Configure Cloudflare WAF for Arctic Wolf monitoring using Logpush
You can configure ® to send the necessary logs to Arctic Wolf® for security monitoring using Logpush.
Complete these steps to configure Logpush jobs to send logs to Arctic Wolf using the Arctic Wolf webhook API.
These resources are required:
- A Enterprise plan
- A user with Super Administrator, Administrator, or Log Share Edit permissions for the Cloudflare account
Get the webhook token and URL
Configure Audit logs Logpush job
Configure HTTP Requests Logpush job
Repeat these steps for each domain (zone) that you want Arctic Wolf to monitor. If you add a domain later, repeat these steps to add the domain to monitoring.
Configure Firewall events Logpush job
Configure Firewall events using one of these methods:
-
If your account covers all of the zones that you want Arctic Wolf to monitor, and your account supports Firewall events as an account-scoped dataset, follow the steps in Configure Firewall events as an account-scoped dataset.
- Otherwise, follow the steps in Configure Firewall events as a zone-scoped dataset.
Configure Firewall events as an account-scoped dataset
Configure Firewall events as a zone-scoped dataset
Repeat these steps for each domain (zone) that you want Arctic Wolf to monitor. If you add a domain later, repeat these steps to add the domain to monitoring.