CloudrawSetup guides
Download PDF
Integrations · For IT admins

Send Cloudraw events to your SIEM

Stream Cloudraw audit events, alerts and app-firewall decisions to Splunk, Microsoft Sentinel, Datadog, Amazon S3, syslog over TLS or your own HTTPS endpoint.

Last updated 7 October 2026 · Download this guide as PDF

Overview: what Cloudraw sends

Cloudraw can stream its events to the tools your security team already uses. You add a destination, choose which streams it gets, and Cloudraw sends new events as they happen. You can have up to 10 destinations per workspace, of any mix of types.

What is sent

There are two streams. A new destination gets both unless you pick only one.

StreamWhat it containskind in the record
AuditEvery entry in your workspace audit log: admin changes, sign-in and access settings, people and device actions, ended sessions, recordings viewed or deleted, destination changes, and so on.audit
AlertsEvery notification the console shows (for example connector offline, certificate expiring, security alerts), and a Resolved record when the condition clears.alert
Alerts (app firewall)Every app-firewall decision: a program that was blocked, or would have been blocked in report-only mode. Sent even when the app-firewall alert switch is off, and without the one-per-hour limit the console uses.app_firewall
Note

Individual connections and session traffic are not streamed. Admin actions on sessions, such as End session or playing a recording, are in the audit stream. A new destination starts from now. Older audit entries are not sent.

Record format

Every record has the same fields, whatever the destination:

{ "at": "2026-10-07T09:12:44.311Z", "tenant": "<your workspace id>", "kind": "audit | alert | app_firewall", "action": "e.g. siem.create, app_firewall.blocked, resolved", "severity": "info | warning | critical", "message": "short human-readable text", "data": { ... details of the event ... } }
  • Audit records always have severity info. The message is <who>: <action>. data holds the audit entry's fields, the actor, and the entry's chain hash and sequence number, so your SOC can check that nothing is missing. Fields whose names look like secrets (token, secret, password, API key and similar) are replaced with [redacted].
  • App-firewall records have severity warning (blocked) or info (would have been blocked). data holds the device, person, connection, program path, publisher, reason and whether the block was enforced.
  • Each destination type wraps the record in the format the provider expects. The provider sections below show how.

Delivery and retries

  • Events are sent in batches of up to 100, usually within a few seconds.
  • Audit stream: nothing is lost. Cloudraw keeps a position for each destination. If the destination fails, Cloudraw holds the entries and retries (after 5 s, 30 s, 2 min, 10 min, then every 30 min) until it works. Entries arrive in order. After a failure a batch can arrive twice, so de-duplicate on the hash in data.
  • If a destination keeps failing for 15 minutes, Cloudraw raises a security alert: "Log shipping to your <type> destination is failing since … Audit entries are held and will be delivered when it recovers." The alert clears itself when delivery works again.
  • Alerts stream: best effort. A failed batch is retried with the same back-off, up to 6 attempts, and then dropped. Up to 2,000 alert records wait per destination. Beyond that the oldest are dropped. The destination's delivery status shows how many were delivered and dropped.
  • Cloudraw always checks the TLS certificate and never follows redirects. Only ports 443, 8088, 8443 and 6514 are allowed. The destination must be reachable on a public address: private, loopback and link-local addresses, internal host names (localhost, *.local, *.internal, *.localdomain) and cloudraw.com hosts are refused. This is checked again every time Cloudraw connects.

Add a destination

  1. Prepare the provider sideFollow the section for your provider below. Keep the values you collect at hand.
  2. Open SIEM streamingIn the Cloudraw admin console go to Settings→Integrations→SIEM streaming and click Add destination.
  3. Pick the type and fill in the fieldsUse the field table in your provider's section. Choose the streams: Audit, Alerts, or both.
  4. SaveCloudraw checks the values right away and tells you what is wrong. After saving, secret fields show only ••••••••. They are stored encrypted and never shown again.
  5. Send a test eventClick Test (see below).

You need the Owner or Security admin role to add, test or delete destinations. Auditors can see them.

Important

A destination cannot be edited. To change a value or rotate a secret, add a new destination with the new values, test it, then delete the old one. Do it in that order: a new destination starts from now, so deleting first would leave a gap in your audit trail.

Test a destination

Test sends one real record right away, with no retry, and shows the provider's answer. The record looks like this:

kind: alert · action: siem.test · severity: info · message: "Cloudraw test event — the destination is reachable"

If it works, the destination status changes to streaming. If not, it changes to error and the error text is shown. You can run 10 tests per destination per hour.

Splunk (HTTP Event Collector)

Cloudraw sends to the Splunk HTTP Event Collector (HEC). Works with Splunk Enterprise and Splunk Cloud Platform.

In Splunk

  1. Create an index (recommended)Go to Settings→Indexes→New Index. Name it, for example, cloudraw, and save.
  2. Turn on HECGo to Settings→Data inputs→HTTP Event Collector. On Splunk Enterprise click Global Settings, set All Tokens to Enabled, keep Enable SSL on, and note the port (default 8088).
  3. Create the tokenClick New Token. Name: Cloudraw. Leave Enable indexer acknowledgement off. Click Next.
  4. Input settingsSource type: Automatic (Cloudraw sets it). Under Allowed Indexes add your cloudraw index and make it the Default Index. Click Review, then Submit.
  5. Copy the token valueIt is a GUID. You need it in Cloudraw.

Your HEC URL is the event endpoint:

Splunk Enterprise: https://splunk.example.com:8088/services/collector/event
Splunk Cloud: https://http-inputs-<your-stack>.splunkcloud.com/services/collector/event
Warning

Splunk Enterprise ships HEC with a self-signed certificate. Cloudraw rejects it. Give HEC a certificate from a public CA that matches the host name (or put HEC behind a load balancer that has one). Splunk Cloud already has a valid certificate.

Cloudraw field → value

Cloudraw fieldValueRequired
urlThe full HEC event URL, ending in /services/collector/event. Must be https://, on port 443, 8088, 8443 or 6514, with no user name or password in the URL.Yes
hec_tokenThe HEC token value. Sent as Authorization: Splunk <token>.Yes
indexIndex name, up to 80 characters. Leave empty to use the token's default index. If you set it, the token must allow that index.No
sourcetypeUp to 80 characters. Leave empty and Cloudraw uses cloudraw:audit, cloudraw:alert or cloudraw:app_firewall per record.No

Each record becomes one HEC event with host and source set to cloudraw, time set from the record, and the full record as event.

Test it

Click Test in Cloudraw, then search in Splunk:

index=cloudraw source=cloudraw event.action="siem.test"

Troubleshooting

Message or symptomCause and fix
HTTP 403Wrong or disabled token. Check the token value and that it is enabled.
HTTP 400Often indexer acknowledgement is on for the token (Cloudraw does not send a channel ID), or index is not in the token's allowed indexes. Turn acknowledgement off, or fix the index.
HTTP 404The URL path is wrong. Use /services/collector/event.
…: SELF_SIGNED_CERT_IN_CHAIN, DEPTH_ZERO_SELF_SIGNED_CERT or UNABLE_TO_VERIFY_LEAF_SIGNATUREHEC uses a self-signed or private certificate. Use a public CA certificate (see the warning above).
url: port 8089 not allowed (allowed: 443, 8088, 8443, 6514)8089 is the Splunk management port, not HEC. Use the HEC port.

Microsoft Sentinel

Cloudraw sends to Microsoft Sentinel through the Azure Monitor Logs Ingestion API into a custom table in the Log Analytics workspace that Sentinel uses. (The older HTTP Data Collector API is retired and is not used.) This takes about 20 minutes.

In Microsoft Entra and Azure

  1. Register an appIn the Microsoft Entra admin center go to Identity→Applications→App registrations→New registration. Name: Cloudraw log ingestion. Single tenant. No redirect URI. Click Register. On Overview copy the Application (client) ID and the Directory (tenant) ID.
  2. Create a client secretGo to Certificates & secrets→Client secrets→New client secret, click Add and copy the secret's Value (not the Secret ID). No API permissions are needed.
  3. Create a Data Collection EndpointIn the Azure portal go to Monitor→Settings→Data Collection Endpoints→Create. Use the same region as your Log Analytics workspace. When it is created, open it and copy the Logs Ingestion URL from Overview. It looks like https://<name>-abcd.westeurope-1.ingest.monitor.azure.com.
  4. Save a sample fileSave this as cloudraw-sample.json on your computer. Azure uses it to build the table columns: [{"TimeGenerated":"2026-10-07T09:00:00.000Z","Tenant":"example","Kind":"audit","Action":"siem.test","Severity":"info","Message":"sample","Data":{"actor":"admin@example.com"}}]
  5. Create the custom table and DCRGo to Log Analytics workspaces→your workspace→Settings→Tables→Create→New custom log (DCR-based).
    • Table name: for example Cloudraw. Azure adds _CL, so the table is Cloudraw_CL.
    • Data collection rule: Create a new data collection rule, for example cloudraw-dcr.
    • Data collection endpoint: the one from step 3.
    Click Next, upload cloudraw-sample.json, keep the default transformation (source), click Next, then Create.
  6. Copy the DCR immutable ID and stream nameGo to Monitor→Settings→Data Collection Rules→cloudraw-dcr and click JSON View. Copy immutableId (starts with dcr-). Under streamDeclarations copy the stream name, for example Custom-Cloudraw_CL.
  7. Give the app permission to sendIn the same DCR open Access control (IAM)→Add→Add role assignment. Choose the role Monitoring Metrics Publisher. Under Members choose User, group, or service principal, select Cloudraw log ingestion, then Review + assign. The role can take up to 30 minutes to work.
Note

Cloudraw sends these columns: TimeGenerated, Tenant, Kind, Action, Severity, Message and Data (dynamic). The sample file above creates exactly these.

Cloudraw field → value

Cloudraw fieldValueRequired
tenant_idDirectory (tenant) ID. Must be a GUID.Yes
client_idApplication (client) ID. Must be a GUID.Yes
client_secretThe client secret Value.Yes
endpointThe DCE Logs Ingestion URL. Must be https:// and the host must end in .ingest.monitor.azure.com. Cloudraw only ever sends the access token to that kind of host.Yes
dcr_immutable_idThe DCR immutableId: dcr- followed by 32 hex characters.Yes
stream_nameCustom- followed by letters, digits or _, for example Custom-Cloudraw_CL.Yes
Important

Note when the client secret expires. When it does, delivery stops (audit entries are held). Rotate it by adding a new Cloudraw destination with the new secret, testing it, and then deleting the old destination.

Test it

Click Test in Cloudraw. The first records can take 5 to 10 minutes to appear. Then run this in Microsoft Sentinel→Logs:

Cloudraw_CL | where Action == "siem.test" | sort by TimeGenerated desc

Troubleshooting

Message or symptomCause and fix
entra token: invalid_clientWrong or expired client secret, or you pasted the Secret ID. Create a new secret and use its Value.
entra token: unauthorized_client or entra token: invalid_requestThe client ID or tenant ID is wrong, or the app is in a different tenant. Copy both again from the app's Overview page.
HTTP 403 — …The app does not have Monitoring Metrics Publisher on the DCR, or the role is not active yet. Check the role assignment and wait up to 30 minutes.
HTTP 404 — … or HTTP 400 — …Wrong dcr_immutable_id or stream_name, or the DCE and DCR are in different regions. Check the DCR's JSON View. Azure's own message follows the dash.
endpoint must be an Azure Monitor ingestion endpoint (*.ingest.monitor.azure.com)You pasted a different URL (for example the workspace or DCR resource URL). Use the DCE Logs Ingestion URL.
dcr_immutable_id looks like dcr-<32 hex>You pasted the DCR name or resource ID. Use immutableId from JSON View.
stream_name must be Custom-<TableName>The stream name must start with Custom-. Copy it from streamDeclarations.
tenant_id and client_id must be GUIDsPaste the IDs, not the names.
Test is OK but the table stays emptyIngestion can take up to 10 minutes on a new table. Check that the table name in your query matches the table you created.

Datadog

Cloudraw sends to the Datadog Logs intake API (v2).

In Datadog

  1. Create an API keyGo to Organization Settings→API Keys→New Key. Name it Cloudraw and copy the key. Use an API key, not an Application key.
  2. Find your siteLook at the address bar when you are signed in to Datadog. app.datadoghq.com means site datadoghq.com. app.datadoghq.eu means datadoghq.eu. us3.datadoghq.com, us5.datadoghq.com, ap1.datadoghq.com and ap2.datadoghq.com are their own sites. US1-FED is ddog-gov.com.

Cloudraw field → value

Cloudraw fieldValueRequired
keyThe Datadog API key. Sent as the DD-API-KEY header.Yes
siteOne of datadoghq.com, us3.datadoghq.com, us5.datadoghq.com, datadoghq.eu, ap1.datadoghq.com, ap2.datadoghq.com, ddog-gov.com. Default: datadoghq.com.No
serviceValue of the service attribute, up to 60 characters. Default: cloudraw.No

Each record becomes one log with ddsource:cloudraw, hostname:cloudraw, status set to the severity, tags tenant:<id> and kind:<kind>, the message, and the full record under the cloudraw attribute.

Test it

Click Test in Cloudraw, then open Logs→Explorer and search:

source:cloudraw @cloudraw.action:siem.test

Troubleshooting

Message or symptomCause and fix
HTTP 403 — …Wrong API key, an Application key instead of an API key, or the key belongs to a different site. Check the key and the site.
site must be one of datadoghq.com, us3.datadoghq.com, …Type only the site, for example datadoghq.eu, without https:// or app..
Test is OK but nothing in LogsCheck the time range, and that no exclusion filter on your log index drops source:cloudraw.

Amazon S3

Cloudraw writes each batch as one NDJSON file (one JSON record per line) to your S3 bucket. Use this for long-term archive, or to feed a SIEM that reads from S3.

In AWS

  1. Create the bucketIn the S3 console click Create bucket. The name may only use lowercase letters, digits and dashes. No dots. Note the AWS Region. Keep Block all public access on.
  2. Create an IAM policyIn the IAM console go to Policies→Create policy→JSON and paste this, with your bucket name and prefix: { "Version": "2012-10-17", "Statement": [{ "Effect": "Allow", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::<your-bucket>/<your-prefix>/cloudraw/*" }] } Without a prefix, use arn:aws:s3:::<your-bucket>/cloudraw/*. Name the policy cloudraw-log-export.
  3. Create an IAM userGo to Users→Create user. Name: cloudraw-log-export. No console access. Choose Attach policies directly and select cloudraw-log-export.
  4. Create an access keyOpen the user, go to Security credentials→Create access key, choose Third-party service, and copy the Access key and Secret access key.
Note

Cloudraw signs requests with a long-term access key (Signature Version 4). Temporary credentials and IAM roles are not supported. If your bucket uses SSE-KMS with your own key, also allow kms:GenerateDataKey on that key for this user.

Cloudraw field → value

Cloudraw fieldValueRequired
bucketBucket name: 3 to 63 lowercase letters, digits and dashes, no dots.Yes
regionThe bucket's region code, for example eu-central-1.Yes
access_keyThe IAM access key ID.Yes
secret_keyThe IAM secret access key.Yes
prefixFolder inside the bucket, up to 200 characters. Letters, digits, / _ . - only, no ... Leave empty to write at the top of the bucket.No

Files are named like this (time in UTC):

<prefix>/cloudraw/<workspace id>/YYYY/MM/DD/HHMMSS-<random>.ndjson

Test it

Click Test in Cloudraw. A new .ndjson file with one line appears under today's date folder.

Troubleshooting

Message or symptomCause and fix
HTTP 403Wrong access key or secret, or the policy does not allow s3:PutObject on the path Cloudraw writes to. Check that the resource ARN includes cloudraw/* after your prefix. With SSE-KMS, check the KMS permission.
HTTP 301 or HTTP 400The region is not the bucket's region. Check the bucket's Properties tab.
HTTP 404The bucket name is wrong or the bucket does not exist.
bucket: lowercase letters, digits and dashes (no dots)Buckets with dots in the name are not supported. Create a bucket without dots.
region like eu-central-1Type the region code, not the name ("Europe (Frankfurt)").
prefix: letters, digits, / _ . - onlyRemove spaces and other characters from the prefix.

Syslog over TLS

Cloudraw sends RFC 5424 syslog messages over TLS (RFC 5425) to your syslog server or SIEM collector, for example rsyslog, syslog-ng, QRadar or ArcSight. TLS is always on. Plain TCP and UDP are not supported.

On your syslog server

  1. Open a TLS listenerSet up a TCP listener with TLS, normally on port 6514. Cloudraw uses octet-counting framing (RFC 5425), which rsyslog and syslog-ng accept on TLS inputs.
  2. Install a server certificateThe certificate must match the host name Cloudraw connects to. If you connect by IPv4 address, the certificate needs that address in its Subject Alternative Names. It can come from a public CA, or from your own private CA (see ca_pem).
  3. Make it reachableThe listener must have a public IP address that Cloudraw can reach. Allow it in your firewall.
Note

Cloudraw does not present a client certificate. If your listener requires mutual TLS, turn that off for Cloudraw's connection and limit access by firewall instead.

Cloudraw field → value

Cloudraw fieldValueRequired
hostDNS name or IPv4 address of the listener. IPv6 addresses are not accepted here. Private, loopback and internal names are refused.Yes
portDefault 6514. Must be one of 443, 8088, 8443 or 6514.No
ca_pemOnly if your server certificate comes from a private CA. Paste the CA certificate in PEM format (-----BEGIN CERTIFICATE----- …). It must be a CA certificate (basicConstraints CA:TRUE). When set, Cloudraw trusts only this CA for this destination.No

Each record is one message. Facility is authpriv (10). Severity is critical (2), warning (4) or info (6). The header is cloudraw orchestrator as host name and app name, the message ID is the record's kind, and the message body is the full record as JSON:

<86>1 2026-10-07T09:12:44.311Z cloudraw orchestrator - alert - {"at":"…","kind":"alert","action":"siem.test",…}

Test it

Click Test in Cloudraw and look for a message with message ID alert and "action":"siem.test". A successful test means Cloudraw finished the TLS handshake and wrote the message. Syslog has no reply, so check that the message actually arrived.

Troubleshooting

Message or symptomCause and fix
<host>:6514: ECONNREFUSED, …: timeout or …: deadline exceededThe listener is not running, or a firewall blocks Cloudraw. Check the port and firewall.
…: UNABLE_TO_VERIFY_LEAF_SIGNATURE, SELF_SIGNED_CERT_IN_CHAIN or DEPTH_ZERO_SELF_SIGNED_CERTCloudraw does not trust the server certificate. Paste your private CA in ca_pem, or use a public CA certificate. A self-signed server certificate that is not a CA does not work.
…: ERR_TLS_CERT_ALTNAME_INVALIDThe certificate does not match the host name or IP address in host.
…: CERT_HAS_EXPIREDRenew the server certificate.
… resolves to a non-public addressThe host name resolves to a private address. Use a name that resolves to the listener's public address.
port 514 not allowed (allowed: 443, 8088, 8443, 6514)Plain syslog ports are not supported. Use a TLS listener on 6514.
ca_pem must be a PEM certificate / ca_pem must be a CA certificate (basicConstraints CA:TRUE)Paste the CA certificate (not the server certificate or a private key), including the BEGIN and END lines.
host must be a DNS name or IPv4 addressRemove https://, ports or spaces from host.

Generic HTTPS endpoint

Use this for any collector that accepts JSON over HTTPS, for example a log pipeline (Vector, Fluent Bit, Logstash HTTP input, Cribl) or your own service.

On your endpoint

  1. Accept a JSON POSTCloudraw sends POST with Content-Type: application/json and this body, with up to 100 records per request: { "source": "cloudraw", "events": [ { "at": "…", "tenant": "…", "kind": "…", "action": "…", "severity": "…", "message": "…", "data": { … } } ] }
  2. Check the token (recommended)If you set a token, Cloudraw sends Authorization: Bearer <token>. Reject requests without it.
  3. Answer quickly with 2xxAny 2xx status means delivered. Anything else, including a redirect, counts as a failure and is retried. Answer within 8 seconds.
  4. Use a valid certificateThe endpoint needs a certificate from a public CA on port 443, 8088, 8443 or 6514.
Tip

This destination is not signed. If you need each request signed with a shared secret, use Cloudraw Webhooks instead, which send an HMAC signature header.

Cloudraw field → value

Cloudraw fieldValueRequired
urlFull https:// URL. Port 443, 8088, 8443 or 6514. No user name or password in the URL. Public host only.Yes
tokenSent as Authorization: Bearer <token>. Leave empty to send no Authorization header.No

Test it

Click Test in Cloudraw. Your endpoint gets one request with one record whose action is siem.test. Cloudraw shows the HTTP status your endpoint returned.

Troubleshooting

Message or symptomCause and fix
HTTP 401 or HTTP 403Your endpoint rejected the token. Check the token value.
HTTP 301, HTTP 302 or HTTP 308Your endpoint redirects. Cloudraw does not follow redirects. Use the final URL.
url: https:// requiredPlain HTTP is not supported.
url: credentials in the URL are not allowed — use the token fieldsRemove user:password@ from the URL and put the secret in token.
<host>: timeout or <host>: deadline exceededYour endpoint took too long. Answer first, then process.

Troubleshooting (all destinations)

Message or symptomCause and fix
<field> is requiredA required field is empty. See the field table for your provider.
url: port 9000 not allowed (allowed: 443, 8088, 8443, 6514)Only these ports are allowed. Publish your collector on one of them.
url: private, loopback and link-local addresses are not allowed or … resolves to a non-public addressThe destination is on a private network. Cloudraw only sends to public addresses. Publish the collector on a public address (for example through a reverse proxy) and restrict it by firewall and token.
url: internal host names are not allowedNames like localhost, *.local, *.internal, *.localdomain and cloudraw.com hosts are refused. Use a public DNS name.
…: ENOTFOUNDThe host name does not resolve in public DNS.
at most 10 destinations per tenantDelete a destination you no longer use.
too many test events this hour10 tests per destination per hour. Wait and try again.
Secrets cannot be stored safely right now (encryption key missing on this server). Retry later; …A temporary problem on the Cloudraw side. Try again later. If it persists, contact support.
Security alert: "Log shipping to your … destination is failing since …"Delivery has failed for 15 minutes. Audit entries are held, not lost. Open the destination to see the last error, fix it on the provider side, and click Test. The alert clears when delivery works again.
Some alert records are missing after a long outageThe alerts stream drops a batch after 6 failed attempts, and keeps at most 2,000 waiting records. The destination's delivery status shows how many were dropped. The audit stream is never dropped.
The same audit record arrived twiceDelivery is at-least-once. De-duplicate on data.hash.