A RAM user can use the log query and analysis function of WAF only after the Alibaba Cloud account grants the required permissions to the RAM user.
Background information
The following table describes the types of operations and accounts that are required
to enable and use the log query and analysis function.
You can grant permissions to RAM users based on your business requirements.
Operation type | Required account |
---|---|
Activate Log Service. You only need to perform this operation once. | Alibaba Cloud accounts |
Authorize WAF to write log data to the dedicated Logstore in Log Service in real time. You only need to perform this operation once. |
|
Use the log query and analysis function. |
|
Scenario | Permission | Procedure |
---|---|---|
Grant all operation permissions of Log Service to RAM users. | AliyunLogFullAccess |
For more information about how to grant permissions, see Grant permissions to a RAM user. |
Grant log viewing permissions to RAM users after you use your Alibaba Cloud account to enable the log query and analysis function of WAF and complete the cloud resource access authorization. | AliyunLogReadOnlyAccess |
For more information about how to grant permissions, see Grant permissions to a RAM user. |
Grant only the permissions to enable and use the log query and analysis function of WAF to RAM users. The RAM users are not granted other management permissions on Log Service. | Permissions that are defined in a custom permission policy | For more information about how to customize a permission policy, see the following operation procedure. |