Cloudflare Logs gets new datasets, new destinations, and a refreshed setup flow

Cloudflare has overhauled its Logs product for Enterprise customers, adding two new datasets, direct integrations with major analytics platforms, and support for any S3-compatible storage destination. The changes are accompanied by a redesigned Logpush configuration interface in the dashboard.

Two new datasets expand visibility

Cloudflare Logs has long covered HTTP requests and Spectrum connections, with Gateway HTTP and DNS logs added as part of Cloudflare for Teams. The new Firewall Events dataset provides detailed records of everything the WAF handles, including whether a request was blocked outright or served a CAPTCHA challenge. While this data could previously be streamed to a SIEM via API, it can now be enabled directly from the dashboard.

The second addition, Network Error Logging (NEL) Reports, captures information from clients that are unable to reach Cloudflare's network. This dataset is available by request through an account manager.

S3-compatible storage opens up more destinations

Cloudflare Logs previously supported AWS, Azure, and Google Cloud as storage targets. The new S3-compatible API support extends that list to any object storage service that speaks the S3 protocol, including:

  • Digital Ocean Spaces
  • Backblaze B2
  • Alibaba Cloud OSS
  • JD Cloud Object Storage Service
  • Oracle Cloud Object Storage
  • Linode Object Storage

The expanded list is notable for customers that rely on on-premise storage or use Bandwidth Alliance partners, who can move data without egress fees.

Direct pushes to analytics platforms

Moving high-volume log data from object storage into an analytics tool often means building and maintaining a fragile integration layer. To avoid that, Cloudflare now offers direct log destinations for four platforms: Splunk, Sumo Logic, Datadog, and Microsoft Azure Sentinel. The first three can be configured from the dashboard; Azure Sentinel is set up through the Microsoft Azure Marketplace.

Cloudflare positions these integrations as a way to enrich the telemetry already present in customers' SIEMs and monitoring stacks. A typical use case is investigating an L7 DDoS attack: after blocking source IPs, security teams often want to search across all their infrastructure for past activity from those addresses, inspect WAF-blocked payloads, and set alerts for similar behavior. That kind of correlation requires log data to live alongside other infrastructure telemetry.

Redesigned Logpush configuration

The Logpush setup flow, still located under the Analytics > Logs tab, has been rebuilt around a clearer step-by-step process. The new interface first asks users to choose a dataset — which is where the Firewall Events and NEL Reports options now appear. After selecting the fields to push, users pick a destination from the expanded list of storage and analytics providers.

BLOG-493 Embedded Image - Qi0jVf

Still to come

Cloudflare says more datasets and destinations are in development. Planned logging pipeline features include account-level log delivery and the ability to filter logs by criteria such as error codes. No release timeline was provided for those additions.