Simple Log Service (SLS) is a cloud-native, low-cost platform that collects, processes, stores, queries, analyzes, monitors, and integrates logs, metrics, and traces at scale in real time. It powers observability, DevOps, security auditing, and business analytics.
Use cases
-
Log management: Omnichannel log collection, tiered storage, and real-time, petabyte-scale query and analysis.
-
Unified data pipeline/data lake: Unified ingestion from multiple sources, real-time cleansing and distribution, acting as an enterprise data bus.
-
Business analysis and monitoring: Connects system data with business data to deliver insights at the minute or even second level.
-
End-to-end observability and operations: Correlated analysis of logs, metrics, and traces, with AIOps for anomaly detection and root cause analysis.
-
Log security and compliance auditing: Centralized log collection across multiple accounts and regions, built-in audit rules, and SIEM integration to meet compliance requirements.
Why choose Simple Log Service?
Compared to self-managed solutions like ELK, SLS offers these advantages:
-
Unified ingestion: Supports multiple data types, including logs, metrics, and traces, from clients, servers, IoT devices, mobile apps, cloud products, open-source systems, multi-cloud environments, and on-premises servers.
-
Efficient processing: Real-time data processing during collection, at write time, and after writing, with built-in functions and a stream processing engine.
-
Unified storage: Breaks down data silos and supports tiered storage with automated lifecycle management.
-
Intelligent analysis: Queries tens of billions of data records in seconds. It provides nearly 100 built-in analysis functions, supports local Agent Skill for intelligent log query and analysis.
-
End-to-end observability: Unified storage and correlated analysis for logs, metrics, and traces with AIOps-driven anomaly detection and root cause analysis.
-
Cost-effective: Uses a pay-as-you-go model that can reduce TCO by over 50%. Elastic scaling handles petabytes daily and absorbs traffic spikes.
-
Out-of-the-box: Built-in enterprise apps including CloudLens (observability) and FinOps (cost analysis). Compatible with various open-source engines.
Core features
Data collection
-
Multi-source ingestion: Supports client logs (web, app, IoT), server and application logs, Alibaba Cloud product logs (such as RDS, SLB, and OSS), standard protocols (such as Syslog, SNMP, and HTTP), and open-source system logs (such as Nginx, MySQL, and Kafka). It connects data across accounts, clouds, and hybrid environments.
-
Multiple collection methods: Supports the self-developed LoongCollector (an upgraded version of Logtail), WebTracking for front-end collection, SDKs, and APIs.
-
High reliability: Resumable uploads, elastic scaling, and multi-path transmission (public network, internal network, Global Accelerator). Automatically discovers new instances and collects their logs.
Data processing
SLS processes data in real time during data collection, at write time, and after writing. Operations include structuring, cleansing, filtering, formatting, masking, encrypting, routing, and enriching. Built-in functions cover text processing, JSON parsing, regex extraction, field mapping, and data conversion. A high-throughput, low-latency stream processing engine supports SPL statements.
Data storage
SLS stores data with redundancy for durability and availability while optimizing costs through intelligent tiering.
-
Unified storage platform: Breaks down data silos by supporting unified storage for logs, metrics, and traces.
-
Intelligent lifecycle management: For hot data, it supports high-frequency access with millisecond response times. For cold data, it provides infrequent access and automatically transitions to Infrequent Access or Archive storage to reduce storage costs.
-
High availability and durability: Multi-replica redundant storage ensures no data is lost. Storage types include Standard and Query.
Query and analysis
-
High-performance query engine: Supports Index-based query (responds to queries on tens of billions of data records in seconds) and Scan-based query and analysis (Scan) (for lightweight analysis). It includes nearly 100 built-in query and analysis functions (statistical, aggregate, string, time, etc.). It also supports cross-Store federated queries (StoreView) and high-precision analysis with Dedicated SQL.
-
Intelligent operations capabilities: Integrates AIOps to provide anomaly detection, root cause analysis, and intelligent inspection capabilities. Supports scheduled SQL queries for report generation.
-
Compatibility with multiple products: Supports federated queries with external data sources, allowing you to use data from MySQL, PostgreSQL, OSS, and CSV files as external storage for query and analysis. It can also connect to third-party tools like Elasticsearch and Azure for query and analysis.
Data monitoring (visualization and alerting)
-
Visualization: Provides the dashboard feature with over 10 built-in chart types (tables, line charts, bar charts, maps, etc.). It also supports custom dashboards, console embedding, and drill-down analysis. It can be integrated with third-party systems like Grafana and Quick BI.
-
Intelligent alerting: One-stop solution covering alert monitoring, management, and notification. Supports unified alerting across sources, accounts, and conditions. Intelligent noise reduction eliminates alert storms. Notification channels include phone, SMS, DingTalk, WeChat, Lark, and webhooks.
Data output and integration
SLS supports downloading logs to a local machine or shipping logs to other cloud products. You can also use the SLS platform for real-time data consumption.
-
Data consumption: Supports real-time consumption via Spark Streaming, Flume, and Flink.
-
Data shipping: Supports real-time shipping to cloud products such as OSS, MaxCompute, and TSDB.
Get started
Get started with SLS in three stages. Each stage lists basic steps for all users and optional advanced steps.
|
Preparation |
Data ingestion |
Data application |
|
|
Core goal |
Understand core concepts and complete basic setup to prepare for data ingestion. |
Securely and efficiently transfer various types of data, such as logs, metrics, and traces, into Simple Log Service. |
Leverage your data for business value through query, analysis, monitoring, and alerting. |
|
Basic steps |
|
|
|
|
Optional/advanced steps |
|
|
|
Billing
Billing methods
-
Pay-as-you-go: Suitable for scenarios where business volume changes frequently.
-
Resource plan: Suitable for scenarios with relatively stable business volume.
Billing modes and billable items
-
Billable items for the pay-by-feature mode: Fine-grained billing. Each feature is charged independently, which is ideal for scenarios where feature usage is well-defined and costs need to be controlled precisely.
-
Billable items for the pay-by-ingested-data mode: Simplified billing. The core fee is based on the volume of ingested raw data, which is ideal for scenarios with frequent queries and analysis where a simple cost model is preferred.
FAQ
Data usage policy
Alibaba Cloud does not use or disclose your business data without your authorization, except as required to perform your service requests or as required by laws and regulations. Review the Service Terms.
Internal usage at Alibaba Cloud
Yes. Simple Log Service is the internal logging and monitoring platform for Alibaba, proven at scale during multiple Double 11 global shopping festivals. Developers within Alibaba Cloud also use Simple Log Service in many projects.
Service stability during data surges
SLS elastically scales to handle petabytes of data per day, absorbing traffic spikes and ensuring service stability.
Disabling the service and stopping billing
To stop billing, address both data collection and resource storage:
-
Stop log collection: After collection is stopped, the collector no longer transmits new logs.
-
Clean up storage resources: Delete the corresponding Project and LogStore in Simple Log Service. Ensure all associated resources are deleted to avoid charges for storage space usage.
For more information, see Stop billing.
Data retention period
You can store data permanently or for a specified period. Data that exceeds the specified retention period is automatically deleted. You can also enable intelligent storage tiering to transition data older than a specified period to Infrequent Access or Archive storage to reduce storage costs.