From the Security Policy menu, select the security policy.
In the filter details, select Evasion Technique Detected from the Violation menu.
Click Go.
To view the reason the violation was triggered, select the Evasion technique detected.
Also you can increase or decrease the number of decoding passes that the system attempts to achieve normalization before a violation will be triggered. For example, setting this value to 2 triggers a violation if more than one pass is required to decode the entity, allowing only single-encoded entities.
Refer to the below article
https://support.f5.com/csp/article/K7929
Hope this is helpful!