Managing Your Cloudflare Data Collection and Events

Role Availability Read-Only Investigator Analyst Manager

After you configure the BlueApp for Cloudflare and have a successful connection, you should make sure that the scheduled collection job is enabled. For each deployed sensor, USM Anywhere includes an out-of-the-box log collection job to support BlueApp for Cloudflare data collection. You can then use rules to manage the events Any traffic or data exchange detected by LevelBlue products through a sensor or external devices such as a firewall. that USM Anywhere generates and stores, as well as the alarms Alarms provide notification of an event or sequence of events that require attention or investigation. that it generates from specific types of events.

Important: The Cloudflare service can generate numerous log messages, depending on the traffic and number of the website assets it manages. When you have BlueApp for Cloudflare configured, and the log collection job enabled, the number of events produced in USM Anywhere could be excessive and consume large amounts of data storage. To address this, you should add the suggested filtering rule to eliminate standard "HTTP OK" events.