eWalker WAF

Download 10
Last updated Nov 2, 2024

ewalker-waf-audit-logs

Get audit logs from eWalker WAF devices.

ewalker-waf-audit-logs [profile=PROFILE] [duration=NUM{mon|w|d|h|m|s}] [from=yyyyMMddHHmmss] [to=yyyyMMddHHmmss] [order=ORDER]
profile=PROFILE
eWalker WAF connect profile code
duration=NUM{mon|w|d|h|m|s}
Scan only recent data. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example, 10s means data from 10 seconds earlier.
from=yyyyMMddHHmmss
Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
to=yyyyMMddHHmmss
End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
order=ORDER
Scan direction. desc or asc.

Output Fields

FieldTypeNameDescription
_timeDateTimeLog time
profileStringConnect profileeWalker WAF connect profile code
device_ipIP addressDevice IPWAF device ip address
es_indexStringIndexElastic index name
es_idStringLog IDElastic log id
server_typeStringServer typee.g. wafweb, wafserver, wafproxy, yts, yts2
userStringUsere.g. system
actionStringActione.g. insert, closed, attempts, issue
action_descStringAction description
resultStringSubjecte.g. custom_rule, access token, login
msgStringMessagee.g. ewafadmin custom_rule insert Success
changesStringChangese.g. ID [ewafadmin] 중복 로그인
subjectStringsubjectsubject