Azure WAF logging analytics and alerting | Part 2 of 2

  Рет қаралды 10,166

Cloud Inspired

Cloud Inspired

Күн бұрын

Subscribe here, new videos posted weekly:
/ @cloudinspired
This video is Part 2 covering Web Application Firewall or WAF for short logging and diagnostics using Application Gateway and Log Analytics.
We will also take a look at the WAF logs, running queries to search log data and email alerting of that data.
Part 2 covers WAF logging and diagnostics using:
Application Gateway Analytics
Log Analytics for Application Gateway Firewall Logs
Log Analytics running queries to search log data
Email alerting
Part 1 video is here • Azure Web Application ...

Пікірлер: 19
@simonbutler3516
@simonbutler3516 3 жыл бұрын
Thanks for posting these 2 videos. I was totally stuck! Cheers.
@CloudInspired
@CloudInspired 3 жыл бұрын
No problem Simon, Glad it helped!
@morecklgust
@morecklgust 8 ай бұрын
This was really helpful even after 4 years, Thanks I do have one question in detection mode I get "Matched" and "Detected" in action_s. I created custom rules that should allow (Pass) the traffic. it is just nebulous to me what will happen in prevention mode. Can you tell me?
@devopsengineer1798
@devopsengineer1798 3 жыл бұрын
where is the query in description ?
@bproducer
@bproducer 3 жыл бұрын
Why is your custom rule being listed as a mandatory rule and cannot be disabled?
@matteustace5769
@matteustace5769 2 жыл бұрын
@Cloud Inspired It looks like MS has changed something, you can no longer find "Azure Application Gateway Analytics" in the marketplace. Possibly this is just standard in Log Analytics Workspaces now, but probably time for a re-shoot of that section of hte video!
@CloudInspired
@CloudInspired 2 жыл бұрын
Thanks Matt. I`ll check it out!
@mohamedfarouk4870
@mohamedfarouk4870 4 жыл бұрын
Thanks a lot for this great video it is really very helpfull
@CloudInspired
@CloudInspired 4 жыл бұрын
Glad it helped you Mohamed.
@gururajma5448
@gururajma5448 4 жыл бұрын
Hi, In Log Analytics, i am not able to set the query action_s == "Blocked". action_s field itself not appearing in query box. could you plz help me how to get that "action_s"
@CloudInspired
@CloudInspired 4 жыл бұрын
Hello - Are you referring to this part of the video: kzbin.info/www/bejne/q4ixgpKHdraEatE If so, cut and paste the following query into log analytics and run the query. AzureDiagnostics | where Category == "ApplicationGatewayFirewallLog" and action_s == "Blocked" It should then show all "blocked" events in the application gateway firewall logs if these type of events are present in the logs? If no events are present as "Blocked" under "action_s", these shouldn`t display. Try running: AzureDiagnostics | where Category == "ApplicationGatewayFirewallLog" to see what "action_s" type is displayed?
@ayekula
@ayekula 3 жыл бұрын
Thanks a lot for sharing Very good information and explaining in detail.....Thanks, Could you please share me how to send these Blocked logs to SIEM
@CloudInspired
@CloudInspired 3 жыл бұрын
Thanks Ayekula, you could use Log Analytics integration with Power BI if that helps for your requirements? docs.microsoft.com/en-us/azure/azure-monitor/logs/log-powerbi Then set data alerts in the Power BI service.
@midnightwatchman1
@midnightwatchman1 4 жыл бұрын
This is a good video but for me represent everything wrong with video presentation over writing articles, all the information you need is between 5:01 and 5:05 but then you have to rewind that spot and 10 times to hear what the presenter said and writing on the video is just too fuzzy
@CloudInspired
@CloudInspired 4 жыл бұрын
Hi Steve, thanks for the comment. Its really down to personal preference and the advantages and disadvantages of a video over an article. Also regarding the content, this all depends what knowledge you require at the time of viewing. Videos are released and built up, trying to keep them as simple and quick as possible from start to finish with all the components required to achieve the result. Trying not to jump too much into the outcome without covering what’s required first, otherwise this can be confusing to the viewer if they have no previous knowledge of the subject.
@midnightwatchman1
@midnightwatchman1 4 жыл бұрын
@@CloudInspiredthese days finding articles on new technology is getting hard to find. you have to wait on a book or try and see if the Microsoft documentation is up to standard. once the video is done at a reasonable speed it is ok and the presenter does skip too much it fine. thank you for the reply and thanks for the tip. you would believe how that one tip saved my life
@CloudInspired
@CloudInspired 4 жыл бұрын
No problem Steve, glad it helped you. All the best.
@CarlosDiaz-nc8wl
@CarlosDiaz-nc8wl 3 жыл бұрын
Thanks!
@CloudInspired
@CloudInspired 3 жыл бұрын
Your welcome Carlos
Azure Web Application Firewall (WAF) | Part 1 of 2
18:53
Cloud Inspired
Рет қаралды 29 М.
Microsoft Azure Log Analytics Worksapce
16:53
Concepts Work
Рет қаралды 29 М.
Azure Application Gateway - Monitoring and Logging
14:33
MadeForCloud
Рет қаралды 2,5 М.
Microsoft Azure Application Gateway Deep Dive
1:03:29
John Savill's Technical Training
Рет қаралды 123 М.
How to Tune Your Azure WAF
56:43
Microsoft Security Community
Рет қаралды 7 М.
Understanding DNS in Azure
26:59
John Savill's Technical Training
Рет қаралды 126 М.
Web Application Firewall Azure Configuration | WAF Step by Step
14:08
Meet Kamal Today - Cloud Mastery
Рет қаралды 31 М.
Azure Networking - #13 - Azure Front Door
19:45
Azure Academy
Рет қаралды 39 М.
Azure Networking, User Defined Routes, and Network Virtual Appliances
21:24
Azure Front Door [FULL COURSE IN 2.5 HOURS]
2:33:31
Hussein Awad
Рет қаралды 26 М.