Configure a Simple Log Service Project and Logstore to receive resource change logs, resource non-compliance events, compliance snapshots, and scheduled resource snapshots for querying and analysis.
Prerequisites
-
Simple Log Service is activated. Activate Simple Log Service.
ImportantActivating Simple Log Service is free. Charges apply when Cloud Config delivers resource data to Simple Log Service and when you query and analyze logs. Billing overview.
-
To deliver large files to a bucket in Object Storage Service (OSS), activate OSS and create a bucket. For more information, see Console quick start.
NoteEnsure that the specified Region, Account, and Bucket Name for the large file recipient address match those of the regular file delivery address.
Background
Deleting the Project invalidates the delivery task in Cloud Config and stops data delivery. For more information, see Manage a Project.
Procedure
Log on to the Cloud Config console.
Optional. In the upper-left corner, select an account group.
This operation is required only if you are using a management account of a resource directory. Otherwise, you do not need to perform the operation.
In the left-side navigation pane, click .
-
On the Deliveries page, click Create Delivery in the upper-left corner.
-
On the Create Delivery page, enter a Delivery Name, set Channel Type to Log Service, and then configure the related parameters for Simple Log Service.
The following table describes the delivery parameters.
-
Historical Configuration Changes: Cloud Config delivers a resource change log to Simple Log Service when a resource configuration changes.
-
Non-compliance Events: Cloud Config delivers a resource non-compliance event to Simple Log Service when a resource is evaluated as non-compliant.
-
Scheduled Snapshots: By default, Cloud Config delivers scheduled resource snapshots to Simple Log Service at 00:00:00 and 12:00:00 every day.
-
Compliance Snapshot: By default, Cloud Config delivers compliance snapshots to Simple Log Service at 00:00:00 and 12:00:00 every day.
-
Create a new log item in this account.: In the Cloud Config console, select a region, and then create a Project and a Logstore. The Project name and Logstore name must be unique within the same account and region.
NoteA Logstore created through Cloud Config has no pre-configured indexes. To analyze the delivered data, you must enable indexing for the Logstore in the Simple Log Service console. For more information, see Create an index.
-
Select an existing log item in this account.: In Simple Log Service, select an existing region, Project, and Logstore.
NoteEnsure that the selected Logstore is empty or contains only data consistent with the data to be delivered. Otherwise, you cannot query and analyze the delivered data.
-
Select an existing topic from other enterprise management accounts or delegated accounts (available only for a management account or delegated administrator account): Specify the Alibaba Cloud Resource Name (ARN) of the Logstore in the destination account. The ARN includes the Region, Members, Project Name, and Logstore Name.
Member accounts cannot configure data delivery and must follow the settings specified by the management account.
NoteIf the management account has configured a delegated administrator account for Cloud Config, the delegated administrator account can configure data delivery on behalf of the management account. For more information about how to add a delegated administrator account, see Add a delegated administrator account.
-
If set, files larger than 1 MB are automatically transferred to the specified Object Storage Service (OSS) bucket.
-
If not set, files larger than 1 MB are discarded.
Parameter
Description
Content
Select the resource data to deliver to Simple Log Service. Valid values:
NoteIf you set Daily Delivery Time, Cloud Config delivers data at the specified time.
Logstore Source
The source of the Project in Simple Log Service. Valid values:
Events of Specified Resource Type
The resource types for data delivery. For a list of resource types supported by Cloud Config, see Supported resource types and resource relationships.
Daily Delivery Time
The time of day to deliver scheduled resource snapshots and/or compliance snapshots.
NoteIf you do not set this parameter, Cloud Config delivers data at 00:00:00 and 12:00:00 by default.
Recipient Address For Large Files
The destination for large files delivered to Simple Log Service.
-
-
Click OK.
-
(Optional) In the Confirm Operation dialog box, click OK.
This operation is required only if you are using a management account of a resource directory. Otherwise, you do not need to perform the operation.
NoteThe new delivery applies only to all members in the current account group.
Next steps
View the delivery results, then query and analyze the data.
-
On the Deliveries page, click the ID of the delivery you created.
-
On the delivery details page, find Logstore Name in the Extended Information section and click the Logstore name to open it in the Simple Log Service console.
-
In the Error dialog box, click Close. This error code
IndexConfigNotExistindicates that indexing is not enabled for the Logstore.NoteLogstores created from Cloud Config do not have indexing enabled by default.
-
Enable indexing for the Logstore.
-
Query and analyze the logs in the Logstore.
For more information, see Quick start for query and analysis.
NoteFor sample files in JSON format, see Sample resource change log, Sample resource non-compliance event, and Sample scheduled resource snapshot.