> For the complete documentation index, see [llms.txt](https://cybrhawksoc.gitbook.io/cybrhawk-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cybrhawksoc.gitbook.io/cybrhawk-docs/siem-integrations/dns-security/cloudflare-dns.md).

# CloudFlare DNS Security

CybrHawk integrates with **Cloudflare DNS Security** to ingest DNS query and policy enforcement logs.\
This integration provides visibility into malicious domains, blocked queries, phishing attempts, and user DNS activity.

***

## Integration Method

Cloudflare DNS logs are delivered via **AWS SQS (Simple Queue Service)**.\
Cloudflare Logpush exports DNS security logs into an AWS SQS queue, which CybrHawk securely ingests into the SIEM platform.

For setup, follow the [AWS SQS Integration Guide](/cybrhawk-docs/siem-integrations/public-cloud/aws-sqs.md).

***

## Prerequisites

* A Cloudflare Enterprise account with **DNS Security Logpush** enabled.
* Access to an AWS account to configure **SQS queues**.
* Cloudflare account permissions to create and manage **Logpush jobs**.
* CybrHawk-provided SQS subscription details for integration.

***

## Next Steps

1. Configure Cloudflare DNS Security **Logpush** to deliver logs to your AWS SQS queue.
2. Follow the [AWS SQS integration steps](/cybrhawk-docs/siem-integrations/public-cloud/aws-sqs.md) to prepare the queue.
3. Send the SQS queue details (ARN, region, access keys if applicable) to 📧 **<socv2@cybrhawk.com>**.
4. CybrHawk engineers will validate ingestion and confirm DNS logs are flowing into the platform.

***
