Control: 2.7 Ensure Web Application Firewall access and security log service is enabled
Description
Log Service collects log entries that record visits to and attacks on websites that are protected by Alibaba Cloud Web Application Firewall (WAF), and supports real-time log query and analysis. The query results are centrally displayed in dashboards.
Remediation
Perform the following ensure the Anti-DDoS access and security log is enabled:
From Console
- Logon to WAF Console.
- Choose
App Market > App Management
. - Select the region where your WAF instance is located.
- Click
Upgrade
inReal-time Log Query and Analysis Service
. Enable
Log Service.- Select the log storage period and the log storage size, and click
Buy Now
. - Return to the WAF Console and choose
App Market > App Management
, and then clickAuthorize
inReal-time Log Query and Analysis Service
. - Click
Agree
to authorize WAF to write log entries to your exclusive logstore. - Return to the WAF Console and choose
App Market > App Management
and then, clickConfigure
inReal-time Log Query and Analysis Service
. - On the
Log Service
page, select the domain name of your website that is protected by WAF, and turn on theStatus
switch on the right to enable WAF Log Service. These log entries can be queried and analyzed in real time.
Usage
Run the control in your terminal:
powerpipe control run alicloud_compliance.control.cis_v100_2_7
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run alicloud_compliance.control.cis_v100_2_7 --share
SQL
This control uses a named query:
manual_control