Server log monitoring for your Shopify store

Shopify gives merchants no server logs, and theme analytics only sees browsers that run JavaScript. Salience monitors every storefront request through a Cloudflare zone you own (products, collections, search, sitemap and robots.txt), with verified crawler identities and alerts that name the paths and addresses involved.

Any Shopify plan, through a Cloudflare account you own. No app, no theme change and no code change.

The Log Explorer page for shop.example once Shopify is connected through Cloudflare O2O Worker: the Website setup strip shows Logs Receiving, and the table fills with Googlebot requesting /products/wireless-headphones, status 200, Verified; ClaudeBot requesting /collections/sale, status 200, Verified; Googlebot (claimed) requesting /collections/all, status 200, Unverified; Bingbot requesting /products/running-shoes.js, status 200, Crawl waste. First hour on the store: 27,905 requests.

Other log sources

Bots, scrapers and crawlers do not appear in Shopify Analytics

Every storefront analytics app works the same way: a script in your theme, firing when a browser renders a page. That is a reasonable way to count shoppers and a hopeless way to see anything else.

Watching sessions in Shopify Analytics and having no idea whether a traffic change was real shoppers, a scraper mirroring your catalogue, or an AI crawler working through every product page.

Suspecting a competitor is scraping your prices, and having nothing to show for it: no addresses, no request counts, no pattern, nothing anyone could act on.

Finding out that a collection or product URL has been returning errors to Googlebot only when the traffic has already gone, because nothing was watching the requests themselves.

Asking Shopify support for server logs, and being told, correctly, that merchants do not get them on any plan.

See your Shopify server log, request by request

Once your domain runs through your own Cloudflare zone, every storefront request is visible: humans, verified crawlers, AI agents and scrapers, separated and counted.

The Salience dashboard for shop.example, last 24 hours. Website setup 5 of 6 completed. Traffic over time in fifteen-minute buckets, human and bot requests stacked. Bot identity evidence: 12.1K verified requests, 762 unverified claims, 2.7K with verification unknown. Total requests 34.2K, up 7.0% on the previous period. Unique IPs 15.3K, up 2.0%. Bot traffic 45.5%, down 1.9 points. AI crawlers 18.5%, down 8.0 points.

Requests reach Salience within seconds and show in reports within about fifteen minutes. Checkout is the one exception, and it is excluded by Shopify's platform rules rather than by choice.

Catch the scrapers mirroring your catalogue

Price and product scraping is the most common automated traffic a storefront receives, and the hardest to evidence. Salience surfaces repeated, systematic requests across your product and collection paths, groups them by source address and user agent, and separates them from the verified crawlers you want.

200+Crawler identities recognised, verified against published ranges where providers publish them

Recommendations on shop.example, IPs to block: 45.133.5.188, 1 requests, seen as bot impersonation surge, /products.json, 1h ago; 185.218.86.24, 1 requests, seen as bot impersonation surge, /collections.json, 1h ago; 88.166.28.185, 2 requests, seen as traffic spike, /collections/all?page=47, 4h ago; 34.12.128.52, 16 requests, seen as hacking probe, /cart/add.js, 15h ago; 62.60.130.228, 3 requests, seen as hacking probe, /checkouts/, 19h ago.

Know which AI systems are reading your products

GPTBot, ClaudeBot, PerplexityBot and the rest are increasingly how products get discovered and described. Salience separates model-training crawls from AI-search indexing and from user-triggered retrieval, and flags anything borrowing an AI user agent without the addresses to back it up.

SecondsFrom a request hitting your storefront to it appearing in Salience

Sitemap Coverage on shop.example: 31,041 Total Active URLs, 22,514 Recently Crawled, 7,912 Stale, 615 Never Crawled, 73% Coverage Rate. /products/wireless-headphones first seen 23/01/2026, 135 recorded crawls, last crawled 15h ago by Bingbot, Crawled; /collections/sale first seen 29/04/2026, 1 recorded crawls, last crawled 22/03/2026 by Googlebot Smartphone, Stale; /collections/all first seen 25/02/2026, 2 recorded crawls, last crawled 25/02/2026 by Bingbot, Stale; /products/running-shoes first seen 14/02/2026, 2 recorded crawls, last crawled 14/02/2026 by Googlebot, Stale.

See a broken collection page before rankings drop

Theme edits, app installs and URL changes break storefront paths quietly. Status codes are tracked per path and section against your own baseline, so a collection starting to answer Googlebot with 404s is an alert the same hour, with the URLs listed.

5 minDetection cycle on Starter plans and above

Status code detail for 4xx Client Error on shop.example, last 24 hours: Total Requests 3,272, % of All Traffic 9.58%, Unique Codes 4. Individual status codes: 403 2,337, 71.4% of 4xx; 404 896, 27.4% of 4xx; 405 29, 0.9% of 4xx; 499 10, 0.3% of 4xx. Top paths: /products/running-shoes 155, /collections/sale 142, /products/wireless-headphones 119, /collections/all 98, /pages/shipping 90, /products/linen-shirt 42.

How it works

Connect

Point your shop domain at a Cloudflare zone you own (the configuration Shopify officially supports), deploy the Salience Worker on it and set the route's failure mode to Fail open. Guided instructions are in the app, and the setup guide covers the DNS carefully.

We analyse

Every storefront request is classified against the crawler registry, verified against published provider ranges, grouped by URL section and compared with your own history, sitemap and robots.txt.

Get answers

Dashboards, alerts by email, Slack or webhook, plain-English querying, an API and a CLI. Nothing is installed in your Shopify admin or your theme.

Specification

Collection method
Your own Cloudflare zone in front of the storefront, via Shopify's Orange-to-Orange support
Data freshness
Within seconds
Typical setup time
Roughly 30–60 minutes, mostly DNS and Cloudflare setup
Plan requirement
A Shopify plan on a custom domain you control, plus a free Cloudflare plan. No app, no plan change
Permissions needed
Control of your domain's DNS and a Cloudflare account you own
Code or DNS changes
DNS only: your shop domain moves behind Cloudflare. No theme or code changes
Historical import
No. Shopify exposes no historical server logs; history builds from connection
Key limitation
The /checkout path cannot be monitored: Shopify disables Cloudflare Workers and Snippets there. This is storefront monitoring: no checkout, payment, transaction or conversion visibility, and no access to Shopify's origin logs.

Doesn't Shopify Analytics already cover this?

For its purpose, thoroughly, and it is genuinely good at that purpose. Shopify Analytics, Live View and the reports give you sessions, conversion, revenue by channel and real-time order activity, which is exactly what you want when the question is about shoppers. The difference is not quality, it is physics: those tools are built on JavaScript running in a browser, and the traffic this page is about does not run JavaScript. A scraper, a crawler or an AI agent fetches your page, takes the HTML and leaves. Nothing in a browser-based tool ever knows it happened.

Shoppers, sessions and conversion

Shopify Analytics
Its core purpose, and the right tool
Salience
Not attempted: Salience does not measure shoppers

Bots, crawlers and scrapers

Shopify Analytics
Invisible: they do not execute theme JavaScript
Salience
Every request recorded and classified

Bot identity verified against published ranges

Shopify Analytics
Out of scope
Salience
Included, across 200+ crawler identities

Search crawler behaviour and crawl waste

Shopify Analytics
Not available
Salience
By section and URL pattern, joined to your sitemap

AI crawler activity

Shopify Analytics
Not available
Salience
Training, AI-search and user-triggered retrieval, separated

Error and status monitoring per path

Shopify Analytics
Not available
Salience
Against your own baseline, alerted in minutes

Checkout, payment and order data

Shopify Analytics
Yours, in full
Salience
Never visible: Shopify disables Workers on /checkout

When the native tooling is all you need

If your question is about shoppers (how many, from where, what they bought, what it was worth), Shopify Analytics is the correct answer and Salience adds nothing. We do not see checkout, orders or revenue, and we do not want to. Salience is for the other half of your traffic: the automated half your analytics cannot record.

Facts about the integration

No merchant logos and no five-star quotes on this page. These are properties of the product you can check on the free tier in an afternoon.

200+Crawler identities in the registry
16Alert detectors on your stream
5 minDetection cycle, Starter and above
SecondsFrom storefront request to visible

Illustrative, not a customer incident

A single datacentre address works through /collections/* and /products/* overnight, one request every two seconds, rotating four browser user agents and never once loading an image or a script. Shopify Analytics records none of it, because nothing executed the theme's JavaScript. Salience records all of it, names the address and the paths, and the merchant decides whether to rate-limit it at their own Cloudflare edge.

Everything included

One connection, one request stream. No per-feature setup and no second pipeline to maintain.

Verified bot and AI crawler identities

Claimed identities checked against official IP ranges where providers publish them; anything unverifiable is marked unverified rather than guessed at.

Scraper and automation patterns

Systematic catalogue traversal, user-agent rotation and unusual request timing surfaced with the addresses and paths responsible.

Collections, products and pages separately

Products, collections, search, blog, sitemap and robots.txt tracked as their own areas, so a problem lands with the section named.

Crawl budget and coverage

Which product and collection URLs Googlebot actually reaches, which it never has, and where its time is being wasted.

Error and status monitoring

2xx through 5xx per path, with spike detection against your own baseline rather than a fixed threshold.

Alert detectors on a five-minute cycle

Each alert names the affected addresses, user agents and paths, and carries a written triage note with a recommended next step.

Sitemap and robots.txt context

Fetched and diffed daily, correlated with crawl activity, so a coverage change links back to the edit behind it.

Alerts by email, Slack and webhook

Dashboards, email and Slack alerts, webhooks, a public API, a CLI, an MCP server, CSV exports and shared read-only dashboards.

Recommendations with a rule for your Cloudflare WAF

Addresses to block and fake crawler user agents, scored from the last 30 days of alerts, with a WAF custom-rule expression generated from the list and ready to paste.

Products, collections and search as segments

A one-click library saves products, categories, search results, pagination and parameter URLs as segments, applied to all history and used in every report, alert and export.

Site checks every night

Twenty-one checks on crawler access, security hygiene and serving quality, each pass, warn or fail with the evidence, 30 days of history and an alert when a verdict changes.

Weekly report and daily digest

A weekly email report per site, a daily digest of lower-severity alerts, and email for anything above the severity you set.

Which products AI assistants send shoppers to

Shoppers arriving from ChatGPT, Perplexity, Claude, Gemini or Copilot are counted per landing product, with each AI company's fetches set against the shoppers it sent back.

Trust & data protection

Privacy and data protection

You are the controller

We process only on your instructions. GDPR Art. 28 DPA on every account, nothing to sign.

UK data residency

AWS eu-west-2 (London). Encrypted in transit (TLS 1.2+) and at rest (AES-256).

Server-side collection

No browser tracking script and no client-side pixel.

No sale, no pooling

Your logs are never sold, never used for advertising, never shared between customers. DPA, sub-processor list and security overview available.

What is collected

  • Timestamp, method, host and path
  • Status code and response size
  • Client address and user agent
  • Referrer, country and cache status

What is never collected

  • Anything on /checkout
  • Payment, transaction and conversion data
  • Shopify's own origin logs

Priced on requests, not seats, and the Cloudflare zone you need is free. Start on the free tier with 500,000 requests a month and upgrade when your store traffic does.

Crawler intelligence from $19/mo.

Priced on requests, not seats. Unlimited users on every plan except Solo. Start on the free tier and upgrade when your traffic does. Free trial, no card needed.

Prices in
Free$0
  • 500K requests/mo
  • 1 site
  • 30 days history
  • Unlimited users
  • Real-time analytics, bot and AI detection
Solo$19/mo
  • 5M requests/mo
  • 1 site (+2)
  • 6 months history
  • 1 seat
  • Sitemap and Search Console
Starter$49/mo
  • 20M requests/mo
  • 5 sites (+5)
  • 1 year history
  • Unlimited users
  • Real-time analytics with bot and AI-crawler verification
GrowthPopular$149/mo
  • 100M requests/mo
  • 15 sites (+15)
  • 2 years history
  • Unlimited users
  • AI allowance: ~600 answers or ~60 reports a month
Pro$499/mo
  • 500M requests/mo
  • 50 sites, no ceiling
  • 4 years history
  • Unlimited users
  • AI allowance: ~3,000 answers or ~300 reports a month
EnterpriseTalk to us
  • 1B requests/mo
  • Unlimited sites
  • Custom history
  • Unlimited users
  • SSO / SAML and audit log

Common questions

Can Shopify merchants access server logs at all?

Not from Shopify. Shopify runs the origin servers and no plan tier, app or API exposes raw access logs to merchants. This is one of the most-asked questions in the Shopify forums and the answer has always been no. What you can observe is every request to your own custom domain, by routing it through a Cloudflare zone you own, which Shopify officially supports.

Why can't you monitor checkout?

Shopify disables Cloudflare Workers and Snippets on the /checkout path, so no Worker, ours or anyone's, runs there. That means no checkout, payment, transaction or conversion visibility from Salience. It is a hard platform limit, we state it plainly, and Shopify's own reporting remains the right place for that data.

Do I need a Shopify app, or a plan upgrade?

Neither. There is no Shopify app to install, no theme edit, no code change and no Shopify plan requirement. What you need is a custom domain you control and a Cloudflare account, which is free at the tier required. The Workers Free plan caps logging at 100,000 Worker requests a day across the account; Workers Paid, $5 a month, includes 10 million requests and removes the daily cap.

Will this slow my storefront down or affect SEO?

Your shopper's response is never held while data is sent to Salience. Traffic continues to be served by Shopify exactly as before; your Cloudflare zone simply sits in front of it, which is a configuration Shopify supports and documents.

What does the Cloudflare free plan allow?

The zone itself is free. The Worker that collects the logs runs under Cloudflare's Workers Free plan, which allows 100,000 Worker requests a day across your whole Cloudflare account, resetting at 00:00 UTC. The Worker runs once for every request to your shop domain, including product images, theme scripts and bot traffic, so a busy store can use the allowance in a few hours. When it runs out, Cloudflare stops running the Worker until midnight and Salience stops receiving logs for the rest of the day; the store keeps serving as long as the route is set to Fail open. Workers Paid, $5 a month, includes 10 million requests and removes the daily cap (developers.cloudflare.com/workers/platform/pricing/).

Can this take my store down?

Not if every route the Worker is on has its failure mode set to Fail open, which is why the setup asks you to check it. Fail open means that if the Worker cannot run, because the daily allowance is used up or it errors, Cloudflare passes the request straight through to Shopify, so your store can never go down because of this Worker. Fail closed would return errors instead. The setting is in your Cloudflare account under Workers & Pages, then the Worker, then Settings, then Domains & Routes: edit each route and set Failure mode.

How long does setup take, and do I need a developer?

Around 30 to 60 minutes, most of it DNS and Cloudflare configuration rather than anything Shopify-specific. It is well within the reach of anyone comfortable editing DNS records; if that is not you, the work can be delegated from inside Salience without sharing your account.

Is this safe to do to a live store?

It is a supported Shopify configuration, but it is still a DNS change to a revenue-critical domain, so treat it as one. The setup guide covers the precautions that matter (chiefly leaving mail records unproxied and checking your HTTPS settings before you switch), and the change is reversible at any point.

How is this different from a bot-blocking app?

Blocking apps act; Salience explains. We identify and evidence automated traffic (addresses, user agents, paths, verification status) and recommend what to do. Enforcement happens in your own Cloudflare rules, where you stay in control and keep one place to audit.

What happens to our data, and where is it stored?

You are the controller; Salience processes only on your instructions under a GDPR Art. 28 DPA that applies to every account. Data is stored encrypted in AWS eu-west-2 (London), never sold, never used for advertising and never pooled between customers.

Can we see data from before we connected?

No. Shopify exposes no historical server logs to import, so a storefront's history in Salience begins at connection. If you also run servers of your own, their historical Apache, Nginx or CloudFront logs can be imported alongside.

Can we remove it later?

Yes, at any time and from your side alone. Remove the Worker route and collection stops immediately; revert the DNS and your domain leaves your Cloudflare zone entirely. Nothing in your Shopify account was ever changed.

Your logs already show what Google and the AI crawlers are doing.

Any Shopify plan, through a Cloudflare account you own. No app, no theme change and no code change.