Skip to content

Manage datasets

Last updated View as MarkdownAgent setup

Log Explorer allows you to enable, disable, or delete datasets available to query in Log Search.

Supported datasets

Log Explorer currently supports the following datasets:

Zone level

Account level

Enable Log Explorer

To begin storing logs, enable the desired datasets through the dashboard or API.

Dashboard

  1. In the Cloudflare dashboard, go to the Log Explorer > Manage datasets page.

    Go to Manage datasets ↗
  2. Select Add dataset.

  3. Choose a dataset and, for zone-level datasets, a zone.

  4. Under Select fields, choose the fields that Log Explorer should ingest.

  5. Under Filter logs, choose whether to ingest all events or only events that match a filter.

  6. Select Add.

Configure fields and filters

Use Select fields to control which data points Log Explorer stores. Fields are grouped by category, and each category shows its selected field count. Select a category to add or remove all fields in that group, or expand the category to select individual fields. Each field shows its data type.

Required fields remain selected and are marked Required. Fields that Cloudflare no longer recommends are marked Deprecated. Select Select all to include every available field, or Reset to default to restore the dataset defaults.

Use Filter logs to ingest All events or Only events matching a filter. A filter condition consists of a field, an operator, and a value. All conditions within a group must match. An event can match any filter group.

To change the fields or filter for an enabled dataset, go to Log Explorer > Manage datasets. Find the dataset, select Actions > Edit, update the configuration, and select Update.

API

Use the Log Explorer API to enable each dataset you want to store. It may take a few minutes after a log stream is enabled before you can view the logs.

The following curl command is an example for enabling the zone-level dataset http_requests, as well as the expected response when the command succeeds.

curl https://api.cloudflare.com/client/v4/zones/{zone_id}/logs/explorer/datasets \
--header "Authorization: Bearer <API_TOKEN>" \
--json '{
  "dataset": "http_requests"
}'
{
	"result": {
		"dataset": "http_requests",
		"object_type": "zone",
		"object_id": "<ZONE ID>",
		"created_at": "2025-06-03T14:33:16Z",
		"updated_at": "2025-06-03T14:33:16Z",
		"dataset_id": "01973635f7e273a1964a02f4d4502499",
		"enabled": true,
		"deletion_protection": true
	},
	"success": true,
	"errors": [],
	"messages": []
}

To enable an account-level dataset, replace zones/{zone_id} with accounts/{account_id} in the curl command. For example:

curl https://api.cloudflare.com/client/v4/accounts/{account_id}/logs/explorer/datasets \
--header "Authorization: Bearer <API_TOKEN>" \
--json '{
  "dataset": "access_requests"
}'

Delete a dataset

Deleting a dataset permanently removes the dataset and its stored data. Deletion runs asynchronously. You cannot recreate the same dataset for the account or zone while deletion is in progress.

  1. In the Cloudflare dashboard, go to Log Explorer > Manage datasets.

    Go to Manage datasets ↗
  2. Find the dataset and select Actions > Delete.

  3. If deletion protection is enabled, disable it in the confirmation dialog.

  4. Enter the dataset name and select Delete.

  1. Set deletion_protection to false with the Update an account or zone dataset method.
  2. Delete the dataset with the Delete an account or zone dataset method.

Was this helpful?