Alibaba Cloud WAF Web Application Firewall
Collect Alibaba Cloud WAF Web Application Firewall Metrics data
Configuration¶
Install Func¶
It is recommended to subscribe to Guance Integration - Extensions - DataFlux Func (Automata)
For self-deploying Func, refer to Self-deploy Func
Enable Script¶
Note: Please prepare the Alibaba Cloud AK that meets the requirements in advance (for simplicity, you can directly grant the global read-only permission
ReadOnlyAccess)
Enable Script Manually¶
-
Log in to the Func console, click [Script Market], enter the Guance Script Market, and search for:
integration_alibabacloud_waf_v3 -
Click [Install], then enter the corresponding parameters: Alibaba Cloud AK ID, AK Secret, and account name.
-
Click [Deploy Startup Script], the system will automatically create the
Startupscript set and configure the corresponding startup script. -
After enabling, you can see the corresponding automatic trigger configuration in "Manage / Automatic Trigger Configuration". Click [Execute] to execute it immediately once without waiting for the scheduled time. Wait a moment, you can check the execution task records and corresponding logs.
Verification¶
- In "Manage / Automatic Trigger Configuration", confirm whether the corresponding task has the corresponding automatic trigger configuration, and you can also check the corresponding task records and logs to see if there are any exceptions.
- In Guance, check if asset information exists in "Infrastructure / Custom".
- In Guance, check if there is corresponding monitoring data in "Metrics".
Metrics¶
Web Application Firewall metrics are under the aliyun_acs_waf Measurement. The following are the metric details.
| Metric | Description | Unit | Demissions |
|---|---|---|---|
| 4XX_ratio-wafv3 | 4XX Ratio V3 | % | userId,instanceId,resource |
| 5XX_ratio-wafv3 | 5XX Ratio V3 | % | userId,instanceId,resource |
| acl_blocks_5m-wafv3 | ACL Block Count (5m) V3 | count | userId,instanceId,resource |
| acl_rate_5m-wafv3 | ACL Block Rate (5m) V3 | % | userId,instanceId,resource |
| cc_blocks_5m-wafv3 | CC Protection Block Count (5m) V3 | count | userId,instanceId,resource |
| cc_rate_5m-wafv3 | CC Protection Block Rate (5m) V3 | % | userId,instanceId,resource |
| qps-wafv3 | QPS_V3 | countS | userId,instanceId,resource |
| qps_ratio-wafv3 | QPS Ratio Growth Rate V3 | % | userId,instanceId,resource |
| qps_ratio_down-wafv3 | QPS Ratio Decline Rate V3 | % | userId,instanceId,resource |
| waf_blocks_5m-wafv3 | Web Attack Block Count (5m) V3 | count | userId,instanceId,resource |
| waf_qps-wafv3 | Instance Dimension QPS | countS | userId,instanceId |
| waf_qps-wafv3-max | Instance Dimension Max QPS | countS | userId,instanceId |
| waf_rate_5m-wafv3 | Web Attack Block Rate (5m) V3 | % | userId,instanceId,resource |
| waf_rate_5m-wafv3_v2 | Web Attack Block Rate (5m) V3 (New) | % | userId,instanceId,resource |