Amazon AWS S3 REST API log source parameters for Cloudflare Logs
If IBM® QRadar® does not automatically detect the log source, add a Cloudflare Logs log source on the QRadar Console by using the Amazon AWS S3 REST API protocol.
When you use the Amazon AWS S3 REST API protocol, there are specific parameters that you must configure.
|Log Source type||Cloudflare Logs|
|Protocol Configuration||Amazon AWS S3 REST API|
|Log Source Identifier||
Type a unique name for the log source.
The Log Source Identifier can be any valid value and does not need to reference a specific server. The Log Source Identifier can be the same value as the Log Source Name. If you have more than one Cloudflare Logs log source that is configured, you might want to identify the first log source as Cloudflare1, the second log source as Cloudflare2, and the third log source as Cloudflare3.
|Event Format||Select LINEBYLINE from the list.|
|Use as a Gateway Log Source||Select this option for the collected events to flow through the QRadar Traffic Analysis engine and for QRadar to automatically detect one or more log sources.|
|Log Source Identifier Pattern||
This option is available when Use as a Gateway Log Source is set to yes.
Use this option if you want to define a custom Log Source Identifier for events being processed. This field accepts key value pairs to define the custom Log Source Identifier, where the key is the Identifier Format String, and the value is the associated regex pattern. You can define multiple key value pairs by entering a pattern on a new line. When multiple patterns are used, they are evaluated in order until a match is found and a custom Log Source Identifier can be returned.
|Show Advanced Options||Select this option.|
This option is available when Show Advanced Options is set to yes.
Type a regex for the file pattern that matches the files that you want to pull; for example, .*?\.log\.gz
For a complete list of Amazon AWS S3 REST API protocol parameters and their values, see Amazon AWS S3 REST API protocol configuration options.