NGINX App Protect WAF 101 - Part 2: Policy Tuning Using Third-Party Monitoring Tools @nginx_official
NGINX App Protect WAF 101 - Part 2: Policy Tuning Using Third-Party Monitoring Tools  @nginx_official
Uploaded April 2023 | Updated September 2026, 1 week ago
In Part 2 of the NGINX App Protect WAF 101 series, we discuss “Policy Tuning Using Third-Party Monitoring Tools.” In this demo, we review when to update your NGINX App Protect WAF policy and how to go about doing so. We provide a basic overview of the process, what to look for that would indicate your policy many need to be updated, how to update the policy, apply it, and check to see if you have positive results.

This demo will showcase the OWASP Juice Shop modern app that has vulnerabilities associated with it and needs protection. It is hosted on a container and NGINX Plus with NGINX App Protect WAF is installed on it with the default policy to provide the needed app protection. We will use a third-party logging and monitoring dashboard tool, an ELK stack, to review the log output from NGINX App Protect WAF and help monitor the application.

We will look at an alert, the violation associated with it, and drill down into the event details and show how to apply policy tuning. NGINX App Protect WAF is lightweight and can be integrated easily into your CI/CD workflows to enable app security policies to be tested in lower environments prior to reaching production.

docs.nginx.com/nginx-app-protect-waf

Additional Resources:

Webpage: NGINX App Protect WAF
bit.ly/41IEYtc

Datasheet: NGINX App Protect WAF
bit.ly/40sebzX

Blog: Automate Security with NGINX App Protect WAF to Reduce the Cost of Breaches
nginx.com/blog/automate-security-f5-nginx-app-protect-f5-nginx-plus-to-reduce-cost-of-breaches

Free Trial: Test Drive NGINX App Protect WAF for 30 Days
bit.ly/3Ad9WOk
NGINX App Protect WAF 101 - Part 2: Policy Tuning Using Third-Party Monitoring ToolsZero Trust and Kubernetes Secure Services Visibility with F5 NGINXAccelerate Microservices Deployments with AutomationEnable API Key Authentication with API Connectivity ManagerManaging Certificates with Instance ManagerMigrate Workloads with F5 NGINXaaS for AzureShift Left for More Secure Apps with NGINXEverything You Need to Know About QUIC and HTTP3Learn to Start Delivering Microservices at Microservices March 2023Build, Deliver, and Visualize Your Kubernetes AppF5 NGINX Ingress Controller: Installation and Reporting Usage to F5NGINX Unit - Run Multiple Application Services Together
NGINX |

NGINX App Protect WAF 101 - Part 2: Policy Tuning Using Third-Party Monitoring Tools

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER