Cloudflare Traces show how production requests move through Cloudflare and record traces from actual traffic on your domain. Each trace contains spans for supported steps in the request path, such as Rules, request routing, Cache, Workers, and origin connections. A span records how long an operation took, its outcome, and related attributes, which helps you see where a request slowed down or failed.
Use Cloudflare Traces to answer questions such as:
- Why was a request blocked or challenged, and which security rule took action?
- Was the URL rewritten by a Transform Rule before it reached the application?
- Which Page Rules, Snippets, or Workers handled or changed the request?
- Was the response served from cache, and where was time spent between Cloudflare, the origin connection, and the application?
- Was the behavior isolated to a particular Cloudflare location or region?
Enable tracing separately for each domain in your account. To manage sampling, context, export destinations, and trace rules, refer to Configuration.
Use Add filter or enter a query to search across traces for the selected time range. To find the trace for one request, filter on its Ray ID.
Open a trace to see the full request path as a hierarchy of spans. Each row represents one operation, and its bar shows when the operation ran and how long it took. Expand a span to inspect its child operations, or search for a span by name.
Select a span to open its details. The detail panel shows the span status, service, trigger, span and trace IDs, duration compared to similar spans, and recorded attributes. You can search or copy the attributes while investigating the operation.
No. Tracing has no measurable overhead on request processing. Requests that are not sampled skip tracing entirely.
A Worker in the request path may not have Workers tracing enabled. Enable it using observability.traces.enabled = true in your Wrangler configuration.
If the response was served from cache, Cloudflare did not contact your origin. Check the cloudflare.cache.status attribute on the cache span to confirm it was a HIT rather than an origin connection.
Filter by Ray ID in the dashboard with cloudflare.ray_id = "<ray>". To guarantee a particular request is captured regardless of the default sample rate, create a trace rule that matches a custom debug header and sets the sample rate to 100%.
Not yet. Sampling is head-based ↗︎ — the decision happens when a request arrives, before the outcome is known. Tail-based sampling is not currently supported.
Header names and the operations performed on them are captured. Header values are not captured. URLs and query strings are captured.
No. Span names and structure may change as the product evolves. Do not build hard dependencies on the exact shape of Cloudflare-emitted spans.