Skip to content

Logs

Last updated View as Markdown Agent setup

Review detailed logs for your Zero Trust organization.

Log retention

Cloudflare stores Zero Trust logs for different periods of time based on the service and plan type:

Free Standard Access Gateway Enterprise
Admin logs 18 months 18 months 18 months 18 months 18 months
Access logs 24 hours 30 days 30 days 24 hours 180 days
DNS logs 24 hours 30 days 24 hours 30 days 180 days1
Network logs 24 hours 30 days 24 hours 30 days 30 days
HTTP logs 24 hours 30 days 24 hours 30 days 30 days
DEX logs 7 days 7 days 7 days 7 days 7 days
Device posture logs 30 days 30 days 30 days 30 days 30 days

Log Explorer Beta

Log Explorer users can store Zero Trust logs directly within Cloudflare in an R2 bucket and access them with the dashboard or API. Log Explorer supports the following Zero Trust datasets:

For more information, refer to Log Explorer.

Customer Metadata Boundary

You can use Cloudflare Zero Trust with the Data Localization Suite to restrict data storage to a specific geographic region. For more information, refer to Customer Metadata Boundary.

Data privacy

For more information on how we use this data, refer to our Privacy Policy.

Footnotes

  1. Enterprise users on per query plans cannot store DNS logs via Cloudflare. You can still export logs via Logpush. For more information, contact your account team.

Was this helpful?