Cloudflare Logs Now Flow Directly Into IBM QRadar SIEM

When an alert fires at midnight, the speed and quality of your triage depend on how quickly you can pull together context from across your entire environment. Security teams need a single view that spans endpoints, networks, applications, and cloud services — without waiting on log exports or juggling multiple consoles.

Cloudflare’s application services — DNS, CDN, WAF — plus its Zero Trust offerings (Access and Gateway) all generate logs that can expose what’s happening in front of and inside your corporate applications. Until now, getting those logs into IBM QRadar SIEM required an intermediate storage step. That changes with a new direct integration: Cloudflare customers can push logs straight from Logpush into QRadar SIEM, eliminating the middle layer and cutting both delivery latency and storage costs.

What the Direct Integration Adds

QRadar SIEM aggregates events from users, endpoints, clouds, applications, and networks, then distills millions of raw events into a prioritized alert queue. Automated, AI-driven enrichment and root cause analysis speed up investigation work, helping teams classify incidents quickly — whether that means dismissing a false positive or waking up on-call staff.

Cloudflare’s reverse proxy and enterprise security products sit in front of much of that traffic, so the logs they produce are a natural fit for QRadar’s detection and response workflows. The strengthened partnership between IBM and Cloudflare means mutual customers can now build those workflows with Cloudflare data arriving directly, rather than via S3 buckets.

The existing S3-based ingestion path remains supported for teams that already rely on it. For those ready to switch to the new direct method, the configuration details are covered in the Cloudflare Logs DSM guide, with additional context available in the QRadar Community blog.