Cloudflare Zero Trust logs now flow into Datadog Cloud SIEM
Cloudflare's Zero Trust platform covers network access, secure web gateway filtering, cloud access security broker (CASB) controls, and data loss prevention for devices managed by IT. Organizations using these in-line services often aggregate the resulting logs into Datadog Cloud SIEM for threat detection, investigation, and automated response. Datadog Cloud SIEM processes operational and security logs in real time, using out-of-the-box integrations, detection rules, and workflow blueprints to identify and remediate threats across dynamic, cloud-scale environments.
Cloudflare previously offered a Datadog dashboard for its CDN product, covering metrics like response times, HTTP status codes, and cache hit rate. The new general availability of the Cloudflare Zero Trust integration extends that relationship. The Cloudflare Content Pack inside Cloud SIEM ships with a dashboard and detection rules designed for Zero Trust log data, giving security teams visibility into activity across applications, devices, and users in their Zero Trust deployment.
“Our Datadog SIEM integration with Cloudflare delivers a holistic view of activity across Cloudflare Zero Trust integrations–helping security and dev teams quickly identify and respond to anomalous activity across app, device, and users within the Cloudflare Zero Trust ecosystem. The integration offers detection rules that automatically generate signals based on CASB findings, and impossible travel scenarios, a revamped dashboard for easy spotting of anomalies, and accelerates response and remediation to quickly contain an attacker’s activity through an out-of-the-box workflow automation blueprints.”
– Yash Kumar, Senior Director of Product, Datadog
Enabling the integration
To bring Cloudflare Zero Trust logs into Datadog, start by creating a Logpush job from the Cloudflare dashboard or API, with all fields enabled for each dataset you want to ingest. Eight account-scoped datasets are available: Access Requests, Audit logs, CASB findings, Gateway logs (DNS, Network, HTTP), and Zero Trust Session Logs.
Next, install the Cloudflare Tile from the Datadog Integration catalog. Datadog's out-of-the-box log processing pipeline will automatically parse and normalize the incoming Cloudflare Zero Trust logs.
Out-of-the-box security content
Once logs are flowing, the Cloudflare Content Pack provides a dashboard with a dedicated Zero Trust section. Widgets surface activity across the applications, devices, and users in your Cloudflare Zero Trust environment, so anomalies can be spotted and investigated quickly.
Datadog also includes a set of detection rules tailored to Cloudflare Zero Trust data:
CASB finding detection
Cloudflare CASB findings report security risks for integrated SaaS applications such as Microsoft 365 and Google Workspace. A new Datadog detection rule alerts on any CASB finding, with the severity varying by the finding's type. This helps teams identify and fix misconfigurations or other security issues before they become full-blown breaches.
Impossible travel detection
A common attack pattern involves a user logging in from one location and then, moments later, appearing to log in from somewhere physically impossible to reach. Datadog's Impossible Travel detection rule flags this when two consecutive log lines for a user show a distance of more than 500 km traveled at over 1,000 km/h. Security administrators can then decide whether the activity warrants investigation or response.
Next steps
Cloudflare and Datadog customers can now use the enhanced dashboards and new detection rules to get a more complete view of their Zero Trust security posture. Additional detection rules and integrations are planned. Cloudflare customers using Datadog can start exploring the integration today via the Cloudflare documentation or Datadog's integration catalog.



