Cloudflare Zero Trust logs gain Sumo Logic Cloud SIEM support
Cloudflare has expanded its Logpush integration with Sumo Logic's Cloud SIEM to cover Zero Trust products, giving joint customers automated normalization and correlation of security logs across Cloudflare Gateway, Access, and related services. The update builds on the existing Cloudflare App for Sumo Logic and is aimed at reducing alert fatigue and speeding up triage for security analysts.
Cloudflare Zero Trust deployments generate substantial log volumes documenting who accessed what, when, and from where—including websites visited, application sign-ins, and data shared from SaaS services. Previously, automated correlation of Cloudflare security signals in Sumo Logic covered only core services such as WAF and bot detection events. The expanded support now brings visibility into Zero Trust components, which has grown more critical with distributed work and hybrid and multi-cloud architectures.
The newly supported log types in Sumo Logic Cloud SIEM include:
- Cloudflare Gateway (Network, DNS, HTTP)
- Cloudflare Remote Browser Isolation (included with Gateway logs)
- Cloudflare Data Loss Prevention (included with Gateway logs)
- Cloudflare Access (Access audit logs)
- Cloudflare Cloud Access Security Broker (Findings logs)
By converging this security and network data, the integration is designed to produce high-fidelity insights that help analysts triage faster and reduce noise from Zero Trust log streams.
"As a long time Cloudflare partner, we've worked together to help joint customers analyze events and trends from their websites and applications to provide end-to-end visibility and improve digital experiences. We're excited to expand this partnership to provide real-time insights into the Zero Trust security posture of mutual customers in Sumo Logic's Cloud SIEM."
— John Coyle, Vice President of Business Development, Sumo Logic
Setting up the integration
To use the expanded integration, customers first enable Logpush to Sumo Logic, which sends Cloudflare logs directly to Sumo Logic's cloud-native platform. From there, install the Cloudflare App from the App Catalog; Cloud SIEM customers then forward logs to Cloud SIEM for automated normalization and correlation.
- Enable Logpush to Sumo Logic. Cloudflare Logpush supports pushing logs directly to Sumo Logic via the Cloudflare dashboard or via API.
- Install the Cloudflare App for Sumo Logic. Locate and install the Cloudflare app from the App Catalog. A dashboard preview is available before installation. Once installed, Cloudflare Dashboards display key information for all core services.
- (Cloud SIEM customers) Forward logs to Cloud SIEM. After the previous steps, enable the updated parser for Cloudflare logs by adding the
_parserfield to the S3 source created during Cloudflare App installation.
Cloudflare's Logpush service is available to Enterprise customers only. Organizations without a SIEM tool can consider Cloudflare R2 for log storage as a scalable, cost-effective alternative, with the provider continuing to work with technology partners on additional integrations for Zero Trust visibility.



