Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Cloudflare Logpush] Add support for new fields and Page Shield data stream #9809

Open
chemamartinez opened this issue May 7, 2024 · 1 comment
Labels
Integration:Cloudflare Logpush Cloudflare Logpush Team:Security-Service Integrations Security Service Integrations Team

Comments

@chemamartinez
Copy link
Contributor

Cloudflare has updated most of their event datasets with new fields that the integration doesn't support. Here there is a table with the fields that are missed so far.

Data stream  Fields
dns_firewall ResponseReason
firewall LeakedCredentialCheckResult
Ref
gateway_dns  CustomResolveDurationMs
CustomResolverAddress
CustomResolverPolicyID
CustomResolverPolicyName
CustomResolverResponse
IsResponseCached
MatchedIndicatorFeedIDs
MatchedIndicatorFeedNames
QueryIndicatorFeedIDs
QueryIndicatorFeedNames
gateway_http  DownloadMatchedDlpProfileEntries
DownloadMatchedDlpProfiles
SessionID
UploadMatchedDlpProfileEntries
UploadMatchedDlpProfiles
gateway_network  DetectedProtocol
http_request  CacheReserveUsed
ClientRegionCode
ContentScanObjResults
ContentScanObjTypes
JA3Hash
LeakedCredentialCheckResult
RequestHeaders
ResponseHeaders
WorkerWallTimeUs
network_analytics  AttackVector
ColoCity
ColoCode
DestinationASNName
RuleName
SourceASNName
network_session DetectedProtocol
workers_trace  Entrypoint
ScriptVersion

Reference: https://developers.cloudflare.com/logs/reference/log-fields/

On the other hand, a new dataset called Page Shield has been added.

@chemamartinez chemamartinez added Integration:Cloudflare Logpush Cloudflare Logpush Team:Security-Service Integrations Security Service Integrations Team labels May 7, 2024
@elasticmachine
Copy link

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Integration:Cloudflare Logpush Cloudflare Logpush Team:Security-Service Integrations Security Service Integrations Team
Projects
None yet
Development

No branches or pull requests

2 participants