The AWS Web Application Firewall helps protect web applications and APIs against common web exploits by monitoring the HTTP and HTTPS requests forwarded to other Amazon services. You can use predefined Managed Rules (which are regularly updated to block new threats) and/or write your own security rules. Pricing is based on how many rules you deploy, and on your volume of incoming web requests.
How to get data flowing
This integration is facilitated through Cribl Stream’s Amazon Kinesis Firehose Source.
Configure AWS WAF to send logs from your web ACL (access control list) to an Amazon Kinesis Data Firehose.
Configure Stream to read data from Firehose via Sources > Amazon Firehose.
Specify the IP address, port, authorization tokens, and any TLS credentials to use when connecting to Amazon Firehose.
Stream will start fetching data as the Firehose stream becomes available.