View raw logs
Use the Log Analysis feature to view raw log details and download them.
Background
On the page, the Raw Logs tab displays details of each log entry, including the time, content, and log fields. For descriptions of log fields, see Log types and field descriptions. On the Raw Logs tab in the Simple Log Service (SLS) console, the query results display log entries where __topic__ is aegis-log-login, and the account_expire and additional fields are empty.
Procedure
-
Log on to Security Center console.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
-
On the left side of the Raw Logs tab, click a field to add it to the Search & Analyze search box.
NoteFor example, after you select and click the aegis-log-process field, the field is added to the search bar. Click Search & Analyze to view logs related to that field.
The auto-generated query in the search bar uses the format:
* and __topic__ : aegis-log-process. -
The Raw Logs tab provides the following additional operations:
-
In the field list on the left (this panel contains the "Displayed Fields" and "Indexed Fields" areas, with icons next to each field for adding, removing, and viewing statistics):
-
In the Displayed Fields area, click the
icon next to a field to remove it from the Display Style list and the log details on the right. -
In the Indexed Fields area, click the
icon next to a field to add it to the Displayed Fields list. The field then also appears in the log details on the right. -
: View the field's Basic Distribution and Statistical Metrics. -
: Save the current Displayed Fields layout as a custom view. You can select it from the drop-down list at the top. -
Tag Settings:: Set the field as a system tag. -
Alias: Enable this option to replace field names with configured aliases. Fields without an alias retain their original names.
-
-
In the data display area on the right:
The top of the page displays three tabs: Raw Logs, Graph, and Log Clustering. The Displayed Fields panel on the left lists the
__topic__and__source__fields. The main area displays the queried log entries.-
In the Raw Data list:
-
: Copy the log content. -
: Use SLS Copilot to summarize log content, find errors, and more.
-
-
: Export logs by selecting a time range and download tool. For details, see Export Logs. -
> JSON Configurations: Set the JSON display type and expansion level. -
> Event Settings: Configure events for raw logs. For details, see Event Settings.
-
-