AWS Security Blog
Tag: Anomaly detection
Analyze AWS WAF logs using HAQM OpenSearch Service anomaly detection built on Random Cut Forests
April 23, 2025: We updated the code, screenshots, and narrative. This blog post shows you how to use the machine learning capabilities of HAQM OpenSearch Service to detect and visualize anomalies in AWS WAF logs. AWS WAF logs are streamed to HAQM OpenSearch Service using HAQM Kinesis Data Firehose. Kinesis Data Firehose invokes an AWS […]
How to improve visibility into AWS WAF with anomaly detection
When your APIs are exposed on the internet, they naturally face unpredictable traffic. AWS WAF helps protect your application’s API against common web exploits, such as SQL injection and cross-site scripting. In this blog post, you’ll learn how to automatically detect anomalies in the AWS WAF metrics to improve your visibility into AWS WAF activity, […]