Some CT log lookups may take 24H to show a cert (or sometimes longer). I don't see it in censys.io either but your Entrust tool does show a new cert which looks valid.
But, that's only part of the "renewal". The other is that your webserver (or other service) is using the new cert. I can't test this because your Origin Server is behind Cloudflare CDN.
But, you should be able to test this because you know the Origin Server IP and maybe even have a DNS name to talk to it directly.
In fact, checking the cert your Origin Server is using is more reliable than using the CT logs