Cloudflare and CrowdStrike Team Up on Email Security Log Analysis
Cloudflare and CrowdStrike have extended their partnership to integrate Cloudflare Email Security with CrowdStrike Falcon LogScale. Joint customers can now route email detection data into Falcon LogScale for centralized ingestion, querying, and visualization alongside their other log sources.
Falcon LogScale is CrowdStrike's log management and analytics platform, built to handle petabyte-scale streaming data from varied sources. It offers real-time search, customizable dashboards, and visualization tools that help security teams spot anomalies, hunt for threats, and investigate incidents. The platform is designed to scale with growing log volumes while maintaining performance, making it a consolidation point for organizations looking to streamline their log analysis operations.
Getting Detection Data into Falcon LogScale
The integration works by sending Cloudflare Email Security detections to a Falcon LogScale instance via a webhook. To configure it, customers first install the Cloudflare Email Security package from the Falcon LogScale marketplace.

Next, an ingest token must be created under the "Ingest Tokens" tab in Falcon LogScale settings. After copying the token, users go to the Cloudflare Email Security dashboard, open the Settings section, and select the Alert Webhooks tab. From there, they choose "+ New Webhook," pick the SIEM option, and select "Other" from the dropdown. The webhook requires the following details:
- Auth Token: Bearer [INGEST TOKEN]
- Target:
https://cloud.community.humio.com/api/v1/ingest/hec/raw

Customers control which events are forwarded by selecting the expanded option when configuring the webhook—for example, sending only malicious and suspicious detections. Detection data begins flowing to Falcon LogScale within a few minutes of webhook creation.
Out-of-the-Box Content
When the Cloudflare Email Security package is installed from the Falcon LogScale marketplace, it includes a parser for field extraction and a prebuilt dashboard. The parser lets Falcon LogScale query detection data effectively, while the dashboard provides teams with immediate visibility into email security events.

The bundled dashboard includes visualizations and queries intended as a starting point. Customers can extend it by writing their own queries, creating custom widgets, and building a dashboard tailored to their specific use cases.
Cloudflare and CrowdStrike plan to broaden this integration beyond email security to other components of the Zero Trust Suite, allowing customers to relay logs and detection data from those products into Falcon LogScale as well.



