Skip to content

ZachChristensen28/ta_cloudflare_audit

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

36 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Cloudflare Audit Add-on (ta_cloudflare_audit) for Splunk

GitHub Appinspect GitHub release (latest SemVer) Cloudflare API Compatibility Splunk Cloud Compatibility

This Splunk Technical Add-on allows collection of Audit events on a scheduled interval from Cloudfare's API.

Documentation

Full documentation coming Soon.

API Token Requirements (not global token)

Create a custom token with the following permissions.

Setting Item Permission
Account Access: Audit Logs Read
Account Account Settings Read

*Include All accounts for Account Resources.

  • Set Client IP address Filtering and TTL as needed.

Disclaimer

This Technical Add-on (TA) is not affiliated with Cloudflare, Inc. and is not sponsored or sanctioned by the Cloudflare team. Cloudflare is and the Cloudflare web badges are registered trademarks of Cloudflare, Inc. Please visit https://www.cloudflare.com/ for more information about Cloudflare.

About

Info Description
ta_cloudflare_audit 0.0.2 - Splunkbase - TBD | GitHub

Issues or Feature Requests

Please open an issue or feature request on Github.