Overview
The Cloudflare integration uses the Cloudflare API to ingest:
- Audit logs — account and zone-level changes (DNS, page rules, certificates, members)
- Firewall events — WAF, rate limiting, bot management, and custom rule actions
- Workers and Access activity (where enabled)
For high-volume HTTP and Spectrum data, configure Logpush to push to S3/GCS/Azure and connect Atatus to that bucket instead.
Prerequisites
- A Cloudflare account.
- Account or zone admin permission to create API tokens.
- The Account ID (and Zone ID if scoping to a single zone), visible on the right pane of the Cloudflare dashboard.
Step 1: Create an API token in Cloudflare
- Sign in to the Cloudflare dashboard.
- Go to My Profile → API Tokens → Create Token.
- Click Get started under Create Custom Token and grant:
- Account → Audit Logs → Read
- Zone → Firewall Services → Read (per zone)
- Zone → Analytics → Read (per zone)
- Restrict the token to the specific account/zones you want Atatus to read.
- Click Continue to summary, then Create Token, and copy the token value immediately.
Step 2: Connect Cloudflare in Atatus
- In Atatus, go to Security → Cloud SIEM → Integrations.
- Locate the Cloudflare card and click Connect.
- Fill in the form:
| Field | Description | Example |
|---|---|---|
| API Token | Cloudflare API token from Step 1. | •••••••• |
| Account ID | Cloudflare account ID. | abc1234567890def |
| Zone ID | Optional; restrict ingestion to a single zone. | def0987654321abc |
| Poll Interval (minutes) | How often to fetch new events. | 5 |
| Enabled | Turn collection on. | true |
- Click Connect.
Verification
- The Cloudflare card shows Configured.
- Audit and firewall events appear in Security → Cloud SIEM → Audit Logs → Events with source
cloudflare.
+1-415-800-4104