Skip to content
downpipes docs

Connect downpipes to the tools you already run

downpipes runs alongside your Cloudflare backups and reports into the rest of your stack. This section has one setup guide per supported product, so you can go straight to the vendor you run and follow the exact steps for it rather than a generic recipe.

The guides fall into three groups.

Identity

Sign in to the downpipes console with the identity provider your organisation already runs. Each guide covers the one or two provider-specific values the preset needs (a tenant id, an Okta domain, a realm) plus how group-to-role mapping reaches downpipes. The shared mechanics of a connection live on Connect OIDC or OAuth2 and Connect SAML.

SIEM

Forward the hash-chained audit trail to the SIEM you run, by push, by pull or by an object-store drop. Each guide names the format, the sink and the exact one-time step that platform needs before your events parse. Only Splunk and Datadog parse a first-time feed with no field mapping on your side; every other guide states plainly what its platform needs first. The push mechanics common to all of them live on Forwarding the audit log to your SIEM.

The SIEM section of the Integrations screen in the console, headed SIEM with a count of 22 and a note reading 2 auto-parse. Twenty-two tiles are shown, each with a mark, a name and an Add action: Splunk and Datadog carry an Auto-parses badge, and the rest, among them Microsoft Sentinel, QRadar, Elastic, CrowdStrike Falcon Next-Gen SIEM, ArcSight, Sumo Logic, Graylog, Google Security Operations, FortiSIEM, Cortex, LogRhythm, Securonix, Rapid7 InsightIDR, Exabeam, Panther, Devo, Logpoint, Cribl and Wazuh, carry none. The last of the twenty-two is a Custom endpoint tile rather than a named vendor.

The console says the same thing the paragraph above does, and it is worth checking against the screen rather than taking on trust: the section counts twenty-two SIEM destinations, twenty-one named platforms plus a custom endpoint, and marks two of them as auto-parsing. The badge is on Splunk and Datadog, and on nothing else. The screen shows one category at a time; the identity and monitoring groups sit beside this one on the same page.

Monitoring

Alert your on-call and watch your fleet from your own tools: incident platforms get dedup and auto-resolve, metrics platforms read a Prometheus-compatible endpoint or take a direct OTLP push, and chat and generic channels are honestly notification-only. Each guide is the specific setup for that channel.

Every destination is opt-in, configured from your own console, and off until you set it up. Where a method has not been confirmed with a live test against the real platform, the guide says so instead of claiming it.

Last updated .