Documentation · Beta
CASB (Cloudflare)
The CASB integration brings Cloudflare's Cloud Access Security Broker findings — misconfigurations and risks across your connected SaaS and cloud apps — into Crowswatch, where you can review them alongside everything else and alert your team.
How it works
Crowswatch connects to Cloudflare CASB in two parts:
- An API token lets Crowswatch list your connected integrations (SaaS/cloud apps) and flagged assets, refreshed periodically.
- Findings — the security issues themselves — are delivered to Crowswatch, because Cloudflare has no API to list them. You choose how: automatic delivery via a CASB policy (recommended), manual sends, or Logpush.
Step 1: Connect your token
- In Cloudflare, create an account-scoped API token with Cloudflare CASB Read permission.
- In Crowswatch, open CASB in the sidebar and enter your API token and Cloudflare Account ID.
- Save. Crowswatch generates a per-team webhook secret and shows it once — copy it now; you can regenerate it later if needed.
Once connected, Crowswatch pulls your connected apps and assets and keeps them refreshed (about every 15 minutes).
Step 2: Add the webhook destination
Every delivery method goes through the same webhook destination, so set that up first:
- On the Crowswatch CASB Setup tab, copy the Webhook URL and HMAC secret.
- In Cloudflare One, go to Integrations → Webhooks and add a destination using that URL and secret with HMAC-Signing. Use Test delivery to confirm it's reachable.
Step 3: Choose how findings arrive
| Method | Best for | Delivery |
|---|---|---|
| Policy (recommended) | Hands-off, ongoing delivery | Cloudflare sends every new matching finding automatically |
| Manual send | Trying it out, back-filling existing findings | You pick findings in Cloudflare and click Send webhook |
| Logpush (Enterprise) | Enterprise plans already using Logpush pipelines | Cloudflare pushes every new finding in batches |
Option A: Automatic delivery with a policy
CASB policies trigger a webhook (and optionally an automated remediation) as soon as Cloudflare detects a finding.
- In Cloudflare One, go to Cloud & SaaS findings → Policies and select Create a policy.
- Name it, choose the vendor(s), integrations, and finding types to match. Create one broad policy or several scoped ones — every matching finding lands in Crowswatch either way.
- Under actions, select Send webhooks and pick your Crowswatch destination.
- Toggle Enable policy and create it.
Option B: Manual webhook
To send a specific finding — or back-fill findings that existed before your policy — open Cloud & SaaS findings in Cloudflare, select an instance, and choose Send webhook → your Crowswatch destination.
Option C: Automatic delivery with Logpush
On a Cloudflare Enterprise plan, a Logpush job delivers every new finding automatically.
- On the Crowswatch CASB Setup tab, copy the Logpush destination URL (it embeds your secret as an
Authorizationheader parameter). If the secret shows as a placeholder, regenerate it first so the real value is filled in. - In Cloudflare One, go to Insights → Logs → Manage Logpush and create a job.
- Choose the CASB Findings dataset and an HTTP endpoint destination, and paste the URL.
- Submit. Cloudflare validates the endpoint, then pushes new findings in near-real-time batches.
Reviewing findings & alerting
Findings appear on the CASB page with severity (critical/high/medium/low), finding type, the connected app, and the affected asset. To be notified, add a CASB rule to an alert channel — see the Alerts guide — where you can set a severity threshold and scope by application and finding type.
Troubleshooting
Cloudflare says the destination is invalid (401)
The URL is still carrying the placeholder secret. Replace <HMAC_SECRET> with your actual webhook secret (regenerate and copy it from the Setup tab if you no longer have it).
I sent a finding but nothing appeared
Confirm the destination URL points at your team’s integration and the secret matches. A Cloudflare test ping is acknowledged but intentionally stores nothing.
My policy is enabled but no findings arrive
Policies only fire for findings discovered after the policy was enabled, and only for the vendors, integrations, and finding types it matches. Check the policy scope, and back-fill older findings with a manual send.
Findings show but fields are blank
Make sure you’re on the latest Crowswatch — the finding parser handles both the Logpush schema and Cloudflare’s manual-send shape. Re-sending the same finding refreshes the stored row.
