首页 Change the billing method of log analysis from subscription to pay-as-you-go

Change the billing method of log analysis from subscription to pay-as-you-go

更新时间: 2026-05-14 16:32:40

To enable dynamic scaling of log storage during log analysis and enable custom configuration of storage periods for different types of logs, Security Center provides the pay-as-you-go billing method for log analysis. When you use the pay-as-you-go billing method, you are charged based on the actual usage of log storage. You can also configure custom storage periods for different types of logs. This topic compares the subscription and pay-as-you-go billing methods for log analysis. This topic also describes how to change the billing method from subscription to pay-as-you-go.

Comparison of billing methods

Billing method

Pricing

Advantage

Disadvantage

Log storage description

Subscription

Log analysis is a value-added feature. You must pay for log storage when you purchase the log analysis feature in the Security Center console. Fee = 0.5yuan/GB/month.

The subscription billing method allows you to estimate the log storage that you require in advance and create a budget.

If the log storage is exhausted, subsequent logs cannot be written and log data may be lost.

All logs are stored in the Logstore named sas-log.

Pay-as-you-go

You are charged based on your actual usage of log storage. Your fee is billed to Simple Log Service. For more information, see Pricing of Simple Log Service.

The pay-as-you-go billing method allows you to configure custom storage periods for different types of logs.

You must monitor the usage of log storage to prevent the risks of over budget.

Different types of logs are stored in different Logstores. Each Logstore corresponds to a log type. For more information, see Log storage location.

Precautions

  • You cannot rollback the change operation. After you change the billing method to pay-as-you-go, you cannot change the billing method to subscription.

  • After you change the billing method to pay-as-you-go, new logs are stored by log type, and the log storage of the new logs is billed based on the pay-as-you-go billing method. The subscription billing method is not automatically disabled. Existing logs are still stored, and the log storage of the existing logs is billed based on the subscription billing method.

    • Existing logs cannot be migrated to the log storage that is billed based on the pay-as-you-go billing method. If you no longer require the subscription billing method, you can cancel your subscription and request a refund for the canceled subscription. To request a refund, you must clear the log storage that is billed based on the subscription billing method and downgrade your specifications. For more information, see Cancel the subscription billing method and request a refund. If the log storage that is billed based on the subscription billing method is cleared, you can no longer view relevant log data.

    • If you do not clear the log storage or downgrade your specifications, the two billing methods are used at the same time. The subscription billing method remains in effect until the log storage that you purchase by using this method expires. After you change the billing method to pay-as-you-go, you can no longer view relevant log data stored in the log storage that is billed based on the subscription billing method in the Security Center console. You can view the data only in the Simple Log Service console. For more information about how to view log data, see View the stored log data for which log storage is billed based on the subscription billing method.

Procedure

  1. Visitthe Security Center log pay-as-you-go application page,and log on with your Alibaba Cloud account,complete the applicant information as prompted,clickSubmit

    After you submit the application,Security Center sendsapprovalSMS notification to the mobile phone number that you provided。After you receive the SMS message,proceed to the next step。

    Important

    RAM users are not supported forRAMapplying for log pay-as-you-go,Applications can be submitted only by Alibaba Cloud accounts。

  2. Return to the Security Center console。

  3. Return to the Security Center console。 In the top navigation bar, select the region of the asset that you want to manage. You can select China or Outside China. In the left-side navigation pane, choose Risk Governance > Log Analysis.

    If you have enabled the threat analysis and response feature, choose Agentic SOC > Log Management in the left-side navigation pane. On the Log Management page, click Go to Log Analysis in the upper-right corner.

  4. On the Log Analysis page, move the pointer over the tip icon to the right of Subscription and click Upgrade Now. In the Note message, click OK.

  5. In the Switch to Pay-as-you-go panel, configure the following parameters and click OK.

    Parameter

    Description

    Configuration Mode

    Specify a configuration mode for log storage. Valid values:

    • Quick Configuration: If you select this option, you can specify the same storage period and cold storage settings for all types of logs.

    • Advanced Settings: If you select this option, you must specify whether to store a specified type of log and specify a storage period and cold storage settings for this type of log.

    Region

    Select a region where you want to store the logs from the drop-down list.

    After the billing method is changed to pay-as-you-go, you cannot change the region.

    Data Retention Period

    Specify a storage period for log data. Valid values: 1 to 3000. Unit: days.

    Cold Storage

    Enable or disable cold storage. After you enable cold storage, you must specify a storage period for hot storage. You must set the hot storage period to a value that is greater than or equal to seven days and less than the value of Data Retention Period.

    If a log is stored longer than the specified storage period for hot storage, the log is moved to cold storage, and you are charged for the usage of the cold storage. For more information about the billing of cold storage, see Billable items for pay-by-feature.

Related operations

View the stored log data for which log storage is billed based on the subscription billing method

  1. On the Log Analysis page, move the pointer over the tip icon to the right of Subscription and click Go to View.

  2. View the log data that is stored in the Logstore dedicated to Security Center in the Simple Log Service console.

Disable the subscription billing method and request a refund

If you do not want to retain the log data that is stored based on the subscription billing method, perform the following steps to delete the logs and request a refund:

  1. On the Log Analysis page, move the pointer over the Tip icon to the right of Subscription and click Delete Logs. In the Note message, click OK.

    The system requires approximately 1 to 2 hours to delete the logs. The time varies based on the size of your logs.

  2. After the log are deleted, go to the Log Analysis page, move the pointer over the Tip icon to the right of Subscription, and then click Refund After Downgrade.

  3. On the Downgrade page, set Log Analysis to 0, read and select Security Center Terms of Service, and then click Buy Now.

    The refund amount for the canceled subscription that is displayed on the Downgrade page shall prevail.

    After you request a refund, you cannot view the information about the subscription billing method on the Log Analysis page.

Disable the pay-as-you-go billing method

If you want to disable the pay-as-you-go billing method, log on to the Simple Log Service console to delete the Logstore that is dedicated to Security Center. For more information, see Stop billing or delete a logstore. For more information about the Logstores that are used in the pay-as-you-go billing method, see Log storage location.

Log storage location

If you change the billing method of log analysis to pay-as-you-go, Simple Log Service automatically creates Logstores for Security Center by log type. The following table describes the Logstore for each type of log. To navigate to the Logstore that stores logs, click Advanced Management of Simple Log Service in the upper-right corner of the Log Analysis page of the Security Center console.

Log type

Log sub-type

Logstore

Host Logs

Brute Force

aegis-log-crack

Login

aegis-log-login

Network

aegis-log-network

Process

aegis-log-process

Account Snapshot

aegis-snapshot-host

Port Snapshot

aegis-snapshot-port

Process Snapshot

aegis-snapshot-process

DNS Requests

aegis-log-dns-query

Client Events

aegis-log-client

Security Logs

Baseline

sas-security-log

Alert

Vulnerability

Configuration Assessment

Network Protection

Application Protection

Malicious File Detection

Network Logs

(No longer supported)

Session

sas-log-session

Local DNS

local-dns

DNS

sas-log-dns

Access Log

sas-log-http

阿里云首页 云安全中心 相关技术圈