Cloud Firewall and Simple Log Service offer a log analysis feature. This feature provides a one-stop service to collect, query, analyze, process, and use traffic logs from your assets in real time. This helps you monitor and protect your network assets and meet classified protection compliance requirements. This topic describes how to enable the log analysis feature in the Cloud Firewall console to collect traffic logs in Simple Log Service.
Prerequisites
The service-linked role for Cloud Firewall,
AliyunServiceRoleForCloudFW, is created. For more information, see Grant permissions to Cloud Firewall to access cloud resources.If you use a Resource Access Management (RAM) user, grant the RAM user permissions to query and analyze logs of Cloud Firewall. For more information, see Authorize a RAM user to query and analyze logs.
Limitations
This feature is available in the Premium Edition, Enterprise Edition, Ultimate Edition, and Pay-as-you-go Edition of Cloud Firewall. It is not supported in the Free Edition or the Hangzhou Finance Cloud Basic Edition.
Enable the log analysis feature
Method 1
Go to the Cloud Firewall purchase page.
Enable the Log Analysis feature, set the log storage capacity that you want to purchase, click Buy Now, and complete the payment.
For more information about the configuration, see Subscription 2.0.

Log on to the Cloud Firewall console.
In the navigation pane on the left, choose .
Click Enable Now to enable the log analysis feature.
Method 2
Log on to the Cloud Firewall console.
In the navigation pane on the left, choose .
On the Log Analysis page, click Upgrade Now or Enable Now.
Follow the on-screen instructions to enable the log analysis feature.
On the Log Analysis page in the Cloud Firewall console, turn on the Log Delivery switch in the upper-right corner. Then, turn on the switches for the required traffic logs.
You can analyze the following types of logs: Internet Traffic Logs, VPC Traffic Logs, DNS Traffic Logs, IPv6 Traffic Logs, and NAT Traffic Logs.
The log analysis feature collects all traffic logs that Cloud Firewall records in real time.
Related operations
Operation | Description |
Disable log shipping | On the Log Analysis page, click the LogSearch tab. Then, click the Log Shipping switch and select the log types that you want to disable. Important Disabling the log shipping feature does not automatically delete the Project or the shipped logs. Therefore, after you disable log shipping, delete the Project that was automatically created in the Simple Log Service console to avoid unnecessary fees. For more information, see Manage a Project. |
Modify log storage configurations | To set the log type, modify the log storage region, change the log storage duration, manage the bucket, or delete logs, see Modify log storage configurations. Warning
|
References
You can query and analyze the collected logs in real time to promptly identify traffic exceptions and protect your assets. For more information, see Query and analyze logs.
To prevent new logs from being dropped because the storage space is full, you must monitor your log storage usage. We recommend that you enable alert notifications for Log Storage Capacity. For more information, see Alert notifications.
How do I reduce the storage capacity for the log analysis feature?
Can I export traffic logs of Cloud Firewall to a third-party system?
After you push traffic logs to Simple Log Service, you can query, analyze, download, ship, and process logs, and create alerts within the service. For more information, see Common operations on logs of cloud services.