Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 2 Next »

About the Device

Imperva, cloud-based website security solution features the industry’s leading WAF technology and provides strong two-factor authentication and bot access control. Imperva’s advanced client classification engine analyzes all incoming traffic to protected site, preventing access to malicious and unwanted visitors.

Device Information

 Entity

Particulars

Vendor Name

Imperva

Product Name

Cloud Web Application Firewall

Type of Device

Cloud

Collection Method

Log Type

 Ingestion label

Preferred Logging Protocol

Log Collection Method

Imperva CEF

IMPERVA_CEF

API Pull

CyberHub

Device Configuration

To configure log integration

  1. Sign in to your my.imperva.com account and navigate to the WAF Logs Setup 

  2. On the top menu bar, click Account > Account Management.

  3. On the sidebar, click SIEM Logs > WAF Log Setup.

  4. Click Activate logs.

To obtain API URL, API Key and API ID

  1. Sign in to your Imperva Cloud WAF console.

  2. On the sidebar, click Logs > Log Setup.

  3. For Connection. Select Imperva API.

From this window copy and keep API Key handy, this will be required for further Integration configuration.
Copy API ID and Log Server URI.

  1. Configure the additional options:
    Select the Format for the log files as CEF
    Compress logs: By default, log files are compressed.

  2. Click Save 

  3. On the sidebar, click Log Levels.

  1. Select a log level for each site to enable logging or leave disabled. There are two levels of logs:
    a) Security Logs include the Imperva security events log.
    b) All Logs comprises a comprehensive log of every request and response (access logs), as well as the security events log. (Select All Logs)

Logs are typically synchronized within 10 minutes, although it may take up to 30 minutes or more depending on system load.

Integration Parameters

Property

Default Value

Description

Log Server URL

https://logs1.incapsula.com/<Repo_ID>

URL generated in Log Configuration section, Shared by customer.

API ID

 Custom Value

API ID Shared by Customer.

API Key

 Custom Value

API Key Shared by Customer.

  • No labels