Cloudflare and CrowdStrike Expand Integration Coverage

Cloudflare is broadening its CrowdStrike integrations, building on the recently announced Falcon Next-Gen SIEM collaboration. The expanded partnership now brings Cloudflare Email Security and Cloudflare Zero Trust logging into Falcon Next-Gen SIEM, giving security teams a unified view across email threats, access requests, and web activity.

By combining Cloudflare’s edge telemetry with CrowdStrike’s SIEM dashboards and automation workflows, organizations can correlate data from multiple sources to identify risky behavior and respond faster to potential compromises. Happy Cog, a digital agency using the integration, highlighted the value of combining Cloudflare’s Zero Trust capabilities with Falcon Next-Gen SIEM for a comprehensive threat landscape view.

Email Security Alerts in Falcon Next-Gen SIEM

Cloudflare Email Security customers can now push indicator of compromise (IoC) alerts directly to Falcon Next-Gen SIEM. These alerts notify analysts when suspicious activity occurs — such as a user interacting with a phishing email — enabling early detection of account compromise or insider threats. Configurable policies in Cloudflare Email Security control which events get forwarded, so teams can prioritize high-signal alerts.

Zero Trust Logs in Falcon Next-Gen SIEM

Cloudflare’s Zero Trust platform is also being integrated with Falcon Next-Gen SIEM. Mutual customers can send logs from Cloudflare Access and Cloudflare Gateway to Falcon, where they can be visualized, analyzed, and incorporated into detections. This enables security teams to build CrowdStrike workflows that trigger automated responses based on Cloudflare log events.

For example, if Falcon detects that a user’s access request appears fraudulent or that a user is engaging with risky websites, the platform can trigger Cloudflare to move that user to an affected user group and enforce adaptive access controls — such as isolating or quarantining the user’s access.

Connecting Cloudflare Zero Trust Logs to Falcon

To get started, Falcon Next-Gen SIEM customers navigate to the Data Connectors tab in their dashboard and select the Cloudflare Data Connector. After naming and saving the connector, the system generates an API key and API URL. The key is displayed only once, so it should be noted immediately.

Next, in Cloudflare, create an HTTP logpush job via API and use the following format for the destination_conf field:

"destination_conf": "<API URL>?header_Authorization=Bearer%20<API KEY>&tags=<ZONE>,dataset:<DATASET>"

Note the following:

  • <ZONE> is optional for account-level logpush jobs.
  • <DATASET> uses dot-delimited syntax, so http_requests becomes http.requests.

Once the logpush job is active, events will appear in the My Connectors section of the Falcon dashboard. From there, teams can search Cloudflare events and build Falcon Fusion SOAR automation workflows and custom correlation rules based on the incoming log data.

Unified Telemetry for Faster Response

The shared telemetry between CrowdStrike and Cloudflare is designed to reduce mean time to containment and give organizations a clearer path to decisive action against risks. With both platforms working together, teams can block suspicious activity, surface high-fidelity alerts, and accelerate investigation workflows. Customers interested in deployment guidance can reach out to Cloudflare for a consultation on their existing environment.