February 15, 2022
With the proliferation of security SaaS platforms, such as Cloudflare, Proofpoint, and PingOne, enterprises must figure out how to integrate third-party data shipped over the internet into their analytics and SIEM platforms. This requirement to integrate third-party data raises a host of security, infrastructure, and data quality questions. Enterprises can lower risk, and complete projects faster, by using Cribl Stream Cloud to solve their challenges in managing third-party SaaS platform data.
These challenges get easier with the release of Stream Cloud. Use Stream Cloud to handle connections from all of your SaaS data sources. Then transform the data to your preferred format and ship it to your logging platform.
Cloudflare is a very popular SaaS platform that provides several services, including managed DNS, CDN, WAF, and DDOS mitigation. It has an enormous scale and provides detailed data that any enterprise would want in its analytics and SIEM platforms.
If your enterprise requires Cloudflare logging, it only needs to do the following to integrate Cloudflare into Stream Cloud:
If you choose the AWS S3 bucket option, then create a Stream S3 Source.
If you choose Splunk HEC, then create a Splunk HEC Source.
Use the Cloudflare console to configure logging per your data-source decisions.
Once you make your ingest decision, then you determine your format:
Finally, ship the data securely – using the method of your choice – back to your analytics platform.
Adopting Stream Cloud to integrate SaaS logging reduces risk and increases speed to the solution, giving enterprises easier, faster access to SaaS platform data while maintaining a strong security posture. Want more information? Join the Community Slack and sign up for Cribl.Cloud, free up to 1 TB/day, at https://cribl.cloud/