Use Imperva Cloud WAF log integration or SIEM export in CEF, JSON, or another structured format. CEF is supported by the converter.
Do not log raw credentials, tokens, or full authorization headers.
Keep site/application name, host, origin, region/data center, and client country. These fields make compliance evidence stronger.