Overview
The log service for Web Application Firewall (WAF), powered by Alibaba Cloud Log Service, helps you collect and store web access logs and protection logs for your WAF-protected domains. This service provides log query and analysis, statistical charts, and alerting. You can also integrate and forward logs to downstream computing services, allowing you to focus on analysis rather than manual log management.
Intended users
- Large enterprises and organizations with compliance requirements for storing host, network, and security logs for their cloud assets, such as financial firms and government agencies.
- Enterprises with their own security operations center that need to centralize the collection and management of security alerts and other logs, such as those in real estate, e-commerce, finance, and government sectors.
- Technically advanced enterprises that require in-depth analysis of cloud asset logs and automated alert handling, such as those in the IT, gaming, and finance industries.
- Users who need to trace security incidents, generate periodic security reports, or meet classified protection requirements.
Use cases
- Tracing web attack logs to identify the source of security threats.
- Monitoring web request activity to understand status and trends.
- Quickly assessing security operations effectiveness and responding to anomalies promptly.
- Exporting security logs to self-managed data and computing centers.
Benefits
- Compliance support: Store website access logs for more than six months to help meet classified protection requirements.
- Flexible configuration:
- Easily configure the collection of web access logs and protection logs.
- Customize the log retention period and storage capacity, and specify which websites to collect logs from.
- Modify or customize report templates to quickly gain insights into your website's business and security posture.
- Real-time analysis: Powered by Alibaba Cloud Log Service, this feature provides real-time log analysis, an out-of-the-box report center, and interactive data exploration, reducing analysis time from minutes to seconds and giving you immediate visibility into web attacks and access details.
- Real-time alerting: Customize monitoring and alert rules based on specific metrics to ensure a prompt response when exceptions occur in critical services.
- Ecosystem integration: Integrate with other services like real-time computing, cloud storage, and data visualization solutions to further unlock the value of your data.
Features
| Feature | Description |
| Log collection | After activating the WAF log service, you can enable log collection for your WAF-protected domains. WAF collects and stores log data for a domain only after log collection is enabled for that domain, making the data available for you to query and analyze. For details about the log fields supported by WAF, see Log fields supported by WAF. You can modify the default log settings, including the log retention period, the log fields to store, and the storage type (All logs or Blocked logs). For more information, see Modify log settings. |
| Log query and analysis | Use query and analysis statements to examine your collected log data. A query and analysis statement consists of a Log Service-specific query statement (Search) and an SQL-92 standard analysis statement (Analytics), separated by a vertical bar (|). After an analysis statement is executed, the analysis results are displayed in a table by default. You can also view the results in other formats, such as line charts, bar charts, and pie charts. You can also create an alert based on a query statement. After an alert is created, Log Service periodically runs the query and sends a notification if the results meet the predefined conditions. This enables real-time monitoring of your services. For specific instructions, see Log alerts. |
| Dashboards | A dashboard is a real-time analytics console in Log Service. You can display multiple statistical charts from query and analysis results on a single dashboard. The WAF log service includes pre-configured dashboards for common operational and security scenarios: the Operation Center, Access Center, and Security Center. These dashboards allow you to quickly check your website's business and security data by simply adjusting the time range, without needing to write complex queries. You can also subscribe to a dashboard to schedule and push its content to specified recipients by email or via DingTalk group messages. |
| Managing log storage space | You can periodically check your log storage usage. You can upgrade the storage capacity or clear stored logs. |
| Integrating WAF logs with a Syslog server | You can use a Python script to integrate WAF logs into a Syslog server. This helps you meet compliance and audit requirements, and centrally manage all related logs in your security operations center. |