Skip to main content
AWS Web Application Firewall Add-on app icon

AWS Web Application Firewall Add-on

The purpose of this add-on is to provide value to your AWS Web Application Firewall (WAF) logs. This is done by making the logs CIM compliant, adding tagging for Enterprise Security data models, and other knowledge objects to make searching and visualizing this data easy. This add-on also provides a concise guide for how to get your AWS WAF logs into Splunk using AWS Kinesis Firehose (see README for more details).Built by Hurricane Labs
splunk product badge

Default Version 1.0.6

December 16, 2025

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 6.x, 5.x, 4.x

Rating
4
(4)

Log in to rate this app

Support
Not Supported

The purpose of this add-on is to provide value to your AWS Web Application Firewall (WAF) logs. This is done by making the logs CIM compliant, adding tagging for Enterprise Security data models, and other knowledge objects to make searching and visualizing this data easy. This add-on also provides a concise guide for how to get your AWS WAF logs into Splunk using AWS Kinesis Firehose (see README for more details). +Built for Splunk Enterprise 6.x.x and higher +CIM Compliant (CIM 4.0.0 or higher) +Ready for Enterprise Security +Built around JSON format from AWS Kinesis Firehose ++https://docs.splunk.com/Documentation/AddOns/released/Firehose/ConfigureFirehose ++https://docs.aws.amazon.com/waf/latest/developerguide/logging.html