Enable Logpush to Google Cloud Storage
Cloudflare Logpush supports pushing logs directly to Google Cloud Storage (GCS) via the Cloudflare dashboard or via API.
Manage via the Cloudflare dashboard
Enable Logpush to Google Cloud Storage via the dashboard.
To enable the Cloudflare Logpush service:
Log in to the Cloudflare dashboard.
Select the Enterprise account or domain you want to use with Logpush.
Go to Analytics & Logs > Logs.
Click Add Logpush job. A modal window opens where you will need to complete several steps.
Select the dataset you want to push to a storage service.
Select the data fields to include in your logs. Add or remove fields later by modifying your settings in Logs > Logpush.
Select Google Cloud Storage.
Enter or select the following destination information:
- Bucket path
- Daily subfolders
- For Grant Cloudflare access to upload files to your bucket, make sure your bucket has added Cloudflare’s IAM as a user (if you did not add it already).
Click Validate access.
Enter the Ownership token (included in a file or log Cloudflare sends to your provider) and click Prove ownership. To find the ownership token, click the Open button in the Overview tab of the ownership challenge file.
Click Save and Start Pushing to finish enabling Logpush.
Once connected, Cloudflare lists Google Cloud Storage as a connected service under Logs > Logpush. Edit or remove connected services from here.
Create and get access to a GCS bucket
Cloudflare uses Google Cloud Identity and Access Management (IAM) to gain access to your bucket. The Cloudflare IAM service account needs admin permission for the bucket.
Ensure Log Share permissions are enabled, before attempting to read or configure a Logpush job. For more information refer to the Roles section.
To enable Logpush to GCS:
Create a GCS bucket. Refer to instructions from GCS.
In Storage > Browser > Bucket > Permissions, add the member
logpush@cloudflare-data.iam.gserviceaccount.com
withStorage Object Admin
permission.