Configure AWS WAF for Arctic Wolf monitoring

You can configure Amazon Web Services (AWS)® Web Application Firewall (WAF)® for Arctic Wolf® monitoring.

WAF logs contain detailed information about the traffic that your web access control list (ACL) analyzes. This information includes the web request timestamp, source, destination, and the action for the matching rule. Arctic Wolf analyzes web ACL logs that result in Block requests to prioritize analyses for high risk web requests.

Note: By default, Arctic Wolf does not alert on WAF events until you indicate that you are ready to receive alerts. As a result, you can make frequent changes to your WAF rules without receiving alerts. When you have configured a stable ruleset, contact your Concierge Security® Team (CST) to enable alerts.

These resources are required:

  • An AWS WAF subscription
  • An active web ACL

These actions are required:

Configure web ACL logging

  1. Sign in to the AWS Management Console with the account that you use to manage web ACLs.
  2. Open the Amazon S3 Console.
  3. In the navigation menu, click Buckets.
  4. Find the S3 bucket that will be used as the destination of your WAF logs.
    Note: Make sure that the name of your S3 bucket starts with aws-waf-logs-. If it does not, create a new S3 bucket with this naming scheme. For more information, see Configure an AWS S3 bucket for Arctic Wolf monitoring.
  5. Complete the steps in Permissions to publish logs to Amazon S3 to publish logs to Amazon S3.

Enable web ACL logging

Tip: For information from Amazon about web ACL logging, see https://docs.aws.amazon.com/waf/latest/developerguide/logging.html.
  1. Sign in to the AWS Management Console with the account that you use to manage web ACLs.
  2. In the navigation menu, click Web ACLs.
  3. Click the name of the web ACL that you want to enable logging for.
  4. On the Logging and metrics tab, in the Logging section, click Enable.
  5. In the Logging destination section, select the logging destination that you configured.
    Note: Make sure to select the S3 bucket that begins with aws-waf-logs-.
  6. Click Save.
    Note: You must enable logging for web ACLs for all regions that a web ACL is present.