INVESTIGATION

Security Visibility

Use the control plane to understand both policy outcomes and the activity behind them. Review application decisions, network enforcement, runtime events, and administrative changes with the relevant project and agent context.

CAPABILITIES

What it provides

  • WAF decision streams with action, category, and available match details.
  • Host and network enforcement event views.
  • Runtime context and detection-rule results for investigation.
  • Audit logs, retention settings, and supported SIEM delivery configuration.

DEPLOYMENT WORKFLOW

How to use it

  1. 01

    Connect agents and confirm telemetry is reaching the correct project.

  2. 02

    Review event details alongside the policy and agent responsible for the action.

  3. 03

    Set retention and supported external delivery options for your investigation workflow.

CONFIGURATION & OPERATION

Where it fits in your setup

Use the project Overview, Firewall, Runtime Security, and Audit Log views. Preserve scan details when investigating upload outcomes so incomplete scanning is not mistaken for a malware match.

COVERAGE & LIMITS

What to account for

Visibility depends on delivered telemetry, configured retention, and the fields available for each event. A missing event is not proof that no activity occurred. Size storage and retention for your traffic volume.

Put the policy into practice.

Follow the documentation and validate with your own workload.

Open documentation →