V2.25.0 Introducing Identity: context behind every change

WINDOWS OBSERVABILITY, CONNECTED.

Every event.
More understanding.

Your fleet is telling a story. Bring Windows events, server performance and IIS requests together to see what changed—and where to look next.

Windows Events / Fleet overviewILLUSTRATIVE DATA

Your fleet, in focus.

Events and measured performance. One shared view.

Last 24 hours
Computers24
Events2.8M
Errors142
Warnings386
Event activity Information Warning Error
00:0006:0012:0018:0024:00
COMPUTERCPUMEMORYEVENTS
APP-SERVER-0172%12.4 / 16 GB842,106
WEB-SERVER-0228%7.8 / 32 GB610,284
Built on an open data foundation
Cloudflare Workers
R2 SQL
Apache Iceberg
Workers AI

ONE PLATFORM. THE WHOLE PICTURE.

Follow the signal.
Keep the context.

Move from a fleet-wide view to the event that matters. Every layer gives you a more useful next question.

QUERY & CORRELATION

One investigation.
Every connected signal.

Search Windows events and IIS requests together. Narrow by host, drill into message fields, and graph counts without losing your place.

  • Ask in plain English or write a precise search
  • Compare events, CPU, memory and IIS in host detail
  • Share the exact view with your team

AI THAT KEEPS THE EVIDENCE IN VIEW.

A useful first read.
A clear next step.

Start with a summary of what changed across your fleet. Investigate a host, scan selected events, or ask what a new event type might mean.

Measured figures sit beside the fleet summary. Saved analyses keep the context available for the next person who picks up the investigation.

✧Fleet summaryEXAMPLE

LAST 24 HOURS · COMPARED WITH THE DAY BEFORE

A change worth investigating.

WEB-SERVER-02 recorded more 5xx responses during a period of elevated CPU. Review the aligned host timeline to see which events occurred in the same window.

CPU peak94%
5xx requests128
Window14:00–15:00
↳ Correlation gives you somewhere to look. It does not establish the cause.

FROM OVERVIEW TO ANSWERS.

Less switching.
More investigating.

A connected workflow for the questions infrastructure teams ask every day.

01 / ORIENT

See what needs attention.

Start with fleet activity, measured CPU and memory, or a daily AI summary. Pressure highlights the worst stretch in the selected window.

02 / INVESTIGATE

Follow the evidence.

Open a host, line up its signals in time, and drill into the underlying events or requests. Filter, count and visualise the details.

03 / HAND OVER

Share the whole context.

Send a link to the exact search, time range, individual event or saved AI analysis so another team member can pick up where you left off.

▤

Security, in context.

A watchlist of 25 security event types, failed sign-ins and account lockouts—with guidance on what each event means and what to check.

⌁

Web performance, connected.

Explore IIS status codes, response times and failing pages, then open the surrounding Windows events for the same host.

⊞

Software behind the noise.

Trace event volume from hosts through software and providers to severity. See which components are driving the activity.

LATEST IN WINDOWS EVENTS.

More context.
With every release.

Recent improvements connect major changes with identity context, surface unfamiliar events and reveal the files behind your data lake.

v2.25.0LATEST

A change on a server. The people to ask.

Line up service installs, software changes, restarts and account activity with interactive sign-ins. See the account Windows recorded, when available, and who signed in during the hour before.

Release details

Explore major events and sign-ins on a shared timeline, zoom into a period, and open the underlying records in Query. Review sign-in methods, source locations, admin accounts, failed sign-ins and lockouts. Recorded accounts and nearby sign-ins stay separate: presence alone does not establish responsibility.

IDENTITY
v2.24.0

Know what’s in your bucket.

See live table data, older data files, metadata and objects outside your tables. Understand the difference between catalog sizes and total bucket storage.

Release details

With the R2 bucket binding configured, a row per table shows where space goes. Older data files can be freed as the snapshots that reference them expire.

DATA LAKE
v2.23.0

Spot what your fleet hasn’t seen before.

Distinguish event types that are new to the fleet from those that are new to an individual host, against at least 30 days of prior history.

Release details

Explore a 30-day strip, open events from the flow diagram, and request an AI explanation of new types, likely causes and suggested checks. Analyses can be saved and shared.

ANOMALIES
v2.22.0

Follow events back to their software.

Explore a flow from hosts to software to severity. Include or exclude components, then drill into providers and their events.

Release details

Software is inferred from each event’s provider, including Windows, SQL Server, IIS, Defender and VMware. Expand the diagram to focus on larger flows.

SOFTWARE
v2.21.0

Ask a question. See the breakdown.

Ask AI to graph failed logons by account or 5xx errors by page. It creates an editable count query, with results as a table, bars or over time.

Release details

Count queries stay visible and editable. The selected chart view is preserved in shared links, and counts can be downloaded as CSV.

AI + QUERY

Based on the application’s release notes through v2.25.0.

A FEW USEFUL DETAILS.

Built for the
way you investigate.

What data does Windows Events bring together?

Windows event logs, measured host CPU and memory, and IIS requests. The explorer queries data held in R2 Data Catalog as Apache Iceberg tables using R2 SQL.

Can I use it without AI?

Yes. Fleet views, manual search, filters, counts, charts and drill-downs work independently of AI. AI assists with query writing, summaries and explanations when you choose to use it.

How do shared links work?

Links preserve views such as the tab, time range, search and open host. Saved analyses can also be linked when storage is configured. Recipients still need access to the application; a shared link does not grant access.

Does the website show live infrastructure data?

No. The visuals here use illustrative data to explain the product. Open the application to explore your environment with your existing access.

Does Identity show who caused a change?

Identity shows the account recorded by Windows when the event includes one, separately from people who signed in to the host during the preceding hour. A nearby sign-in is context for an investigation, not proof that the person caused the change.

YOUR NEXT INVESTIGATION STARTS HERE.

Make sense of
what’s happening.

Windows events. Real performance. Connected context.