Skip to content

Latest commit

 

History

History
15 lines (11 loc) · 1.44 KB

File metadata and controls

15 lines (11 loc) · 1.44 KB
title Per-zone post-quantum visibility in Logpush and Log Explorer
description The http_requests dataset now includes ClientTLSKeyExchangeGroup, exposing the TLS key exchange negotiated on every client-to-Cloudflare connection.
products
logs
log-explorer
date 2026-08-20

Cloudflare Radar publishes global statistics on post-quantum key agreement adoption across all Cloudflare traffic, but until now customers had no way to see the same measurement scoped to their own zones. This is now possible because the http_requests Logpush dataset — also queryable in Log Explorer — includes a new ClientTLSKeyExchangeGroup field.

The field reports the TLS key exchange group negotiated on the client-to-Cloudflare connection, by group name. Post-quantum connections appear as X25519MLKEM768, and classical connections appear as X25519, P-256, or another named group. A value of UNK means the group could not be determined, and NONE means either RSA key exchange was used OR TLS was not used.

With this field, you can build per-zone reports showing what percentage of your inbound HTTPS traffic is protected by post-quantum key agreement, break the number down by hostname, path, user agent, or country, and push the data into your SIEM via any Logpush destination.