Havelsan Kalkan WAF Response Integration via API

Purpose

This guide explains how to configure the Havelsan Kalkan WAF Response integration in Logsign USO, so that Incidents and Alarms can automatically, or an analyst can manually, update a cloud WAF service's negative security ruleset directly from a Logsign Incident. This is a Response (action) integration, configured under Settings > Integrations > Responses > +Device.

Prerequisites

  • A Havelsan Kalkan WAF deployment with its management API reachable from the Logsign server.
  • An account with permission to modify WAF ruleset configuration.

Step 1: Prepare Kalkan WAF for API Access

  1. Log in to the Kalkan WAF management console with an administrator account.
  2. Create (or designate) a dedicated account for Logsign to use, and note its username and password.
  3. Note the WAF management host address.

Step 2: Configure the Integration in Logsign USO

In Logsign USO, go to Settings > Integrations > Responses, search for Havelsan Kalkan WAF, click Configure then +Device, and fill in:

FieldDescription
Device NameFree-text label identifying this Kalkan WAF device in Logsign.
HostManagement host address of your Kalkan WAF. Include the http:// or https:// scheme explicitly; a value without one is rejected.
UsernameThe account username from Step 1.
PasswordPassword for that account. Stored encrypted at rest.

The underlying configuration schema does not formally mark any of these fields as required, but all three (Host, Username, Password) are functionally necessary for the integration to connect; fill in all three and click Create to save the device.

Available Methods

  • update-cwaf-service (Containment) — updates a cloud WAF service's negative security ruleset. Args (both required): name (the WAF service to update), negative_rules (an array of rule categories to enable, such as IP reputation, SQL injection, XSS, and DoS protection rules).

Troubleshooting

SymptomLikely causeWhat to check
401 UnauthorizedWrong Username/Password.Re-enter the Username and Password fields and confirm the account can log in to the Kalkan WAF console directly.
403 ForbiddenThe account does not have permission to modify WAF service configuration.Confirm the account's role in Kalkan WAF includes configuration/ruleset management.
update-cwaf-service fails to find the serviceWrong name value.Confirm the name matches an existing cloud WAF service exactly as configured in Kalkan WAF.

Notes and Limits

  • This integration only has one method, updating the negative security ruleset for a named service; it has no method to view the current ruleset before changing it, so track your intended rule state outside Logsign if you need to confirm changes were applied as expected.
  • The exact console navigation path for creating a dedicated account was not independently verified against a live Kalkan WAF deployment during this research (not independently verified); the field names and method behavior above are taken directly from Logsign's integration code.
Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more
Become a Certified Logsign User/Administrator
Sign-up for Logsign Academy and take the courses to learn about Logsign USO Platform in detail. Enjoy the courses, and get your badges and certificates. In these courses, you'll learn how to use Logsign in your work and add value to your career.
Visit Our Blog
Our Logsign USO Platform illustrate our expertise. So do the blog. Through our blog posts, deepen your knowledge on various SecOps topics or get updated about important news & modern approaches for cybersecurity. Get into the habit of reading valuable information provided by Logsign. Be a step ahead.