Query logs

Updated at:

Security Center integrates with Simple Log Service (SLS) to query and analyze host logs and security logs from your assets. Security Center provides real-time log collection, storage, and SLS-based query and analysis, report alerting, and downstream computing and delivery capabilities.

Prerequisites

Log analysis is enabled. For more information, see Enable log analysis.

Procedure

Select a log type to query and analyze collected log data in real time, view or edit dashboards, and configure alert monitoring rules.

  1. Log on to Security Center console.

    1. In the left-side navigation pane, choose Risk Governance > Log Analysis. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

    2. In the upper-left corner of the Log Analysis page, select the log type you want to view and set the status to Enable. Host log types include Login Activities, Network Connections, Process Startup, Brute-force Attacks, Account Snapshots, Network Snapshots, and Process Snapshots. Each type has a corresponding enable/disable toggle on the right.

    3. On the Log Analysis page, query and analyze logs.

      You can perform the following operations:

      • The Log Analysis page displays the query and analysis results for the log type selected in Step 3, and the system automatically matches a query statement. In the query bar of the sas-log project, enter a query statement such as __topic__:aegis-log-login. The query results display the number of matching log entries and a histogram showing their distribution over time.

      • Click the time above the Search & Analyze button. In the Time panel, set the log time range by using quick options such as 1 Minute, 5 Minutes, 15 Minutes, 1 Hour, 1 Day, This Week, or This Month, or by using Custom to specify a custom range. You can also select Round to Hour to align the time to the nearest hour. After you configure the time range, click OK, and then click Search & Analyze to view log information within the specified time range.

      Note

      Security Center retains logs for 180 days. Each log entry is automatically deleted on the 180th day after its log timestamp.