Skip to main content
Cloudflare R2 Log Ingestion Add-on for Splunk app icon

Cloudflare R2 Log Ingestion Add-on for Splunk

Ingests Cloudflare Logpush logs from R2 into Splunk via a stdlib-only S3-compatible modular input.

splunk product badge

Default Version 1.0.2
July 16, 2026
Compatibility
Splunk Enterprise, Splunk Cloud
Platform Version: 10.4, 10.2, 10.0, 9.4
Rating

5

(1)

Log in to rate this app
Support
Developer Supported
Cloudflare R2 Log Ingestion is a Splunk Technology Add-on (TA) that pulls Cloudflare Logpush log files directly from a Cloudflare R2 bucket into Splunk, using a purpose-built modular input that speaks R2's S3-compatible API. Key capabilities: - Works with any Cloudflare Logpush dataset (Gateway DNS, HTTP Requests, Access, Audit, and more) - fully dataset-agnostic - One input per bucket/prefix, each with its own sourcetype and index, so a single Splunk instance can ingest multiple Logpush datasets side by side - Credentials live in a reusable, encrypted Account (stored via Splunk's storage/passwords, never in inputs.conf); any number of Cloudflare accounts can feed the same Splunk instance - Checkpointing via a typed KV Store processed-key set plus a configurable lookback window, so restarts don't lose progress and late-delivered Logpush batches are still picked up (not a single fragile monotonic cursor) - The R2 access layer is pure Python standard library - no boto3, no botocore, no vendored AWS SDK to keep patched Pairs well with the Cloudflare App for Splunk for dashboards and field extractions once the data is in Splunk. Requirements: Splunk Enterprise 9.4 or higher. Requires KV Store, so it runs on a heavy forwarder, IDM, standalone, or search head - not a Universal Forwarder. This release targets on-premises Splunk Enterprise only; Splunk Cloud is not currently a supported deployment target.

Categories

SIEM

Created By

Cloudflare, Inc

Type

addon

Downloads

5

Resources

Log in to report this app listing