Sentinel Cloudflare Dataconnector documentation

Copper Contributor

We have enabled the new Cloudflare dataconnector:

Microsoft Azure Marketplace

 

Unfortnalty, there is not much documentation about configuring this connector.

 

To activate the connector, one of the tasks is to configure Logpush on Cloudflare.

Which data sets, logs or log fields are required for this dataconnector?

There a lots of logs, like http, firewall etc. Selecting them all would probably result in huge amounts of logs. Are they all needed?

2 Replies
Hi,
I am working on this connector as well. To my knowledge you have to first chose either one of the log types, and then proceed with the integration. Whether you need all the logs or not is based on your requirement.
Try Webhooks (In Microsoft its build using Logic Apps with a Rest API), as an example, I recently ingested PageShield alerts in Sentinel LAW..