Gateway logs now cover every on-ramp!
Hey everyone, it's me, Shii-chan! Today I've got a small but genuinely handy update about Zero Trust logging.
Cloudflare ChangelogWhat was announced?
From Cloudflare's Changelog: Network Session Logs for traffic proxied through Cloudflare Gateway are now generated for every on-ramp, no matter the type.
Concretely, traffic from proxy endpoints (PAC files) and Browser Isolation egress — on-ramps that previously did not produce session logs — are now logged too.
The story so far
Until now, even when traffic went through Gateway, some on-ramps just didn't emit session logs. Proxy endpoints and Browser Isolation egress were exactly those cases, so during audits or troubleshooting you could end up thinking "wait, where's the log for this traffic?"
What changes
From now on, traffic coming in through any on-ramp produces session logs the same way, so those gaps get filled and your visibility goes way up. Being able to follow every path at a consistent granularity is a real win for anyone doing security operations or audits.
One heads-up: if you already consume the zero_trust_network_sessions dataset via Logpush or Log Explorer and use these on-ramps, you may see increased log volume. It's worth checking your destination capacity and costs just in case.
Dive Deep
Field definitions live in the Zero Trust Network Session Logs docs. When you want to analyze the traffic from those logs, take a look at Network session analytics.
Wrap-up
- Network Session Logs for Gateway traffic are now generated for all on-ramps
- Previously excluded proxy endpoints (PAC files) and Browser Isolation egress are now logged
- If you use
zero_trust_network_sessionsvia Logpush / Log Explorer, log volume may increase
This one is for operations and security folks who care about log visibility in Zero Trust!