Identify Mesh, Workers VPC, and Cloudflare Tunnel replicas in network logs
You can now tell a person on a laptop apart from a Mesh node or an AI agent running on Workers, without matching on connector email addresses or Mesh IP ranges — and see exactly which Cloudflare Tunnel and cloudflared replica received each session.
Gateway network logs and Zero Trust Network Session Logs now identify two new kinds of traffic:
- Mesh — Traffic sent from or delivered to a Cloudflare Mesh node. Previously, Mesh nodes were logged the same way as devices running the Cloudflare One Client, because Mesh nodes run the client in headless mode.
- Workers VPC — Traffic sent by a Worker through a Workers VPC binding. Previously, Workers VPC sessions were not recorded in Network Session Logs.
To view these values in the dashboard, go to Zero Trust > Insights & Logs > Logs > Network logs, select Columns, and turn on Traffic Source and Traffic Destination. Both values also appear under Network query details when you open a log entry.
The zero_trust_network_sessions dataset, available through Logpush, includes the following fields:
| Field | Description |
|---|---|
OnrampType |
How the session entered Cloudflare One. Values: CF1_CLIENT, MESH, WORKERS_VPC, MAGIC, OTHER. |
Offramp |
Where the session was routed. Sessions routed to a Mesh node report MESH. |
SourceName |
Name of the Worker that started the session. Only populated for Workers VPC sessions. |
SourceID |
Stable identifier of the Worker that started the session. Only populated for Workers VPC sessions. |
DestinationReplicaID |
The replica that served the session, such as a specific replica of a Mesh node or a cloudflared replica of a Cloudflare Tunnel. |
For example, OnrampType = 'WORKERS_VPC' AND Offramp = 'MESH' returns every session where a Worker reached a service behind a Mesh node, and SourceName tells you which Worker it was.
With DestinationReplicaID, you can now confirm which Cloudflare Tunnel and which cloudflared replica received traffic for a specific session. Combine it with the existing DestinationTunnelID field to trace a session to an exact tunnel replica — or Mesh node replica — when you run multiple replicas for high availability. The replica ID matches the Connector ID shown in the dashboard, so you can stream that replica's logs with cloudflared tail --connector-id.
Sessions logged before this change are not backfilled. For all available fields, refer to Zero Trust Network Session Logs.