FAQ and troubleshooting

Updated at:

Find solutions to common Log Audit Service errors and get answers to frequently asked questions.

Common errors and troubleshooting

Error type

Error message

Cause

Solution

Account configuration

LogException{httpCode=-1 errorCode='IllegalResourceDirectoryAccounts' errorMessage='IllegalResourceDirectoryAccounts: account not ResourceDirectory master or admin user' requestId=''}

The current account is a regular central account, which cannot use a resource directory to collect logs from multiple accounts.

To use this feature, the central account must be the management account or a delegated administrator of the resource directory. For more information, see Collect logs from multiple accounts.

Configure multi-account collection in custom authentication mode. For more information, see custom authentication mode.

LogException{httpCode=-1 errorCode='IllegalAction.MultiAccountsIllegal' errorMessage='IllegalAction: the multi_account: 1234567*** may be already configured by other central account or contain central account' requestId=''}

A conflict exists in the multi-account configuration.

  • If Account A is already a central account with Log Audit Service enabled, it cannot be added as a member account to another central account, Account C.

  • If Account A is already a member account of Central Account B, it cannot be added as a member account to Central Account C.

To add the account 1234567*** as a member account to the current central account, perform one of the following steps:

  • If 1234567*** is a central account, first delete all audit resources under the central account 1234567***. For more information, see Delete log audit resources.

  • If 1234567*** is a member account under another central account, you must first delete the multi-account collection configuration for account 1234567*** from that central account.

The EtlMetaAlreadyExist error occurs when you add a new member account to a central account.

The account was previously a central or member account whose Log Audit Service Projects were deleted while log collection was still active. Always stop log collection for all cloud products before deleting Projects, as described in Delete Log Audit Service resources. Deleting active Projects prevents the system from recognizing the new configuration.

Submit a ticket to contact the Log Service team.

Error message: The current management account has multi-account log collection configured. Go to Log Audit Service in the SLS console and delete the multi-account configuration first. Error code: DeregisterDA.Deny.TrustedService.

You tried to change the delegated administrator in the resource directory console without first removing the multi-account configuration for the original delegated administrator.

Remove the multi-account configuration from the central account of the current delegated administrator. If log collection is configured for all member accounts, switch to custom mode and clear all selections. Then, change the delegated administrator.

Permission configuration

The role not exists: acs:ram::123456******:role/sls-audit-service-monitor.

The permissions for the sls-audit-service-monitor role of member account 123456****** have been deleted or modified.

Reconfigure the permissions for the sls-audit-service-monitor role. For more information, see Custom authorization for log collection and synchronization.

Permission denied, action: log:CreateApp,resource: app/audit or Permission denied, action: log:GetApp,resource: app/audit

The RAM user lacks the necessary permissions to perform operations in Log Audit Service.

Grant the required permissions to the RAM user. For more information, see Grant a RAM user the permissions to perform operations on Log Audit Service.

Quota limit

init_sls_assets failed because of ServerException [HTTP Status: 400 Error:DashboardError LogException{httpCode=403 errorCode='ExceedQuota' requestId='622854*********'}

A resource quota has been exceeded. Log Service limits basic resources such as Shards. For more information, see Basic resource limits.

If you receive an ExceedQuota error for a Project in Log Audit Service, submit a ticket to increase the resource quota.

init_sls_assets failed because of ServerException [HTTP Status: 400 Error:CreateProjectFailed Account 123456***** most has 50 project

The number of Projects under the account exceeds the quota. Log Service limits basic resources such as Projects and Shards. For more information, see Basic resource limits.

If the number of Projects under a single account in Log Audit Service exceeds the quota, submit a ticket to increase the resource quota.

Audit resources

When you try to change the log retention period, the system displays the following message: This Logstore is dedicated to the Log Audit Service application. To modify its properties, such as the retention period, go to the Global Configurations page of Log Audit Service.

N/A

On the Global Configurations page of Log Audit Service, modify the log retention period, hot data retention period, and other settings.

When you try to delete a Logstore, the system returns the error Operation not authorized.

A Logstore in Log Audit Service may be associated with built-in dashboards and alerts and cannot be deleted individually.

  • If you want to delete only the logs within the Logstore, go to the Global Configurations page. Change the log retention period for the Logstore to the minimum value, save the change, and then disable log collection for the corresponding cloud product. The existing logs will be deleted after the retention period expires.

  • If you must delete the Logstore, you can do so by deleting the Project that contains it. For more information, see Delete Log Audit Service resources.

LogException{httpCode=-1 errorCode='DeleteFailed' message='delete auditJob error' requestId=''}

Central Projects are supported only in specific regions. If you specify an unsupported region, such as China (Chengdu), Log Audit Service creates a Project named slsaudit-center-${uid}-${Region} in that region, but the service does not function correctly and you cannot switch back to a supported region.

Note

The following regions are supported:

  • China: China (Qingdao), China (Beijing), China (Zhangjiakou), China (Hohhot), China (Ulanqab), China (Hangzhou), China (Shanghai), China (Shenzhen), and China (Hong Kong)

  • Regions outside China: Singapore, Japan (Tokyo), Germany (Frankfurt), Indonesia (Jakarta), and Malaysia (Kuala Lumpur)

Manually delete the incorrect Project (slsaudit-center-${uid}-${Region}) by using the command-line interface (CLI) or by calling an API operation. Then, select a supported region for the central Project. For information about how to delete a Project, see Related operations.

The Multi-account Configurations > Global Configurations menu items are missing in Log Audit Service.

Log collection is not enabled for the central account in Log Audit Service.

Enable log collection for the central account. For more information, see Enable and manage log collection.

FAQ

  • Why does my change to the log retention period not take effect if I make it right before I disable log collection? For example, I change the retention period to 1 day for Server Load Balancer (SLB) Layer 7 access logs to clear existing data, but after I disable collection, the period remains 180 days.

    You must save the retention period change before disabling log collection. Otherwise, the change does not take effect. To update the log retention period, perform the following steps:

    1. On the Global Configurations page of Log Audit Service, click Modify.

    2. Change the log retention period for the target log type, and then click Save.

      Note

      Make sure that log collection is enabled when you save the change. After saving, wait for one minute before proceeding.

    3. Click Modify again.

    4. Disable log collection for the target log type, and then click Save.

  • How do I check the log collection status?

    In the Log Audit Service console, go to the Access to Cloud Services > Access Status page.

  • What should I do if the system reports a permission error or an invalid AccessKey pair?

    Verify that the account permissions are configured correctly. For single-account collection, see Initial configuration. For multi-account collection, see Custom authorization for log collection and synchronization. For example, this issue can occur if the ReadOnlyAccess policy under System Policy is not attached to the sls-audit-service-monitor role.

  • What should I do if the system reports that a specific service is not enabled for my account?

    This usually means a required feature is not enabled for a specific cloud product. For more information, see Supported Alibaba Cloud services. For example, this issue can occur if you have activated Security Center but have not enabled the Log Analysis feature.

  • Why is the number of built-in alert rules on the Alert Center page of the slsaudit-center-${uid}-${region} Project different from the number on the Audit alerts page of Log Audit Service?

    • In addition to rules for Log Audit Service, the slsaudit-center-${uid}-${region} Project also contains alert rules for other features, such as data transformation.

    • The Audit alerts page of Log Audit Service displays rules only for cloud products with log collection enabled. The Alert Center page of the slsaudit-center-${uid}-${region} Project does not have this requirement.

    • Because of factors such as different regions and language versions, the number of built-in alert monitoring rules on the Audit alerts page of the Log Audit Service may differ from the number on the Alert Center page of the slsaudit-center-${uid}-${region} Project.

  • Why are the numbers of alert policies, action policies, and alert templates on the Alert Center page of the slsaudit-center-${uid}-${region} Project different from those on the Audit alerts page of Log Audit Service?

    The Audit alerts page of Log Audit Service shows only the alert policies, action policies, and alert templates for Log Audit Service. The slsaudit-center-${uid}-${region} Project may also contain configurations from other associated applications, causing the counts to differ.

  • Why can't I find performance logs for ApsaraDB RDS for MySQL and PolarDB for MySQL on the Audit Query page?

    The Audit Query page displays query links only for 'log' data. Performance logs are 'Metric' data. To access them, go to the Global Configurations page, click the central Project name (for example, slsaudit-center-{Account ID}-cn-hangzhou), and then find the Metric Storage page in the Log Service console.

  • What should I do if Log Audit Service stops working because I accidentally deleted the sls-audit-service-monitor role or modified its permission policy in the RAM console?

    • If you use a central account and used an sls-audit-service-monitor role that was created by using an AccessKey to enable Log Audit Service, you only need to return to the Global Configurations page of Log Audit Service and follow the on-screen instructions to complete the authorization. For more information, see First-time configuration.

      Note

      The original sls-audit-service-monitor role is still supported if the role exists and its permission policy is correct. To prevent accidental deletion or modification, we strongly recommend upgrading to the service-linked role (SLR) authorization method.

    • If your account is a member account, find the sls-audit-service-monitor role in the RAM console (or create it if it does not exist) and modify its permission policy. For more information, see Custom authorization for log collection and synchronization.