Network Analytics
Network Analytics provides real-time visibility into Magic Transit traffic that enters and leaves Cloudflare's network through GRE or IPsec tunnels.
Data is aggregated into time intervals that vary based on the selected zoom level. For example, a daily view shows 24-hour averages, which can flatten short-term traffic spikes. As a result, longer time intervals display lower peak bandwidth values compared to more granular views like five-minute intervals.
Refer to the Network Analytics documentation to learn more.
With Magic Transit, you can account for traffic flows that enter Cloudflare's network, are blocked by DDoS rules or Magic Firewall, and leave Cloudflare's network. This visibility allows you to track the total packets and bytes that traverse Cloudflare's network and are ultimately destined for your network. It also provides increased visibility into traffic flows that are unaccounted for.
The complete list of filters includes:
- A list of your top tunnels by traffic volume.
- Traffic source and destination by traffic type, on-ramps and off-ramps, IP addresses, and ports.
- Destination IP ranges and ASNs.
- Protocols and packet sizes.
- Samples of all GRE or IPsec tunnel traffic entering or leaving Cloudflare's network.
- Mitigations applied (such as DDoS and Magic Firewall) to traffic entering Cloudflare's network.
Refer to Access Magic Tunnel traffic analytics to learn how to access these filters.
-
Go to the Network Analytics page.
Go to Network analytics -
In the All Traffic tab, scroll to Top Insights to access network traffic filters. By default, the dashboard shows five items, but you can display up to 25 items at once. To change the number of items, select the drop-down menu.
-
(Optional) Hover over a traffic type. You can then filter for that traffic or exclude it from the results.
-
To adjust the scope of information displayed, scroll to All traffic > Add filter.
-
In the New filter popover, select the data type from the left drop-down menu, an operator from the middle drop-down menu, and an action from the right drop-down menu. For example:
<DESTINATION_TUNNELS> | _equals_ | <NAME_OF_YOUR_TUNNEL>This lets you examine traffic from specific Source tunnels and/or Destination tunnels.
- For Magic Transit,
Non-Tunnel trafficoften represents traffic from the public Internet or traffic via CNIs.
The label Non-Tunnel traffic is a placeholder, and more specific labels will be applied to this category of traffic in the future.
Was this helpful?
- Resources
- API
- New to Cloudflare?
- Directory
- Sponsorships
- Open Source
- Support
- Help Center
- System Status
- Compliance
- GDPR
- Company
- cloudflare.com
- Our team
- Careers
- © 2025 Cloudflare, Inc.
- Privacy Policy
- Terms of Use
- Report Security Issues
- Trademark
-