All Products
Search
Document Center

Simple Log Service:Usage notes

Last Updated:Aug 18, 2023

Simple Log Service and Alibaba Cloud Virtual Private Cloud (VPC) jointly provide the flow log feature. You can use the feature to record the traffic of a VPC, the traffic of an elastic network interface (ENI) in the VPC, and the traffic of a vSwitch in the VPC. You can check access control rules, monitor network traffic, and troubleshoot network errors based on the flow logs. This topic describes the assets, billing, and limits of the flow log feature.

Feature description

You can use the flow log feature to capture the network traffic of a specified ENI, VPC, or vSwitch. If you enable the flow log feature for a VPC or a vSwitch, traffic that is transferred over the ENIs in the VPC or the vSwitch is captured. The ENIs that are created after the flow log feature is enabled are included.

The flow log feature captures traffic, records the traffic information in logs, and then sends the logs to Simple Log Service. Each log records a five-tuple of network traffic that is captured within a specified time window. The time window is approximately 10 minutes. During this time window, the flow log feature aggregates traffic data and sends the traffic data as logs to Simple Log Service. For more information about the fields in flow logs, see Log fields.

Assets

  • Custom project and Logstore

    Important
    • Do not delete the project or Logstore that is related to VPC flow logs. Otherwise, VPC flow logs cannot be sent to Simple Log Service.

    • When you create a custom Logstore, note that billable items that are involved vary based on the billing mode of the Logstore. For more information, see Billable items.

    • If you select Turn on FlowLog Analysis Report Function when you enable the flow log feature, the data retention period of the Logstore that stores VPC flow logs is forcefully changed to seven days.

  • Dedicated dashboards

    By default, Simple Log Service generates three dashboards after you enable the feature.

    Note

    We recommend that you do not make changes to the dedicated dashboards because the dashboards may be upgraded or updated at any time. You can create a custom dashboard to visualize query results. For more information, see Create a dashboard.

    Dashboard

    Description

    Logstore Name-vpc_flow_log_traffic_cn

    Displays the overall traffic information about a VPC. The information includes Source Address Heat Map by Bytes, Top 10 Flow by Bytes, and Top 10 Action/Protocol by Bytes.

    Logstore Name-vpc_flow_log_rejection_cn

    Displays information about the traffic that is rejected by security groups and network ACLs. The information includes Total REJECT Bytes, REJECT Bytes Ratio, Total REJECT Packets, and REJECT Packets Ratio.

    Logstore Name-vpc_flow_log_overview_cn

    Displays the overall information about a VPC. The information includes Total Actions, Total ACCEPT Bytes, Total REJECT Bytes, and Total ACCEPT Packets.

Billing

The flow log feature allows you to deliver only the network logs that are extracted to Simple Log Service. When you use the flow log feature, you are charged for Simple Log Service usage and network log extraction.

  • Fee of network log extraction

    You are charged based on the data amount of network logs that are extracted. The fees are included in the bills of Simple Log Service. For more information, see Billing of flow logs.

  • Fee of Simple Log Service usage

    • If the dedicated Logstore uses the pay-by-feature billing mode, you are charged for storage, read traffic, number of requests, data transformation, and data shipping after the flow logs are collected from VPC to Simple Log Service. The fees are included in the bills of Simple Log Service. For more information, see Billable items of pay-by-feature.

    • If the dedicated Logstore uses the pay-by-ingested-data billing mode, you are charged for storage and read traffic over the Internet after the flow logs are collected from VPC to Simple Log Service. The fees are included in the bills of Simple Log Service. For more information, see Billable items of pay-by-ingested-data.

Limits

  • Supported regions

    The VPC that you use must reside in the same region as the project that you specify in Simple Log Service. The following table describes the regions in which the flow log feature is supported.

    Area

    Supported region

    Asia Pacific

    China (Qingdao), China (Beijing), China (Zhangjiakou), China (Hohhot), China (Ulanqab), China (Hangzhou), China (Shanghai), China (Nanjing - Local Region), China (Fuzhou - Local Region), China (Shenzhen), China (Heyuan), China (Guangzhou), China (Chengdu), China (Hong Kong), Japan (Tokyo), South Korea (Seoul), Singapore (Singapore), Australia (Sydney), Malaysia (Kuala Lumpur), Indonesia (Jakarta), Philippines (Manila), Thailand (Bangkok), and India (Mumbai)

    Europe & Americas

    Germany (Frankfurt), UK (London), US (Silicon Valley), and US (Virginia)

    Middle East

    UAE (Dubai)

  • Resources

    ItemLimitAdjustable
    Maximum number of flow logs that can be created in each region10No
    ECS instance families that do not support flow logs
    • When you enable flow logs for a VPC or a vSwitch, ECS instances in the VPC or vSwitch do not support flow logs if they belong to the following instance families. Other ECS instances that meet the requirements support flow logs:
    • ENIs that are associated with ECS instances of the following instance families do not support flow logs:

      ecs.c1, ecs.c2, ecs.c4, ecs.ce4, ecs.cm4, ecs.d1, ecs.e3, ecs.e4, ecs.ga1, ecs.gn4, ecs.gn5, ecs.i1, ecs.m1, ecs.m2, ecs.mn4, ecs.n1, ecs.n2, ecs.n4, ecs.s1, ecs.s2, ecs.s3, ecs.se1, ecs.sn1, ecs.sn2, ecs.t1, and ecs.xn4.

    Upgrade the ECS instances that do not support flow logs. For more information, see Upgrade the instance types of subscription instances and Change the instance type of a pay-as-you-go instance.

  • You can use the flow log feature to capture the traffic of a VPC, the traffic of an ENI in the VPC, and the traffic of a vSwitch in the VPC. If you enable the flow log feature for a VPC, ENIs in the VPC, and vSwitches in the VPC, only one set of flow logs are generated.