...
An analyst wants to detect malicious network traffic in web applications. Using the WAF ACL SQS collector to send firewall logs to Devo, the analyst will find malicious IP activity. As a result, the analyst will use Access Control Lists to block the traffic, preventing attackers from cross-site scripting.
...
Authorize SQS Data Access.
For this service, the bucket name must start with
aws-waf-logs-
.
In WAF, select a Web ACL.
Select “Logging” and “Enable.”
Set the destination to the S3 bucket previously authorized.
Run It
In the Cloud Collector App, create an SQS Collector instance using this parameters template, replacing the values enclosed in < >
.
...