M ManySignal
MS
CF
Integration

Cloudflare Integration

Edge security signals from Cloudflare in your unified threat timeline.

What this integration does

Cloudflare meets agentic SOC

Cloudflare protects millions of web properties with WAF, DDoS mitigation, Bot Management, and Zero Trust networking. ManySignal ingests Cloudflare Logpush streams (HTTP, Firewall, DNS, Gateway) and Cloudflare's Audit Log, correlating edge-layer signals with identity and cloud data to detect web application attacks, data exfiltration, and insider misuse.

HTTP request log ingestion via Cloudflare Logpush to S3 or R2

Firewall event ingestion (WAF, Rate Limiting, Bot Management)

DNS query log ingestion for C2 domain detection

Data collected

  • Cloudflare HTTP request logs
  • WAF and firewall rule match events
  • DNS query logs
  • Zero Trust Access session events
  • Cloudflare Audit Log

Actions supported

  • Add IP to Cloudflare IP block list
  • Create Cloudflare firewall rule to block request pattern
  • Enable Cloudflare Under Attack Mode
  • Block user from Cloudflare Zero Trust Access policy
  • Purge Cloudflare cache for affected resources

Getting started

Set up in minutes

  1. 1

    Configure Logpush

  2. 2

    Generate a Cloudflare API token

  3. 3

    Connect in ManySignal

Cloudflare Integration: frequently asked questions

Does ManySignal work with Cloudflare's free plan?

Logpush is a Cloudflare Enterprise feature. The Audit Log and basic Firewall Events API are available on Pro and Business plans for limited ingestion use cases.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.