This guide explains how to configure Cloudflare Logpush to deliver supported Cloudflare datasets to a Pondurance-managed Amazon S3 destination.
Each Cloudflare dataset requires a separate Logpush job. Pondurance will provide the destination details and approved dataset list through a secure channel.
Note: Cloudflare Logpush availability depends on your Cloudflare plan. If Logpush is not available in your dashboard, contact your Cloudflare account representative.
Confirm that you have:
Pondurance currently uses the AWS Region us-east-2 for this destination.
Important: Treat the AWS credentials as secrets. Do not include them in email threads or support tickets.
Sign in to the Cloudflare dashboard.
Open Analytics & Logs -> Logpush at the account or zone level required for the dataset.
Click Create a Logpush job.

Select S3-Compatible as the destination.

Enter the destination details provided by Pondurance:
s3.us-east-2.amazonaws.comus-east-2
Click Continue.
Select the dataset to send to Pondurance.
Enter a descriptive job name.
Under If logs match, include all events unless Pondurance has provided a specific filter.
Under Send the following fields, select all available fields.
Review the configuration, then click Submit.

Repeat Steps 1–3 for every dataset Pondurance has approved.
Replace {customer_org_code} with the customer organization code provided by Pondurance. Prefixes are case-sensitive and must include the trailing /.
| Cloudflare Dataset | S3 Path Prefix |
|---|---|
DNS logs (dns_logs) |
{customer_org_code}/cloudflare_logpush_dns/ |
Firewall events (firewall_events) |
{customer_org_code}/cloudflare_logpush_firewall_event/ |
HTTP requests (http_requests) |
{customer_org_code}/cloudflare_logpush_http_request/ |
NEL reports (nel_reports) |
{customer_org_code}/cloudflare_logpush_nel_report/ |
Spectrum events (spectrum_events) |
{customer_org_code}/cloudflare_logpush_spectrum_event/ |
| Cloudflare Dataset | S3 Path Prefix |
|---|---|
Access requests (access_requests) |
{customer_org_code}/cloudflare_logpush_access_request/ |
Audit logs (audit_logs) |
{customer_org_code}/cloudflare_logpush_audit/ |
CASB Findings (casb_findings) |
{customer_org_code}/cloudflare_logpush_casb/ |
Device posture results (device_posture_results) |
{customer_org_code}/cloudflare_logpush_device_posture/ |
DNS Firewall Logs (dns_firewall_logs) |
{customer_org_code}/cloudflare_logpush_dns_firewall/ |
Gateway DNS (gateway_dns) |
{customer_org_code}/cloudflare_logpush_gateway_dns/ |
Gateway HTTP (gateway_http) |
{customer_org_code}/cloudflare_logpush_gateway_http/ |
Gateway Network (gateway_network) |
{customer_org_code}/cloudflare_logpush_gateway_network/ |
Magic IDS Detections (magic_ids_detections) |
{customer_org_code}/cloudflare_logpush_magic_ids/ |
Network Analytics Logs (network_analytics_logs) |
{customer_org_code}/cloudflare_logpush_network_analytics/ |
Zero Trust Network Session Logs (zero_trust_network_sessions) |
{customer_org_code}/cloudflare_logpush_network_session/ |
Sinkhole HTTP Logs (sinkhole_http_logs) |
{customer_org_code}/cloudflare_logpush_sinkhole_http/ |
Workers Trace Events (workers_trace_events) |
{customer_org_code}/cloudflare_logpush_workers_trace/ |
Important: Configure only the datasets Pondurance has confirmed are in scope.
s3:PutObject for the required prefix./.Delivery timing varies by dataset and event volume. Allow up to 30 minutes after enabling a job before escalating the issue.
Contact your Pondurance onboarding representative and include:
Do not include the AWS Secret Access Key.