Cloudflare spent Birthday Week this year on a problem most of its customers complain about but few vendors fix: the bill for watching your own infrastructure. On October 2, 2026, the company launched eight updates that fold logs, traces, analytics, alerts, dashboards, querying, and data export into a single Observability platform, and it rewired the pricing underneath all of it. Starting December 1, 2026, every customer pays one rate for data ingested and stored, not a patchwork of per-feature, per-event, and per-span charges.
The timing is not an accident. Engineering teams have spent two years watching observability bills climb faster than the infrastructure they monitor, and Datadog, New Relic, and Splunk have each taken criticism for pricing structures that punish exactly the kind of scale Cloudflare’s own customers are chasing. By bundling its own telemetry tools into the edge network it already runs, Cloudflare is betting that predictable, GB-based pricing is now a bigger selling point than any single dashboard feature.
What Cloudflare Actually Shipped on October 2
Cloudflare’s announcement lists eight discrete releases, and most of them are aimed at closing gaps between products that previously lived in separate dashboards. The company bundled a single home for exploring logs across every Cloudflare service, a new tracing product, a unified query layer, one pricing model covering the whole stack, custom alerting, 30-day analytics retention across all plans, custom dashboards, and self-serve access to Logpush, its export tool.
“Today, we’re launching eight major updates that bring your logs, traces, analytics, alerts, dashboards, and exporting into one observability platform, with simpler and more predictable pricing,” Cloudflare said in the announcement post. The phrasing matters: Cloudflare is explicitly selling simplicity as a feature, not just functionality.
The centerpiece for most engineering teams will be the new Logs home, which merges Workers Observability with the existing Log Explorer. From one screen, a developer can switch between HTTP request logs, firewall events, Workers execution logs, Containers output, R2 storage activity, and AI Gateway traffic without jumping between separate products. That consolidation alone addresses a common complaint: Cloudflare’s telemetry tools grew organically as the company added services, and each one shipped its own logging interface.
Cloudflare Traces Enters Open Beta
The most technically significant piece of the launch is Cloudflare Traces, now available in open beta. Traces extends the tracing Cloudflare already offered inside Workers to the rest of the request path, covering security rule evaluation, transformations, cache decisions, routing, Worker execution, and origin handling in a single trace. For a team debugging a slow or failing request, that means following one transaction from the edge all the way to the origin server without stitching together logs from four different products by hand.
This is the feature that puts Cloudflare in more direct competition with distributed tracing tools from Datadog, Honeycomb, and Grafana Tempo. Those products built their business on exactly this kind of request-level visibility, usually for backend services running in a customer’s own cloud account. Cloudflare’s version only sees what happens inside its own network, which is a narrower scope, but for any application that already routes traffic through Cloudflare, it removes a step that used to require a separate APM vendor.
One SQL API to Query Everything
Cloudflare also shipped a unified SQL API, reachable from the Cloudflare CLI, a new Observability MCP server for AI agents, or a native binding inside Workers code. The API queries Analytics Engine data directly, which means teams can pull observability data into their own tooling or scripts instead of relying solely on the dashboard. The MCP server angle is notable on its own: Cloudflare is explicitly building for a world where AI coding agents query infrastructure telemetry as part of debugging, not just humans clicking through a UI.
-- Example: querying Workers error rates via the new unified SQL API
SELECT
scriptName,
count(*) AS errorCount,
avg(cpuTimeMs) AS avgCpuMs
FROM workers_observability
WHERE outcome = 'exception'
AND datetime >= now() - INTERVAL '1' HOUR
GROUP BY scriptName
ORDER BY errorCount DESC
LIMIT 10;
That kind of query previously required pulling data through separate endpoints for Workers logs and Analytics Engine, then joining it client-side. Collapsing it into one API is a small technical change with an outsized effect on how fast a team can answer a production question.
The New Pricing Model, Line by Line
Pricing is where this announcement will actually move budgets. Cloudflare is replacing its prior event-based and per-product pricing for logs and traces with a single ingestion-and-storage model, effective December 1, 2026 for Paid plans and at renewal for Enterprise accounts. The Free plan keeps 0.5 GB per day of ingestion with seven-day retention. Paid and Enterprise plans get 50 GB of ingestion per billing cycle and roughly 10 GB-month of storage included, with overage priced at $0.25 per GB ingested and $0.10 per GB-month stored.
There are two carve-outs worth flagging. Unsampled security datasets, the full-fidelity firewall and threat logs some teams need for compliance, are billed separately at $1 per GB ingested, with 30 days of retention included. And Logpush, the export tool that used to be Enterprise-only, is now available on every self-serve plan, with 25 GB per month free to Cloudflare-owned destinations like R2 and $0.03 per additional GB, or 25 GB per month free to external destinations with $0.10 per additional GB beyond that.
Queries, dashboards, alerts, and standard analytics carry no additional charge under the new model, according to Cloudflare’s own pricing documentation. That is a deliberate contrast with vendors who meter dashboard users or alert rule counts as separate line items.
Cloudflare Observability Pricing at a Glance
| Plan or Feature | Included Ingestion | Included Storage | Retention | Overage Ingestion | Overage Storage |
|---|---|---|---|---|---|
| Free | 0.5 GB/day | — | 7 days | Not available | Not available |
| Paid | 50 GB/billing cycle | ~10 GB-month | Up to 1 year (coming soon) | $0.25/GB | $0.10/GB-month |
| Enterprise | 50 GB/billing cycle (at renewal) | ~10 GB-month | Up to 1 year (coming soon) | $0.25/GB | $0.10/GB-month |
| Unsampled security datasets | — | — | 30 days included | $1.00/GB | — |
| Logpush to Cloudflare destinations | 25 GB/month free | — | — | $0.03/GB | — |
| Logpush to external destinations | 25 GB/month free | — | — | $0.10/GB | — |
Source: Cloudflare Observability pricing documentation, effective December 1, 2026.
Why Cloudflare Picked a Fight on Pricing, Not Just Features
Observability pricing has been a sore point across the industry for years. Datadog, the category leader, charges $0.10 per GB ingested per month for log management according to its own pricing page, which looks cheap next to Cloudflare’s $0.25 rate until you read the fine print. Indexing those logs for fast search costs roughly $1.70 per million events on top of ingestion, and APM pricing runs $31 to $47 per host per month depending on tier. Custom metrics beyond the included allowance per host bill separately too, and any team running Kubernetes at scale generates thousands of unique timeseries that push past that allowance quickly.
That stacking effect is the exact complaint Cloudflare is aiming at. A single, all-in rate per GB ingested and per GB-month stored is easier to forecast than a bill assembled from ingestion, indexing, host count, span volume, and metric cardinality. Whether $0.25 per GB actually works out cheaper depends entirely on how much of a team’s data needs indexing versus raw storage, since Cloudflare’s rate covers both uses at one price while Datadog, Grafana, and New Relic split those costs into separate charges.
How the Major Observability Vendors Price Ingestion
| Vendor | Ingestion / Write Price | Notable Extra Costs | Published Free Tier |
|---|---|---|---|
| Cloudflare Observability | $0.25/GB ingested + $0.10/GB-month stored | Unsampled security data billed at $1/GB separately | 0.5 GB/day (Free plan) |
| Datadog Log Management | $0.10/GB ingested per month | ~$1.70 per million indexed events, plus APM at $31–$47/host/month | No published free log-ingestion allowance |
| Grafana Cloud Logs | $0.05/GB processing + $0.40/GB write | $0.10/GB-month retention charged separately | 50 GB ingested/month, 14-day retention |
| New Relic | $0.40/GB (Original Data) or $0.60/GB (Data Plus) | $99–$349 per user/month for full platform access | 100 GB/month |
| Splunk Cloud | No public flat rate, ingest-volume or activity-based contracts | Public government filing shows $822.25 per GB/day/year at the 1,000–1,999 GB/day tier | None publicly listed |
Sources: Datadog, Grafana Cloud, New Relic, Splunk. Splunk’s disclosed rate comes from a public-sector procurement filing and uses a per-GB-per-day-per-year unit, so it is not directly comparable to the monthly rates above without converting the billing period.
Splunk’s own pricing materials confirm that ingest-volume billing is the unit it charges on, but the company does not publish a single universal rate, instead quoting customers based on ingest volume, retention, and provisioned compute capacity. That opacity is itself a selling point for any vendor, Cloudflare included, willing to publish a flat number.
Cloudflare’s Pattern: Undercut on Price, Bundle on Infrastructure
This is not the first time Cloudflare has used pricing to attack an adjacent market this year. The Basin data platform reached general availability with pricing undercutting AWS by roughly half, and R2 object storage has spent years marketing itself against S3 on the strength of eliminating egress fees entirely, a comparison detailed in Cloudflare’s own R2 versus S3 breakdown. Observability follows the same playbook: take a cost center that is painful at hyperscaler or specialist-vendor rates, undercut it, and justify the lower price by pointing out that the data already flows through Cloudflare’s network anyway.
That infrastructure advantage is real. A request that already passes through Cloudflare’s edge for DNS, WAF, or CDN service generates telemetry Cloudflare can capture without an additional agent or sidecar. Datadog, New Relic, and Grafana Cloud all require instrumentation inside a customer’s own application or infrastructure to collect the same data. Cloudflare’s pitch is that if you are already paying for the network, the observability layer on top should be close to free to add.
What This Means for DevOps and Platform Teams
For teams already running meaningful traffic through Cloudflare, the practical upside is consolidation. A platform team that previously paid for Cloudflare’s network services plus a separate Datadog or Grafana Cloud contract for logs and traces now has a real option to drop one of those two bills, at least for the portion of telemetry generated at the edge. That does not eliminate the need for application-level observability inside a customer’s own servers or containers, since Cloudflare Traces only covers what happens on Cloudflare’s network.
Teams running workloads on Cloudflare Containers stand to benefit most directly, since Containers logs now show up in the same unified Logs home as Workers, R2, and AI Gateway activity. For a team that has consolidated most of its edge compute onto Cloudflare already, this closes one of the last remaining gaps between Cloudflare’s platform and a dedicated observability vendor.
The calculus is less clear for teams with most of their infrastructure in AWS, Azure, or GCP, where Cloudflare only sees the edge slice of traffic. For those teams, this launch is more likely to shrink a line item than replace a vendor outright.
Market Impact: Pressure on an Already Crowded Field
Observability vendors have spent the last two years fending off complaints about unpredictable bills, and several, including Grafana Labs and New Relic, have already introduced usage-based or consumption-capped pricing tiers to compete on cost rather than just feature breadth. Cloudflare entering with a single, low, publicly listed rate adds pressure specifically on the low end of the market: teams with modest telemetry volumes who felt priced out of full-featured observability platforms now have a credible low-cost option that still includes tracing and a query layer, not just basic log storage.
It is unlikely to dent enterprise contracts with Datadog or Splunk in the near term. Those deals typically bundle infrastructure monitoring, synthetic testing, security monitoring, and dozens of integrations that Cloudflare’s product does not attempt to replicate. But for startups and mid-market teams evaluating a first or second observability vendor, Cloudflare now belongs in that conversation in a way it did not before October 2.
Historical Context: From CDN to Full Observability Stack
Cloudflare launched publicly on September 27, 2010, and this release landed during the company’s 2026 Birthday Week, the annual product-launch event it runs around that anniversary each September. The pattern of shipping dense batches of announcements during that week goes back years, and it has become the company’s preferred venue for stacking several product launches that each build toward the same strategic goal: turning Cloudflare from a CDN and security layer into a full application platform.
That shift has been visible in stages. Workers launched in 2017 as an edge compute product. R2 object storage arrived in 2022 specifically to undercut S3 egress pricing. D1, Cloudflare’s serverless database, followed, and Basin extended that data-platform ambition further this year. Observability is the logical next layer: once a company runs compute, storage, and data processing on your platform, offering monitoring for all of it under one bill is a natural extension rather than a new bet.
The Competitive Landscape Cloudflare Is Stepping Into
Datadog remains the category leader by feature breadth, covering infrastructure monitoring, application performance monitoring, security monitoring, synthetic testing, and log management from one console, which is why enterprise buyers still default to it despite the cost complaints. Grafana Cloud leans on its open-source roots and the popularity of Grafana dashboards, with its Loki-based logging and componentized pricing appealing to teams that want to pay only for the pieces they use. New Relic markets an all-in-one platform with per-user pricing layered on top of data costs, aiming at teams that value simplicity over granular cost control. Splunk, the oldest name in the group, still dominates in large enterprise and government deployments where its search language and compliance tooling are entrenched, even though its ingest-based pricing is widely described as the least transparent of the group.
Cloudflare does not match any of these vendors feature for feature. It has no synthetic monitoring product, no infrastructure host agent, and no server-side APM for applications running outside its own network. What it has instead is a lower published price, a tracing product tied directly to the edge traffic many of its customers already route through Cloudflare, and the beginnings of an AI-agent-facing interface through its new MCP server. That is a narrower but sharper pitch than trying to out-feature Datadog directly.
Five Predictions for Where This Goes Next
- Expect Cloudflare to extend Traces beyond open beta to general availability within two to three quarters, following the same beta-to-GA cadence it used for Basin and D1.
- Competing vendors will likely respond with their own simplified, flat-rate tiers aimed at the same cost-conscious mid-market segment Cloudflare is targeting first.
- The Observability MCP server points toward AI coding agents querying production telemetry directly during debugging sessions, a workflow likely to show up in GitHub Copilot, Cursor, and similar tools integrating with Cloudflare’s API over the next year.
- Enterprise customers with heavy unsampled security-log requirements will push back on the $1 per GB rate for that tier, since compliance-driven logging volumes can dwarf standard application logs.
- Expect further consolidation announcements tying Observability into Cloudflare’s AI Gateway and Workers AI products, since usage-based AI billing depends on exactly the kind of granular request-level telemetry Traces now captures.
What Teams Should Do Before December 1, 2026
Any team currently on Cloudflare’s Enterprise plan should confirm when its contract renews relative to the December 1 effective date, since Enterprise pricing changes apply at renewal rather than on a fixed calendar date. Teams on Paid plans should audit current log and trace volume against the new 50 GB per billing cycle allowance before the switch, since usage that fit comfortably under the old model might cross into overage charges under the new one depending on how heavily a given account uses Workers, Containers, or firewall logging.
Teams evaluating whether to consolidate an existing Datadog or Grafana Cloud contract onto Cloudflare Observability should pilot it against a single service first. Cloudflare Traces is still in open beta, and beta products carry the usual caveat: features and pricing details can still shift before general availability.
Frequently Asked Questions
When does Cloudflare’s new observability pricing take effect?
The new ingestion-and-storage pricing model applies to Paid plans starting December 1, 2026. Enterprise accounts move to the new model at their next contract renewal rather than on a fixed date.
How much does Cloudflare charge per GB for logs and traces?
Beyond the included allowance, Cloudflare charges $0.25 per GB ingested and $0.10 per GB-month stored, according to its official pricing documentation. Unsampled security datasets are billed separately at $1 per GB ingested.
Is Cloudflare Observability cheaper than Datadog?
It depends on usage. Datadog’s base log ingestion rate of $0.10 per GB is lower than Cloudflare’s $0.25 per GB, but Datadog charges separately for indexing, APM hosts, and custom metrics, while Cloudflare’s rate covers ingestion and storage without those additional per-feature charges. Teams with heavy indexing or high host counts may find Cloudflare cheaper overall. Teams with low indexing needs may find Datadog cheaper.
What is Cloudflare Traces?
Cloudflare Traces, launched in open beta on October 2, 2026, gives request-level visibility across security rules, transformations, cache decisions, routing, Worker execution, and origin handling in a single trace, extending tracing that previously only existed for Workers.
Does the new pricing model replace Logpush pricing?
Logpush now has its own usage-based pricing and is available on self-serve plans for the first time, not just Enterprise. It includes 25 GB per month free to Cloudflare-owned destinations like R2, billed at $0.03 per additional GB, or 25 GB per month free to external destinations at $0.10 per additional GB.
Can Cloudflare Observability fully replace Datadog or Grafana Cloud?
Not for most teams. Cloudflare only captures telemetry for traffic that passes through its own network, so it has no visibility into infrastructure or applications running entirely inside AWS, Azure, or GCP without Cloudflare in front of them. Teams with significant edge traffic on Cloudflare can realistically shrink their reliance on a separate vendor, but full replacement depends on how much of the stack already runs on Cloudflare.
What is the Observability MCP server?
It is a Model Context Protocol server Cloudflare shipped alongside the unified SQL API, letting AI coding agents and tools query Cloudflare’s observability data programmatically rather than only through the dashboard.




