Collect WAF telemetry today
WAF logs are ingested now, on MVP1. The Universal Log Parser is vendor-agnostic, so WAF syslog is normalised to OCSF v1.3 and enters the same detection pipeline as your firewall, endpoint, and identity telemetry. No separate WAF module, no waiting.
- --Any WAF that emits syslog, including UBIKA WAAP
- --OCSF v1.3 normalisation for WAF block and alert events
- --PII scrubbed on-premise before anything leaves your network
- --Write a custom parser for an unrecognised WAF format in minutes
Correlated web attack detection
WAF verdicts are not read in isolation. Sigma correlates them against endpoint, network, and authentication telemetry, so a blocked request that precedes a successful login becomes one incident rather than two disconnected alerts.
- --OWASP Top 10 patterns mapped to MITRE ATT&CK
- --SQL injection, XSS, and path traversal surfaced from WAF events
- --Correlated with authentication events to catch credential stuffing
- --G-Score contribution weighted by verdict volume and severity
Automated WAF response: Fabric Action, MVP2
What is not live yet is autonomous response on the WAF itself. That arrives with Fabric Action in MVP2, where the UBIKA Web Application Firewall is one of four response components alongside the Stormshield firewall, the HAProxy load balancer, and Wallix privileged access management.
- --Stormshield Firewall: response driver live today
- --HAProxy Load Balancer: MVP2
- --UBIKA Web Application Firewall: MVP2
- --Wallix Privileged Access Management: MVP2
Reclaim your security data.
60-day full-platform trial. No credit card. No inbound firewall changes. Live in under an hour.