Deny All WAF Analytics

Deny All WAF Dashboards

Adding the Deny All WAF Dashboard

  1. Go to Settings >> Knowledge Base >> Dashboards.

  2. Select VENDOR DASHBOARD from the drop-down.

  3. Click the Use icon from Actions.

Dashboard

Adding the Deny All WAF Dashboard

  1. Click Choose Repos.

Deny All WAF Ask Repos Panel

Selecting Repos

  1. Select the repo and click Done.

Deny All WAF Ask Repos Panel

Selecting Repos

  1. Click Ok.

You can find the LP_Deny All Web Application Firewall dashboard under Dashboard.

Confirmation for Repo

Deny All WAF Dashboard

Confirmation for Repo

Deny All WAF Dashboard

LP_Deny All Web Application Firewall Dashboard

Widgets available in the dashboard LP_Deny All Web Application Firewall provide:

Widget Name

Description

Top 10 Source Address

An overview of the top 10 source addresses detected by Deny All WAF.

Top 10 Firewall Rule

An overview of the top 10 firewall rules included in Deny All WAF.

Firewall Request Rejection Reason

An overview of the reasons for firewall requests rejection by Deny All WAF.

Firewall Request Rejection - list

An overview of the lists of reasons to reject firewall requests.

Top 10 Messages

An overview of the top 10 messages detected by Deny All WAF.

Top 10 Sources in SQL Injection Attack

An overview of the top 10 SQL Injection attack source addresses detected by Deny All WAF.

Top 10 Countries in SQL Injection Attack

An overview of the top 10 countries from where the SQL Injection Attack originated.

SQL Injection Details

An overview of the SQL Injection attack details (sources, type of threats, country).

Deny All WAF Alerts

Alerts available in the LP_Deny All WAF are:

DenyAllWAF SQL Injection Attack

  • Trigger condition: A SQL injection attack is detected.

  • ATT&CK Category: Initial Access

  • ATT&CK Tag: Exploit Public-Facing Application

  • ATT&CK ID: T1190

  • Minimum Log Source Requirement: DenyAll WAF

  • Query:

norm_id=DenyAllWAF label=SQL label=Injection

Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support