The purpose of this add-on is to provide value to your AWS Web Application Firewall (WAF) logs. This is done by making the logs CIM compliant, adding tagging for Enterprise Security data models, and other knowledge objects to make searching and visualizing this data easy. This add-on also provides a concise guide for how to get your AWS WAF logs into Splunk using AWS Kinesis Firehose (see README for more details). +Built for Splunk Enterprise 6.x.x and higher +CIM Compliant (CIM 4.0.0 or higher) +Ready for Enterprise Security +Built around JSON format from AWS Kinesis Firehose ++https://docs.splunk.com/Documentation/AddOns/released/Firehose/ConfigureFirehose ++https://docs.aws.amazon.com/waf/latest/developerguide/logging.html
(0)
Categories
Created By
Type
Downloads
Licensing
Splunk Answers
Resources