All Products
Search
Document Center

Agent Security Center:Agent Loop

Last Updated:Aug 12, 2026

Agent Security Center records the runtime activity, network behavior, and security events of your agents, and stores the resulting logs for compliance audit and incident investigation. Enable the log analysis feature to configure log delivery and retention per log type, and adjust the settings as your compliance requirements change.

What is Agent Loop

Agent Loop is the log analysis module of Agent Security Center. It comprehensively records and traces agent runtime behavior, network communications, and security events, providing end-to-end log collection and analysis capabilities from runtime behavior to security events for enterprise AI agents, meeting compliance audit and security operations requirements. Key capabilities:

  • Trace agent call chains, covering the complete chain of LLM (Large Language Model) calls and tool calling.

  • View agent runtime overview, including agent count, Trace count, model call composition, and tool duration distribution.

  • Query and analyze various logs using SQL-like statements, with support for statistical charts, intelligent patrol inspection, and log clustering views.

  • Investigate security alerts and risk events, and retain audit evidence.

Log types

Log type

LogStore name

Description

Agent Tracing Logs

agentloop-tracing

Runtime status, events, and performance metrics of agents.

Agent Process Logs

agent-process

Startup, runtime, and resource usage of host processes.

Agent DNS Logs

agent-dns

DNS queries and domain name resolution activity of agents.

Agent Network Logs

agent-network

Network traffic and connection information.

Agent Alert Logs

agent-alert

Security alerts and risk events.

Supported regions

Chinese mainland

Region

Region ID

Cloud type

China (Hangzhou)

cn-hangzhou

Alibaba Finance Cloud, Public cloud (shared)

China (Shanghai)

cn-shanghai

Public cloud

China (Shanghai) - Finance Cloud

cn-shanghai-finance-1

Alibaba Finance Cloud

China (Qingdao)

cn-qingdao

Public cloud

China (Beijing)

cn-beijing

Public cloud

China (Beijing) - Alibaba Gov Cloud

cn-north-2-gov-1

Alibaba Gov Cloud

Alibaba Gov Cloud

cn-haidian-cm12-c01

Alibaba Gov Cloud

China (Beijing) - Finance Cloud

cn-beijing-finance-1

Alibaba Finance Cloud

China (Zhangjiakou)

cn-zhangjiakou

Public cloud

China (Hohhot)

cn-huhehaote

Public cloud

China (Ulanqab)

cn-wulanchabu

Public cloud

China (Shenzhen)

cn-shenzhen

Public cloud

China (Shenzhen) - Finance Cloud

cn-shenzhen-finance-1

Alibaba Finance Cloud

Fuzhou

[TODO: confirm Region ID]

Local cloud

China (Nanjing)

cn-nanjing

Local cloud

China (Heyuan)

cn-heyuan

Public cloud

China (Guangzhou)

cn-guangzhou

Public cloud

China (Chengdu)

cn-chengdu

Public cloud

China (Qingdao) - Haier dedicated

cn-qingdao-acdr-ut-1

Public cloud

Zhengzhou (China Unicom JV)

cn-zhengzhou-jva

China Unicom JV

Outside the Chinese mainland

Region

Region ID

China (Hong Kong)

cn-hongkong

Singapore

ap-southeast-1

Australia (Sydney)

ap-southeast-2

Malaysia (Kuala Lumpur)

ap-southeast-3

Indonesia (Jakarta)

ap-southeast-5

Philippines (Manila)

ap-southeast-6

Thailand (Bangkok)

ap-southeast-7

Japan (Tokyo)

ap-northeast-1

South Korea (Seoul)

ap-northeast-2

India (Mumbai)

ap-south-1

Germany (Frankfurt)

eu-central-1

UK (London)

eu-west-1

US (Silicon Valley)

us-west-1

US (Virginia)

us-east-1

UAE (Dubai)

me-east-1

Saudi Arabia (Riyadh)

me-central-1

Mexico

na-south-1

Prerequisites

Enable Agent Loop

  1. Go to the Agent Security Center - Agent Loop, in the upper-left corner of the page, select the region where the assets to be protected are located: Chinese Mainland or Outside Chinese Mainland.

  2. On the Agent Loop page, click Configure Now.

  3. In the configuration dialog, configure the log storage region and retention period for each log type.

    • Select Storage Region: Storage regions are grouped into Chinese mainland and outside the Chinese mainland. Select the region closest to your workload deployment for optimal performance. For supported regions, see Supported regions.

    • Log delivery scope: Log types are enabled by default. You can disable log types that are not required.

    • Configure Log Retention Period: The default retention period is 180 days, and the minimum is 7 days. Expired data is automatically deleted.

  4. After configuration, click OK to complete the configuration.

  5. After configuration, the system automatically creates a log project in the format aliyun-aisc-log-${uid}-${regionId}. You can go to the Simple Log Service console to view the corresponding data.

    Note

    For the LogStore corresponding to each log type, see Log types.

    • ${uid}: Your Alibaba Cloud account ID.

    • ${regionId}: The selected storage region ID.

Modify log delivery scope and retention period

After the log analysis space is created, you can change the delivery scope or data retention period at any time.

  1. On the Agent Loop Log Details tab, click Log Delivery Settings in the upper-right corner of the page.

  2. On the Log Delivery Settings page, you can perform the following operations:

    • Modify log delivery scope: In the Log Storage Management area, turn the delivery switch on or off.

      Important

      Turning off all log delivery switches only stops receiving new logs. Stored logs still incur storage fees. To completely disable the feature, go to the Simple Log Service console and delete the corresponding log project.

      • Modifying the delivery scope does not affect stored historical data.

      • After delivery is disabled, the log type stops collecting new data, but existing data is retained until it expires and is automatically deleted.

    • Modify data retention period:

      1. In the Log Storage Management area, in the target log row, click the icon after the data retention time.

      2. In the modification dialog, modify the storage time and click Confirm.

      Note

      The retention period must be between 7 and 3650 days. Changes take effect immediately.

View and analyze logs

View agent runtime behavior

Agent Loop visualizes agent runtime overview across dimensions such as Agent, Trace, model calls, and tool calls, so you can quickly view the overall runtime status of agents.

  1. On the Agent Loop page, click the Agent Loop Visualization tab.

  2. At the top of the page, select a time range (last 7 days, last 30 days, or custom), or enter an agent name, model name, session ID, or Trace ID in the search box to filter.

  3. View the following statistics:

    • Agent count, Trace count, LLM call count, and Tool call count.

    • Agent list: displays the runtime overview of each agent.

    • Model call composition: displays the proportion distribution of different model calls.

    • Tool duration distribution: displays the tools ranked by cumulative duration for the current agent.

Query log details

On the log details page, you can use SQL-like (Structured Query Language) statements to query and analyze various agent logs, with support for multiple views and intelligent analysis.

  1. On the Agent Loop Log Details tab.

  2. In the log type dropdown, select the log type to query.

  3. Select a query time range, enter a query statement, and click Query/Analyze.

    Note

    If you just enabled Agent Loop, logs may have a delay of approximately 1 hour. Try again later.

  4. In the result area, switch views to examine query results. The following views are supported. For more information, see Query and analysis quick start.

    • Raw logs: View raw log data.

    • Statistical charts: View statistical results in chart format.

    • Intelligent patrol inspection: Automatically inspect logs for anomaly patterns.

    • Log clustering: Automatically group similar logs.

Cross-region migration

When your business deployment location changes, you can migrate log storage to another region.

Procedure

  1. On the Agent Loop Log Details tab, click Log Delivery Settings in the upper-right corner of the page.

  2. On the Log Delivery Settings page, in the Log Delivery Region area, click Edit Region.

  3. In the region selection dialog, select the target region. For supported regions, see Supported regions.

Migration process and impact

  1. The old region stops receiving new log data.

  2. After the new region log storage is created, it immediately starts receiving delivered data.

  3. Old region data is retained for a 7-day transition period and automatically deleted after the transition period ends.

    Important

    During the transition period, the old region storage still occupies the metering quota (that is, incurs fees). To release the old region metering quota in advance, go to the Simple Log Service console and manually delete the old region log storage project.

Billing

Agent Loop uses the pay-as-you-go billing model. You are charged based on actual usage, and bills are delivered on the following day (T+1).

  • Billing unit: Billed by storage capacity per hour. Storage under 1 TB in a given hour is billed as 1 TB.

  • Metering: Storage is archived every hour. Hourly measurements accumulate throughout the day, and the bill for that day is pushed the next day (T+1).

    Example: If your storage is stable at 3 TB for the entire day, the daily measurement is 24 hours × 3 TB = 72 TB·hours, and the daily fee is USD 21.6 (72 TB·hours × USD 0.3/TB/hour).

  • Pricing: USD 0.3/TB/hour.

Overdue payments and unsubscription

Overdue payments

  • Feature impact: If the current account has overdue payments, Agent Loop immediately stops delivering new logs.

  • Data deletion:

    • Within the retention period: A 15-day data retention period is provided after overdue. During the retention period, historical data is not deleted and remains viewable.

    • After the retention period expires: The Agent Security Center instance is immediately released, and Agent Loop is also closed. Data is deleted at T+3 or at 24:00 (UTC+8) that night, and cannot be recovered after deletion.

Unsubscription

Based on actual business requirements, you can choose either of the following methods to unsubscribe:

  • Unsubscribe from the entire Agent Security Center

    • Procedure: See Unsubscribe from Agent Security Center.

    • Feature impact: The entire Agent Security Center instance is immediately released, and Agent Loop is also closed. New log delivery stops and historical data is no longer viewable.

    • Data deletion: After the instance is released, data is deleted at T+3 or at 24:00 (UTC+8) that night, and cannot be recovered after deletion.

  • Close Agent Loop only

    • Procedure: Agent Security Center console does not provide a separate close entry. To close it, go to the Simple Log Service console and manually delete the automatically created log project (aliyun-aisc-log-${uid}-${regionId}).

    • Feature impact: New log delivery stops immediately and historical data is no longer viewable.

    • Data deletion: After you manually delete the project, historical data is deleted at the same time and cannot be recovered.