Log management

更新时间:
复制 MD 格式

Without centralized log storage, security teams must manually correlate alerts across disparate sources, making compliance auditing and threat investigation time-consuming. When you need centralized security log storage for compliance auditing, threat investigation, or log archival, use Log Management to store, query, and analyze Security Center logs from a single place.

Log types

Security Center supports two categories of logs with different operational purposes:

  • Security Center logs are raw logs generated by Security Center modules — including vulnerability scans, security alerts, and client events. Use these for real-time alert investigation and day-to-day operational queries. Requires enabling Log Management.

  • Standardized logs are logs that Agentic SOC normalizes into a common schema after ingesting traffic from connected sources. Use these for cross-source correlation, custom detection rules, and compliance archiving. Requires enabling both Log Management and Agentic SOC.

The following table summarizes the data sources and field references for each log type.

Log type

Data source

Field reference

Security Center logs

Vulnerability logs, security alert logs, and client event logs generated by Security Center modules

Log categories and field descriptions

Standardized logs

Logs normalized from Agentic SOC ingestion traffic (Real-time Consumption) and custom rules (endpoint detection and response (EDR) alert logs, firewall alert logs)

In the Security Center console, go to Agentic SOC > Integration Center. On the Standardized Rule tab, click View Standard Fields to open the Standard Fields panel.

DNS logs

DNS query and response traffic captured from your network environment, including domain name resolution requests and answers

Standardized fields for DNS logs follow the V2 format. See Log format standardization V2 for field descriptions.

Local DNS logs

Internal DNS resolution traffic from your local DNS servers, including recursive queries and cache hits

Standardized fields for Local DNS logs follow the V2 format. See Log format standardization V2 for field descriptions.

Network session logs

Network flow and session data capturing bidirectional communication between endpoints, including connection direction and protocol type

Standardized fields for Network Session logs follow the V2 format. See Log format standardization V2 for field descriptions.

Web logs

HTTP and HTTPS request and response traffic, including URL paths, methods, status codes, and user agents

Standardized fields for Web logs follow the V2 format. See Log format standardization V2 for field descriptions.

Billing

Log Management offers two billing methods. Choose based on how predictable your log volume is:

  • Subscription — best for stable, high-volume environments where you want predictable costs. Priced at USD 100 per 1,000 GB-month. Minimum purchase is 1,000 GB; increments are 1,000 GB.

  • Pay-as-you-go — best for variable or lower-volume environments. Billed daily at USD 7.2 per 1,000 GB based on total daily storage usage.

Important

Pay-as-you-go billing rounds up to the nearest 1,000 GB. For example, 1,900 GB of daily usage is charged as 2,000 GB.

Querying and exporting logs from the Security Center console is free. After Log Management delivers logs to Simple Log Service (SLS), additional SLS fees may apply for data transformation or data shipping:

  • Pay-by-feature Logstore: Data transformation, data shipping, and internet-facing stream reads are charged. See Billable items in the pay-by-feature billing mode.

  • Pay-by-ingested-data Logstore: Data transformation and data shipping are free. Internet read traffic is charged. See Billable items in the pay-by-ingested-data billing mode.

Log storage

When you enable Log Management, Security Center automatically creates a dedicated SLS project named aliyun-cloudsiem-data-<Alibaba Cloud account ID>-<RegionID> and a Logstore to store your logs.

The storage region depends on the region you select in the upper-left corner of the Security Center console:

  • Chinese Mainland — logs are stored in China (Shanghai) by default.

  • Outside Chinese Mainland — logs are stored in the Singapore region by default.

Important

You can change the log storage region only in the dialog box that appears when you enable pay-as-you-go billing. If you purchase on a subscription basis, the region is fixed at purchase time.

You can view the project and Logstore in the Simple Log Service console. Do not delete them.

Once log delivery is active, logs are retained until the configured retention period ends, then automatically deleted. For subscription billing, if storage capacity is exhausted, new log delivery stops. Security Center sends a notification when usage reaches 80% of your purchased capacity. See Notification settings to configure alerts.

Enable or disable Log Management

Prerequisites

  • The current account must have the AliyunSASFullAccess permission or an equivalent RAM policy to manage Log Management.

  • To use standardized logs, both Log Management and Agentic SOC must be enabled.

  • Log storage is available in selected regions only. Check the Log Management page for the list of supported regions.

Enable Log Management

Log Management can be enabled using either the subscription or pay-as-you-go billing method.

  1. Log on to the .

  2. In the left navigation pane, choose Detection and Response > Log Management. In the upper-left corner, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.

    If you have purchased Agentic SOC log ingestion traffic on a subscription basis or enabled pay-as-you-go for Agentic SOC, the navigation entry changes to Agentic SOC > Log Management.
  3. On the Log Management page, click Activate Subscription or Activate Pay-as-you-go.

    • Subscription: On the purchase page, under Agentic SOC, set Purchase or Not to Yes, select the log storage capacity, click Order Now, and complete the payment. See Purchase Security Center for available features and pricing.

    • Pay-as-you-go: In the dialog box, read the billing rules, select a storage region, and click Activate and Authorize.

    If you have already purchased Agentic SOC log ingestion traffic, click Enable Pay-as-you-go for Log Management in the upper-right corner of the page, or upgrade your service to add log storage capacity for Agentic SOC. See Upgrades and downgrades.

After enabling, return to the Log Management page and verify that the service status shows Active and Log Usage displays a non-zero value. Logs should begin appearing in the Log Service Logstore within a few minutes.

Disable Log Management

  1. Log on to the .

  2. In the left navigation pane, choose Agentic SOC > Log Management. In the upper-left corner, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.

    Note

    If the Agentic SOC navigation entry is not visible in the left navigation pane, choose Detection and Response > Log Management instead.

  3. On the Log Management page, verify that Log Usage shows 0 GB. If log usage is not 0, click Delete in the upper-right corner, wait for the logs to be cleared, then continue.

  4. Disable the service based on your billing method:

    • Subscription

      • Method 1 — Downgrade:

        1. On the Overview page, click Change > Downgrade.

        2. On the Order Downgrade tab, set Log Storage Capacity in the Agentic SOC section to 0 GB.

        3. Accept the Security Center Service Agreement and click Order Now.

        4. In the left navigation pane, click Overview to return to the Security Center overview page.

      • Method 2 — Unsubscribe: Submit a to unsubscribe from your Security Center instance.

    • Pay-as-you-go: On the Overview page of the Security Center console, in the Pay-as-you-go section, turn off the Log Management switch.

      Warning

      Turning off the Log Management switch automatically disables log delivery and deletes the corresponding Logstore. Deleted log data cannot be recovered.

Using Agentic SOC log ingestion traffic without log storage capacity

Note

This section covers an edge case scenario. Most users who have purchased log storage capacity can skip this section.

If you have purchased Agentic SOC log ingestion traffic (subscription or pay-as-you-go) but have not purchased log storage capacity, you can query a subset of standardized logs on the Log Management page — specifically, logs from access policies where Standardization Method is set to Scan Query.

In this configuration:

  • Security Center logs cannot be delivered or viewed.

  • Standardized logs from Real-time Consumption access policies cannot be delivered or viewed.

image

For a full comparison of features available under different billing configurations, see Purchase and enable the Agentic SOC feature.

Security Center logs

Enable log delivery

After you purchase log storage capacity, Agentic SOC enables delivery for all Security Center log types by default. If you have not purchased the corresponding value-added services (such as application protection or malicious file detection), the delivery switches for those log types remain disabled.

Click Log Settings on the Log Management page to view and update delivery status for each log type.

image

Query Security Center logs

Log query methods are the same as those in the Log Analysis feature. For more information, see Custom log query and analysis.

  1. In the left navigation pane, choose Agentic SOC > Log Management. In the upper-left corner, select the region where your assets are located.

  2. In the upper-left corner of the Log Management page, click Security Center Logs and select the log type to view.

    image

  3. Set a time range and use search statements to retrieve logs and view analysis results.

Standardized logs

How delivery works

Standardized logs are produced when Agentic SOC normalizes ingested logs into a common schema. Delivery is automatic — you cannot enable or disable it manually. Delivery is triggered in two scenarios:

  • When an access policy's Standardization Method is set to Real-time Consumption, Agentic SOC delivers the normalized logs to the corresponding Logstore, organized by standardized category. A log delivery task is created automatically when you create the access policy.

  • When custom rules generate alert logs (such as EDR alert logs or firewall alert logs), those logs are also delivered automatically.

On the Standardized Log tab of the Log Settings panel, the Number of references column shows how many access policies with Real-time Consumption are associated with each standardized category and structure.

image

Query standardized logs

Agentic SOC supports searching logs by standardized structure and querying across multiple Logstores using datasets (StoreView). For cross-Logstore query and analysis examples, see Common query/analysis result examples.

Network logs

Agentic SOC ingests and normalizes four categories of network logs: DNS logs, Local DNS logs, Network Session logs, and Web logs. Each log type is standardized into a common schema with a dedicated EtlMetaName for identification and routing. All network logs follow the V2 standardized log format.

DNS logs

DNS logs capture DNS query and response traffic from your network environment, including domain name resolution requests, authoritative answers, and resolver behavior. Use these logs to detect domain generation algorithm (DGA) activity, tunneling attempts, and malicious domain resolution.

NDR (Network Detection and Response) and Beaver are two log collection pipelines used by Agentic SOC. When analyzing DNS answer fields, note that NDR and Beaver format responses differently.

Field

Description

Example

query_name

Domain name queried. Mapped from the original qname field.

example.com

query_type

DNS record type queried (A, AAAA, MX, CNAME, TXT, and others).

A

answer

DNS response data. Note: NDR and Beaver differ in answer field formatting. NDR returns the answer field as an array (multiple records), while Beaver returns answers as a semicolon-separated string (;). Normalize accordingly during analysis.

93.184.216.34

rcode

DNS response code (NOERROR, NXDOMAIN, SERVFAIL, and others).

NOERROR

protocol_type

Transport protocol used for the DNS query. The original numeric enum values (0 for UDP, 1 for TCP) are converted to standardized text values: udp and tcp.

udp

EtlMetaName: sas_sas-log-dns_v2

Central repository address: Navigate to Agentic SOC > Integration Center > DNS log source to view the assigned Logstore endpoint.

Note

To deliver DNS logs, create an access policy in the Agentic SOC Integration Center and set the log source type to DNS logs.

Local DNS logs

Local DNS logs capture internal DNS resolution traffic from your local DNS servers, including recursive queries, cache hits, and internal zone lookups. Use these logs to monitor internal DNS health, detect lateral movement via DNS, and audit internal domain resolution patterns.

Field

Description

Example

query_name

Domain name queried by the internal client. Mapped from the original qname field.

internal.corp.local

query_type

DNS record type queried (A, AAAA, PTR, SRV, and others).

PTR

answer

Local DNS response data. The same NDR/Beaver formatting difference applies as described for DNS logs.

10.0.0.5

dns_server_ip

IP address of the local DNS server that processed the query.

10.0.0.2

client_ip

IP address of the client that initiated the DNS query.

10.0.1.15

EtlMetaName: sas_sas-log-localdns_v2

Central repository address: Navigate to Agentic SOC > Integration Center > Local DNS log source to view the assigned Logstore endpoint.

Note

To deliver Local DNS logs, create an access policy in the Agentic SOC Integration Center and set the log source type to Local DNS logs.

Network session logs

Network session logs capture bidirectional communication flows between endpoints, including connection metadata such as source and destination addresses, ports, protocol, session duration, and byte counts. Use these logs for network traffic analysis, anomaly detection, and forensic investigation.

Field

Description

Example

net_connect_dir

Connection direction. Mapped from the original in_out field. Values: in (inbound) or out (outbound).

out

src_ip

Source IP address of the connection.

10.0.1.10

dst_ip

Destination IP address of the connection.

203.0.113.5

dst_port

Destination port number.

443

protocol

Transport layer protocol. Protocol type enum values are converted to lowercase standardized form: tcp, udp, icmp.

tcp

EtlMetaName: sas_sas-log-net-session_v2

Central repository address: Navigate to Agentic SOC > Integration Center > Network Session log source to view the assigned Logstore endpoint.

Note

To deliver Network Session logs, create an access policy in the Agentic SOC Integration Center and set the log source type to Network Session logs.

Web logs

Web logs capture HTTP and HTTPS request and response traffic, including URL paths, request methods, response status codes, user agents, and referer headers. Use these logs to detect web application attacks, monitor API usage patterns, and audit external service access.

Field

Description

Example

http_method

HTTP request method (GET, POST, PUT, DELETE, and others).

POST

url

Requested URL path, including query string.

/api/v1/login?redirect=/dashboard

status_code

HTTP response status code.

200

user_agent

User agent string from the HTTP request header.

Mozilla/5.0 (Windows NT 10.0; Win64; x64)

host

Host header value (domain name or IP with port).

api.example.com:443

EtlMetaName: sas_sas-log-web_v2

Central repository address: Navigate to Agentic SOC > Integration Center > Web log source to view the assigned Logstore endpoint.

Note

To deliver Web logs, create an access policy in the Agentic SOC Integration Center and set the log source type to Web logs.

Configure network log delivery

To ingest and deliver DNS, Local DNS, Network Session, and Web logs, follow these steps:

  1. Enable Log Management. See Enable or disable Log Management.

  2. In Agentic SOC > Integration Center, create an access policy for each log type (DNS, Local DNS, Network Session, or Web).

  3. Verify that logs appear on the Log Management page.

Log storage management

Modify the log retention period

The default retention period for delivered logs is 180 days. Modify it as needed to meet your compliance or cost requirements.

  1. In the left navigation pane, choose Agentic SOC > Log Management. In the upper-left corner, select your region.

  2. In the upper-right corner of the Log Management page, click Log Settings.

  3. On the Security Center Logs or Standardized Log tab, click the image icon in the Log Retention Period column to update the value.

Increase or delete storage capacity

On the Agentic SOC > Log Management page, you can view your current log usage and total purchased capacity.

  • Scale Out: Click Scale Out to purchase additional log storage capacity. When capacity is exhausted, new logs cannot be delivered until more capacity is purchased.

  • Delete: Click Delete to delete all stored logs. The deletion process takes 0–24 hours.

Warning

Cleared logs cannot be restored. Export and back up any logs you need to retain before clearing.

Reduce log delivery volume

If your log storage costs are high, you can reduce the volume of logs delivered to Simple Log Service (SLS) by identifying and disabling log types that are not critical to your security operations.

Security Center delivers multiple categories of host logs to SLS, including logon logs, network connection logs, and process startup logs. When log volume is high — for example, 80 ECS instances can generate 1.7 TB of logs over 30 days — storage costs for long retention periods such as 180 days can become significant.

Step 1: Identify high-volume log types in the SLS console

  1. Log on to the Simple Log Service (SLS) console.

  2. In the left navigation pane, find the Logstore associated with your Security Center project.

  3. Use the __topic__ field to group and compare log volume by log type. The __topic__ field contains the log category identifier, which allows you to view the storage share of each log type.

  4. Identify the log types that consume the most storage. Typical high-volume log types include:

    • Logon logs

    • Network connection logs

    • Process startup logs

Step 2: Disable unnecessary log types in Security Center

  1. Log on to the .

  2. In the left navigation pane, choose Agentic SOC > Log Management.

  3. On the Log Management page, click Log Settings in the upper-right corner.

  4. Based on your analysis from Step 1, locate the log types that generate the most storage volume, and turn off the toggle for each type you want to disable.

Note

After you disable a log type, Security Center stops delivering logs of that type to SLS. Logs that are already stored in SLS are not deleted and remain accessible.

Before disabling a log type, verify that the type is not required for security auditing, compliance, or incident investigation purposes.

FAQ

Why can't I enable pay-as-you-go billing for Log Management?

There are three common reasons:

Reason 1: You have an active subscription for Agentic SOC log storage or log analysis.

Unsubscribe from the existing subscription, then enable pay-as-you-go for Log Management.

Reason 2: Your Agentic SOC feature is on the 1.0 architecture.

image

Upgrade the Agentic SOC feature from 1.0 to 2.0, then enable pay-as-you-go for Log Management.

If you prefer not to upgrade to the 2.0 architecture, you can still use Log Management by purchasing log storage capacity on a subscription basis.

Reason 3: You purchased Agentic SOC log storage on or before April 26, 2024.

After upgrading to the 2.0 architecture, your original subscription capacity is preserved and Log Management continues to work normally. To switch from subscription to pay-as-you-go, follow the steps for Reason 1. For architecture upgrade details, see [Notice] Upgrade of the Agentic SOC feature.

What is the difference between Log Analysis and Log Management?

Both features provide security log query and analysis in Security Center, but they differ in scope and flexibility.

Feature

Supported log types

Billing

Storage region

Retention period

Log Management (recommended)

Security Center logs and standardized logs

Subscription or pay-as-you-go

Default: China (Shanghai). Changeable only when enabling pay-as-you-go.

Configurable in the Log Settings panel

Log Analysis

Security Center logs only

Subscription only

Default: China (Hangzhou). Not changeable.

180 days. Not changeable.

Use Log Management if you need standardized log storage, flexible billing, or configurable retention — for example, to meet classified protection compliance requirements.

What's next

  • Export logs: Download logs or query results to your local machine from the Security Center console, Cloud Shell, or a CLI. See Export logs.

  • Ship logs to OSS: Deliver logs to OSS for long-term archiving. See Create an OSS data shipping job (new version).

  • Set up capacity alerts: Enable notifications so you are alerted before storage runs out. See Notification settings.