All Products
Search
Document Center

Cloud Enterprise Network:Monitoring and logging

Last Updated:Jun 21, 2026

Monitoring and logging are essential to ensure your CEN resources and associated workloads are available, healthy, and operating smoothly. Alibaba Cloud provides a suite of services for monitoring, logging, and auditing, such as Network Intelligence Service (NIS), CloudMonitor, and Cloud Config. You can use these services to continuously collect monitoring data, gain real-time insight into the usage and performance of your CEN resources, and respond promptly to alerts.

Network Intelligence Service (NIS)

Alibaba Cloud Network Intelligence Service (NIS) is an intelligent, self-service platform that provides capabilities for network planning, deployment, and operations in the cloud. NIS helps you plan and use your network resources more effectively by providing reference data for network planning and helping you detect and resolve network issues.

CEN is integrated with NIS. You can use NIS to diagnose transit router instances, analyze inter-region and intra-region traffic, and analyze traffic paths to keep your workloads running.

Instance diagnostics

The instance diagnostics feature of CEN checks the configuration and operational status of Enterprise Edition transit router instances. It also suggests smart remedies for any detected issues. For a list of supported diagnostic items and instructions on how to use this feature, see Diagnose a transit router instance.

Traffic analysis

The traffic analysis feature allows you to monitor both real-time and historical network traffic. It generates time-series charts in the console based on the analysis results. You can use the traffic data and metrics to troubleshoot and resolve issues.

When using CEN, you can analyze the inter-region and intra-region traffic that flows through it:

  • Inter-region traffic analysis: Analyze the inbound and outbound inter-region traffic that passes through an Enterprise Edition transit router. The traffic data can be displayed as a 5-tuple. For more information, see Use public traffic analysis.

  • Intra-region traffic analysis: Analyze the inbound and outbound cross-VPC traffic that passes through an Enterprise Edition transit router within the same region. For more information, see Use public traffic analysis.

Reachability analyzer

When you use CEN to establish network connectivity, you can use the reachability analyzer to diagnose network connectivity between resources and ensure your workloads run correctly. For more information, see Use reachability analyzer.

Alibaba Cloud Health Status

We recommend that you monitor the health status of your cloud resources in real time to act on any anomalies immediately. For more information, visit the Alibaba Cloud Health Status homepage.

On the Alibaba Cloud Health Status page, you can view the real-time status of Alibaba Cloud services in each region and find out how to subscribe to RSS feeds for service exceptions.

The left-side navigation pane lists products by category, such as Compute, Containers, Storage, Network & CDN, and Security. The main area displays a table with the Current Status and daily health status for the last seven days for each product. A summary at the top shows the number of products with an abnormal, warning, or normal status.

CloudMonitor

CEN is integrated with CloudMonitor from Alibaba Cloud, which is available for free. You can use CloudMonitor to monitor system events and various metrics for CEN in real time. By analyzing this information, you can verify that your system is operating correctly. You can also create alert rules for system events and metrics to receive notifications and promptly address issues when anomalies occur.

System event monitoring

The event monitoring feature of CloudMonitor automatically collects cloud product faults and O&M events. It provides a centralized portal for querying and analyzing system events across all your cloud products, giving you a clear view of their operational status. After you classify resources into application groups, system events are automatically associated with the resources in those groups. This consolidation helps you analyze and resolve business failures faster.

CloudMonitor also provides an alerting feature for events. You can configure alerts based on event severity and receive notifications through email, or DingTalk, or by setting up a callback URL. This helps you stay informed of critical events and handle them promptly to create a closed-loop, automated O&M process.

For information about the CEN system events collected by CloudMonitor and how to create alert rules for them, see Monitor route entry resources.

Metric monitoring

The cloud service monitoring feature of CloudMonitor automatically retrieves metric data for the cloud resources in your Alibaba Cloud account. You can view monitoring charts for each cloud service to understand the operational status of your resources. You can also create alert rules to monitor your resources. When the conditions of an alert rule are met, CloudMonitor automatically sends a notification, keeping you informed of your resource status.

CEN provides different metrics for different resources. Refer to the following documents to learn about the supported metrics for each CEN resource and how to create alert rules for them.

Note

The preceding documents describe how to create alert rules for metrics in the CEN console. If you want to create alert rules in the CloudMonitor console, see Create an alert rule.

Related documents

Note

By default, an Alibaba Cloud account has full permissions on all resources, while a RAM user has no permissions. If a RAM user needs to view monitoring information, ensure the Alibaba Cloud account has granted the necessary permissions to the RAM user. For more information about CloudMonitor permissions, see Grant permissions to a RAM user.

Log Service

Alibaba Cloud Log Service is a cloud-native platform for observability and analysis. It offers a scalable, low-cost, and real-time service for data such as logs, metrics, and traces. Log Service provides a one-stop solution for data collection, processing, query and analysis, visualization, alerting, consumption, and delivery, enhancing your digital capabilities in development, operations, and security. For more information, see What is Log Service?.

CEN is integrated with Log Service. You can enable Log Service by using the flow log feature of CEN. This allows you to analyze and process traffic information for CEN resources, enabling real-time monitoring and auditing. For example, you can use the captured traffic information to analyze bandwidth usage, troubleshoot network issues, optimize traffic costs, and detect abnormal traffic.

CEN flow logs

Flow logs capture information about inter-region traffic between transit routers and traffic from virtual border router (VBR) connections within a specified capture window. You can set the capture window to 1 minute or 10 minutes. During the capture window, flow logs aggregate the captured traffic data and then write this data to Log Service as flow log records.

  • For the fields captured by flow logs, see Flow logs.

  • To learn how to configure the flow log feature for inter-region connections and VBR connections, see Flow logs.

    After you create a flow log, traffic information from inter-region and VBR connections is stored in a Logstore within Log Service. By default, log data is stored for 180 days, but you can modify this retention period. For more information, see Modify Logstore configuration.

  • To learn how to query and analyze log information in the Log Service console, see Query overview and Analysis overview.

Note
  • Only Enterprise Edition transit routers in some regions support flow logs. For more information about the supported regions, see Flow log limits.

  • Querying and analyzing logs in the Log Service console may incur fees. For more information, see Log Service billing.

  • By default, an Alibaba Cloud account has full permissions on all resources, while a RAM user has no permissions. If a RAM user needs to use Log Service, make sure the Alibaba Cloud account has granted the necessary permissions to the RAM user. For more information, see Create a RAM user and grant permissions.

Cloud Config

Alibaba Cloud Cloud Config is a resource auditing service that provides centralized tracking of cloud resource configuration history and compliance auditing. It helps you monitor resource compliance and ensure the continuous compliance of your infrastructure.

CEN is integrated with Cloud Config, which is available for free. Because Cloud Config supports only specific Alibaba Cloud services, only a subset of your resources may appear in the resource list. For the CEN resource types supported by Cloud Config, see Supported Cloud Services.

Cloud Config can detect the operational records of your Alibaba Cloud account and all associated RAM users. By default, it records resource configuration changes every 10 minutes.

You can view the operational records of your CEN resources in the Cloud Config console. For more information, see View the resource list.

Cloud Config can deliver the configuration change history and non-compliant events of your cloud resources to a specified Logstore in Log Service, allowing for centralized query and analysis. You can deliver the configuration change history and non-compliant events of your CEN products to Log Service to ensure continuous compliance. For more information, see Deliver data to Log Service.

ActionTrail

Alibaba Cloud ActionTrail is a service that helps you monitor and record activities in your Alibaba Cloud account. This includes access to and use of cloud products and services through the Alibaba Cloud console, OpenAPI, and developer tools. You can download these events or save them to Log Service or OSS. You can then perform behavior analysis, security analysis, resource change tracking, and compliance auditing.

CEN is integrated with ActionTrail. For a list of CEN audit events supported by ActionTrail, see Auditable events for CEN. For details on the content of recorded audit events, see Management event structure. To learn how to query audit events, see Get started with event query.

By default, ActionTrail tracks and records events from the last 90 days. To retain logs longer, you must create a trail to record the events in Log Service or OSS. For more information, see Create a trail.

After you deliver events to Log Service or OSS, you can query or analyze them in the respective consoles. For more information, see Query events in the Log Service or OSS console.

If you need to track historical events, submit a ticket to request these permissions.