Enable the log analysis feature

更新时间:
复制 MD 格式

Cloud Firewall and Simple Log Service offer a log analysis feature. This feature provides a one-stop service to collect, query, analyze, process, and use traffic logs from your assets in real time. This helps you monitor and protect your network assets and meet classified protection compliance requirements. This topic describes how to enable the log analysis feature in the Cloud Firewall console to collect traffic logs in Simple Log Service.

Prerequisites

Limitations

This feature is available in the Premium Edition, Enterprise Edition, Ultimate Edition, and Pay-as-you-go Edition of Cloud Firewall. It is not supported in the Free Edition or the Hangzhou Finance Cloud Basic Edition.

Enable the log analysis feature

Method 1

  1. Go to the Cloud Firewall purchase page.

  2. Enable the Log Analysis feature, set the log storage capacity that you want to purchase, click Buy Now, and complete the payment.

    For more information about the configuration, see Subscription 2.0.

    image

  3. Log on to the Cloud Firewall console.

  4. In the navigation pane on the left, choose Log Monitoring > Log Analysis.

  5. Click Enable Now to enable the log analysis feature.

Method 2

  1. Log on to the Cloud Firewall console.

  2. In the navigation pane on the left, choose Log Monitoring > Log Analysis.

  3. On the Log Analysis page, click Upgrade Now or Enable Now.

  4. Follow the on-screen instructions to enable the log analysis feature.

  5. On the Log Analysis page in the Cloud Firewall console, turn on the Log Delivery switch in the upper-right corner. Then, turn on the switches for the required traffic logs.

    You can analyze the following types of logs: Internet Traffic Logs, VPC Traffic Logs, DNS Traffic Logs, IPv6 Traffic Logs, and NAT Traffic Logs.

    The log analysis feature collects all traffic logs that Cloud Firewall records in real time.

Related operations

Operation

Description

Disable log shipping

On the Log Analysis page, click the LogSearch tab. Then, click the Log Shipping switch and select the log types that you want to disable.

Important

Disabling the log shipping feature does not automatically delete the Project or the shipped logs. Therefore, after you disable log shipping, delete the Project that was automatically created in the Simple Log Service console to avoid unnecessary fees. For more information, see Manage a Project.

Modify log storage configurations

To set the log type, modify the log storage region, change the log storage duration, manage the bucket, or delete logs, see Modify log storage configurations.

Warning
  • Regularly monitor your bucket usage while you use the log analysis feature. If the bucket usage exceeds 70%, promptly upgrade the storage capacity to ensure that new logs can be stored.

  • After you clear a bucket, the log data cannot be restored. Use this feature with caution.

References

  • After you push traffic logs to Simple Log Service, you can query, analyze, download, ship, and process logs, and create alerts within the service. For more information, see Common operations on logs of cloud services.