A security engineer has configured an AWS WAF Web ACL to protect a public-facing web application. The engineer needs to monitor WAF logs for specific attack patterns (e.g., SQL injection attempts, cross-site scripting) and receive real-time alerts when these patterns are detected. The logs should be stored centrally for auditing and forensics. Which solution provides the most effective way to meet these requirements?
- APublish WAF metrics to CloudWatch and create alarms on metric thresholds for attack types.
- BEnable WAF logging and configure it to send logs to a CloudWatch Logs log group. Create CloudWatch Logs subscription filters to send matching log events to a Lambda function for alerting and to an S3 bucket for archival.
- CConfigure WAF to send logs to an S3 bucket, then use CloudWatch Alarms on S3 object creation to trigger a Lambda function for pattern matching and alerting.
- DIntegrate WAF with AWS Config to monitor WAF rule changes and trigger alerts for non-compliant configurations.
Show answer & explanationAnswer & explanation
Correct answer: B. Enable WAF logging and configure it to send logs to a CloudWatch Logs log group. Create CloudWatch Logs subscription filters to send matching log events to a Lambda function for alerting and to an S3 bucket for archival.
AWS WAF can send its detailed logs directly to a CloudWatch Logs log group. From CloudWatch Logs, subscription filters can be configured to match specific attack patterns within the log events. These matching events can then be streamed in real-time to a Lambda function for custom alerting (e.g., sending to Slack, PagerDuty) and simultaneously to an S3 bucket for long-term archival and forensic analysis.
Why the other options are wrong
- A. WAF metrics in CloudWatch provide aggregated counts (e.g., blocked requests), but they lack the detailed log event data needed to identify *specific attack patterns* (e.g., the exact SQL injection string) for granular alerting and forensic analysis.
- C. While S3 can store logs, processing them in real-time for specific patterns using Lambda triggered by S3 object creation is less efficient and has higher latency than using CloudWatch Logs subscription filters for real-time event streaming.
- D. AWS Config monitors WAF *rule changes* and configurations, not the actual *attack patterns* detected by WAF during runtime. This doesn't meet the requirement for monitoring attack patterns and real-time alerts.
AWS WAF Logging to CloudWatch Logs with Filters
A method to capture detailed AWS WAF traffic logs, send them to Amazon CloudWatch Logs, and use CloudWatch Logs subscription filters to stream specific log patterns for real-time analysis and alerting.
- WAF provides detailed logs of requests it processes.
- CloudWatch Logs offers centralized log storage and analysis.
- Subscription filters enable real-time pattern matching and streaming.
- Integrates with Lambda for custom alerting and S3 for archiving.
Memory trick: WAF logs to CloudWatch, filters trigger Lambda to shout for patterns.