AWS WAF logs
You can integrate AWS Web Application Firewall (WAF) logs with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
AWS WAF logs product overview
AWS WAF is a managed web application firewall that protects websites, APIs, and applications from bots, exploits, and Layer 7 attacks, letting you create rules that block common attack patterns such as SQL injection and cross-site scripting.
What we ingest
Sophos XDR collects AWS WAF logs from an Amazon S3 bucket: you deploy a CloudFormation template that provisions a Lambda function, which forwards web ACL log files to Sophos XDR as they are delivered to the bucket. The following log categories are collected:
- Web ACL activity: AWS WAF web request logs and the actions taken.
Event and data types
We ingest the following event and data types from AWS WAF logs:
- Web ACL activity: AWS WAF web request events from web ACL logging, including the request detail, matched rule, and terminating action (allow, block, CAPTCHA, or challenge). Normalized to HTTP telemetry.
Data provided by this integration
Data provided by AWS WAF logs gets normalized to the following schemas:
http
For more information about using schemas in Data Lake Search, see Schemas and logical types.