UpPrevious Next
Sheriff CSMâ„¢
DenyAll Web Application Firewall (WAF)
When you configure DenyAll Web Application Firewall (WAF) to send log data to Sheriff CSM, you can use the DenyAll Web Application Firewall plugin to translate raw log data into normalized events for analysis. The table below provides some basic information for the plugin:
Plugin Information
Device | Details |
Vendor | DenyAll |
Device Type | Web Application Firewall |
Connection Type | Syslog |
Data Source Name | Denyall-waf |
Data Source ID | 1922 |
Integrating DenyAll WAF
Before you configure the DenyAll WAF integration, you must have the IP Address of the Sheriff CSM Sensor (Deputy).
To configure DenyAll WAF to send Syslog messages to Sheriff CSM
- Log in to the DenyAll web UI.
-
From the top menu, select Management > Alerting.
-
From the left-side menu, select Alerting Profiles.
-
Click Add and then enter the following information in the dialog box that appears:
- Facility: Select the facility to use to log messages.
- Host: Enter the Sheriff CSM IP Address.
- Name: Enter a name for the new alerting profile.
- Port: Enter 514.
- Protocol: Enter UDP.
- Severity: Select the desired severity level for messages to be returned.
- Type: Select Syslog.
-
Click OK to close the dialog box.
-
From the left-side menu, select Logs Alerting configurations.
-
Click Add and then enter the following information into the dialog box that appears:
- Name: Enter a profile name.
- Frequency: Select the frequency of alert reporting.
- Format: Select Default.
- Destinations: Select <profile_name>(syslog).
-
Ensure that Send security logs and Send IAM logs options are both selected.
- Click OK to close the dialog box.
Plugin Enablement
For plugin enablement information, see
Enable Plugins.
Additional Resources and Troubleshooting
https://www.denyall.com/products/web-application-firewall/
https://www.denyall.com/resources/glossary/
For troubleshooting, see the vendor documentation.