SAG-1000 devices support the flow log feature. Flow logs capture information about the inbound and outbound traffic of SAG-1000 devices to help you monitor network traffic and troubleshoot network issues. To capture traffic, you must first create a flow log.
Prerequisites
-
If you want to store flow logs in Simple Log Service (SLS), make sure that:
-
Simple Log Service is activated. For more information, see the Simple Log Service product page.
-
You have created a project and a Logstore. For more information, see Manage projects and Create a basic Logstore.
-
-
If you plan to use a NetFlow collector, ensure the SAG device can reach it over the network.
-
When you create a flow log for the first time, you must click Flow Log on the Authorize Now page. You are then redirected to the Resource Access Management (RAM) console to grant SAG access to SLS by assigning it the AliyunVPCLogArchiveRole.
Procedure
-
Log on to the Smart Access Gateway console.
-
In the top navigation bar, select a region.
-
In the left-side navigation pane, choose Flow Log. On the Flow Log page, click Create Flow Log.
-
In the Create Flow Log panel, configure the following parameters and click OK.
You can store captured traffic data in a Simple Log Service Logstore, on your NetFlow collector, or both. The following table describes the parameters.
Parameter
Description
Resource Group
Select a resource group for the flow log.
Name
Enter a name for the flow log.
Output Interval Under Active Connections
The interval, in seconds, for exporting flow logs from active connections. Valid values: 60 to 6000. Default: 300.
Output Interval Under Inactive Connections
The interval, in seconds, for exporting flow logs from inactive connections. Valid values: 10 to 600. Default: 15.
Deliver Flow Log Data To
Configure the parameters based on your selected storage destination.
-
To store log data in Simple Log Service, select SLS and configure the following parameters.
-
SLS region: The region where the Simple Log Service project resides.
-
SLS project: The project to which the Logstore belongs.
-
SLS Logstore: The Logstore that stores flow log data.
-
-
To store log data on your NetFlow collector, select Netflow and configure the following parameters.
-
NetFlow Collector Address: The IP address of the NetFlow collector. For example, 192.168.0.2.
-
NetFlow Collector Port: The port used by the NetFlow collector. The default value is 9995.
-
NetFlow Version: The version of the NetFlow protocol. Valid values: V5, V9, and V10. The default value is V9.
-
-
To store log data in both destinations, select ALL and then configure the parameters for both SLS and NetFlow.
-