AWS WAF

Connecting AWS WAF logs to your Panther Console

Overview

Panther supports ingesting Amazon Web Services (AWS) Web Application Firewall (WAF) logs via AWS S3.

How to onboard AWS WAF logs to Panther

To pull WAF logs into Panther, you will need to set up an S3 bucket in the Panther Console to stream data from your AWS account.

  1. In the lefthand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search "AWS" to see the list of available log sources.

  4. Select AWS WAF Web ACL.

  5. Select AWS S3 bucket for your source to begin setup. Follow Panther’s documentation for configuring S3 for Data Transport.

Panther-built detections

See Panther's prewritten AWS rules in the panther-analysis Github repository.

Supported AWS WAF logs

AWS.WAFWebACL

WAFWebACL logs represent web access control list (ACL) traffic information. For more details, see AWS's documentation on logging web ACL traffic.

Last updated

Was this helpful?