| _BilledSize |
|
Double |
| _IsBillable |
|
String |
| Act |
The action taken on the request, e.g. ‘REQ_PASSED’, ‘REQ_BLOCKED’. |
String |
| AdditionalReqHeaders |
Additional HTTP request headers captured. |
String |
| AdditionalResHeaders |
Additional HTTP response headers captured. |
String |
| AdditionalRuleInfo |
Additional information about the WAF rule that was triggered. |
String |
| App |
The application protocol, e.g. ‘HTTPS’, ‘HTTP’. |
String |
| AttackName |
The name of the detected attack or event classification. |
String |
| AttackSeverity |
The severity rating of the attack, from 0 to 10. |
String |
| CapSupport |
Client capability support flags for advanced detection. |
String |
| CCode |
The ISO country code of the request origin. |
String |
| CiCode |
The city code of the request origin. |
String |
| ClApp |
The classified client application type. |
String |
| ClAppSig |
The client application signature used for bot detection. |
String |
| Cn1 |
The HTTP response status code. |
String |
| CoSupport |
Client cookie support indicator. |
String |
| Cpt |
The client port number of the request. |
String |
| Customer |
The Imperva customer account name. |
String |
| DeliveryRuleDetails |
Details about the content delivery rule applied to the request. |
String |
| DeviceExternalId |
External device identifier from the WAF. |
String |
| DeviceFacility |
The facility or module that generated the event, e.g. ‘waf’. |
String |
| DeviceVersion |
The version of the WAF device firmware. |
String |
| Dproc |
The destination process name. |
String |
| End |
The end timestamp of the event in Unix epoch milliseconds. |
String |
| EventProduct |
The product name generating the event, e.g. ‘Incapsula WAF’. |
String |
| EventType |
The type of event, e.g. ‘Normal’, ‘SQL Injection’. |
String |
| EventVendor |
The vendor of the product generating the event. Always ‘Imperva’. |
String |
| FileId |
Unique identifier for the log file. |
String |
| FilePermission |
File permission information associated with the event. |
String |
| FileType |
The type of file involved in the request. |
String |
| In |
The size of the incoming request in bytes. |
String |
| JavascriptSupport |
Whether the client supports JavaScript execution. |
String |
| Latitude |
The geographic latitude of the request origin. |
String |
| LogVersion |
CEF log format version identifier. |
String |
| Longitude |
The geographic longitude of the request origin. |
String |
| PostBody |
The HTTP POST body content, if captured. |
String |
| QStr |
The URL query string parameters. |
String |
| Ref |
The HTTP referer header value. |
String |
| Request |
The requested URL path. |
String |
| RequestClientApplication |
The client application or user agent string of the request. |
String |
| RequestMethod |
The HTTP request method, e.g. GET, POST, PUT, DELETE. |
String |
| RuleName |
The name of the WAF rule that matched the request. |
String |
| SignatureId |
The unique identifier for the security signature that triggered. |
String |
| SIP |
The server IP address that handled the request. |
String |
| SiteId |
The unique identifier for the protected site in Imperva. |
String |
| SiteTag |
Tags associated with the protected site. |
String |
| SourceServiceName |
The hostname or service name of the protected site. |
String |
| SourceSystem |
|
String |
| Spt |
The server port number. |
String |
| Src |
The source IP address of the client making the request. |
String |
| Start |
The start timestamp of the event in Unix epoch milliseconds. |
String |
| Suid |
The session user identifier or email associated with the request. |
String |
| Tag |
Tags associated with the event, such as attack classification labels. |
String |
| TenantId |
Unique identifier of the tenant into which the data connector ingests data. |
String |
| TimeGenerated |
The timestamp when the event occurred, derived from the CEF Start field. |
DateTime |
| Type |
The name of the table |
String |
| Ver |
The TLS or HTTP protocol version used. |
String |
| VID |
The visitor identifier assigned by Imperva for tracking. |
String |
| Xff |
The X-Forwarded-For header value indicating original client IP behind proxies. |
String |