Skip to content

Web Application Firewall Logging / Reporting

Description

Every dynamic website—and online shops in particular—features a multitude of URLs with numerous parameters that must be tested against Web Application Firewall (WAF) rules. Are attacks reliably detected, or are legitimate requests being blocked? With our service, you know exactly which attacks against your application Web Application Firewall has prevented. Gain useful insights into the origin, type, and frequency of attacks to continuously refine your defense strategy. You can also identify so-called "false positives"—requests erroneously blocked by a rule that should have been allowed through. Since there can be many reasons for this, analyzing log files is crucial to avoid losing revenue. While a customer whose request is blocked receives an error message with a support ID they can use to contact your support team, not all customers do so, potentially resulting in lost sales. Our reporting provides a quick overview featuring valuable statistics and a complete list of all blocked requests. This allows you to quickly and reliably identify when a legitimate request to your application has been blocked. You can then promptly adjust the rule, improving customer satisfaction. We capture your WAF events on a separate virtual server. Your setup is not burdened by this task, ensuring your application maintains its full performance. You gain access to a standardized dashboard that allows you to analyze the data in near real-time.

What we aim to achieve with this service

  • Providing details on blocked requests
  • Making it easier for you to adjust the rule set
  • Supporting the implementation of additional defensive measures
  • Reducing "false positives" when blocking requests to prevent potential revenue loss
  • Reliably identifying and allowing legitimate requests
  • Ensuring customer satisfaction through an uninterrupted user experience

What you can expect from our logging

  • Data retention for the last 30 days
  • Provision of data with detailed information on each request

What you can expect from our reporting

  • Customizable analysis period within the retention timeframe
  • Charts showing daily figures for the month:
  • Top 10 requests by URL
  • Top 10 requests by security policy
  • Requests by status
  • Top 10 security policies
  • Top violations (by percentage and over time)
  • Top attack types (by percentage and over time)
  • Number of requests by severity and over time
  • Top client countries and request counts over time

Optional service feature

  • Redundant log servers configured as a cluster for increased availability
  • Extended data retention period

FAQ

Can I customize the dashboard?

To make new features available to all customers as quickly as possible, we do not offer individual customization for specific customers. Updates are rolled out to all setups and will overwrite any custom changes. However, you can commission a custom installation. This solution is tailored precisely to your needs. Please contact our sales team and specify that you would like a central log server (#SAE.ZLS) for your setup.

Important Notes

  • Use of the dashboard outside your setup, or sharing it with third parties, is not permitted.
  • We offer Web Application Firewall logging and reporting as a managed service. You can find further information and details about our managed services on our website.