Overview: what Cloudraw sends
Cloudraw can stream its events to the tools your security team already uses. You add a destination, choose which streams it gets, and Cloudraw sends new events as they happen. You can have up to 10 destinations per workspace, of any mix of types.
What is sent
There are two streams. A new destination gets both unless you pick only one.
| Stream | What it contains | kind in the record |
|---|---|---|
| Audit | Every entry in your workspace audit log: admin changes, sign-in and access settings, people and device actions, ended sessions, recordings viewed or deleted, destination changes, and so on. | audit |
| Alerts | Every notification the console shows (for example connector offline, certificate expiring, security alerts), and a Resolved record when the condition clears. | alert |
| Alerts (app firewall) | Every app-firewall decision: a program that was blocked, or would have been blocked in report-only mode. Sent even when the app-firewall alert switch is off, and without the one-per-hour limit the console uses. | app_firewall |
Individual connections and session traffic are not streamed. Admin actions on sessions, such as End session or playing a recording, are in the audit stream. A new destination starts from now. Older audit entries are not sent.
Record format
Every record has the same fields, whatever the destination:
{ "at": "2026-10-07T09:12:44.311Z", "tenant": "<your workspace id>", "kind": "audit | alert | app_firewall", "action": "e.g. siem.create, app_firewall.blocked, resolved", "severity": "info | warning | critical", "message": "short human-readable text", "data": { ... details of the event ... } }- Audit records always have severity
info. The message is<who>: <action>.dataholds the audit entry's fields, theactor, and the entry's chainhashand sequence number, so your SOC can check that nothing is missing. Fields whose names look like secrets (token, secret, password, API key and similar) are replaced with[redacted]. - App-firewall records have severity
warning(blocked) orinfo(would have been blocked).dataholds the device, person, connection, program path, publisher, reason and whether the block was enforced. - Each destination type wraps the record in the format the provider expects. The provider sections below show how.
Delivery and retries
- Events are sent in batches of up to 100, usually within a few seconds.
- Audit stream: nothing is lost. Cloudraw keeps a position for each destination. If the destination fails, Cloudraw holds the entries and retries (after 5 s, 30 s, 2 min, 10 min, then every 30 min) until it works. Entries arrive in order. After a failure a batch can arrive twice, so de-duplicate on the
hashindata. - If a destination keeps failing for 15 minutes, Cloudraw raises a security alert: "Log shipping to your <type> destination is failing since … Audit entries are held and will be delivered when it recovers." The alert clears itself when delivery works again.
- Alerts stream: best effort. A failed batch is retried with the same back-off, up to 6 attempts, and then dropped. Up to 2,000 alert records wait per destination. Beyond that the oldest are dropped. The destination's delivery status shows how many were delivered and dropped.
- Cloudraw always checks the TLS certificate and never follows redirects. Only ports 443, 8088, 8443 and 6514 are allowed. The destination must be reachable on a public address: private, loopback and link-local addresses, internal host names (
localhost,*.local,*.internal,*.localdomain) andcloudraw.comhosts are refused. This is checked again every time Cloudraw connects.
Add a destination
- Prepare the provider sideFollow the section for your provider below. Keep the values you collect at hand.
- Open SIEM streamingIn the Cloudraw admin console go to Settings→Integrations→SIEM streaming and click Add destination.
- Pick the type and fill in the fieldsUse the field table in your provider's section. Choose the streams: Audit, Alerts, or both.
- SaveCloudraw checks the values right away and tells you what is wrong. After saving, secret fields show only
••••••••. They are stored encrypted and never shown again. - Send a test eventClick Test (see below).
You need the Owner or Security admin role to add, test or delete destinations. Auditors can see them.
A destination cannot be edited. To change a value or rotate a secret, add a new destination with the new values, test it, then delete the old one. Do it in that order: a new destination starts from now, so deleting first would leave a gap in your audit trail.
Test a destination
Test sends one real record right away, with no retry, and shows the provider's answer. The record looks like this:
kind: alert · action: siem.test · severity: info · message: "Cloudraw test event — the destination is reachable"If it works, the destination status changes to streaming. If not, it changes to error and the error text is shown. You can run 10 tests per destination per hour.
Splunk (HTTP Event Collector)
Cloudraw sends to the Splunk HTTP Event Collector (HEC). Works with Splunk Enterprise and Splunk Cloud Platform.
In Splunk
- Create an index (recommended)Go to Settings→Indexes→New Index. Name it, for example,
cloudraw, and save. - Turn on HECGo to Settings→Data inputs→HTTP Event Collector. On Splunk Enterprise click Global Settings, set All Tokens to Enabled, keep Enable SSL on, and note the port (default
8088). - Create the tokenClick New Token. Name:
Cloudraw. Leave Enable indexer acknowledgement off. Click Next. - Input settingsSource type: Automatic (Cloudraw sets it). Under Allowed Indexes add your
cloudrawindex and make it the Default Index. Click Review, then Submit. - Copy the token valueIt is a GUID. You need it in Cloudraw.
Your HEC URL is the event endpoint:
Splunk Enterprise: https://splunk.example.com:8088/services/collector/eventSplunk Cloud: https://http-inputs-<your-stack>.splunkcloud.com/services/collector/event
Splunk Enterprise ships HEC with a self-signed certificate. Cloudraw rejects it. Give HEC a certificate from a public CA that matches the host name (or put HEC behind a load balancer that has one). Splunk Cloud already has a valid certificate.
Cloudraw field → value
| Cloudraw field | Value | Required |
|---|---|---|
url | The full HEC event URL, ending in /services/collector/event. Must be https://, on port 443, 8088, 8443 or 6514, with no user name or password in the URL. | Yes |
hec_token | The HEC token value. Sent as Authorization: Splunk <token>. | Yes |
index | Index name, up to 80 characters. Leave empty to use the token's default index. If you set it, the token must allow that index. | No |
sourcetype | Up to 80 characters. Leave empty and Cloudraw uses cloudraw:audit, cloudraw:alert or cloudraw:app_firewall per record. | No |
Each record becomes one HEC event with host and source set to cloudraw, time set from the record, and the full record as event.
Test it
Click Test in Cloudraw, then search in Splunk:
index=cloudraw source=cloudraw event.action="siem.test"Troubleshooting
| Message or symptom | Cause and fix |
|---|---|
HTTP 403 | Wrong or disabled token. Check the token value and that it is enabled. |
HTTP 400 | Often indexer acknowledgement is on for the token (Cloudraw does not send a channel ID), or index is not in the token's allowed indexes. Turn acknowledgement off, or fix the index. |
HTTP 404 | The URL path is wrong. Use /services/collector/event. |
…: SELF_SIGNED_CERT_IN_CHAIN, DEPTH_ZERO_SELF_SIGNED_CERT or UNABLE_TO_VERIFY_LEAF_SIGNATURE | HEC uses a self-signed or private certificate. Use a public CA certificate (see the warning above). |
url: port 8089 not allowed (allowed: 443, 8088, 8443, 6514) | 8089 is the Splunk management port, not HEC. Use the HEC port. |
Microsoft Sentinel
Cloudraw sends to Microsoft Sentinel through the Azure Monitor Logs Ingestion API into a custom table in the Log Analytics workspace that Sentinel uses. (The older HTTP Data Collector API is retired and is not used.) This takes about 20 minutes.
In Microsoft Entra and Azure
- Register an appIn the Microsoft Entra admin center go to Identity→Applications→App registrations→New registration. Name:
Cloudraw log ingestion. Single tenant. No redirect URI. Click Register. On Overview copy the Application (client) ID and the Directory (tenant) ID. - Create a client secretGo to Certificates & secrets→Client secrets→New client secret, click Add and copy the secret's Value (not the Secret ID). No API permissions are needed.
- Create a Data Collection EndpointIn the Azure portal go to Monitor→Settings→Data Collection Endpoints→Create. Use the same region as your Log Analytics workspace. When it is created, open it and copy the Logs Ingestion URL from Overview. It looks like
https://<name>-abcd.westeurope-1.ingest.monitor.azure.com. - Save a sample fileSave this as
cloudraw-sample.jsonon your computer. Azure uses it to build the table columns: [{"TimeGenerated":"2026-10-07T09:00:00.000Z","Tenant":"example","Kind":"audit","Action":"siem.test","Severity":"info","Message":"sample","Data":{"actor":"admin@example.com"}}] - Create the custom table and DCRGo to Log Analytics workspaces→your workspace→Settings→Tables→Create→New custom log (DCR-based).
- Table name: for example
Cloudraw. Azure adds_CL, so the table isCloudraw_CL. - Data collection rule: Create a new data collection rule, for example
cloudraw-dcr. - Data collection endpoint: the one from step 3.
cloudraw-sample.json, keep the default transformation (source), click Next, then Create. - Table name: for example
- Copy the DCR immutable ID and stream nameGo to Monitor→Settings→Data Collection Rules→cloudraw-dcr and click JSON View. Copy
immutableId(starts withdcr-). UnderstreamDeclarationscopy the stream name, for exampleCustom-Cloudraw_CL. - Give the app permission to sendIn the same DCR open Access control (IAM)→Add→Add role assignment. Choose the role Monitoring Metrics Publisher. Under Members choose User, group, or service principal, select
Cloudraw log ingestion, then Review + assign. The role can take up to 30 minutes to work.
Cloudraw sends these columns: TimeGenerated, Tenant, Kind, Action, Severity, Message and Data (dynamic). The sample file above creates exactly these.
Cloudraw field → value
| Cloudraw field | Value | Required |
|---|---|---|
tenant_id | Directory (tenant) ID. Must be a GUID. | Yes |
client_id | Application (client) ID. Must be a GUID. | Yes |
client_secret | The client secret Value. | Yes |
endpoint | The DCE Logs Ingestion URL. Must be https:// and the host must end in .ingest.monitor.azure.com. Cloudraw only ever sends the access token to that kind of host. | Yes |
dcr_immutable_id | The DCR immutableId: dcr- followed by 32 hex characters. | Yes |
stream_name | Custom- followed by letters, digits or _, for example Custom-Cloudraw_CL. | Yes |
Note when the client secret expires. When it does, delivery stops (audit entries are held). Rotate it by adding a new Cloudraw destination with the new secret, testing it, and then deleting the old destination.
Test it
Click Test in Cloudraw. The first records can take 5 to 10 minutes to appear. Then run this in Microsoft Sentinel→Logs:
Cloudraw_CL | where Action == "siem.test" | sort by TimeGenerated descTroubleshooting
| Message or symptom | Cause and fix |
|---|---|
entra token: invalid_client | Wrong or expired client secret, or you pasted the Secret ID. Create a new secret and use its Value. |
entra token: unauthorized_client or entra token: invalid_request | The client ID or tenant ID is wrong, or the app is in a different tenant. Copy both again from the app's Overview page. |
HTTP 403 — … | The app does not have Monitoring Metrics Publisher on the DCR, or the role is not active yet. Check the role assignment and wait up to 30 minutes. |
HTTP 404 — … or HTTP 400 — … | Wrong dcr_immutable_id or stream_name, or the DCE and DCR are in different regions. Check the DCR's JSON View. Azure's own message follows the dash. |
endpoint must be an Azure Monitor ingestion endpoint (*.ingest.monitor.azure.com) | You pasted a different URL (for example the workspace or DCR resource URL). Use the DCE Logs Ingestion URL. |
dcr_immutable_id looks like dcr-<32 hex> | You pasted the DCR name or resource ID. Use immutableId from JSON View. |
stream_name must be Custom-<TableName> | The stream name must start with Custom-. Copy it from streamDeclarations. |
tenant_id and client_id must be GUIDs | Paste the IDs, not the names. |
| Test is OK but the table stays empty | Ingestion can take up to 10 minutes on a new table. Check that the table name in your query matches the table you created. |
Datadog
Cloudraw sends to the Datadog Logs intake API (v2).
In Datadog
- Create an API keyGo to Organization Settings→API Keys→New Key. Name it
Cloudrawand copy the key. Use an API key, not an Application key. - Find your siteLook at the address bar when you are signed in to Datadog.
app.datadoghq.commeans sitedatadoghq.com.app.datadoghq.eumeansdatadoghq.eu.us3.datadoghq.com,us5.datadoghq.com,ap1.datadoghq.comandap2.datadoghq.comare their own sites. US1-FED isddog-gov.com.
Cloudraw field → value
| Cloudraw field | Value | Required |
|---|---|---|
key | The Datadog API key. Sent as the DD-API-KEY header. | Yes |
site | One of datadoghq.com, us3.datadoghq.com, us5.datadoghq.com, datadoghq.eu, ap1.datadoghq.com, ap2.datadoghq.com, ddog-gov.com. Default: datadoghq.com. | No |
service | Value of the service attribute, up to 60 characters. Default: cloudraw. | No |
Each record becomes one log with ddsource:cloudraw, hostname:cloudraw, status set to the severity, tags tenant:<id> and kind:<kind>, the message, and the full record under the cloudraw attribute.
Test it
Click Test in Cloudraw, then open Logs→Explorer and search:
source:cloudraw @cloudraw.action:siem.testTroubleshooting
| Message or symptom | Cause and fix |
|---|---|
HTTP 403 — … | Wrong API key, an Application key instead of an API key, or the key belongs to a different site. Check the key and the site. |
site must be one of datadoghq.com, us3.datadoghq.com, … | Type only the site, for example datadoghq.eu, without https:// or app.. |
| Test is OK but nothing in Logs | Check the time range, and that no exclusion filter on your log index drops source:cloudraw. |
Amazon S3
Cloudraw writes each batch as one NDJSON file (one JSON record per line) to your S3 bucket. Use this for long-term archive, or to feed a SIEM that reads from S3.
In AWS
- Create the bucketIn the S3 console click Create bucket. The name may only use lowercase letters, digits and dashes. No dots. Note the AWS Region. Keep Block all public access on.
- Create an IAM policyIn the IAM console go to Policies→Create policy→JSON and paste this, with your bucket name and prefix:
{
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Action": "s3:PutObject",
"Resource": "arn:aws:s3:::<your-bucket>/<your-prefix>/cloudraw/*"
}]
}
Without a prefix, use
arn:aws:s3:::<your-bucket>/cloudraw/*. Name the policycloudraw-log-export. - Create an IAM userGo to Users→Create user. Name:
cloudraw-log-export. No console access. Choose Attach policies directly and selectcloudraw-log-export. - Create an access keyOpen the user, go to Security credentials→Create access key, choose Third-party service, and copy the Access key and Secret access key.
Cloudraw signs requests with a long-term access key (Signature Version 4). Temporary credentials and IAM roles are not supported. If your bucket uses SSE-KMS with your own key, also allow kms:GenerateDataKey on that key for this user.
Cloudraw field → value
| Cloudraw field | Value | Required |
|---|---|---|
bucket | Bucket name: 3 to 63 lowercase letters, digits and dashes, no dots. | Yes |
region | The bucket's region code, for example eu-central-1. | Yes |
access_key | The IAM access key ID. | Yes |
secret_key | The IAM secret access key. | Yes |
prefix | Folder inside the bucket, up to 200 characters. Letters, digits, / _ . - only, no ... Leave empty to write at the top of the bucket. | No |
Files are named like this (time in UTC):
<prefix>/cloudraw/<workspace id>/YYYY/MM/DD/HHMMSS-<random>.ndjsonTest it
Click Test in Cloudraw. A new .ndjson file with one line appears under today's date folder.
Troubleshooting
| Message or symptom | Cause and fix |
|---|---|
HTTP 403 | Wrong access key or secret, or the policy does not allow s3:PutObject on the path Cloudraw writes to. Check that the resource ARN includes cloudraw/* after your prefix. With SSE-KMS, check the KMS permission. |
HTTP 301 or HTTP 400 | The region is not the bucket's region. Check the bucket's Properties tab. |
HTTP 404 | The bucket name is wrong or the bucket does not exist. |
bucket: lowercase letters, digits and dashes (no dots) | Buckets with dots in the name are not supported. Create a bucket without dots. |
region like eu-central-1 | Type the region code, not the name ("Europe (Frankfurt)"). |
prefix: letters, digits, / _ . - only | Remove spaces and other characters from the prefix. |
Syslog over TLS
Cloudraw sends RFC 5424 syslog messages over TLS (RFC 5425) to your syslog server or SIEM collector, for example rsyslog, syslog-ng, QRadar or ArcSight. TLS is always on. Plain TCP and UDP are not supported.
On your syslog server
- Open a TLS listenerSet up a TCP listener with TLS, normally on port 6514. Cloudraw uses octet-counting framing (RFC 5425), which rsyslog and syslog-ng accept on TLS inputs.
- Install a server certificateThe certificate must match the host name Cloudraw connects to. If you connect by IPv4 address, the certificate needs that address in its Subject Alternative Names. It can come from a public CA, or from your own private CA (see
ca_pem). - Make it reachableThe listener must have a public IP address that Cloudraw can reach. Allow it in your firewall.
Cloudraw does not present a client certificate. If your listener requires mutual TLS, turn that off for Cloudraw's connection and limit access by firewall instead.
Cloudraw field → value
| Cloudraw field | Value | Required |
|---|---|---|
host | DNS name or IPv4 address of the listener. IPv6 addresses are not accepted here. Private, loopback and internal names are refused. | Yes |
port | Default 6514. Must be one of 443, 8088, 8443 or 6514. | No |
ca_pem | Only if your server certificate comes from a private CA. Paste the CA certificate in PEM format (-----BEGIN CERTIFICATE----- …). It must be a CA certificate (basicConstraints CA:TRUE). When set, Cloudraw trusts only this CA for this destination. | No |
Each record is one message. Facility is authpriv (10). Severity is critical (2), warning (4) or info (6). The header is cloudraw orchestrator as host name and app name, the message ID is the record's kind, and the message body is the full record as JSON:
Test it
Click Test in Cloudraw and look for a message with message ID alert and "action":"siem.test". A successful test means Cloudraw finished the TLS handshake and wrote the message. Syslog has no reply, so check that the message actually arrived.
Troubleshooting
| Message or symptom | Cause and fix |
|---|---|
<host>:6514: ECONNREFUSED, …: timeout or …: deadline exceeded | The listener is not running, or a firewall blocks Cloudraw. Check the port and firewall. |
…: UNABLE_TO_VERIFY_LEAF_SIGNATURE, SELF_SIGNED_CERT_IN_CHAIN or DEPTH_ZERO_SELF_SIGNED_CERT | Cloudraw does not trust the server certificate. Paste your private CA in ca_pem, or use a public CA certificate. A self-signed server certificate that is not a CA does not work. |
…: ERR_TLS_CERT_ALTNAME_INVALID | The certificate does not match the host name or IP address in host. |
…: CERT_HAS_EXPIRED | Renew the server certificate. |
… resolves to a non-public address | The host name resolves to a private address. Use a name that resolves to the listener's public address. |
port 514 not allowed (allowed: 443, 8088, 8443, 6514) | Plain syslog ports are not supported. Use a TLS listener on 6514. |
ca_pem must be a PEM certificate / ca_pem must be a CA certificate (basicConstraints CA:TRUE) | Paste the CA certificate (not the server certificate or a private key), including the BEGIN and END lines. |
host must be a DNS name or IPv4 address | Remove https://, ports or spaces from host. |
Generic HTTPS endpoint
Use this for any collector that accepts JSON over HTTPS, for example a log pipeline (Vector, Fluent Bit, Logstash HTTP input, Cribl) or your own service.
On your endpoint
- Accept a JSON POSTCloudraw sends
POSTwithContent-Type: application/jsonand this body, with up to 100 records per request: { "source": "cloudraw", "events": [ { "at": "…", "tenant": "…", "kind": "…", "action": "…", "severity": "…", "message": "…", "data": { … } } ] } - Check the token (recommended)If you set a token, Cloudraw sends
Authorization: Bearer <token>. Reject requests without it. - Answer quickly with 2xxAny 2xx status means delivered. Anything else, including a redirect, counts as a failure and is retried. Answer within 8 seconds.
- Use a valid certificateThe endpoint needs a certificate from a public CA on port 443, 8088, 8443 or 6514.
This destination is not signed. If you need each request signed with a shared secret, use Cloudraw Webhooks instead, which send an HMAC signature header.
Cloudraw field → value
| Cloudraw field | Value | Required |
|---|---|---|
url | Full https:// URL. Port 443, 8088, 8443 or 6514. No user name or password in the URL. Public host only. | Yes |
token | Sent as Authorization: Bearer <token>. Leave empty to send no Authorization header. | No |
Test it
Click Test in Cloudraw. Your endpoint gets one request with one record whose action is siem.test. Cloudraw shows the HTTP status your endpoint returned.
Troubleshooting
| Message or symptom | Cause and fix |
|---|---|
HTTP 401 or HTTP 403 | Your endpoint rejected the token. Check the token value. |
HTTP 301, HTTP 302 or HTTP 308 | Your endpoint redirects. Cloudraw does not follow redirects. Use the final URL. |
url: https:// required | Plain HTTP is not supported. |
url: credentials in the URL are not allowed — use the token fields | Remove user:password@ from the URL and put the secret in token. |
<host>: timeout or <host>: deadline exceeded | Your endpoint took too long. Answer first, then process. |
Troubleshooting (all destinations)
| Message or symptom | Cause and fix |
|---|---|
<field> is required | A required field is empty. See the field table for your provider. |
url: port 9000 not allowed (allowed: 443, 8088, 8443, 6514) | Only these ports are allowed. Publish your collector on one of them. |
url: private, loopback and link-local addresses are not allowed or … resolves to a non-public address | The destination is on a private network. Cloudraw only sends to public addresses. Publish the collector on a public address (for example through a reverse proxy) and restrict it by firewall and token. |
url: internal host names are not allowed | Names like localhost, *.local, *.internal, *.localdomain and cloudraw.com hosts are refused. Use a public DNS name. |
…: ENOTFOUND | The host name does not resolve in public DNS. |
at most 10 destinations per tenant | Delete a destination you no longer use. |
too many test events this hour | 10 tests per destination per hour. Wait and try again. |
Secrets cannot be stored safely right now (encryption key missing on this server). Retry later; … | A temporary problem on the Cloudraw side. Try again later. If it persists, contact support. |
| Security alert: "Log shipping to your … destination is failing since …" | Delivery has failed for 15 minutes. Audit entries are held, not lost. Open the destination to see the last error, fix it on the provider side, and click Test. The alert clears when delivery works again. |
| Some alert records are missing after a long outage | The alerts stream drops a batch after 6 failed attempts, and keeps at most 2,000 waiting records. The destination's delivery status shows how many were dropped. The audit stream is never dropped. |
| The same audit record arrived twice | Delivery is at-least-once. De-duplicate on data.hash. |