Skip to content
Notifications
Clear all

How do I audit rule changes made by their managed service team?

2 Posts
2 Users
0 Reactions
35 Views
(@kellyh)
Trusted Member
Joined: 3 months ago
Posts: 59
Topic starter   [#7077]

I'm managing an Imperva Cloud WAF implementation where the Managed Rules are handled by their service team. While their support is generally responsive, I need to maintain a clear audit trail for compliance (SOC2). Specifically, I need to track any modifications made to rule actions (from Block to Log, for example), rule exclusions, or custom rule additions.

My current understanding is that these changes are made within the Imperva console, but the direct audit log seems geared towards security events, not configuration changes by their staff. I've reviewed the Activity Log and Audit Trail sections, but the granularity isn't sufficient.

Has anyone established a reliable method to capture this? My ideal outcome would be a programmatic way to achieve the following:

* Detect when a rule's action (Block, Alert, Log, Pass) is modified.
* Identify when a new exclusion (URL, parameter, header) is added to a managed rule group.
* Capture the "changed by" detail (even if it's a service account used by Imperva).

I'm considering a periodic API poll of the relevant endpoints to diff configurations. Before building that, I wanted to check if there's a native feature or established pattern I've missed. My stack for ingesting this data would be Prometheus/Grafana, so an API-based approach is preferable.

If you've implemented something similar, what endpoints did you find most useful? The [Sites API]( https://docs.imperva.com/bundle/api-docs#tag/Sites) seems relevant for fetching the security policy configuration. A snippet of a potential diff check would be helpful.

```bash
# Example of fetching current policy rules (conceptual)
curl -X GET "https://api.imperva.com/sites/v1/sites/{site_id}/security/policy/rules"
-H "x-API-Key: {your_key}"
-H "x-API-Id: {your_id}"
```

Is comparing the JSON output from this call over time the most robust method, or are there better alternatives?

- kelly


Data is not optional.


   
Quote
(@henryw)
Estimable Member
Joined: 3 months ago
Posts: 74
 

I'm in a similar situation with a different vendor. I ended up building a script to poll the API and compare snapshots. It's a bit clunky, but it works.

Before you build it, have you checked if your Imperva account manager can enable a more detailed audit log? Sometimes those logs exist but aren't turned on by default for the customer console. Might be worth a support ticket asking specifically.



   
ReplyQuote