Cloudflare Observability supports logs from the products listed in the table. Turn on each dataset in the location shown under Enablement. Datasets enabled through Log Explorer appear in Logs once your account has Log Explorer and that dataset turned on. Event sizes are estimates and vary by record.
You can also query sampled analytics datasets for your zones in Logs without turning anything on.
| Dataset | Identifier | Enablement | Average event size | Default retention |
|---|---|---|---|---|
| Workers | workers |
On Worker | 4.84 KB | 7 days |
| Containers | containers |
On Worker | 1.88 KB | 7 days |
| R2 Data Access Logs | r2 |
On Bucket | 1.55 KB | 7 days |
| AI Gateway | ai-gateway |
On Gateway | 2 KB | 7 days |
| Issues | real-time-issues |
On Worker | 2.64 KB | 7 days |
| HTTP Requests | http_requests |
On Account | 1.56 KB | 30 days |
| Firewall Events | firewall_events |
On Account | 1.36 KB | 30 days |
| Access Requests | access_requests |
On Account | 446 B | 30 days |
| Audit Logs | audit_logs |
On Account | 2.69 KB | 30 days |
| Audit Logs v2 | audit_logs_v2 |
On Account | 1.73 KB | 30 days |
| Browser Isolation User Actions | biso_user_actions |
On Account | Not published | 30 days |
| CASB Findings | casb_findings |
On Account | 2.67 KB | 30 days |
| DEX Application Tests | dex_application_tests |
On Account | 3.29 KB | 30 days |
| DEX Device State Events | dex_device_state_events |
On Account | 1.98 KB | 30 days |
| Device Posture Results | device_posture_results |
On Account | 730 B | 30 days |
| DNS Firewall Logs | dns_firewall_logs |
On Account | 387 B | 30 days |
| DNS Logs | dns_logs |
On Account | 199 B | 30 days |
| Email Security Alerts | email_security_alerts |
On Account | 6.74 KB | 30 days |
| Gateway DNS | gateway_dns |
On Account | 1.44 KB | 30 days |
| Gateway HTTP | gateway_http |
On Account | 1.47 KB | 30 days |
| Gateway Network | gateway_network |
On Account | 877 B | 30 days |
| IPsec Logs | ipsec_logs |
On Account | 207 B | 30 days |
| Magic BGP Logs | magic_bgp_logs |
On Account | Not published | 30 days |
| Magic IDS Detections | magic_ids_detections |
On Account | 334 B | 30 days |
| NEL Reports | nel_reports |
On Account | 204 B | 30 days |
| Network Analytics | network_analytics_logs |
On Account | 1.31 KB | 30 days |
| Page Shield Events | page_shield_events |
On Account | 443 B | 30 days |
| Sinkhole HTTP Logs | sinkhole_http_logs |
On Account | 705 B | 30 days |
| Spectrum Events | spectrum_events |
On Account | 685 B | 30 days |
| WARP Toggle Changes | warp_toggle_changes |
On Account | 327 B | 30 days |
| Zaraz Events | zaraz_events |
On Account | 7.30 KB | 30 days |
| Zero Trust Network Session Logs | zero_trust_network_sessions |
On Account | 1.21 KB | 30 days |
Logs also lists HTTP requests and firewall events from the GraphQL Analytics API. These datasets need no enablement and have no additional charge. The following sampled analytics datasets are available:
| Dataset | GraphQL dataset | Availability | Retention |
|---|---|---|---|
| HTTP requests | httpRequestsAdaptive |
All plans | At least 31 days |
| Firewall events | firewallEventsAdaptive |
Pro, Business, and Enterprise | At least 31 days |
These datasets use adaptive sampling. Results can omit individual events, and counts can be estimates. Available fields, exact retention, and how far back charts reach depend on your plan. Refer to GraphQL Analytics API limits for details.
To query these datasets for a zone, you need the Zone Analytics Read permission for that zone. Account administrators can grant it on the Members page.
Go to Members ↗For unsampled HTTP requests and firewall events, turn on those datasets through Log Explorer. Log Explorer is a paid add-on. Refer to Pricing for the unsampled security dataset price.
Beginning December 1, 2026, all Cloudflare logs and traces will use the same pricing model. Unsampled security datasets have a different price point of $1 per GB ingested and include 30-day retention. Queries, dashboards, alerts, and analytics do not incur additional charge.
The following logs and traces share account-level ingestion and storage allowances: