Engineering teams managing high-volume CDN logs face a cost-retention tradeoff: indexing everything is expensive, but archiving to object storage fragments investigations across tools. Datadog's Observability Pipelines can process and route raw CDN edge logs to low-cost object storage while forwarding key metrics and high-signal events to Datadog for monitoring. Archive Search then lets teams query those archived logs directly from Datadog using familiar syntax, access controls, and facets — without switching to a separate analytics environment. The workflow supports PII redaction before logs leave your environment, metric generation in transit, multi-CDN normalization via prebuilt pipeline packs for Cloudflare and Akamai, and partition-based scan optimization to reduce query costs. A concrete example shows scanning 751 GB of archived data to isolate 242 relevant WAF block events during a live streaming incident.