Change the billing method of log analysis from subscription to pay-as-you-go
To enable dynamic scaling of log storage during log analysis and enable custom configuration of storage periods for different types of logs, Security Center provides the pay-as-you-go billing method for log analysis. When you use the pay-as-you-go billing method, you are charged based on the actual usage of log storage. You can also configure custom storage periods for different types of logs. This topic compares the subscription and pay-as-you-go billing methods for log analysis. This topic also describes how to change the billing method from subscription to pay-as-you-go.
Comparison of billing methods
|
Billing method |
Pricing |
Advantage |
Disadvantage |
Log storage description |
|
Subscription |
Log analysis is a value-added feature. You must pay for log storage when you purchase the log analysis feature in the Security Center console. Fee = 0.5yuan/GB/month. |
The subscription billing method allows you to estimate the log storage that you require in advance and create a budget. |
If the log storage is exhausted, subsequent logs cannot be written and log data may be lost. |
All logs are stored in the Logstore named sas-log. |
|
Pay-as-you-go |
You are charged based on your actual usage of log storage. Your fee is billed to Simple Log Service. For more information, see Pricing of Simple Log Service. |
The pay-as-you-go billing method allows you to configure custom storage periods for different types of logs. |
You must monitor the usage of log storage to prevent the risks of over budget. |
Different types of logs are stored in different Logstores. Each Logstore corresponds to a log type. For more information, see Log storage location. |
Precautions
-
You cannot rollback the change operation. After you change the billing method to pay-as-you-go, you cannot change the billing method to subscription.
-
After you change the billing method to pay-as-you-go, new logs are stored by log type, and the log storage of the new logs is billed based on the pay-as-you-go billing method. The subscription billing method is not automatically disabled. Existing logs are still stored, and the log storage of the existing logs is billed based on the subscription billing method.
-
Existing logs cannot be migrated to the log storage that is billed based on the pay-as-you-go billing method. If you no longer require the subscription billing method, you can cancel your subscription and request a refund for the canceled subscription. To request a refund, you must clear the log storage that is billed based on the subscription billing method and downgrade your specifications. For more information, see Cancel the subscription billing method and request a refund. If the log storage that is billed based on the subscription billing method is cleared, you can no longer view relevant log data.
-
If you do not clear the log storage or downgrade your specifications, the two billing methods are used at the same time. The subscription billing method remains in effect until the log storage that you purchase by using this method expires. After you change the billing method to pay-as-you-go, you can no longer view relevant log data stored in the log storage that is billed based on the subscription billing method in the Security Center console. You can view the data only in the Simple Log Service console. For more information about how to view log data, see View the stored log data for which log storage is billed based on the subscription billing method.
-
Procedure
-
Visitthe Security Center log pay-as-you-go application page,and log on with your Alibaba Cloud account,complete the applicant information as prompted,clickSubmit。
After you submit the application,Security Center sendsapprovalSMS notification to the mobile phone number that you provided。After you receive the SMS message,proceed to the next step。
ImportantRAM users are not supported forRAMapplying for log pay-as-you-go,Applications can be submitted only by Alibaba Cloud accounts。
-
Return to the Security Center console。
-
Return to the Security Center console。 In the top navigation bar, select the region of the asset that you want to manage. You can select China or Outside China. In the left-side navigation pane, choose .
If you have enabled the threat analysis and response feature, choose in the left-side navigation pane. On the Log Management page, click Go to Log Analysis in the upper-right corner.
-
On the Log Analysis page, move the pointer over the
icon to the right of Subscription and click Upgrade Now. In the Note message, click OK. -
In the Switch to Pay-as-you-go panel, configure the following parameters and click OK.
Parameter
Description
Configuration Mode
Specify a configuration mode for log storage. Valid values:
-
Quick Configuration: If you select this option, you can specify the same storage period and cold storage settings for all types of logs.
-
Advanced Settings: If you select this option, you must specify whether to store a specified type of log and specify a storage period and cold storage settings for this type of log.
Region
Select a region where you want to store the logs from the drop-down list.
After the billing method is changed to pay-as-you-go, you cannot change the region.
Data Retention Period
Specify a storage period for log data. Valid values: 1 to 3000. Unit: days.
Cold Storage
Enable or disable cold storage. After you enable cold storage, you must specify a storage period for hot storage. You must set the hot storage period to a value that is greater than or equal to seven days and less than the value of Data Retention Period.
If a log is stored longer than the specified storage period for hot storage, the log is moved to cold storage, and you are charged for the usage of the cold storage. For more information about the billing of cold storage, see Billable items for pay-by-feature.
-
Related operations
View the stored log data for which log storage is billed based on the subscription billing method
-
On the Log Analysis page, move the pointer over the
icon to the right of Subscription and click Go to View. -
View the log data that is stored in the Logstore dedicated to Security Center in the Simple Log Service console.
Disable the subscription billing method and request a refund
If you do not want to retain the log data that is stored based on the subscription billing method, perform the following steps to delete the logs and request a refund:
-
On the Log Analysis page, move the pointer over the
icon to the right of Subscription and click Delete Logs. In the Note message, click OK. The system requires approximately 1 to 2 hours to delete the logs. The time varies based on the size of your logs.
-
After the log are deleted, go to the Log Analysis page, move the pointer over the
icon to the right of Subscription, and then click Refund After Downgrade. -
On the Downgrade page, set Log Analysis to 0, read and select Security Center Terms of Service, and then click Buy Now.
The refund amount for the canceled subscription that is displayed on the Downgrade page shall prevail.
After you request a refund, you cannot view the information about the subscription billing method on the Log Analysis page.
Disable the pay-as-you-go billing method
If you want to disable the pay-as-you-go billing method, log on to the Simple Log Service console to delete the Logstore that is dedicated to Security Center. For more information, see Stop billing or delete a logstore. For more information about the Logstores that are used in the pay-as-you-go billing method, see Log storage location.
Log storage location
If you change the billing method of log analysis to pay-as-you-go, Simple Log Service automatically creates Logstores for Security Center by log type. The following table describes the Logstore for each type of log. To navigate to the Logstore that stores logs, click Advanced Management of Simple Log Service in the upper-right corner of the Log Analysis page of the Security Center console.
|
Log type |
Log sub-type |
Logstore |
|
Host Logs |
Brute Force |
aegis-log-crack |
|
Login |
aegis-log-login |
|
|
Network |
aegis-log-network |
|
|
Process |
aegis-log-process |
|
|
Account Snapshot |
aegis-snapshot-host |
|
|
Port Snapshot |
aegis-snapshot-port |
|
|
Process Snapshot |
aegis-snapshot-process |
|
|
DNS Requests |
aegis-log-dns-query |
|
|
Client Events |
aegis-log-client |
|
|
Security Logs |
Baseline |
sas-security-log |
|
Alert |
||
|
Vulnerability |
||
|
Configuration Assessment |
||
|
Network Protection |
||
|
Application Protection |
||
|
Malicious File Detection |
||
|
Network Logs (No longer supported) |
Session |
sas-log-session |
|
Local DNS |
local-dns |
|
|
DNS |
sas-log-dns |
|
|
Access Log |
sas-log-http |