Log management overview

Updated at:

Web Application Firewall (WAF) log service collects and stores web access and attack protection logs from WAF protected objects, such as cloud service instances and domain names. Built on Alibaba Cloud Log Service, it provides query and analysis, data visualization, alerting, and downstream computing integration so you can focus on analysis instead of manual log management.

Intended users

  • Large enterprises and organizations with compliance requirements for storing host, network, and security logs for their cloud assets, such as financial firms and government agencies.
  • Enterprises with their own security operations center that need to centralize the collection and management of security alerts and other logs, such as those in real estate, e-commerce, finance, and government sectors.
  • Technically advanced enterprises that require in-depth analysis of cloud asset logs and automated alert handling, such as those in the IT, gaming, and finance industries.
  • Users who need to trace security incidents, generate periodic security reports, or meet classified protection requirements.

Use cases

  • Investigate security threats by tracking web attack logs.

  • Monitor web request activity to understand status and trends.

  • Gain insights into your security operations and respond quickly to anomalies.

  • Send security logs to your own data and computing centers.

Benefits

  • Compliance support: Store website access logs for more than six months to help meet classified protection requirements.
  • Flexible configuration:

    • Configure collection of web access and attack protection logs with minimal setup.

    • Customize log fields and storage types, and select the WAF protected objects, such as cloud service instances or domain names, for log collection.

    • Create or customize report templates based on your business or security needs to quickly assess website security.

  • Real-time analysis: Powered by Alibaba Cloud Log Service, this feature provides real-time log analysis, an out-of-the-box report center, and interactive data exploration, reducing analysis time from minutes to seconds and giving you immediate visibility into web attacks and access details.
  • Real-time alerting: Customize monitoring and alert rules based on specific metrics to ensure a prompt response when exceptions occur in critical services.
  • Ecosystem integration: Integrate with other services like real-time computing, cloud storage, and data visualization solutions to further unlock the value of your data.

Billing

  • Subscription model

    After you activate the Simple Log Service feature, you are charged based on your log storage capacity.

  • Pay-as-you-go model

    Starting August 14, 2026, WAF will gradually upgrade the pay-as-you-go Simple Log Service for WAF. The new billing rules are as follows:

    • For users who activate Simple Log Service for WAF on or after August 14, 2026: WAF handles the billing.

    • For users who activated Simple Log Service for WAF before August 14, 2026: Simple Log Service handles the billing, and WAF does not charge any fees. These users can upgrade the service. After the upgrade, a 180-day parallel period begins. WAF will handle billing after this period.

    For the upgrade announcement, see Web Application Firewall Web Core Protection, Bot Management, and Log Service upgrade notice.

Note

After you activate Simple Log Service, WAF does not configure the feature or store logs by default. To use this feature, you can go to the console and enable Simple Log Service for WAF. For more information, see Enable or disable log service.

Features

Feature

Description

Log Configuration

After you enable log service for WAF, you can enable log collection for protected objects such as cloud service instances and domain names. WAF collects and stores logs only for protected objects with log collection enabled. You can then query and analyze the log data. For more information about the fields in WAF logs, see Fields in logs. To learn how to enable log collection for a protected object, see Configure log settings and manage log storage capacity.

You can change the default log storage settings, including log fields and log types (normal request log, detection log, and block log). For more information, see Configure log settings and manage log storage capacity.

Log Query

Search and analyze collected log data using query statements. For more information, see Log query.

You can create alerts based on query statements. Log Service periodically checks query and analysis results and sends alert notifications when predefined conditions are met, enabling real-time service monitoring. For more information, see Quickly set up log-based alerting.

Log storage capacity upgrade

After you enable log service for Web Application Firewall (WAF), if your log storage capacity is nearly or completely full, upgrade the capacity promptly to prevent write failures to the Logstore. For more information, see Log storage capacity upgrade. For more information about how to handle full log storage, see What do I do if log storage capacity is exhausted?.

Storage Period

Log retention period affects storage costs. A shorter retention period reduces costs. Set an appropriate retention period based on your business requirements, compliance needs, cost, and performance considerations.