Skip to content

AWS WAF logs

You can integrate AWS Web Application Firewall (WAF) logs with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

AWS WAF logs product overview

AWS WAF is a managed web application firewall that protects websites, APIs, and applications from bots, exploits, and Layer 7 attacks, letting you create rules that block common attack patterns such as SQL injection and cross-site scripting.

What we ingest

Sophos XDR collects AWS WAF logs from an Amazon S3 bucket: you deploy a CloudFormation template that provisions a Lambda function, which forwards web ACL log files to Sophos XDR as they are delivered to the bucket. The following log categories are collected:

  • Web ACL activity: AWS WAF web request logs and the actions taken.

Event and data types

We ingest the following event and data types from AWS WAF logs:

  • Web ACL activity: AWS WAF web request events from web ACL logging, including the request detail, matched rule, and terminating action (allow, block, CAPTCHA, or challenge). Normalized to HTTP telemetry.

Data provided by this integration

Data provided by AWS WAF logs gets normalized to the following schemas:

  • http

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation