Log Explorer enables you to store and explore your Cloudflare logs directly within the Cloudflare dashboard or API, giving you visibility into your logs without the need to forward them to third-party services. Logs are stored on Cloudflare's global network using the R2 object storage platform and can be queried via the dashboard or SQL API.
Use Log Explorer when you need to investigate what actually happened with real production traffic:
- Analyzing historical data and trends
- Investigating security incidents after they occur
- Searching for patterns across thousands of requests
- Monitoring application performance over time
- Providing forensic evidence to support teams
Use Cloudflare Trace, shown as Rule simulator in the dashboard, when you need to test what would happen with a simulated request:
- Understanding why a rule did not trigger as expected
- Testing how your rules handle different request scenarios
- Seeing the evaluation order of your rules
- Simulating requests from different geolocations or conditions
The key difference is that Log Explorer shows actual traffic, while Cloudflare Trace shows simulated "what-if" scenarios. Both are separate from Cloudflare Traces, which records how real requests move through Cloudflare.
You can filter and view your logs via the Cloudflare dashboard or the API.
-
In the Cloudflare dashboard, go to Observability > Logs.
Go to Logs ↗ -
Open the dataset selector and choose a Log Explorer dataset, such as HTTP requests. For zone-scoped datasets, select one domain or all domains.
-
Select a preset or custom time range.
-
Add filters by selecting a field, an operator, and a value. To write SQL instead, select Open SQL editor, enter a query against the selected dataset, and select Run query.
SQL queries are available for Log Explorer datasets only. For the filter query language, functions, and keyboard shortcuts, refer to the built-in reference on the Logs page or the Logs overview.
For example, to find an HTTP request with a specific Ray ID, open the SQL editor and enter the following SQL query:
SELECT
clientRequestScheme,
clientRequestHost,
clientRequestMethod,
edgeResponseStatus,
clientRequestUserAgent
FROM http_requests
WHERE RayID = '806c30a3cec56817'
LIMIT 1As another example, to find Cloudflare Access requests with selected columns from a specific timeframe you could perform the following SQL query:
SELECT
CreatedAt,
AppDomain,
AppUUID,
Action,
Allowed,
Country,
RayID,
Email,
IPAddress,
UserUID
FROM access_requests
WHERE Date >= '2025-02-06' AND Date <= '2025-02-06' AND CreatedAt >= '2025-02-06T12:28:39Z' AND CreatedAt <= '2025-02-06T12:58:39Z'To query request headers, response headers, and cookies you must first enable logging for these fields using Custom fields. Configure the list of custom fields using the API or the dashboard; there is no need to modify the Logpush job itself.
The example below shows how to query HTTP requests by date, timestamp, client country, and a custom request header. Be sure to log the specific headers or cookies you plan to query in advance.
SELECT clientip, clientrequesthost, clientrequestmethod, edgeendtimestamp, edgestarttimestamp, rayid, clientcountry, requestheaders
FROM http_requests
WHERE Date >= '2025-07-17'
AND Date <= '2025-07-17'
AND edgeendtimestamp >= '2025-07-17T07:54:19Z'
AND edgeendtimestamp <= '2025-07-18T07:54:19Z'
AND clientcountry = 'us'
AND requestheaders."x-test-header" like '%654AM%';After building your query, you can save it by selecting Save search. Provide a name and description to help identify it later. To view your saved searches, select Saved searches. Queries saved in the previous Log Search page appear as saved searches on the Logs page.
You can also access the Log Explorer dashboard directly from the Security Analytics dashboard. When doing so, the filters you applied in Security Analytics will automatically carry over to your query in Log Explorer.
All the tables supported by Log Explorer contain a special column called date, which helps to narrow down the amount of data that is scanned to respond to your query, resulting in faster query response times. The value of date must be in the form of YYYY-MM-DD. For example, to query logs that occurred on October 12, 2023, add the following to your WHERE clause: date = '2023-10-12'. The column supports the standard operators of <, >, and =.
- Log in to the Cloudflare dashboard ↗︎ and select your account.
- Go to Observability > Logs, select a Log Explorer dataset, and select Open SQL editor.
- Enter the following SQL query:
SELECT
clientip,
clientrequesthost,
clientrequestmethod,
clientrequesturi,
edgeendtimestamp,
edgeresponsestatus,
originresponsestatus,
edgestarttimestamp,
rayid,
clientcountry,
clientrequestpath,
date
FROM
http_requests
WHERE
date = '2023-10-12' LIMIT 500- Narrow your query time frame. Focus on a smaller time window to reduce the volume of data processed. This helps avoid querying excessive amounts of data and speeds up response times.
- Omit
ORDER BYandLIMITclauses. These clauses can slow down queries, especially when dealing with large datasets. For queries that return a large number of records, reduce the time frame instead of limiting to the newestNrecords from a broader time frame. - Select only necessary columns. For example, replace
SELECT *with the list of specific columns you need. You can also useSELECT RayIdas a first iteration and follow up with a query that filters by the Ray IDs to retrieve additional columns. Additionally, you can useSELECT COUNT(*)to probe for time frames with matching records without retrieving the full dataset.