> For the complete documentation index, see [llms.txt](https://docs.scanner.dev/scanner/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scanner.dev/scanner/using-scanner-complete-feature-reference/data-ingestion/sources/cloudflare.md).

# Cloudflare

Cloudflare logs provide visibility into your edge security and network traffic. DNS logs reveal DNS query patterns and potential malicious domains, while HTTP logs capture detailed request metadata including headers, status codes, and security events. These logs are useful for detecting threats, investigating security incidents, and understanding your organization's internet activity.

Cloudflare Logpush allows you to push your Cloudflare logs directly to Amazon S3. This guide walks through how to set up Cloudflare as a log source in Scanner Collect, so that logs can be ingested from S3, normalized, and indexed for search and detection.

Scanner Collect focuses on two Cloudflare zone-scoped datasets: **DNS** and **HTTP**. For all other Cloudflare log types, including account-scoped datasets, teams are welcome to index them from S3 themselves by [creating an Index Rule](/scanner/using-scanner-complete-feature-reference/data-ingestion/create-an-index-rule.md).

## Collect logs in S3

{% stepper %}
{% step %}

### Have a Cloudflare Enterprise subscription

Logpush is only available for Cloudflare Enterprise customers. Confirm that your account has an Enterprise subscription before proceeding.
{% endstep %}

{% step %}

### Set up S3 bucket and Logpush

Follow the [Cloudflare Logpush setup guide](https://developers.cloudflare.com/logs/get-started/enable-destinations/aws-s3/) to configure your S3 bucket and enable Logpush to a bucket that Scanner is linked to.
{% endstep %}

{% step %}

### Configure Logpush format

When setting up Logpush, ensure that files are written as **newline delimited JSON** and **gzipped**.
{% endstep %}
{% endstepper %}

## Create an Index Rule

Once Cloudflare logs are landing in your S3 bucket, [Create an Index Rule](/scanner/using-scanner-complete-feature-reference/data-ingestion/create-an-index-rule.md) to ingest the logs via Scanner Collect for fast search and detections.

### Cloudflare Defaults

During setup, select `Cloudflare: DNS` or `Cloudflare: HTTP` (depending on which logs you want to ingest) as the source type to have the following defaults pre-populated:

* **File Type**: `Json`
* **Compression**: `Gzip`
* **Transformations**: Add Metadata, Parse JSON Columns
* **Timestamp Field**:
  * `.Timestamp` for Cloudflare: DNS
  * `.EdgeStartTimestamp` for Cloudflare: HTTP


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scanner.dev/scanner/using-scanner-complete-feature-reference/data-ingestion/sources/cloudflare.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
