Cloudflare says it lost 55% of all logs pushed to customers over a 3.5-hour period due to a bug on November 14; Cloudflare sends ~4.5T logs to customers daily
Internet security giant Cloudflare announced that it lost 55% of all logs pushed to customers over a 3.5-hour period due to a bug …
Context & Ripple Effects
The incident follows Cloudflare’s work defending customers from sustained attacks, including a month-long DDoS campaign against financial, internet, and telecom organizations. In that setting, log delivery is part of the evidence customers use to investigate traffic and validate protections.
It also adds a different kind of operational failure to Cloudflare’s history: an earlier bug that exposed private user information centered on data leakage, while this event centers on missing customer telemetry.
First-order effects
- Customers that depended on Cloudflare-delivered logs during the affected window have an incomplete record of requests and security events, limiting retrospective investigations and reporting.
- Cloudflare must account for the delivery failure to affected customers and remediate the software path that caused the loss.
Second-order effects
- Security and operations teams may need to reconcile Cloudflare logs with application, network, or SIEM records before treating dashboards and incident timelines from that period as complete.
- The failure raises the value of independent telemetry sources for customers whose detection, compliance, or billing workflows rely on a single log-delivery pipeline.
Third-order effects
- If comparable gaps recur, large edge and security platforms will face stronger customer pressure to make telemetry delivery measurable, auditable, and recoverable rather than treating it as a best-effort byproduct.
- The broader shift is toward resilience designs that cover observability data itself: protection can remain active while customers still lose the evidence needed to verify what happened.
The trend: As security services become core operational infrastructure, customers are demanding the same reliability and recovery guarantees for telemetry as for traffic protection itself.