open-appsec

Supported OS Linux

marketplace
Integration version1.0.0

To find out if this integration is available in your organization, see your Datadog Integrations page or ask your organization administrator.

To initiate an exception request to enable this integration for your organization, email support@ddog-gov.com.

Overview

open-appsec is an open-source, fully automated Web Application and API Security solution. It uses machine learning to analyze HTTP/S requests in real time. The platform provides proactive protection against OWASP Top-10 and zero-day attacks.

This integration collects security event logs from open-appsec and includes a out-of-the-box dashboard and monitor templates.

Dashboards

  • open-appsec Security Threat Overview

Monitors

  • Critical events from a single IP exceed 10 in 10 minutes in open-appsec
  • Normal-reputation IP reaches critical threat level in open-appsec
  • Average WAF threat score exceeds 950 over the last 10 mins in open-appsec
  • Host attack count exceeds 10 in 10 minutes in open-appsec

Data Collected

Logs

The open-appsec integration collects security event logs by tailing the local cp-nano-http-transaction-handler.log file generated by the open-appsec Nano Agent. These logs include WAF threat detections, attack incident types, matched parameters, source reputation, and threat scores.

Metrics

The open-appsec integration does not include any metrics.

Events

The open-appsec integration does not include any events.

Service Checks

The open-appsec integration does not include any service checks.

Support

For support or feature requests, contact Crest Data through the following channels:

Troubleshooting

Need help? Contact Datadog support.


This application is made available through the Marketplace and is supported by a Datadog Technology Partner. Click Here to purchase this application.