Imperva Cloud WAF

Connect Imperva Cloud WAF to Radiant Security to forward security and access logs for AI triage.

Imperva Cloud WAF is a cloud-delivered web application firewall that protects internet-facing applications from threats such as SQL injection, cross-site scripting, credential stuffing, automated bot abuse, and volumetric DDoS attacks. Connecting Imperva Cloud WAF forwards security and access logs to Radiant Security via Amazon S3. Radiant uses these logs to correlate external attack attempts against your web applications with downstream identity, endpoint, and authentication signals during AI triage, giving analysts the full attack chain behind every alert.

This integration supports all Imperva Cloud Application Security services, including Cloud WAF, Attack Analytics, Advanced Bot Protection, Account Takeover Protection, Client-Side Protection, and DDoS Protection. Customers who used Imperva's legacy Incapsula product configure the integration the same way.

Prerequisites

Configure Imperva Cloud WAF

For full vendor instructions, see Imperva SIEM Log Configuration.

1

Add the S3 connection in Imperva

  1. On the top menu bar, click Account > Account Management.

  2. Navigate to SIEM Logs > Log Configuration.

  3. Click Add Connection and select Amazon S3 as the storage type.

  4. Configure the connection:

    • Connection Name: Radiant Security S3

    • Access Key: your AWS Access Key ID with s3:PutObject permission

    • Secret Key: your AWS Secret Access Key

    • Path: your bucket name with a prefix (e.g., your-bucket-name/cloudwaf)

    • Format: select .cef if available

    • Compress logs: select Yes if available

  5. Click Test Connection to verify, then click Save.

2

Enable logging for subscribed services

The available services in this section depend on your Imperva subscription. If the section is not visible, skip this step.

  1. In the Connections table, expand the connection you created and click Edit.

  2. For every service listed under Select Services, set:

    • Log Types: all available log types

    • Format: select .json or .cef (preferably .json)

    • State: Enabled

  3. Click Save.

3

Record your configuration details

You will need the following values when you set up the Radiant side:

  • S3 bucket name

  • S3 bucket path or prefix (e.g., imperva/ or cloudwaf/)

  • AWS region where your bucket is located

Configure S3 and add the data connector in Radiant Security

Now that Imperva is writing logs to your S3 bucket, complete the setup by following the Configure Amazon S3 to forward logs to Radiant Security guide. That guide walks through:

  1. Configuring the bucket policy and creating an SNS topic.

  2. Adding the Amazon Web Services S3 data connector in Radiant Security.

  3. Configuring S3 event notifications so new objects trigger ingestion.

Verify ingestion

After Imperva Cloud WAF begins forwarding, confirm events are reaching Radiant.

  1. In Radiant, navigate to Log Management.

  2. Filter by rs_connectorType:"imperva_cloud_waf".

  3. Confirm recent events appear.

Allow several minutes for events to be parsed, indexed, and available for search.

Last updated

Was this helpful?