Applies to: Cloudflare – Cloud Platform
Cloudflare is a next-generation Content Delivery Network (CDN) that provides content-delivery-network, DDoS mitigation, Internet security and distributed domain-name-server services. Cloudflare's services connects website's visitor and Cloudflare user's hosting provider, acting as a reverse proxy for the websites.
Cloudflare integrates with EventTracker SIEM application to provide security analytics with deep data context, organizations can be confident in their data security strategy. Benefits include scheduled reports, Integrated Cloudflare dashboards and alerts for streamlined investigation.
Reports are the best way to view the historical data (depending on the timeline defined). Some of the EventTracker reports provided for Cloudflare are summary of audit activities such as API key view, login and logout, summary of firewall/ WAF related activities occurring in different Cloudflare zones, such as dropping or discarding an incoming traffic.
Dashboards are graphical representations of activities occurring in Cloudflare zones/UI. These dashboards can be a pie chart, a bar diagram, or a map. This allows user to view the key highlights of Cloudflare events. Some of the dashboards include audit events timeline, UI login activities, dropped traffic by country code, etc.
Alerts such as traffic dropped by firewall or WAF are present in the knowledge packs. These alerts can be configured to forward emails to users/admin of Cloudflare if any suspicious events are detected.
After configuring Cloudflare to deliver events to EventTracker Manager; alerts, dashboards and reports can be configured into EventTracker.
The configuration details are consistent with EventTracker version 9.2 and later and Cloudflare (Cloud platform).
To configure CloudFlare to send logs to EventTracker, refer to the How-to Guide.
For more information please refer to the Integration guide.