blog.cloudflare.com 2 Oct 2026, 13:00 UTC

Cloudflare Unifies Observability Logs, Traces and Analytics for Easier Threat Hunting

Cloudflare Unifies Observability Logs, Traces and Analytics for Easier Threat Hunting
CyberSIXT Evidence Panel Source marked as original reporting

CLOUDFLARE has rolled out eight major updates to its Observability platform, integrating logs, traces, analytics, alerts, dashboards, and export capabilities into a single, more predictable pricing model. The changes are designed to give teams a unified view across Cloudflare products, so a spike in 5xx responses can be investigated without switching datasets or tools.

The updates include: 1) a Logs home that combines Workers Observability and Log Explorer, enabling searches across HTTP events, firewall events, Workers, Containers, R2, and AI Gateway with the option to query across datasets in a single query soon; 2) end-to-end tracing from Cloudflare’s edge to origin, now in open beta, with baseline sampling, Trace Rules, and export to

OpenTelemetry, plus W3C trace context propagation; 3) a unified SQL API for querying telemetry across Cloudflare, usable via the Cloudflare CLI or MCP server, with native bindings in Workers; 4) a single pricing model for all ingested and stored logs and traces, effective from 1 December 2026, based on volume rather than events; 5) custom alerts on observability data,

configurable on any dataset supported by the SQL API, with webhooks and integrations; 6) 30 days of domain analytics retention across all plans, consolidating traffic, performance, security, cache, origin and DNS data; 7) custom dashboards that combine analytics from across Cloudflare with logs and security events; and 8) Logpush now available on all self‑serve plans, with

Transformers for SQL-based output transformations and usage-based pricing.

View full article

Article by CyberSIXT