Stream WAF events to a SIEM
Create a stream that sends the requests WAF analyzed to your SIEM, in Azion Console or with the Azion API, and confirm the delivery.
You can send the events of Web Application Firewall (WAF) to a security information and event management (SIEM) platform from Azion Console or with the Azion API. To send the requests of your applications without WAF data, refer to Endpoints and the guide of your endpoint.
A Data Stream stream reads the WAF Events data source and shapes each event with the WAF Event Collector template. Each log line carries the score the request received, the WAF rules it matched, the attack family, and the action WAF took. For every variable, refer to WAF Events.
The example sends the events to an Apache Kafka topic that your SIEM reads. In the stream form, the endpoint is set in the field labeled Connector.
Select your interface once. The prerequisites and every task below show only that path.
Prerequisites
- An Azion account with the Edit Data Stream permission. For the permissions, refer to Stream settings.
- Firewall with WAF on the account, protecting a workload that receives requests. To set up WAF, refer to the WAF quickstart.
- An endpoint that your SIEM reads. This guide uses an Apache Kafka cluster, with the host and port of its servers for the initial connection and the name of one topic. For the other endpoints a stream can send to, refer to Endpoints.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Create the stream
The stream collects the WAF events of the workload you choose, through a workload filter. Unlike sampling, a workload filter leaves your other streams active.
To create the stream with the API, send a POST request to https://api.azion.com/v4/workspace/stream/streams. Replace [TOKEN VALUE] with your personal token, <workload-id> with the ID of your workload, and the cluster values with your own:
The waf data source is WAF Events in the Console, and template 4 is WAF Event Collector. The API requires kafka_topic and use_tls: send true to encrypt the events with TLS, or false to send them unencrypted. A 201 answer carries the stored stream under data. Keep its id: it identifies the stream in every later request, such as /v4/workspace/stream/streams/<stream-id>. For every key of the body, refer to Stream settings.
Saving the stream checks the format of each field and does not contact the cluster. A wrong server address or topic surfaces only when the stream sends. An activation takes effect after one to two minutes.
Confirm the delivery
Real-Time Events records every send of a stream, delivered or not, with the status code the endpoint returned. Send a few requests to the workload that WAF analyzes, then wait about a minute. A stream sends a batch every 60 seconds, or sooner when it reaches 2,000 log lines.
To read the sends with the API, query the dataStreamedEvents dataset of the Real-Time Events GraphQL API. Replace the dates with a range that covers the activation of the stream:
The API answers 200 with one record for each send, the latest first. For a stream that sends to S3, a record reads as below. Your records carry the type of your endpoint in endpointType:
A statusCode of 200 means the endpoint accepted the batch, whose size streamedLines gives in log lines and dataStreamed in bytes. An empty dataStreamedEvents list means the stream has not sent in the range. For every field, refer to Real-Time Events GraphQL fields.
A status other than 200 is the answer of the endpoint, and 503 means Data Stream found the endpoint unavailable. For the causes, refer to Troubleshoot Data Stream.
At the SIEM, each log line carries the keys of the WAF Event Collector template. Read these keys to check that the events are the ones WAF analyzed:
waf_attack_actionholds the action WAF took, such as$BLOCKor$PASS.waf_attack_familyholds the class of the infraction, such asSQLorXSS.waf_scoreandwaf_matchhold the score of the request and the infractions it matched.blockedreads1when WAF blocked the request. Whilewaf_learningreads1, WAF blocks no request.
To correlate these events with the request data of your applications in one log line, use the Applications data source with the Applications + WAF Event Collector template instead. For the tradeoff, refer to Best practices for Data Stream.