September 6, 2026
Radware CWAAP Event Collector
Collects the Radware CWAAP portal audit (user-activity) log, plus WAF and Web DDoS security events for existing API-based deployments, via the Radware Cloud API. For security events in new deployments, Radware recommends CWAAP Log Exporter (S3, Azure Blob or SFTP) with the matching Splunk input.Built by sean ramatiSplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3
Log in to rate this app
This Splunk add-on collects Radware Cloud Application Protection (CWAAP) data through Radware's official Cloud API and indexes it as JSON events: the portal audit log (user activity: logins, configuration changes and other administrative actions), WAF security events (APPWALL_REPORTS) and Web DDoS security events (L7_DDOS_ATTACK_REPORT). Each input can collect any combination of the three, including audit only, which is the migration path for users of the legacy Radware CWAF Event Collector (app 5281) who need user-activity logs from the new CWAAP portal. Recommended use: this add-on is the way to bring the portal audit log into Splunk; that log is available through the API only. For WAF and Web DDoS security events in new deployments, Radware recommends CWAAP Log Exporter, which delivers files to Amazon S3, Azure Blob Storage or SFTP, together with the matching Splunk input, instead of API polling. The WAF and WebDDoS log types remain available for existing API-based deployments. The add-on includes duplicate-safe checkpointing, chunked catch-up after outages, proxy support, a one-time history back-fill and a monitoring dashboard. It runs on Splunk Enterprise 9.3 or later and on Splunk Cloud Platform (vetted for Victoria and Classic). See the Installation tab for deployment guidance.
Log in to report this app listing.