A single surface for logs, traces, analytics and alerts
Investigating a Cloudflare incident usually means pulling signals from several products at once. A 5xx spike can originate in a Worker, at your origin, or in a failed connection between Cloudflare and your origin, and each signal lives under a different product with its own query interface. The eight updates below consolidate logs, traces, analytics, alerts, dashboards and exporting onto one platform, with a common pricing model.
Cloudflare frames this as the first step: more products, datasets and workflows are expected to join the shared platform over the coming months.
Logs and traces
Logs in one home
The new Logs home merges Workers Observability, used for debugging Workers applications and their connected resources, with Log Explorer, used for searching security logs. Datasets include HTTP events, firewall events, Workers, Containers, R2 and AI Gateway, and all of them share the same investigative tooling.
A typical flow starts with a latency increase, grouped by hostname or data center, narrowed to affected paths, and finished by inspecting individual requests by Ray ID. If the trail points at another Cloudflare product, you switch datasets without leaving Logs. Cross-dataset queries are coming soon, which will allow related events from different products to be joined in a single query. Tooling includes raw SQL and built-in filters, natural-language visualizations, and anomaly investigation.

Request-level tracing in open beta
Cloudflare Traces, now in open beta, shows how a request moved through supported security rules, transformations, cache decisions, routing, Workers and origin handling, connecting your configuration to request processing time and routing decisions.
Configuration works in two tiers: a baseline sampling rate for continuous visibility, plus Trace Rules that capture specific traffic at a higher rate during an investigation, targeting hostnames, paths, IP addresses or headers. You can also search by Ray ID and inspect spans in the Cloudflare dashboard. Traces export over OpenTelemetry, and W3C trace context propagation accepts incoming trace context and forwards it to your origin.

Querying, alerting and exporting
A unified SQL API
The new unified SQL API, in beta, queries telemetry across Cloudflare through one SQL dialect, one authentication model and one API, replacing separate integrations for Workers logs, Containers security events, HTTP request logs and analytics data.
Agents can reach it through the Cloudflare CLI, cf, or the Cloudflare Observability MCP server to investigate logs, traces and analytics, with dataset schemas, fields and example queries published to help humans and agents write queries. Workers get the same interface natively through an analytics SQL binding — for example, to meter customer usage from Analytics Engine data for billing workflows, build customer-facing dashboards, generate health reports, or automate incident investigation without a separate API client.
Custom alerts in beta
Notifications, now called Alerts, can be defined on anything the unified SQL API supports: HTTP request logs, Workers events, Workers Analytics Engine datasets, analytics datasets, traces and security events. You pick a dataset in the dashboard or write the condition in custom SQL, then set a threshold, anomaly or SLO, an evaluation window, and a destination.
Example conditions include origin 5xx responses above a threshold for five minutes, a repeatedly failing Container, a rise in Worker errors after a deployment, or trace latency crossing an expected limit. Alerts route to incident management tools, chat platforms and webhooks, and webhooks are now available on all plans, so alerts can reach custom services or an agent that begins investigating immediately.

Pricing for logs and traces
Logs and traces ingested and stored on Cloudflare move to a single Observability subscription and pricing model. Starting December 1, 2026, it applies across all plans — effective upon renewal for Enterprise customers — and covers existing Developer Platform logs, including Workers, Containers and AI Gateway, as well as all tracing data. Because logs and traces vary widely in size, the model bills on the volume you ingest and store rather than an event count.
Plan | Included Usage | Retention | Additional usage |
|---|---|---|---|
Free | 0.5 GB of ingestion per day | 7 days | Not available |
Paid and Enterprise | 50 GB of ingestion | Up to 1 year | $0.25 per GB ingested |
Logpush on self-serve plans
Logpush, previously Enterprise-only, is available on all self-serve plans for exporting Cloudflare logs to existing tools and destinations. Transformers is now generally available and applies any SQL transformation, covering filters, redaction, enrichment and output reshaping without a separate ETL pipeline. Both carry usage-based pricing with a free monthly allowance and simple pricing beyond it.
Export usage | Included each month | Additional usage |
Exports to Cloudflare destinations | 25 GB | $0.03 per GB |
Exports to external destinations | 25 GB | $0.10 per GB |
Logpush Transformers | 1 GB | $0.04 per GB |
Setup and full pricing details are in the Logpush documentation.
Dashboards and domain analytics
Domain analytics now brings traffic, performance, security, cache, origin and DNS data together, so a latency increase can be traced to a specific Cloudflare data center, hostname or origin. Every plan gets 30 days of retention, giving enough history to investigate after the fact, compare against prior weeks, and distinguish one-off spikes from sustained trends.

Custom Dashboards go further, assembling analytics from across Cloudflare with Workers platform logs and traces and security events in a single view. You can track request volume, errors, latency, storage and blocked traffic, then share the dashboard with your team instead of rebuilding queries for each investigation.

What's next
- Longer retention: observability data will be retained for up to one year, supporting recurring-issue investigation, historical comparison and long-term trend analysis.
- OpenTelemetry API support in Workers: further OpenTelemetry APIs will let you add attributes to existing spans or retrieve trace context.
- Easier metrics export: Cloudflare metrics will be sendable to OpenTelemetry-compatible destinations for analysis alongside the rest of your stack.
- Unified pricing from December 1, 2026: the new plan applies to any usage that ingests or stores observability data on Cloudflare, with notice before it takes effect.
The direction is standard, portable interfaces — OpenTelemetry, W3C Trace Context and SQL — so both people and agents can query what happened, identify a failure and verify the fix. Documentation lives at Cloudflare's Observability home.



