↳ GitHub sourceConnector

Cloudflare (Using Blob Container) (via Codeless Connector Framework)

An inconsistency was detected in the sources: variants or an invalid file. Check the files and commit shown below.

Description

The Cloudflare data connector provides the capability to ingest Cloudflare logs into Microsoft Sentinel using the Cloudflare Logpush and Azure Blob Storage. Refer to [Cloudflare documentation](https://developers.cloudflare.com/logs/about/) for more information. <p><span style='color:red; font-weight:bold;'>NOTE</span>: The Cloudflare (Using Blob Container) (via Codeless Connector Framework) data connector available in the solution requires the Azure Blob Storage account and the Microsoft Sentinel workspace to be in the <span style='font-weight:bold;'>same Azure subscription and the same Resource Group</span>. Deploying across different subscriptions or resource groups may result in errors such as <span style='font-weight:bold;'>CreateDataFlowResources not defined</span> during connector configuration.</p>
Declared status
1
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
Create a storage account and a container
Before setting up logpush in Cloudflare, first create a storage account and a container in Microsoft Azure. Use [this guide](https://learn.microsoft.com/en-us/azure/storage/blobs/storage-blobs-introduction) to know more about Container and Blob. Follow the steps in the [documentation](https://learn.microsoft.com/en-us/azure/storage/common/storage-account-create?tabs=azure-portal) to create an Azure Storage account.
Generate a Blob SAS URL
Create and Write permissions are required. Refer the [documentation](https://learn.microsoft.com/en-us/azure/ai-services/translator/document-translation/how-to-guides/create-sas-tokens?tabs=Containers) to know more about Blob SAS token and url.
Collecting logs from Cloudflare to your Blob container
Follow the steps in the [documentation](https://developers.cloudflare.com/logs/get-started/enable-destinations/azure/) for collecting logs from Cloudflare to your Blob container.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Connect Cloudflare Logs to Microsoft Sentinel
To enable Cloudflare logs for Microsoft Sentinel, provide the required information below and click on Connect. >
The Blob container's URL you want to collect data from
The Blob container's storage account resource group name
The Blob container's storage account location
The Blob container's storage account subscription id
The event grid topic name of the blob container's storage account if exist. else keep empty.
The data flow using event grid to send 'blob-created event' notifications. There could be only one event grid topic for each storage account. Go to your blob container's storage account and look in the 'Events' section. If you already have a topic, please provide it's name. Else, keep the text box empty.
toggle

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
CloudflareDefinition
Additional source files 1Solutions/Cloudflare CCF/Data Connectors/CloudflareLog_CCF/CloudflareLog_ConnectorDefinition.jsonsource ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.