Connect data from Microsoft web application firewall
You can stream logs from the Azure Application Gateway’s Microsoft web application firewall (WAF). This WAF protects your applications from common web vulnerabilities such as SQL injection and cross-site scripting, and lets you customize rules to reduce false positives. Follow these instructions to stream your Microsoft Web application firewall logs into Azure Sentinel.
Prerequisites
- An existing application gateway resource
Connect to Microsoft web application firewall
If you already have Microsoft web application firewall, make sure you have an existing gateway resource. Once your Microsoft web application firewall is deployed and getting data, the alert data can easily be streamed into Azure Sentinel.
- In the Azure Sentinel portal, select Data connectors.
- In the Data connectors page, select the WAF tile.
- Go to Application Gateway resource and choose your WAF.
- Select Diagnostic settings.
- Select + Add diagnostic setting under the table.
- In the Diagnostic settings page, type a Name and select Send to Log Analytics.
- Under Log Analytics Workspace select the Azure Sentinel workspace.
- Select the log types that you want to analyze. We recommended: ApplicationGatewayAccessLog and ApplicationGatewayFirewallLog.
- To use the relevant schema in Log Analytics for the Microsoft web application firewall alerts, search for AzureDiagnostics.
Next steps
In this document, you learned how to connect Microsoft web application firewall to Azure Sentinel. To learn more about Azure Sentinel, see the following articles:
- Learn how to get visibility into your data, and potential threats.
- Get started detecting threats with Azure Sentinel.
Feedback
Loading feedback...