Source

AWS WAF

Monitor requests to protect web applications and APIs against common exploits

The AWS Web Application Firewall helps protect web applications and APIs against common web exploits by monitoring the HTTP and HTTPS requests forwarded to other Amazon services. You can use predefined Managed Rules (which are regularly updated to block new threats) and/or write your own security rules. Pricing is based on how many rules you deploy, and on your volume of incoming web requests.

How to get data flowing

This integration is facilitated through Cribl Stream’s Amazon Kinesis Firehose Source.

  • Configure AWS WAF to send logs from your web ACL (access control list) to an Amazon Kinesis Data Firehose.

  • Configure Stream to read data from Firehose via Sources > Amazon Firehose.

  • Specify the IP address, port, authorization tokens, and any TLS credentials to use when connecting to Amazon Firehose.

  • Stream will start fetching data as the Firehose stream becomes available.

Cribl, the Data Engine for IT and Security, empowers organizations to transform their data strategy. Customers use Cribl’s suite of products to collect, process, route, and analyze all IT and security data, delivering the flexibility, choice, and control required to adapt to their ever-changing needs.

We offer free training, certifications, and a free tier across our products. Our community Slack features Cribl engineers, partners, and customers who can answer your questions as you get started and continue to build and evolve. We also offer a variety of hands-on-Sandboxes for those interested in how companies globally leverage our products for their data challenges.