# Cloudflare Unveils Eight Major Upgrades to Its Observability Platform
Cloudflare has announced a sweeping set of enhancements designed to consolidate logging, tracing, analytics, alerts, dashboards, and data export into a single, unified observability experience. Alongside these capabilities, the company is introducing simpler, more predictable pricing structures across all plan tiers. These changes mark a significant step toward making infrastructure visibility more accessible and actionable for teams of all sizes.
## A Unified Platform for Complete Visibility
One of the most fundamental challenges in modern infrastructure management is that signals from different services often live in separate tools with different query languages and interfaces. A spike in server errors might originate from a serverless function, an origin server, or a global routing issue — but finding the root cause has historically required switching between multiple products and learning distinct workflows for each.
Cloudflare’s approach addresses this by treating observability as a platform-wide capability rather than a feature siloed to individual products. The goal is to provide a single pane of glass that reflects how applications truly behave, giving teams the complete context they need to resolve issues quickly. The eight updates detailed below represent the first major phase of this initiative, with additional products, datasets, and workflows expected to join the unified platform over the coming months.
## 1. Centralized Log Investigation
A new Logs home interface has been introduced that merges Workers Observability — previously used for debugging serverless applications — with Log Explorer, which handles searching across security-related logs. This combined environment lets users select from a growing catalog of log datasets, including HTTP events, firewall events, serverless function executions, container workloads, object storage activity, and AI gateway traffic.
The interface supports both raw SQL queries and built-in visual filters for narrowing down specific events. Users can create visualizations using natural language descriptions and investigate anomalies that are automatically detected. A key benefit is the ability to switch between datasets without leaving the logs environment, enabling seamless cross-product investigation. Cross-dataset querying is expected to roll out soon, allowing teams to connect related events across multiple Cloudflare products in a single query.
## 2. End-to-End Request Tracing in Open Beta
Cloudflare Traces has entered open beta, offering a request-level view of how traffic moves through the entire platform. This includes visibility into security rule evaluations, transformation steps, cache decisions, routing logic, serverless function execution, and origin server handling. Rather than seeing isolated metrics, users can trace the full journey of individual requests and understand how their configuration choices influence processing time and routing behavior.
The tracing system includes a configurable baseline sampling rate that provides continuous visibility, along with Trace Rules that let teams capture higher-resolution data for specific traffic patterns during investigations. Targeting can be done by hostname, URL path, IP address, or HTTP header, with results searchable by Ray ID. Traces can be exported using OpenTelemetry standards, and W3C trace context propagation allows teams to pass trace context to their own origin servers.
## 3. Unified SQL API for Agent and Human Queries
A major new unified SQL API is being launched in beta, enabling both human operators and automated agents to query telemetry data using a single, consistent interface. Rather than needing separate integrations for each data source — such as serverless logs, container security events, HTTP request logs, and analytics — all of these can now be queried using the same SQL dialect, authentication model, and API endpoint.
The Cloudflare CLI (`cf`) provides command-line access to this API, and an Observability MCP server enables AI agents to investigate logs, traces, and analytics directly. Dataset schemas, field definitions, and example queries are publicly available to help both technical teams and automated tools construct effective queries. Additionally, a native SQL binding is being added directly to the Workers runtime, allowing serverless functions themselves to query analytics data for tasks like usage metering, billing workflows, customer-facing dashboards, and automated incident response.
## 4. Simplified, Volume-Based Pricing Model
Cloudflare is consolidating all ingested and stored log and trace data under a single unified Observability subscription. Beginning December 1, 2026, this pricing model will apply across all plan tiers, including existing Developer Platform services such as serverless functions, containers, AI gateway, and all tracing data.
The new model is based on the actual volume of data ingested and stored, rather than an event-based counting model. This approach better reflects the reality that log and trace data can vary dramatically in size. The paid and enterprise tiers include substantial free allowances, with straightforward overage pricing for additional usage. Detailed pricing tables are available in the official documentation.
## 5. Custom Alerting on Observability Data
The alerting system — now rebranded as “Alerts” — has been significantly upgraded. Users can now define custom alert conditions on any dataset supported by the unified SQL API, including HTTP request logs, serverless function events, analytics datasets, traces, and security events. Alert conditions can be specified using a visual interface or custom SQL queries.
Teams can set thresholds, anomaly detection rules, or service level objectives, define evaluation windows, and choose routing destinations. Alerts can be sent to incident management platforms, chat tools, and webhooks — with webhook support now available on all plans. This enables automated workflows where alerts trigger investigations, route notifications to the right teams, or initiate remediation actions.
## 6. Consolidated Domain Analytics with Extended Retention
Domain analytics have been consolidated into a single view that brings together traffic, performance, security, caching, origin, and DNS metrics. Instead of piecing together data from multiple products, teams can now see how these signals relate to each other in one place. If latency increases, users can immediately determine whether it correlates with a specific data center, hostname, or origin server.
A significant addition is the extension of retention to 30 days of domain analytics on every plan, including free tiers. A full month of historical data provides enough context to investigate issues after they occur, compare current performance with the same period in previous weeks, and distinguish between one-time spikes and sustained trends.
## 7. Customizable Dashboards
Pre-built dashboards cover common use cases, but many applications span multiple Cloudflare services. The new Custom Dashboards feature allows teams to create personalized views that bring together analytics from across the platform, serverless platform logs and traces, and security events — all in a single screen.
Teams can track request volume, error rates, latency, storage utilization, and blocked traffic, then share these dashboards with colleagues and stakeholders. By having a persistent, shared view of the most relevant signals, teams avoid the need to rebuild queries each time they investigate an issue.
## 8. Logpush Availability on All Plans
Logpush, previously restricted to enterprise-tier customers, is now available on all self-serve plans. This allows any user to export all Cloudflare logs to their preferred tools and destinations. A new Transformers capability, now generally available, enables users to apply SQL-based transformations to exported data — including filtering, field redaction, enrichment, and reshaping — without needing a separate ETL pipeline.
Usage-based pricing has been introduced for Logpush and Transformers, each with a free monthly allowance and simple overage rates. Exports to Cloudflare destinations and external destinations each include 25 GB of free monthly usage, while Transformers include 1 GB of free processing.
## Looking Ahead
Several additional enhancements are on the roadmap. Longer retention periods of up to one year for logging and tracing data will enable deeper historical analysis and trend identification. Expanded OpenTelemetry API support in the Workers runtime will allow teams to add custom attributes to spans and propagate trace context more flexibly. Improved metrics export capabilities will make it easier to send Cloudflare data to OpenTelemetry-compatible backends alongside telemetry from other systems.
The new unified pricing model takes effect on December 1, 2026, and teams will be notified before the change applies to their accounts.
## Frequently Asked Questions
**What is Cloudflare’s unified observability platform?**
It is a single environment that combines logs, traces, analytics, alerts, and dashboards from across all Cloudflare products, enabling teams to investigate issues using consistent tools and interfaces regardless of which service generated the data.
**When does the new pricing take effect?**
The unified observability pricing model begins on December 1, 2026. Existing Enterprise customers will see the change apply upon renewal.
**Can I try tracing before it fully launches?**
Yes, Cloudflare Traces is currently in open beta, meaning anyone can sign up and start using it without waiting for a general availability release.
**What data sources are available in the new Logs home?**
Available datasets include HTTP request logs, firewall events, serverless function logs, container logs, object storage activity logs, and AI gateway logs.
**Do I need to be an enterprise customer to use Logpush?**
No. Logpush is now available on all self-serve plans, including the free tier.
**Can AI agents interact with observability data?**
Yes. The unified SQL API and Cloudflare’s Observability MCP server enable automated agents to query logs, traces, and analytics, set up alerts, and configure export jobs using natural language or code.
**What OpenTelemetry support is available?**
Cloudflare supports W3C trace context propagation for distributed tracing, OpenTelemetry export for trace data, and is actively expanding OpenTelemetry APIs in the Workers runtime for span attribute enrichment and context propagation.
## Conclusion
The introduction of a unified observability platform represents a meaningful shift in how infrastructure data is organized and accessed. By bringing together previously fragmented data sources under consistent pricing, tooling, and interfaces, Cloudflare is lowering the barrier to comprehensive visibility — both for human operators and the automated agents that increasingly handle incident response and troubleshooting.
The combination of SQL-based querying, standardized export formats, and extensible alerting creates a foundation that can adapt to a wide range of use cases, from real-time debugging to long-term performance analysis. As additional products and datasets are incorporated into the platform, the value of this unified approach will continue to grow.
Thank you for reading



