
4/24/2020 · Patrick R. Donahue
What this post added
This post introduces the ability to stream specific Firewall Events directly to SIEM platforms using Cloudflare Logs and Logpush jobs. Previously, users had to ingest all request logs and filter them client-side, which was costly and inefficient. This new feature allows for targeted delivery of security-related events, arriving much faster (within 60 seconds) and reducing the volume of data processed by SIEMs and security teams. The post also provides a practical guide on setting this up using Terraform and Sumo Logic.