About the Device
Imperva, cloud-based website security solution features the industry’s leading WAF technology and provides strong two-factor authentication and bot access control. Imperva’s advanced client classification engine analyzes all incoming traffic to protected site, preventing access to malicious and unwanted visitors.
Device Information
Entity | Particulars |
---|---|
Vendor Name | Imperva |
Product Name | Cloud Web Application Firewall |
Type of Device | Cloud |
Collection Method
Log Type | Ingestion label | Preferred Logging Protocol | Log Collection Method |
---|---|---|---|
Imperva CEF | IMPERVA_CEF | API Pull | CyberHub |
Device Configuration
To configure log integration
Sign in to your my.imperva.com account and navigate to the WAF Logs Setup
On the top menu bar, click Account > Account Management.
On the sidebar, click SIEM Logs > WAF Log Setup.
Click Activate logs.
To obtain API URL, API Key and API ID
Sign in to your Imperva Cloud WAF console.
On the sidebar, click Logs > Log Setup.
For Connection. Select Imperva API.
From this window copy and keep API Key handy, this will be required for further Integration configuration.
Copy API ID and Log Server URI.
Configure the additional options:
Select the Format for the log files as CEF
Compress logs: By default, log files are compressed.Click Save
On the sidebar, click Log Levels.
Select a log level for each site to enable logging or leave disabled. There are two levels of logs:
a) Security Logs include the Imperva security events log.
b) All Logs comprises a comprehensive log of every request and response (access logs), as well as the security events log. (Select All Logs)
Logs are typically synchronized within 10 minutes, although it may take up to 30 minutes or more depending on system load.
Integration Parameters
Property | Default Value | Description |
---|---|---|
Log Server URL | https://logs1.incapsula.com/<Repo_ID> | URL generated in Log Configuration section, Shared by customer. |
API ID | Custom Value | API ID Shared by Customer. |
API Key | Custom Value | API Key Shared by Customer. |