Imperva Cloud WAF
You can integrate Imperva Cloud WAF with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Imperva Cloud WAF product overview
Imperva Cloud WAF is a cloud-based (SaaS) web application firewall that protects web applications and APIs in real time against OWASP Top 10 threats such as SQL injection and cross-site scripting, combining bot protection, API security, and DDoS mitigation, delivered from Imperva's global points-of-presence network.
What we ingest
Sophos XDR collects Imperva Cloud WAF logs from an Amazon S3 bucket: you configure Imperva's near-real-time SIEM log integration to forward logs to an S3 bucket in JSON format, then deploy a Lambda function that forwards them to Sophos XDR. The following log categories are collected:
- Security alerts: Account takeover, client-side protection, and DDoS attack detections.
- Audit activity: Account audit-trail and DDoS configuration events.
- Authentication: Administrative sign-in events.
Event and data types
We ingest the following event and data types from Imperva Cloud WAF:
- Security alerts: Imperva Cloud WAF detections including account takeover (ATO), client-side protection, and DDoS attack events, with the detection and affected application. Normalized to third-party security alert telemetry.
- Audit activity: Account audit-trail activity and DDoS protection configuration events, with the actor and action. Normalized to cloud audit telemetry.
- Authentication: Administrative sign-in events from the audit trail, with the user and result. Normalized to authentication telemetry.
Data provided by this integration
Data provided by Imperva Cloud WAF gets normalized to the following schemas:
authcloudauditthirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.