AWS WAF (v1.0.22)

Amazon Web Services Web Application Firewall (WAF)

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Categories
Network Security

Integrations (1)

Modeling rules (1)

Parsing rules (1)

README

AWS WAF

This pack includes Cortex XSIAM content.

<~XSIAM>

Configuration on Server Side

Collect Events from Vendor

In order to use the collector, use the Amazon S3 collector.

Amazon S3

To create or configure the Amazon S3 collector, use the information described here.

  1. Navigate to Settings > Configuration > Data Sources > Amazon S3.
  2. Press Add New Istance.
  3. Fill in the following parameters:

| Field Name | Description | Value |
|——————-|—————————————————————————————————-|——————-|
| SQS URL | The ARN of the Amazon SQS that you configured in the AWS Management Console. | <YourSQSURL> |
| Name | A descriptive name for your log collection configuration. | <InstanceName> |
| AWS Client ID | The access key ID, which was received when configuring access keys for the AWS IAM user in AWS. | <AWSClientID> |
| AWS Client Secret | The secret access key, which was received when configuring access keys for the AWS IAM user in AWS. | <AWSClientSecret> |
| Log Type | Select Generic to configure your log collection to receive generic logs from Amazon S3. | Generic |
| Log Format | Select the log format type as JSON. | Json |
| Vendor | Set as ‘aws’. | aws |
| Product | Set as ‘waf’. | waf |
| Compression | Select ‘gzip’. | gzip |
</~XSIAM>

AWS WAF is a web application firewall service that lets you monitor web requests that are forwarded to an Amazon API Gateway API, an Amazon CloudFront distribution, or an Application Load Balancer.
You can protect those resources based on conditions that you specify, such as the IP addresses that the requests originate from.

What does this pack do

This integration enables you to: