Skip to content

Cloudflare SSE

You can integrate Cloudflare SSE with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Cloudflare SSE product overview

Cloudflare One is Cloudflare's Security Service Edge (SSE) platform, converging Zero Trust Network Access (ZTNA), Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), DNS filtering, and firewall-as-a-service to secure access to the web, cloud services, and private applications from a single global network.

What we ingest

Sophos XDR collects Cloudflare data via Cloudflare Logpush, which forwards logs to a Sophos XDR data collector over Amazon S3 or an HTTP endpoint. The following log categories are collected:

  • Web activity: Zone HTTP requests, Gateway (SWG) HTTP traffic, and firewall events.
  • DNS activity: Zone and Gateway DNS resolver queries.
  • Intrusion detections: Magic IDS and WAF-based detections.
  • Threat findings: CASB findings.
  • Access and authentication: Zero Trust Access requests.
  • Audit and device posture: Account audit logs and device posture results.

Event and data types

We ingest the following event and data types from Cloudflare SSE:

  • Web activity: Zone HTTP requests, Gateway (SWG) HTTP traffic, and firewall events, including the URL, method, action, and client. Normalized to HTTP telemetry.
  • DNS activity: Zone and Gateway DNS resolver queries and responses, including the queried domain and action. Normalized to DNS query telemetry.
  • Intrusion detections: Cloudflare Magic IDS detections and WAF/HTTP intrusion detections, including the signature and endpoints. Normalized to network intrusion detection telemetry.
  • Threat findings: CASB findings for cloud application risks. Normalized to third-party security alert telemetry.
  • Access and authentication: Zero Trust Access request events, with the user, application, and result. Normalized to authentication telemetry.
  • Audit and device posture: Account audit-log activity and Zero Trust device posture results. Normalized to cloud audit telemetry.

Data provided by this integration

Data provided by Cloudflare SSE gets normalized to the following schemas:

  • auth
  • cloudaudit
  • dnsquery
  • http
  • nids
  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation