Linking Imperva (Thales) as a source
Let AI connect your sources for you
Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

This source is currently in alpha. The interface and available tables may change.
The Imperva (Thales) Cloud Application Security connector syncs your web application security data into the PostHog Data warehouse, including site inventory, visitor traffic, hit statistics, and bandwidth metrics – so you can analyze security traffic patterns alongside your product data.
Imperva Cloud Application Security (now part of Thales) provides web application security services including DDoS protection, WAF, CDN, and bot management.
Prerequisites
You need an Imperva Cloud Application Security account with API access. In the Imperva Cloud Security Console, go to Account > My Profile > API keys to generate credentials. You'll need:
- API ID – the identifier for your API key
- API key – the secret key value
- Account ID – your numeric account identifier (found in account settings)
Your credentials need read access to both sites and statistics.
Adding a data source
- In PostHog, go to the Sources tab of the data pipeline section.
- Click + New source and click Link next to this source.
- Enter your credentials (see Configuration below) and click Next.
- Select the tables you want to sync, choose a sync method and frequency, then click Import.
Once the syncs are complete, you can start querying this data in PostHog.
When linking Imperva, you'll need:
- API ID – your Imperva API ID from the management console
- API key – your Imperva API key from the management console
- Account ID – your numeric Imperva account ID (digits only)
Sync modes
Each table can be synced in one of several modes, depending on what the source supports:
- Webhook (when available) – the source pushes changes to PostHog in real time. Fastest freshness, lowest ongoing cost, and the only mode that reliably captures updates and deletes.
- Incremental – only new or updated rows are synced on each run, using a cursor field (such as an
updated_attimestamp). Cheaper than a full refresh, but deletes aren't captured. - Append only – new rows are appended using a cursor field; existing rows are never updated. Ideal for immutable, append-only tables like event logs.
- Full refresh – the whole table is reloaded on every sync. Use it when a table has no reliable cursor or when you need deletions reflected.
See sync methods for a full explanation of how each mode works and how to choose between them.
The sites table syncs as full refresh only. Timeseries tables (visits_timeseries, hits_timeseries, bandwidth_timeseries) support both incremental and full refresh syncs using the timestamp field.
Statistics tables contain daily aggregates covering up to the last 90 days, subject to your Imperva subscription plan. Older data outside this window is not available from the API. Incremental syncs re-read the previous day to capture updates to recent buckets.
Configuration
| Option | Type | Required |
|---|---|---|
API ID | password | Yes |
API key | password | Yes |
Account ID | text | Yes |
Supported tables
| Table | Description | Sync method | Incremental field | Primary key |
|---|---|---|---|---|
sites | Websites associated with the selected Imperva account. | Full refresh | — | — |
visits_timeseries | Daily account visit counts, split by human and bot traffic. | Incremental, Full refresh | timestamp | — |
hits_timeseries | Daily account hit statistics for human, bot, and blocked traffic, including rates per second. | Incremental, Full refresh | timestamp | — |
bandwidth_timeseries | Daily account bandwidth and throughput between clients and Imperva proxy servers. | Incremental, Full refresh | timestamp | — |
Troubleshooting
- If you get an authentication error, check that your API ID and API key are correct and haven't expired. Regenerate them in the Imperva console under Account > My Profile > API keys.
- If you get a permission error, verify your account ID is correct and your API credentials have access to both the sites and statistics APIs.
- If you see a plan-related error, the statistics you're trying to sync may require a higher Imperva subscription tier. Contact Imperva support to verify your plan includes API access to the requested data.
If your sync is failing or data looks wrong, see the Data warehouse troubleshooting guide. If that doesn't help, contact support – we're happy to help.