AWS Security Blog

Umesh Ramesh

Author: Umesh Ramesh

Figure 1: End-to-end architecture

Analyze AWS WAF logs using HAQM OpenSearch Service anomaly detection built on Random Cut Forests

April 23, 2025: We updated the code, screenshots, and narrative. This blog post shows you how to use the machine learning capabilities of HAQM OpenSearch Service to detect and visualize anomalies in AWS WAF logs. AWS WAF logs are streamed to HAQM OpenSearch Service using HAQM Kinesis Data Firehose. Kinesis Data Firehose invokes an AWS […]

Centrally manage AWS WAF (API v2) and AWS Managed Rules at scale with Firewall Manager

October 29, 2021: AWS KMS is replacing the term customer master key (CMK) with AWS KMS key and KMS key. The concept has not changed. To prevent breaking changes, AWS KMS is keeping some variations of this term. More info. September 9, 2021: HAQM Elasticsearch Service has been renamed to HAQM OpenSearch Service. See details. […]

Enabling serverless security analytics using AWS WAF full logs, HAQM Athena, and HAQM QuickSight

September 9, 2021: HAQM Elasticsearch Service has been renamed to HAQM OpenSearch Service. See details. Traditionally, analyzing data logs required you to extract, transform, and load your data before using a number of data warehouse and business intelligence tools to derive business intelligence from that data—on top of maintaining the servers that ran behind these […]

Using AWS Firewall Manager and WAF to protect your web applications with master rules and application-specific rules

Jeff Barr’s blog post introducing AWS Firewall Manager describes how you can centrally manage a set of web application firewall rules to protect all the applications in an AWS Organization. This blog post will take you through the specific steps to implement firewall rules using both AWS Web Application Firewall (AWS WAF) and AWS Firewall […]