Imperva Automated Security Event Alerts
Every hour, WebRun opens the Imperva dashboard, reads blocked attack counts and traffic anomaly signals for every protected site, saves a dated incident snapshot to Google Drive, and posts a Slack alert naming any site that crosses your threshold.
How do I get alerted when Imperva detects a security event spike?
WebRun checks every Imperva protected site each hour, reading blocked attack counts and traffic anomaly signals. It saves an incident snapshot to Google Drive for later review and posts a Slack alert naming any site that crosses your threshold, so a real attack spike gets noticed within the hour instead of surfacing in a monthly report.
- Security event spikes get caught within the hour
- Every incident gets a saved snapshot for later review
- Slack stays quiet on hours nothing crosses the threshold
Built for Security teams · DevOps teams · ecommerce site owners · enterprise IT teams
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
my.imperva.comin a real browser with your saved login - no setup, no API keys. -
1
Imperva - check blocked attacks and anomalies
WebRun opens Imperva to check blocked attacks and anomalies. - Open the Imperva dashboard and review every protected site
- Read blocked attack counts and traffic anomaly signals for the last hour
- Flag any site crossing your set threshold
Done when Every protected site has a current security reading.
-
2
Google Drive - save the incident snapshot
WebRun opens Google Drive to save the incident snapshot. - Save the incident snapshot as a dated file in your shared Drive folder
- Keep a running record for later review
Done when This run's snapshot is saved to Drive.
-
3
Slack - alert on threshold breach
WebRun opens Slack to alert on threshold breach. - Post an alert to your security channel naming any site that crossed the threshold
- Include the attack count and the anomaly signal
- Stay quiet when every site is under threshold
Done when The team gets an alert only when a site crosses the threshold.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it change a security rule or block an IP on its own?
No. WebRun only reads attack and traffic data and reports it. Changing a security rule or blocking an IP always stays a manual step in Imperva.
What counts as a threshold breach?
A clear spike in blocked attacks or an unusual traffic anomaly on a protected site compared to its normal pattern, the numbers you define as worth a look.
Does it check every protected site on the account?
Yes. It reviews every site under Imperva protection each hour, not just your primary one.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.