WAF logs, read today
Web application firewall logs enter the same detection flow as the rest of your estate.

When an analyst confirms a threat, Fabric sends the block to your Stormshield firewall from the same screen. Nothing runs until a person approves it.
An analyst confirms each block. Unblock works the same way.
Commands leave from the Sidecar inside your network, so nothing outside connects in.
Every action records who sent it, when, the target and the commands the firewall received.
Before the block is sent, the analyst sees the target, the firewall that will apply it and who is asking.
Your web application firewall logs are read like any other source, then correlated with endpoint, network and identity events.
Web application firewall logs enter the same detection flow as the rest of your estate.
A blocked web request followed by a successful sign-in becomes one case instead of two separate alerts.
Once an analyst confirms the web attack, Fabric can block the source at your Stormshield firewall.
Web-driven blocks are recorded exactly like every other Fabric action.
| Capability | Status |
|---|---|
| Block or unblock a source on Stormshield SNS | Available |
| Analyst approval before any action | Always on |
| Action audit trail | Available |
| Other firewall brands | Ask us about your firewall |
60-day full-platform trial. No credit card. No inbound firewall changes. Live in under an hour.
Hello. I am iNTelligence, the GhostAnalyst AI assistant. Ask me about our features, pricing, deployment, or how we compare to other SIEM platforms.