Use Simple Log Service for KMS
This topic describes how to enable Simple Log Service and how to query and analyze logs.
Enable Simple Log Service
You can enable Simple Log Service for KMS when purchasing a KMS instance. For more information, see Purchase and enable a KMS instance. You can also enable it after purchase by following these steps:
Log on to the Key Management Service console. In the top navigation bar, select a region. In the left-side navigation pane, choose .
-
After you select an instance ID, click Buy Now. Set Log Analysis to Enable and select a log storage capacity.
-
Read and select Terms of Service, click Buy Now, and complete the payment.
Authorization and Logstore creation
After you enable the feature, the system automatically performs the following operations:
-
Resource Access Management (RAM) automatically creates the service-linked role
AliyunServiceRoleForSLSSecurityLens, which authorizes Simple Log Service to access KMS resources. -
Simple Log Service automatically creates a dedicated project named
kms-log-{KMS instance ID}for the KMS instance. You can view the project on the homepage of the Simple Log Service console. A dedicated Logstore namedkms_audit_logis created in the project to manage the log data of the KMS instance.
Query and analyze logs
-
On the Simple Log Service for KMS page, select an instance ID.
-
(Optional) Enter a key ID, secret ID, HTTP status code, request ID, or gateway type. Then, click Search to query logs by the specified filter conditions.
-
Set a query time range.
Note-
Only logs within the configured retention period can be queried.
-
Query results may include logs generated up to 1 minute before or after the specified time range.
-
-
Enter a query statement in the search box and click Search & Analyze. For more information, see Log search overview and Overview of log query and analysis.
Note-
Query and analysis operations do not incur additional fees.
-
You can also configure alert rules based on query charts in dashboards to monitor the service status in real time. For more information, see Configure an alert monitoring rule.
-
Increase log storage capacity
Log storage capacity can only be increased. After you increase the capacity, you cannot downgrade the capacity.
Log on to the Key Management Service console. In the top navigation bar, select a region. In the left-side navigation pane, choose .
-
Find the target KMS instance and click Upgrade in the Actions column.
-
In the Upgrade panel, set Log Storage Capacity, read and select Terms of Service.
-
Click Buy Now and complete the payment.
Log storage duration
After you enable Simple Log Service, logs are rolled over based on the configured retention period T starting from the first day of use. The logs generated on day T+1 overwrite the logs stored on day 1. In other words, logs from the most recent T days are always retained.
If the log storage capacity is full before the logs for T days are stored, new logs are no longer stored. In this case, you must increase the log storage capacity.
Extend log retention period
You can only extend the log retention period. After the retention period is extended, it cannot be shortened.
-
Log on to the . In the top navigation bar, select a region. In the left-side navigation pane, choose .
-
Find the target KMS instance and click Modify Retention Period.
-
The system displays the allowed range below the text box based on the current actual log retention period of the instance.
-
Enter a new retention period within the allowed range, and then click OK.
Enable shared gateway log delivery
When you access a KMS instance through a shared gateway, the invocation logs on the shared gateway side are delivered to the Logstore of the instance only after you enable shared gateway log delivery. After this feature is enabled, it cannot be disabled.
-
Log on to the . In the top navigation bar, select a region. In the left-side navigation pane, choose .
-
Find the target KMS instance and click Enable Shared Gateway Log Forwarding.
-
In the dialog box that appears, click Enable.
FAQ
-
How do I renew Simple Log Service for KMS?
Simple Log Service for KMS cannot be renewed separately. It is renewed together with your KMS instance. For more information, see Billing.
-
The "Current instance version is too low" message appears and I cannot use Simple Log Service. What do I do?
Contact Alibaba Cloud technical support to upgrade your KMS instance. Otherwise, you cannot use Simple Log Service.