Overview

The Cloudflare integration uses the Cloudflare API to ingest:

  • Audit logs — account and zone-level changes (DNS, page rules, certificates, members)
  • Firewall events — WAF, rate limiting, bot management, and custom rule actions
  • Workers and Access activity (where enabled)

For high-volume HTTP and Spectrum data, configure Logpush to push to S3/GCS/Azure and connect Atatus to that bucket instead.


Prerequisites

  • A Cloudflare account.
  • Account or zone admin permission to create API tokens.
  • The Account ID (and Zone ID if scoping to a single zone), visible on the right pane of the Cloudflare dashboard.

Step 1: Create an API token in Cloudflare

  1. Sign in to the Cloudflare dashboard.
  2. Go to My Profile → API Tokens → Create Token.
  3. Click Get started under Create Custom Token and grant:
    • Account → Audit Logs → Read
    • Zone → Firewall Services → Read (per zone)
    • Zone → Analytics → Read (per zone)
  4. Restrict the token to the specific account/zones you want Atatus to read.
  5. Click Continue to summary, then Create Token, and copy the token value immediately.

Step 2: Connect Cloudflare in Atatus

  1. In Atatus, go to Security → Cloud SIEM → Integrations.
  2. Locate the Cloudflare card and click Connect.
  3. Fill in the form:
Field Description Example
API Token Cloudflare API token from Step 1. ••••••••
Account ID Cloudflare account ID. abc1234567890def
Zone ID Optional; restrict ingestion to a single zone. def0987654321abc
Poll Interval (minutes) How often to fetch new events. 5
Enabled Turn collection on. true
  1. Click Connect.

Verification

  • The Cloudflare card shows Configured.
  • Audit and firewall events appear in Security → Cloud SIEM → Audit Logs → Events with source cloudflare.