Getting Data In

Best way to connect Splunk and Cloudflare

vadim_osipov
Engager

Hey guys, 

I am a nebbie with Splunk, but already fell in love with it. Such a great tool! 

I was tasked with storing settings of a website from Cloudflare into Splunk. Without much of a knowledge I wrote a small Python script that basically gets settings data from CF and sends it to Splunk via HEC token, on my local instance. This is one of the ways of doing it, but I'm sure there must be much slicker way. 

Question is, what would you guys recommend to achieve this task? What would be the best practices? 

 

Thanks in advance, 

Vadim

Labels (1)
0 Karma

gordo32
Communicator

That add-on should point to this URL for instructions on how to configure Cloudflare logging: https://developers.cloudflare.com/logs/about

If you download and unzip the add-on, you'll find this URL in the readme.txt, but it should really be added to the Overview page on Splunkbase.

Gord T.

0 Karma

aasabatini
Motivator

Hi @vadim_osipov 

the best pratices  is:

use the official add-on on the splunkbase

https://splunkbase.splunk.com/app/5114/

this add-on is directly developed from cloudflare.

Regards

 

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”

vadim_osipov
Engager

Thanks for a reply!

 

I looked into it and cant a decent way in this App(https://splunkbase.splunk.com/app/5114/) to store settings out of Cloudflare. Maybe I am missing something? 

 

Thanks!

0 Karma

aasabatini
Motivator

Hi @vadim_osipov 

which issue do you have with the add-on?

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma

vadim_osipov
Engager

I don't necessarily have an issue with the add-on. I just don't see how can I gather "settings" of the website using it. Maybe that just escapes me, maybe I'm not too familiar with usage of this. If you could possibly point me to a proper solution. I'd surely appreciate it.

Tags (1)
0 Karma

aasabatini
Motivator

Hi @vadim_osipov 

 

If you read the documentation you can see you need to use a amazon S3bucket to mange the queue.

check the documentation

 

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Note: This post outlines a proposed architecture and serves as an interest check. If we secure commitments ...