Cloudflare unifies observability tools with new SQL API and volume-based pricing
Cloudflare launches a unified observability platform featuring end-to-end tracing, custom alerts via webhooks, and simplified volume-based pricing effective December 2026.
Este artículo solo está disponible en inglés.
Cloudflare has announced eight major updates to its observability suite, consolidating logs, traces, analytics, and alerts into a single platform. Released on October 2, 2026, these changes introduce a unified SQL API, end-to-end request tracing, and a shift to volume-based pricing for data ingestion and storage.
What happened
The update merges previously separate tools like Workers Observability and Log Explorer into a central Logs home. Users can now query datasets from HTTP events, firewall logs, Workers, Containers, R2, and AI Gateway using consistent investigative tools. This consolidation aims to reduce the friction of switching between different product interfaces when diagnosing issues that span multiple parts of the Cloudflare infrastructure.
A significant addition is the open beta of Cloudflare Traces, which provides a request-level view of traffic processing. This feature allows developers to see how security rules, cache decisions, routing, and origin handling interact for specific requests. Users can set baseline sampling rates for continuous visibility or use Trace Rules to capture high-value traffic during active investigations, exporting this data via OpenTelemetry.
The company also introduced a unified SQL API in beta, enabling both human operators and automated agents to query telemetry data across the platform using a single dialect and authentication model. This API supports integration with the Cloudflare CLI and a native binding within Workers, allowing applications to query analytics data directly for usage metering or health reporting without external API clients.
Key details
- Unified Pricing Model: Starting December 1, 2026, pricing for logs and traces will be based on ingestion and storage volume rather than event counts, applying to all plans upon renewal.
- Custom Alerts via Webhooks: Users can now define custom alerts using SQL queries on any supported dataset, with webhook notifications available on all plans, including free tiers.
- Extended Analytics Retention: All plans now include 30 days of domain analytics retention, up from previous limits, allowing for better trend analysis and post-incident investigation.
- Logpush for Self-Serve: The Logpush feature, previously restricted to Enterprise customers, is now available on all self-serve plans, enabling log export to external destinations.
- Transformers Generally Available: SQL-based transformations for filtering, redacting, or enriching logs before export are now generally available with usage-based pricing.
- Free Allowances: The Free plan includes 0.5 GB of daily ingestion with 7-day retention, while Paid plans include 50 GB ingestion and 10 GB-month storage per billing cycle.
Background
Observability refers to the ability to understand the internal state of a system by examining its outputs, such as logs, metrics, and traces. In complex distributed systems, issues often arise from interactions between different components, making it difficult to pinpoint root causes when data is siloed. Traditional monitoring might tell you a server is down, but observability helps explain why it went down by correlating events across the entire stack.
Cloudflare’s previous model required users to navigate different interfaces for security logs, worker debugging, and performance analytics. By unifying these under a single SQL API and dashboard, the company aims to provide a holistic view of application behavior. This approach aligns with industry trends toward OpenTelemetry standards, which facilitate portable and consistent telemetry data collection across diverse environments.
Why it matters
For teams running self-hosted software behind Cloudflare, these changes simplify the debugging process. When an origin server experiences errors, the new tracing capabilities allow developers to see exactly how Cloudflare processed the request before it reached their infrastructure. This visibility helps distinguish between issues caused by Cloudflare’s edge network, configuration errors, or problems within the self-hosted application itself.
The shift to volume-based pricing offers more predictability for high-traffic applications. Previously, event-based counting could lead to unexpected costs during traffic spikes or verbose logging. By charging for gigabytes ingested and stored, teams can better forecast expenses. However, teams must still monitor their data volume to avoid overage charges, especially as retention periods extend up to one year in future updates.
The availability of webhooks for alerts on all plans is particularly useful for smaller teams or individual developers. It enables integration with existing incident management tools or custom automation scripts without requiring an Enterprise contract. This democratizes access to advanced monitoring features, allowing self-hosters to build robust alerting workflows that trigger immediate responses to anomalies.
What you can do
- Review current usage: Check your current log and trace ingestion volumes to estimate costs under the new pricing model taking effect December 1, 2026.
- Enable Cloudflare Traces: Activate the open beta for Cloudflare Traces to gain deeper visibility into request processing and identify latency bottlenecks.
- Configure custom alerts: Set up SQL-based alerts for critical metrics, such as origin 5xx errors or worker failures, and route them to your preferred webhook endpoint.
- Explore the unified Logs home: Use the new consolidated interface to query across different datasets, helping you correlate security events with application performance issues.
- Test Logpush and Transformers: If you export logs to external storage or SIEM tools, test the newly available Logpush feature and use Transformers to redact sensitive data before export.
- Update automation scripts: If you use automated agents or CI/CD pipelines, update them to use the new unified SQL API for querying observability data, simplifying integration logic.



