[Notice] updates on log analysis and CTDR features
Dear Alibaba Cloud users,
To improve our security services, Security Center will update the log analysis and Cloud Threat Detection and Response (CTDR) features on March 27, 2025, UTC+8.
Update details
-
Log Analysis
-
Starting March 27, 2025, the log analysis feature no longer supports the delivery of network logs, including web access logs, DNS logs, network session logs, and local DNS logs.
-
If you have activated network log delivery, the delivery will stop on March 27, 2025. New network log data will not be delivered, but previously delivered data will be preserved and remain available for queries.
-
-
CTDR
-
Starting March 27, 2025, the CTDR feature no longer supports adding DNS logs, web access logs, network session logs, and failed MySQL/FTP logon logs.
-
From March 27, 2025, log management in CTDR no longer supports the delivery of the aforementioned network logs.
-
If you have enabled log management for delivering network logs before this date, the delivery will stop on March 27, 2025. New network log data will not be delivered, but previously delivered data will be preserved and remain available for queries.
-
Update impacts
Effective March 27, 2025, Security Center will discontinue support for network log delivery. This update applies exclusively to Security Center Enterprise and Ultimate. If you require network log delivery, see the alternative solutions below.
Alternative solutions for adding or delivering network logs
Security Center provides alternative solutions for each type of network log. Select the option that best fits your needs.
DNS logs
-
Security Center Log Analysis Feature
Utilize the DNS Request log feature provided by Security Center. For more information, see DNS Request Log.
Note-
DNS request logs do not support recording DNS requests within containers.
-
For Linux servers, only systems with a kernel version of 4.X.X or higher are supported.
-
For Windows servers, only Windows Server 2012 and later versions are supported.
-
-
Network Detection and Response (NDR) Product
Activate the delivery of DNS Logs. For more information, see Enable Log Delivery Capability.
Web access logs
-
Cloud Firewall and Web Application Firewall
-
Cloud Firewall: Enable the NAT border firewall and log analysis features to collect and store web server request logs. For more information, see NAT Border Firewall.
-
Web Application Firewall (WAF): Enable the WAF log service to collect and store web server response logs. For more information, see Log Field Description.
-
-
Network Detection and Response (NDR) Product
Activate the delivery of HTTP Logs. For more information, see Enable Log Delivery Capability.
Network session logs
-
Security Center Log Analysis Feature
Use the Network Connectivity and Network Snapshot log features provided by Security Center. For more information, see Network Connectivity Log and Network Snapshot Log.
NoteNetwork connectivity logs capture all outbound network requests and successful connection requests. Security Center records network connectivity data on servers in real time. An outbound connection (connect) call triggers a record, and an inbound connection (accept) is recorded upon success.
-
Network Detection and Response (NDR) Product
Enable the delivery of 5-tuple Logs. For more information, see Enable Log Delivery Capability.
Local DNS logs
-
Security Center Log Analysis Feature
Utilize the DNS Request log feature provided by Security Center. For more information, see DNS Request Log.
Note-
DNS request logs do not support recording DNS requests within containers.
-
For Linux servers, only systems with a kernel version of 4.X.X or higher are supported.
-
For Windows servers, only Windows Server 2012 and later versions are supported.
-
-
Alibaba Cloud DNS
Failed MySQL/FTP logon logs
No alternative solution is available at this time. If you need this type of log, submit an inquiry through the Network Detection and Response (NDR) product.