Log service migration guide
To improve service quality, Alibaba Cloud Web Application Firewall (WAF) 3.0 upgrades the log service feature starting on August 14, 2026, 00:00:00 (UTC+8). The upgrade is rolled out in batches as a canary release.
This change applies only to users who have activated the log service feature of the WAF 3.0 pay-as-you-go edition. If you are affected, follow this document to migrate all configurations from the old Logstore to the new Logstore within the 180-day parallel operation period.
Pre-migration preparation
1. Verify the canary release status of your WAF instance
-
Log on to the Web Application Firewall 3.0 console. From the top menu bar, select the resource group and region (Chinese Mainland or Outside Chinese Mainland) for the WAF instance.
-
In the navigation pane on the left, choose .
If a WAF 3.0 Log Service Upgrade banner appears at the top of the page and a switch for the old and new Logstores appears below it, your WAF instance has entered the canary release phase of the upgrade and you can proceed with the migration.
2. Compare configurations of the old and new Logstores
Use the switch to select Old Logstore, and record the current index configurations, reports, alert configurations, and dashboard parameters. Then select New Logstore to perform the migration. During the migration, both the old and new Logstores continue to receive data as expected, without affecting existing protection features or log query services.
3. Identify configuration items that require manual migration
The system automatically migrates lifecycle-related parameters, including hot storage TTL, infrequent access storage TTL, data retention period, and index lifecycle. No manual intervention is required. Other configuration items require manual verification or recreation. Follow the instructions below to check each item.
Migration by item
The following table lists the items that require manual migration. Check each item:
Scenarios requiring manual configuration | Migration steps |
If you have deleted default field indexes, added custom field indexes, or modified the tokenizer of default index fields, you need to apply the same changes in the new Logstore. | |
If the Log Public IP feature is enabled, you need to re-enable it in the new Logstore. | |
If you use WebTracking through a frontend SDK or JavaScript to write logs directly and the write address is bound to the old Logstore name, you need to update it to the new Logstore name. | |
If data encryption is enabled for the old Logstore, you need to reconfigure the encryption rules in the new Logstore. | |
If the LogReduce feature is enabled for the old Logstore, you need to re-enable and configure it in the new Logstore. | |
If you have configured Dashboard or Alert Rules, you need to recreate them in the new Logstore. | |
If you have configured data consumption, you need to update the consumer configuration to point to the new Logstore. | |
If you read logs through OpenAPI or an SDK, such as the GetLogs operation, you need to update the Logstore name parameter in your code. If you disable Simple Log Service using the ModifyUserWafLogStatus API, you must perform additional operations based on the migration phase. |
If you confirm that none of the preceding configuration items require manual migration, no manual migration is needed. Wait for the parallel operation period to end and use the new Logstore directly.
Access the console
Log on to the Simple Log Service console.
In the Projects section, click the project you want.
Index field and tokenizer settings
On the Logstores tab, click the target Logstore, and choose
> Search & Analysis.On the Search & Analysis page, click Index Attributes or Attributes in the upper-right corner, and check whether the Field Name, Type, Delimiter, and Enable Analytics configurations are consistent with the old Logstore. For fields that differ, add, delete, or modify them accordingly, and then save the configuration. For more information, see Index-based query and analysis.
Log Public IP settings
On the Logstores tab, click the target Logstore, and choose
> Modify.On the Basic Information page, if the Log Public IP feature is enabled for the old Logstore, you need to apply the same configuration to the new Logstore. For more information, see Manage Logstores.
WebTracking write address update
In your frontend SDK or JavaScript collection code, locate the Logstore parameter of the WebTracking configuration and replace it with the new Logstore name. After you deploy the code, verify that the new Logstore receives data as expected. For more information, see Data collection.
Data encryption configuration
On the Logstores tab, click the target Logstore, and choose
> Modify.On the Encryption Configuration page, if data encryption is configured for the old Logstore, you need to apply the same configuration to the new Logstore. For more information, see Encryption of data in transit.
LogReduce
On the Logstores tab, click the target Logstore, and choose
> Search & Analysis.On the Search & Analysis page, click Index Attributes or Attributes in the upper-right corner, and then turn on the LogReduce switch. For more information, see LogReduce.
Dashboard and alert configuration
Dashboard: After you select the target Project, add a dashboard on the
> Dashboard > Dashboards page. For more information, see Quick start: Create a dashboard.Alert Rules: After you select the target Project, create an alert rule on the
> Alerts > Alert Center page. For more information, see Alerting.
Data consumption update
If data consumption was configured for the old Logstore, you need to update the consumer configuration to point to the new Logstore. For more information, see Overview of real-time consumption.
OpenAPI or SDK calls
Changes to the log reading API
If you read logs using OpenAPI or an SDK, such as theGetLogsAPI, you must update the Logstore name parameter in your code. For more information, see Use GetLogs to query logs.Disabling Simple Log Service by calling
ModifyUserWafLogStatus
After you call the ModifyUserWafLogStatus API to disable the service, the system response depends on the migration stage:Before migration
The system deletes the old Logstore, which is named in the formatwafnew-project-<Alibaba Cloud account ID>-<region>. Billing for Simple Log Service stops immediately.During migration (dual Logstores)
The system deletes both Logstores. The Simple Log Service for the WAF on-demand instance remains enabled. To stop billing completely, go to the Detection and Response > Log Service page and click Downgrade Capacity to decrease the quota. If you do not do this, billing resumes after the parallel migration period ends.After activation or migration
The system deletes the new Logstore, which is named in the formatwafng-project-<Alibaba Cloud account ID>-<region>. The Simple Log Service for the WAF on-demand instance remains enabled. To stop billing completely, go to the Detection and Response > Log Service page and click Downgrade Capacity to decrease the quota. Otherwise, normal billing continues.
FAQ
Can I skip the migration?
If you confirm that none of the configuration items described in this document require manual migration, you do not need to perform the migration. Wait for the parallel operation period to end and use the new Logstore directly.
If configuration items that require manual migration exist, you must complete the migration as described in this document. Otherwise, issues such as new logs not being indexed or queried correctly may occur after the parallel operation period ends, which may affect your business.
How do I verify the migration?
Data consistency verification: Switch to the new Logstore, run your commonly used query statements, and confirm that the results are consistent with the old Logstore.
Associated feature testing: If you have configured dashboards, alert rules, or data consumption, test each feature to verify that it works as expected.
What to do next: After the verification succeeds, you can use the new Logstore for all subsequent operations. The old Logstore automatically stops receiving data after the 180-day parallel operation period ends.
Will protection features or log collection be interrupted during the migration?
No. During the migration, the old and new Logstores continue to receive writes in parallel. Existing protection features and log collection services are not affected.
Is it normal to see two copies of data in the Simple Log Service console during the parallel operation period?
Yes, this is normal. During the parallel operation period, both the old and new Logstores store their own copy of data. The old Logstore automatically stops receiving data after 180 days.
What should I do if high-risk configurations or special scenarios cause exceptions?
If high-risk configurations such as indexes and tokenizers cause query exceptions after the migration, or if other special custom scenarios exist, contact technical support through the DingTalk security service group or your business manager.