Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
32 changes: 23 additions & 9 deletions src/content/docs/log-explorer/faq.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -7,31 +7,31 @@ sidebar:
order: 152
---

### Which fields (or columns) are available for querying?
## Which fields (or columns) are available for querying?

All fields listed in [Datasets](/logs/logpush/logpush-job/datasets/) for the [supported datasets](/log-explorer/manage-datasets/#supported-datasets) are viewable in Log Explorer.

### Why does my query not complete or time out?
## Why does my query not complete or time out?

Log Explorer performs best when query parameters focus on narrower ranges of time. You may experience query timeouts when your query would return a large quantity of data. Consider refining your query to improve performance.

### Why do I not see any logs in my queries after enabling the dataset?
## Why do I not see any logs in my queries after enabling the dataset?

Log Explorer starts ingesting logs from the moment you enable the dataset. It will not display logs for events that occurred before the dataset was enabled. Make sure that new events have been generated since enabling the dataset, and check again.

### My query returned an error. How do I figure out what went wrong?
## My query returned an error. How do I figure out what went wrong?

We are actively working on improving error codes. If you receive a generic error, check your SQL syntax (if you are using the custom SQL feature), and make sure you have included a date and a limit. If the query still fails it is likely timing out. Try refining your filters.

### Where is the data stored?
## Where is the data stored?

The data is stored in Cloudflare R2. Each Log Explorer dataset is stored on a per-customer level, similar to Cloudflare D1, ensuring that your data is kept separate from that of other customers. In the future, this single-tenant storage model will provide you with the flexibility to create your own retention policies and decide in which regions you want to store your data.

### Does Log Explorer support Customer Metadata Boundary?
## Does Log Explorer support Customer Metadata Boundary?

Customer Metadata Boundary is currently not supported for Log Explorer.

### Are there any constraints on the log volume that Log Explorer can support?
## Are there any constraints on the log volume that Log Explorer can support?

We are continually scaling the Log Explorer data platform. At present, Log Explorer supports log ingestion rates of up to 50,000 records per second. If your needs exceed this, contact your account team.

Expand All @@ -49,12 +49,26 @@ Log Explorer billing is based on the volume of logs indexed and stored, measured

## Are logs from attack traffic included in my Log Explorer usage?

Yes. Log Explorer bills are based on the total volume of logs ingested and stored, including attack traffic. Since these logs are often critical for investigating security incidents, they are treated the same as all other log data.
Yes. In general, Log Explorer bills based on the total volume of logs ingested and stored, including attack traffic. Since these logs are often critical for investigating security incidents, they are treated the same as all other log data.

However, logs generated from Layer 7 (L7) DDoS attack traffic are not ingested by default and therefore do not count toward your Log Explorer usage.

## How does Log Explorer store data in R2, and why do I not see it in my own R2 bucket?

Log Explorer uses Cloudflare Logpush and R2 behind the scenes to stream and store logs. For technical and performance reasons, the data is stored in internal, customer-specific R2 buckets managed by Cloudflare. These buckets are single-tenant to keep your data isolated, but they are not visible in your account's R2 interface. You are not billed separately for this storage — it is included in your Log Explorer usage.

## Are Custom Dashboards based on R2 Log Explorer data, or on GraphQL?

Custom Dashboards currently run on GraphQL. Over time, this will evolve to include deeper integration between the two features, such as building charts directly from logs.
Custom Dashboards currently run on GraphQL. Over time, this will evolve to include deeper integration between the two features, such as building charts directly from logs.

## How can I track my Log Explorer usage?

Your monthly usage is displayed at the top of the Log Search and Manage Datasets dashboard sections within Log Explorer.

![Usage display in the dashboard](~/assets/images/log-explorer/log-explorer-usage.png)

## How do I turn off Log Explorer?

Use the Manage Datasets feature to enable or disable ingestion for individual datasets and zones.

To cancel your self-serve subscription, go to **Manage Account** > **Billing** > **Subscriptions**, find the Log Explorer subscription, and select **Cancel**.