Cloud Computing and Data Centers

Cloudflare Unifies Logging, Tracing, and Analytics in a Single Observability Platform

Cloudflare announced eight updates that bring logs, tracing, analytics, alerts, dashboards, and data export together in a unified observability platform. The changes include a unified SQL interface, request tracing in open beta, and Logpush availability for self-service plans, along with a new pricing model beginning December 1, 2026.

2026-10-02
4 min read
73 views
certi.news Editorial Team
Cloudflare Unifies Logging, Tracing, and Analytics in a Single Observability Platform

Cloudflare announced eight major updates to the Cloudflare Observability platform, aiming to bring logs, tracing, analytics, alerts, dashboards, and data export into a single operational experience. The company says the change is intended to reduce the need to switch between separate products when investigating issues such as increased 5xx errors, slow responses, or an unreachable origin server.

A Unified View of Logs and Requests

The new Logs interface combines Workers Observability and Log Explorer, enabling searches across datasets including HTTP events, firewall events, Workers, Containers, R2, and AI Gateway. Users can narrow results by hostname, data center, or path, then inspect individual requests using the Ray ID. Search supports raw SQL queries or ready-made filters, with visualizations generated using natural language, while Cloudflare plans to enable querying across multiple datasets later.

The company also launched Cloudflare Traces in open beta, providing request-level visibility into traffic as it passes through security rules, redirects, caching, routing, Workers, and the origin server. Users can set a baseline sampling rate and then use Trace Rules to capture specific traffic at a higher rate during an investigation. The feature supports exporting traces through OpenTelemetry and propagating trace context according to the W3C Trace Context standard.

Unified SQL and a Greater Role for Agents

Cloudflare is offering the Unified SQL API in beta, allowing people and agents to query logs, tracing, and analytics data using SQL and a unified authentication model and API. The cf command-line tool or Cloudflare's Observability MCP server can also be used to inspect logs, traces, and analytics.

The company is also providing a native SQL interface within Workers, allowing applications to query Analytics Engine data, create health reports, build analytics dashboards for users, or automate some incident investigation tasks without setting up a separate API client.

Pricing, Retention, and Export

Beginning December 1, 2026, Cloudflare will apply unified subscriptions and pricing for ingested and stored log and trace data upon renewal for Enterprise customers. The new model is based on the volume of data ingested and stored rather than event counts. The free plan includes 0.5 gigabytes of ingestion per day with seven days of retention, while paid and Enterprise plans include 50 gigabytes of ingestion and 10 gigabyte-months of storage per billing cycle, with an additional cost of $0.25 per ingested gigabyte and $0.10 per stored gigabyte-month.

Custom alerts are now available in beta, based on thresholds, anomaly conditions, or SLO indicators, with delivery to incident-management tools, chat platforms, and Webhook interfaces. Webhooks are now available on all plans. Cloudflare has also brought traffic, performance, security, caching, origin-server, and DNS analytics together in one place, with domain analytics data retained for 30 days on all plans.

Custom Dashboards allow metrics, logs, traces, and security events to be combined in a single dashboard. Logpush is also now available on all self-service plans instead of being previously limited to Enterprise. Transformers are generally available for filtering, redacting, enriching, or reshaping events using SQL before export.

Why Does This Change Matter?

The actual change is not the addition of a standalone observability tool, but the shift of operational investigation from separate products to a model based on shared context and portable queries. This could benefit teams that jointly manage Workers, Containers, security services, and origin servers, while giving software agents more consistent interfaces for finding the cause of an issue and verifying its resolution.

However, some capabilities remain experimental or under development, including Cloudflare Traces, the Unified SQL API, and custom alerts. Pricing based on ingestion and storage volume may also change usage costs depending on data volume, while retention of up to one year is still listed as an upcoming feature for observed data. Cloudflare says it will later add broader support for OpenTelemetry interfaces and export metrics to destinations compatible with them.

News source
Cloudflare Blog
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news