Configure Cloudflare WAF for Arctic Wolf monitoring using Logpush

You can configure Cloudflare WAF® to send the necessary logs to Arctic Wolf® for security monitoring using Logpush.

Complete these steps to configure Cloudflare WAF Logpush jobs to send logs to Arctic Wolf using the Arctic Wolf webhook API.

These resources are required:

  • A Cloudflare WAF Enterprise plan
  • A user with Super Administrator, Administrator, or Log Share Edit permissions for the Cloudflare account

Get the webhook token and URL

  1. Sign in to the Arctic Wolf Unified Portal.
  2. In the navigation menu, click Data Collection > Cloud Sensors.
  3. Click Add Account +.
  4. On the Add Account page, click Cloudflare WAF Logpush.
  5. In the Name field, enter a unique and descriptive name for the account.
  6. Click Get Credentials.
  7. Copy the client credentials and webhook URL, and then save them in a safe, encrypted location.

    You will use these values to configure the Cloudflare WAF Logpush jobs.

Configure Audit logs Logpush job

  1. Sign in to Cloudflare Dashboard.
  2. Go to Observe > Investigate > Logpush.
  3. Confirm that the page title is Account-scoped Logpush.
  4. Click Create a Logpush job.
  5. Select HTTP destination.
  6. In the HTTP endpoint field, enter the webhook URL and client credentials that you copied in Get the webhook token and URL, in the following format:
    NONE
    <webhook_url>?header_Authorization=Bearer%20<client_credentials>
  7. Click Continue.
  8. In the Dataset list, select Audit logs V2.
  9. Configure these settings:
    • Name — Enter a unique and descriptive name for the Logpush job.
    • Logs to send — Select All logs.
    • Fields — Select Select All.
  10. Click Submit.
    The Logpush job appears in the job list.

Configure HTTP Requests Logpush job

Repeat these steps for each domain (zone) that you want Arctic Wolf to monitor. If you add a domain later, repeat these steps to add the domain to monitoring.

  1. Sign in to Cloudflare Dashboard.
  2. Go to Observe > Investigate > Logpush.
  3. In the banner area, click Select a domain, and then click Continue.
  4. Click the domain (zone) that you want to add to monitoring.
  5. Confirm that the page title is Zone-scoped Logpush.
  6. Click Create a Logpush job.
  7. Select HTTP destination.
  8. In the HTTP endpoint field, enter the webhook URL and client credentials that you copied in Get the webhook token and URL, in the following format:
    NONE
    <webhook_url>?header_Authorization=Bearer%20<client_credentials>
  9. Click Continue.
  10. In the Dataset list, select HTTP requests.
  11. Configure these settings:
    • Name — Enter a unique and descriptive name for the Logpush job.
    • Logs to send — Select All logs.
    • Fields — Select Select All.
  12. Click Submit.
    The Logpush job appears in the job list.

Configure Firewall events Logpush job

Configure Firewall events using one of these methods:

  • If your account covers all of the zones that you want Arctic Wolf to monitor, and your account supports Firewall events as an account-scoped dataset, follow the steps in Configure Firewall events as an account-scoped dataset.

  • Otherwise, follow the steps in Configure Firewall events as a zone-scoped dataset.
Note: If Firewall events isn't available as an account-scoped dataset for your account, contact Cloudflare Support, or use the zone-scoped method instead.

Configure Firewall events as an account-scoped dataset

  1. Sign in to Cloudflare Dashboard.
  2. Go to Observe > Investigate > Logpush.
  3. Confirm that the page title is Account-scoped Logpush.
  4. Click Create a Logpush job.
  5. Select HTTP destination.
  6. In the HTTP endpoint field, enter the webhook URL and client credentials that you copied in Get the webhook token and URL, in the following format:
    NONE
    <webhook_url>?header_Authorization=Bearer%20<client_credentials>
  7. Click Continue.
  8. In the Dataset list, select Firewall events.
  9. Configure these settings:
    • Name — Enter a unique and descriptive name for the Logpush job.
    • Logs to send — Select All logs.
    • Fields — Select Select All.
  10. Click Submit.
    The Logpush job appears in the job list.

Configure Firewall events as a zone-scoped dataset

Repeat these steps for each domain (zone) that you want Arctic Wolf to monitor. If you add a domain later, repeat these steps to add the domain to monitoring.

  1. Sign in to Cloudflare Dashboard.
  2. Go to Observe > Investigate > Logpush.
  3. In the banner area, click Select a domain, and then click Continue.
  4. Click the domain (zone) that you want to add to monitoring.
  5. Confirm that the page title is Zone-scoped Logpush.
  6. Click Create a Logpush job.
  7. Select HTTP destination.
  8. In the HTTP endpoint field, enter the webhook URL and client credentials that you copied in Get the webhook token and URL, in the following format:
    NONE
    <webhook_url>?header_Authorization=Bearer%20<client_credentials>
  9. Click Continue.
  10. In the Dataset list, select Firewall events.
  11. Configure these settings:
    • Name — Enter a unique and descriptive name for the Logpush job.
    • Logs to send — Select All logs.
    • Fields — Select Select All.
  12. Click Submit.
    The Logpush job appears in the job list.