Skip to content

Changelog

New updates and improvements at Cloudflare.

Wi-Fi signal and network performance analytics for Cloudflare One Client devices

Digital Experience Monitoring (DEX) provides visibility into device, network, and application performance across your Cloudflare SASE deployment.

The Device Monitoring page now analyzes hardware and network data between a Cloudflare One Client device and Cloudflare's edge, so you can diagnose connectivity and performance issues. Previously, this data was only available in raw DEX Device State Event logs, which required you to build your own analytics to interpret it.

Device Monitoring summary with connection status, connection mode, Wi-Fi signal strength, traffic performance, and device health

A summary at the top of the page shows the health of each category at a glance, using Good, Fair, and Poor labels:

  • Connection — connection status, Cloudflare One Client mode, and tunnel type over time
  • Wi-Fi signal strength — signal measured in dBm over time, with thresholds that flag a weak signal
  • Traffic performance — upstream and downstream performance, including network throughput on the active interface
  • Device health — hardware metrics such as CPU, memory, and disk
Wi-Fi signal strength and network throughput charts on the Device Monitoring page

You can filter by category and adjust the time range to correlate a device's metrics with a user's reported issue.

These analytics are available to all Cloudflare One customers at no additional cost.

To learn more, refer to the DEX monitoring documentation.

Regionalized IP Bindings for Regional Services

Regional Services now supports Regionalized IP Bindings, letting you regionalize traffic at the IP layer for prefixes you bring to Cloudflare through Bring Your Own IP (BYOIP).

Where Regional Hostnames regionalize traffic by hostname, Regionalized IP Bindings let you bind a CIDR from one of your prefixes to a region — ideal for address-map deployments and any service you address by IP rather than hostname. Cloudflare then terminates TLS and processes traffic to those addresses only within the data centers in that region.

Regionalized IP Bindings requires the Regional Services and Regional Services for BYOIP entitlements. Contact your account team to enable them.

To get started, refer to Regionalized IP Bindings.

Digital experience tests to authenticated resources and enhanced configuration

Digital experience tests now support testing applications protected by Cloudflare Access or third-party authentication. All authentication secrets are managed via Cloudflare Secret Store.

Digital experience tests also have enhanced configuration options including:

  • New HTTP methods (DELETE, PATCH, POST, PUT)
  • Secret Store headers, custom plain text headers, and custom request bodies
  • Advanced settings: follow redirects, response bodies, response headers, and allow untrusted certificates
Digital experience test configuration for Cloudflare Access applicationsDigital experience enhanced test configuration

Cloudflare One Client speed tests

IT teams can now remotely run speed tests from the Cloudflare One Client to Cloudflare's network edge.

Each speed test includes the following metrics:

  • Internet speed: download and upload throughput
  • Latency: download, upload, unloaded latency, and jitter
  • Network quality score: video streaming, webchat/real-time communication (RTC)

In the Cloudflare dashboard ↗︎, go to Zero Trust > Insights > Digital experience > Diagnostics and select Run diagnostics to use the feature today.

Cloudflare One client speed test result

DEX Supports EU Customer Metadata Boundary

Digital Experience Monitoring (DEX) provides visibility into WARP device connectivity and performance to any internal or external application.

Now, all DEX logs are fully compatible with Cloudflare's Customer Metadata Boundary (CMB) setting for the 'EU' (European Union), which ensures that DEX logs will not be stored outside the 'EU' when the option is configured.

If a Cloudflare One customer using DEX enables CMB 'EU', they will not see any DEX data in the Cloudflare One dashboard. Customers can ingest DEX data via LogPush, and build their own analytics and dashboards.

If a customer enables CMB in their account, they will see the following message in the Digital Experience dashboard: "DEX data is unavailable because Customer Metadata Boundary configuration is on. Use Cloudflare LogPush to export DEX datasets."

Digital Experience Monitoring message when Customer Metadata Boundary for the EU is enabled

Cloudflare One Product Name Updates

We are updating naming related to some of our Networking products to better clarify their place in the Zero Trust and Secure Access Service Edge (SASE) journey.

We are retiring some older brand names in favor of names that describe exactly what the products do within your network. We are doing this to help customers build better, clearer mental models for comprehensive SASE architecture delivered on Cloudflare.

What's changing

  • Magic WAN → Cloudflare WAN
  • Magic WAN IPsec → Cloudflare IPsec
  • Magic WAN GRE → Cloudflare GRE
  • Magic WAN Connector → Cloudflare One Appliance
  • Magic Firewall → Cloudflare Network Firewall
  • Magic Network Monitoring → Network Flow
  • Magic Cloud Networking → Cloudflare One Multi-cloud Networking

No action is required by you — all functionality, existing configurations, and billing will remain exactly the same.

For more information, visit the Cloudflare One documentation.

Network Services navigation update

The Network Services menu structure in Cloudflare's dashboard has been updated to reflect solutions and capabilities instead of product names. This will make it easier for you to find what you need and better reflects how our services work together.

Your existing configurations will remain the same, and you will have access to all of the same features and functionality.

The changes visible in your dashboard may vary based on the products you use. Overall, changes relate to Magic Transit ↗︎, Magic WAN ↗︎, and Magic Firewall ↗︎.

Summary of changes:

  • A new Overview page provides access to the most common tasks across Magic Transit and Magic WAN.
  • Product names have been removed from top-level navigation.
  • Magic Transit and Magic WAN configuration is now organized under Routes and Connectors. For example, you will find IP Prefixes under Routes, and your GRE/IPsec Tunnels under Connectors.
  • Magic Firewall policies are now called Firewall Policies.
  • Magic WAN Connectors and Connector On-Ramps are now referenced in the dashboard as Appliances and Appliance profiles. They can be found under Connectors > Appliances.
  • Network analytics, network health, and real-time analytics are now available under Insights.
  • Packet Captures are found under Insights > Diagnostics.
  • You can manage your Sites from Insights > Network health.
  • You can find Magic Network Monitoring under Insights > Network flow.

If you would like to provide feedback, complete this form ↗︎. You can also find these details in the January 7, 2026 email titled [FYI] Upcoming Network Services Dashboard Navigation Update.

Preview: Networking Navigation

Workers Analytics Engine SQL now supports filtering using HAVING and LIKE

You can now use the HAVING clause and LIKE pattern matching operators in Workers Analytics Engine ↗︎.

Workers Analytics Engine allows you to ingest and store high-cardinality data at scale and query your data through a simple SQL API.

Filtering using HAVING

The HAVING clause complements the WHERE clause by enabling you to filter groups based on aggregate values. While WHERE filters rows before aggregation, HAVING filters groups after aggregation is complete.

You can use HAVING to filter groups where the average exceeds a threshold:

SELECT
    blob1 AS probe_name,
    avg(double1) AS average_temp
FROM temperature_readings
GROUP BY probe_name
HAVING average_temp > 10

You can also filter groups based on aggregates such as the number of items in the group:

SELECT
    blob1 AS probe_name,
    count() AS num_readings
FROM temperature_readings
GROUP BY probe_name
HAVING num_readings > 100

Pattern matching using LIKE

The new pattern matching operators enable you to search for strings that match specific patterns using wildcard characters:

  • LIKE - case-sensitive pattern matching
  • NOT LIKE - case-sensitive pattern exclusion
  • ILIKE - case-insensitive pattern matching
  • NOT ILIKE - case-insensitive pattern exclusion

Pattern matching supports two wildcard characters: % (matches zero or more characters) and _ (matches exactly one character).

You can match strings starting with a prefix:

SELECT *
FROM logs
WHERE blob1 LIKE 'error%'

You can also match file extensions (case-insensitive):

SELECT *
FROM requests
WHERE blob2 ILIKE '%.jpg'

Another example is excluding strings containing specific text:

SELECT *
FROM events
WHERE blob3 NOT ILIKE '%debug%'

Ready to get started?

Learn more about the HAVING clause or pattern matching operators in the Workers Analytics Engine SQL reference documentation.

DEX Logpush jobs

Digital Experience Monitoring (DEX) provides visibility into WARP device metrics, connectivity, and network performance across your Cloudflare SASE deployment.

We've released four new WARP and DEX device data sets that can be exported via Cloudflare Logpush. These Logpush data sets can be exported to R2, a cloud bucket, or a SIEM to build a customized logging and analytics experience.

  1. DEX Application Tests
  2. DEX Device State Events
  3. WARP Config Changes
  4. WARP Toggle Changes

To create a new DEX or WARP Logpush job, customers can go to the account level of the Cloudflare dashboard > Analytics & Logs > Logpush to get started.

DEX logpush job creation dashboard

More SQL aggregate, date and time functions available in Workers Analytics Engine

You can now perform more powerful queries directly in Workers Analytics Engine ↗︎ with a major expansion of our SQL function library.

Workers Analytics Engine allows you to ingest and store high-cardinality data at scale (such as custom analytics) and query your data through a simple SQL API.

Today, we've expanded Workers Analytics Engine's SQL capabilities with several new functions:

New aggregate functions: ↗︎

  • countIf() - count the number of rows which satisfy a provided condition
  • sumIf() - calculate a sum from rows which satisfy a provided condition
  • avgIf() - calculate an average from rows which satisfy a provided condition

New date and time functions: ↗︎

  • toYear()
  • toMonth()
  • toDayOfMonth()
  • toDayOfWeek()
  • toHour()
  • toMinute()
  • toSecond()
  • toStartOfYear()
  • toStartOfMonth()
  • toStartOfWeek()
  • toStartOfDay()
  • toStartOfHour()
  • toStartOfFifteenMinutes()
  • toStartOfTenMinutes()
  • toStartOfFiveMinutes()
  • toStartOfMinute()
  • today()
  • toYYYYMM()

Ready to get started?

Whether you're building usage-based billing systems, customer analytics dashboards, or other custom analytics, these functions let you get the most out of your data. Get started with Workers Analytics Engine and explore all available functions in our SQL reference documentation.

Workers Analytics Engine adds supports for new SQL functions

You can now perform more powerful queries directly in Workers Analytics Engine ↗︎ with a major expansion of our SQL function library.

Workers Analytics Engine allows you to ingest and store high-cardinality data at scale (such as custom analytics) and query your data through a simple SQL API.

Today, we've expanded Workers Analytics Engine's SQL capabilities with several new functions:

New aggregate functions: ↗︎

  • argMin() - Returns the value associated with the minimum in a group
  • argMax() - Returns the value associated with the maximum in a group
  • topK() - Returns an array of the most frequent values in a group
  • topKWeighted() - Returns an array of the most frequent values in a group using weights
  • first_value() - Returns the first value in an ordered set of values within a partition
  • last_value() - Returns the last value in an ordered set of values within a partition

New bit functions: ↗︎

  • bitAnd() - Returns the bitwise AND of two expressions
  • bitCount() - Returns the number of bits set to one in the binary representation of a number
  • bitHammingDistance() - Returns the number of bits that differ between two numbers
  • bitNot() - Returns a number with all bits flipped
  • bitOr() - Returns the inclusive bitwise OR of two expressions
  • bitRotateLeft() - Rotates all bits in a number left by specified positions
  • bitRotateRight() - Rotates all bits in a number right by specified positions
  • bitShiftLeft() - Shifts all bits in a number left by specified positions
  • bitShiftRight() - Shifts all bits in a number right by specified positions
  • bitTest() - Returns the value of a specific bit in a number
  • bitXor() - Returns the bitwise exclusive-or of two expressions

New mathematical functions: ↗︎

  • abs() - Returns the absolute value of a number
  • log() - Computes the natural logarithm of a number
  • round() - Rounds a number to a specified number of decimal places
  • ceil() - Rounds a number up to the nearest integer
  • floor() - Rounds a number down to the nearest integer
  • pow() - Returns a number raised to the power of another number

New string functions: ↗︎

  • lowerUTF8() - Converts a string to lowercase using UTF-8 encoding
  • upperUTF8() - Converts a string to uppercase using UTF-8 encoding

New encoding functions: ↗︎

  • hex() - Converts a number to its hexadecimal representation
  • bin() - Converts a string to its binary representation

New type conversion functions: ↗︎

  • toUInt8() - Converts any numeric expression, or expression resulting in a string representation of a decimal, into an unsigned 8 bit integer

Ready to get started?

Whether you're building usage-based billing systems, customer analytics dashboards, or other custom analytics, these functions let you get the most out of your data. Get started with Workers Analytics Engine and explore all available functions in our SQL reference documentation.

DEX MCP Server

Digital Experience Monitoring (DEX) provides visibility into device connectivity and performance across your Cloudflare SASE deployment.

We've released an MCP server (Model Context Protocol) ↗︎ for DEX.

The DEX MCP server is an AI tool that allows customers to ask a question like, "Show me the connectivity and performance metrics for the device used by carly‌@acme.com", and receive an answer that contains data from the DEX API.

Any Cloudflare One customer using a Free, Pay-as-you-go, or Enterprise account can access the DEX MCP Server. This feature is available to everyone.

Customers can test the new DEX MCP server in less than one minute. To learn more, read the DEX MCP server documentation.

Cloudflare One Agent now supports Endpoint Monitoring

Digital Experience Monitoring (DEX) provides visibility into device, network, and application performance across your Cloudflare SASE deployment. The latest release of the Cloudflare One agent (v2025.1.861) now includes device endpoint monitoring capabilities to provide deeper visibility into end-user device performance which can be analyzed directly from the dashboard.

Device health metrics are now automatically collected, allowing administrators to:

  • View the last network a user was connected to
  • Monitor CPU and RAM utilization on devices
  • Identify resource-intensive processes running on endpoints
Device endpoint monitoring dashboard

This feature complements existing DEX features like synthetic application monitoring and network path visualization, creating a comprehensive troubleshooting workflow that connects application performance with device state.

For more details refer to our DEX documentation.