All templates

Imperva Automated Security Event Alerts

Every hour, WebRun opens the Imperva dashboard, reads blocked attack counts and traffic anomaly signals for every protected site, saves a dated incident snapshot to Google Drive, and posts a Slack alert naming any site that crosses your threshold.

Runs on WebRun · Strict Lockdown policy
Every hour, day and night WebRunorchestrates each step
1 Imperva check blocked attacks and anomalies
2 Google Drive save the incident snapshot
3 Slack alert on threshold breach
In short

How do I get alerted when Imperva detects a security event spike?

WebRun checks every Imperva protected site each hour, reading blocked attack counts and traffic anomaly signals. It saves an incident snapshot to Google Drive for later review and posts a Slack alert naming any site that crosses your threshold, so a real attack spike gets noticed within the hour instead of surfacing in a monthly report.

  • Security event spikes get caught within the hour
  • Every incident gets a saved snapshot for later review
  • Slack stays quiet on hours nothing crosses the threshold

Built for Security teams · DevOps teams · ecommerce site owners · enterprise IT teams

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens my.imperva.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Imperva - check blocked attacks and anomalies
    imperva.com
    WebRun in Imperva: check blocked attacks and anomalies
    WebRun opens Imperva to check blocked attacks and anomalies.
    • Open the Imperva dashboard and review every protected site
    • Read blocked attack counts and traffic anomaly signals for the last hour
    • Flag any site crossing your set threshold

    Done when Every protected site has a current security reading.

  3. 2
    Google Drive - save the incident snapshot
    drive.google.com
    WebRun in Google Drive: save the incident snapshot
    WebRun opens Google Drive to save the incident snapshot.
    • Save the incident snapshot as a dated file in your shared Drive folder
    • Keep a running record for later review

    Done when This run's snapshot is saved to Drive.

  4. 3
    Slack - alert on threshold breach
    slack.com
    WebRun in Slack: alert on threshold breach
    WebRun opens Slack to alert on threshold breach.
    • Post an alert to your security channel naming any site that crossed the threshold
    • Include the attack count and the anomaly signal
    • Stay quiet when every site is under threshold

    Done when The team gets an alert only when a site crosses the threshold.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
my.imperva.com
ScheduleRuns automatically on this cadence
Every hour, day and night
DeliveryHow each run's result reaches you
Security alert · Slack
OutputWhat each run produces - An incident snapshot for every site, with a Slack alert on anything crossing your security threshold.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it change a security rule or block an IP on its own?

No. WebRun only reads attack and traffic data and reports it. Changing a security rule or blocking an IP always stays a manual step in Imperva.

What counts as a threshold breach?

A clear spike in blocked attacks or an unusual traffic anomaly on a protected site compared to its normal pattern, the numbers you define as worth a look.

Does it check every protected site on the account?

Yes. It reviews every site under Imperva protection each hour, not just your primary one.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.