Configure Cloudflare WAF for Arctic Wolf monitoring using Log Explorer API

You can configure ® to send the necessary logs to Arctic Wolf® for security monitoring using Log Explorer API.

These resources are required:

  • A plan with the Log Explorer add-on.
  • A user with Super Administrator permissions

Create a Cloudflare API token

  1. Sign in to the Cloudflare Dashboard.
  2. In the navigation menu, select the account to configure from the drop-down list.
  3. Go to Manage Account > API Tokens.
  4. Click Create Token.
  5. In the Token name field, enter a unique and descriptive name.

    For example: Arctic Wolf - Log Monitoring

  6. In the Permission policies section, click Start from scratch.
  7. In Edit Policy, select Entire Account from the drop-down list.
  8. In the search for permission groups field, complete these steps:
    1. Search for Access: Audit Logs and then in Cloudflare One / Zero Trust > Access: Audit Logs select Read.
    2. Search for Account logs and then in Analytics & Logs > Account Logs select Read.
    3. Search for Account Settings and then in Account & Billing > Account Settings select Read.
  9. Click + Add policy.
  10. In Edit Policy, select All Domains from the drop-down list.
    1. Search for Zone and then in DNS & Zones > Zone select Read.
    2. Search for Zone Logs and then in Analytics & Logs > Zone Logs select Read.
  11. Set Token Expiration to No expiration.
  12. To restrict API calls to Arctic Wolf IP addresses, in the Client IP Address Filtering section, add the IP addresses found in the Portail unifié Arctic Wolf under Settings > Allowlist Requirements.
  13. Click Review Token and review the token details.
  14. Click Create Token.
  15. Copy the Account ID and API Token and save them in a safe, encrypted location. You will provide these values later.
    Note: The API token is only displayed once.

Get Zone IDs from the Cloudflare Dashboard

Note: The API integration supports a maximum of 15 zones per account.
  1. In the Dashboard, select the account that you used in Create a Cloudflare API token
  2. In the navigation menu, click Domains > Overview.
  3. For each domain that you want Arctic Wolf to monitor, click ... > Copy zone id and then save the ID in a safe, encrypted location to provide later.

Provide Cloudflare WAF credentials to Arctic Wolf

Note:

Time-based events are polled with a delay to make sure that data is available. If API credentials fail, for example due to expired credentials, Arctic Wolf notifies you and requests a new set of credentials. Provide refreshed credentials promptly to ensure complete data polling and coverage.

  1. Sign in to the Portail unifié Arctic Wolf.
  2. Dans le menu de navigation, cliquez sur Collecte de données > Capteurs cloud.
  3. Click Add Account +.
  4. On the Add Account page, click Cloudflare WAF API.
  5. Configure these settings:
  6. Click Test and submit credentials.