This topic describes how to collect logs from a server across Alibaba Cloud accounts.
Background information
- Application A is deployed on a Linux ECS cluster that belongs to Alibaba Cloud Account A (12****456) and Log Service is activated for the account to manage logs.
- Application B is deployed on a Linux ECS cluster that belongs to Alibaba Cloud Account B (17****397) and Log Service is activated for the account to manage logs.
The enterprise wants to use Log Service that is activated for Alibaba Cloud Account A (12****456) to collect the logs of the two applications and store the logs in two Logstores of the same project. In this case, you must create a Logtail configuration, a machine group, and a Logstore to collect and store the logs of Application B. The Logtail configuration, machine group, and Logstore that are configured for Application A remain unchanged.

Step 1: Create a user identifier file
Step 2: Create a custom ID-based machine group
Step 3: Collect logs
Related operations
- The first role ARN is used to grant the custom role or AccessKey pair the required permissions to read data from a source Logstore. For information about how to grant the required permissions to a RAM role, see Grant the RAM role the permissions to read data from a source Logstore.
- The second role ARN is used to grant the custom role or AccessKey pair the required permissions to write transformation results to a destination Logstore. For information about how to grant the required permissions to a RAM role, see Grant the RAM role the permissions to write data to destination Logstores across Alibaba Cloud accounts.