Skip to content

Imperva WAF Gateway

You can integrate Imperva WAF Gateway with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Imperva WAF Gateway product overview

Imperva WAF Gateway is an enterprise-level web application firewall designed to protect critical applications and APIs across diverse environments, combining advanced intelligence with high-efficacy threat detection and mitigation.

What we ingest

Sophos XDR collects Imperva WAF Gateway syslog data by listening for messages your WAF forwards to a Sophos XDR data collector. The following log categories are collected:

  • Web application firewall alerts: Security violations the WAF detects and acts on for web traffic, including the HTTP request detail and the alert.

Event and data types

We ingest the following event and data types from Imperva WAF Gateway:

  • Web application firewall alerts: Security violations the WAF raises on web traffic, spanning signature, protocol, correlation, and custom violations (such as SQL injection and cross-site scripting), including the alert type, severity, action, attacked application, source, and HTTP request detail. Normalized to HTTP and third-party security alert telemetry.

Data provided by this integration

Data provided by Imperva WAF Gateway gets normalized to the following schemas:

  • http
  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation