ImpervaWAFCloud_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index


Attribute Value
Custom Log V1 Yes 🔶 — uses type-suffixed column names
Supports Transformations ✓ Yes
Ingestion API Supported ✓ Yes
Lake-Only Ingestion ✓ Yes (source)

Contents

Schema (38 columns)

Source: KQL validation test schema

Column Name Type
act_s string
app_s string
CapSupport_s string
ccode_s string
cicode_s string
clapp_s string
clappsig_s string
cn1_s string
COSupport_s string
cpt_s string
Customer_s string
deviceExternalId_s string
deviceFacility_s string
dproc_s string
end_s string
EventProduct_s string
EventType_s string
EventVendor_s string
fileId_s string
latitude_s string
longitude_s string
postbody_s string
qstr_s string
request_s string
requestClientApplication_s string
requestMethod_s string
severity_s string
sip_s string
siteid_s string
sourceServiceName_s string
spt_s string
src_s string
start_s string
suid_s string
TimeGenerated datetime
ver_s string
VID_g string
xff_s string

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Imperva Cloud WAF

Content Items Using This Table (21)

Analytic Rules (10)

In solution ImpervaCloudWAF:

Analytic Rule Selection Criteria
Imperva - Abnormal protocol usage
Imperva - Critical severity event not blocked
Imperva - Forbidden HTTP request method in request
Imperva - Malicious Client
Imperva - Malicious user agent
Imperva - Multiple user agents from same source
Imperva - Possible command injection
Imperva - Request from unexpected IP address to admin panel
Imperva - Request from unexpected countries
Imperva - Request to unexpected destination port

Hunting Queries (10)

In solution ImpervaCloudWAF:

Hunting Query Selection Criteria
Imperva - Applications with insecure web protocol version
Imperva - Non HTTP/HTTPs applications
Imperva - Rare applications
Imperva - Rare client applications
Imperva - Rare destination ports
Imperva - Top applications with error requests
Imperva - Top destinations with blocked requests
Imperva - Top sources with blocked requests
Imperva - Top sources with error requests
Imperva - request from known bots

Workbooks (1)

In solution ImpervaCloudWAF:

Workbook Selection Criteria
Imperva WAF Cloud Overview

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
ImpervaWAFCloud ImpervaCloudWAF

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index