Cloudflare Docs
Cloud Email Security (formerly Area 1)
Edit this page
Report an issue with this page
Log into the Cloudflare dashboard
Set theme to dark (⇧+D)

Crowdstrike Falcon LogScale

When Cloud Email Security detects a phishing email, the metadata of the detection can be sent directly to Falcon LogScale. For this tutorial, you will need a working Falcon LogScale account. You will also need to create a new Ingest Token in your LogScale account. Ingest Tokens identify repositories and are used to configure data ingestion to your repository. Refer to Falcon LogScale documentation for more information.

After creating your Ingest Token:

  1. Log in to the Cloud Email Security dashboard.
  2. Go to Settings (the gear icon).
  3. Go to Email Configuration > Domains & Routing > Alert Webhooks.
  4. Select New Webhook.
  5. In App Type, select SIEM.
  6. Choose Crowdstrike from the dropdown, and paste your Ingest Token into the Auth Code section.
  7. In Target, paste the URL https://cloud.community.humio.com/api/v1/ingest/hec/raw.
  8. Select Publish Webhook.