Short Log4j attack mitigation steps :
Update to the latest version of log4j version 2.17 or higher
Block with WAF [not the best but a first step]
Disable log4j
Patch log4j <<<< IMMEDIATELY >>> >>> use log4j 2.16.0 or higher
Disable JNDI lookups
Disable remote codebases
Check exploitation attempts
Check network perimeter logs to check for indicators of compromise
Configure your IDS to detect attack attempts
Restrict or disable outbound connections.
The Swiss government Cert published the best guidelines: