Requirements
Your site doesn’t have to be hosted on Cloudflare. It can run on Vercel, Netlify, your own servers or anywhere else, as long as its traffic passes through Cloudflare’s proxy:- The domain uses Cloudflare, either with Cloudflare nameservers or with a partial (CNAME) setup on the Business and Enterprise plans.
- The DNS records that serve the site are Proxied (the orange cloud). Records set to DNS only never reach Cloudflare’s edge, so they produce no logs.
GET requests from visitors, which cuts the volume you export.
1
Get your token and destination
Open Traffic in the GEO sidebar and pick Cloudflare Logpush at the top of the install panel. It shows the destination URL with your project’s tracking token already in it:Logpush turns every
header_ parameter into a request header, so Notra receives the token as Authorization: Bearer <token>.2
Log the request headers (recommended)
Cloudflare’s request logs don’t include the You can skip this step. Notra then classifies requests by user agent and referer only, which covers the declared crawlers and assistants and every referral from an AI answer.
Accept, fetch metadata or client hint headers unless you add them as custom fields. With them Notra can see when an agent asks for Markdown and catch agents that pose as a regular browser, which brings the data to the same quality as the tracker package.In the dashboard, open Analytics & Logs, then Logpush, select Edit Custom Fields and add these request headers: accept, accept-language, sec-ch-ua, sec-fetch-mode, traceparent, b3 and x-b3-traceid. With the API, the same rule looks like this:3
Create the Logpush job
In the dashboard, go to Analytics & Logs, then Logpush, and create a job. Choose HTTP destination and paste the destination URL, then pick the HTTP requests dataset and select these fields:Set the timestamp format to RFC 3339 and, if the form offers filters, keep only requests where When you save the job, Cloudflare uploads a small test file to the destination and Notra accepts it.
ClientRequestMethod equals GET and ClientRequestSource equals eyeball.The install panel also has the full API request, which creates the same job with the filter in place. It needs an API token with the Logs Write permission for the zone and reads your tracking token from NOTRA_GEO_TOKEN:4
Verify
Logpush uploads in batches, so the first events show up a minute or two after a crawler visits. The Traffic page switches from the install panel to the dashboard once Notra stores the first AI crawler or referral.
How Notra reads the logs
Notra unpacks each gzipped batch, rebuilds every request from its fields and drops anything that isn’t aGET request for a page from a visitor, so static assets, /api routes and Worker subrequests never count. Every request then goes through the same checks as tracker events: it has to belong to one of the project’s tracked domains, and only AI crawlers and AI referrals are stored. Human requests are discarded on arrival.
Like any log-based source, Logpush only observes traffic. It can’t tag the links in the Markdown you serve for journey tagging, although requests that already carry an ntr tag still join their journey.
Next steps
Vercel log drain
Track sites hosted on Vercel without a code change.
No AI traffic yet
What to check when nothing shows up.