Wider attack surface coverage powered by hundreds of integrations and deeper threat visibility powered by thousands of detections.
Version: Cloudflare - Cloud Platform
Cloudflare is a next-generation Content Delivery Network (CDN) that provides content-delivery-network, DDoS mitigation, Internet security and distributed domain-name-server services. Cloudflare's services connects website's visitor and Cloudflare user's hosting provider, acting as a reverse proxy for the websites.
Cloudflare integrates with Netsurion SIEM application to provide security analytics with deep data context, organizations can be confident in their data security strategy. Benefits include scheduled reports, Integrated Cloudflare dashboards and alerts for streamlined investigation.
Reports are the best way to view the historical data (depending on the timeline defined). Some of the Netsurion reports provided for Cloudflare are summary of audit activities such as API key view, login and logout, summary of firewall/ WAF related activities occurring in different Cloudflare zones, such as dropping or discarding an incoming traffic.
Dashboards are graphical representations of activities occurring in Cloudflare zones/UI. These dashboards can be a pie chart, a bar diagram, or a map. This allows user to view the key highlights of Cloudflare events. Some of the dashboards include audit events timeline, UI login activities, dropped traffic by country code, etc.
Alerts such as traffic dropped by firewall or WAF are present in the knowledge packs. These alerts can be configured to forward emails to users/admin of Cloudflare if any suspicious events are detected.
After configuring Cloudflare to deliver events to Netsurion Manager; alerts, dashboards and reports can be configured into Netsurion.
The configuration details are consistent with Netsurion version 9.2 and later and Cloudflare (Cloud platform).
Download Integration Guide and How-to Guidefor more information and to configuration instructions.