All Products
Search
Document Center

Simple Log Service:Enable the inter-domain analysis feature

Last Updated:Apr 16, 2024

After you enable the inter-domain analysis feature, Simple Log Service automatically creates a data transformation task and generates Virtual Private Cloud (VPC) flow logs that contain information about CIDR blocks. Then, you can analyze the traffic between different CIDR blocks.

Prerequisites

A Flow Log Center instance is configured. For more information, see Configure a Flow Log Center instance.

Background information

Simple Log Service has multiple preset CIDR blocks. The following figure shows the preset CIDR blocks. If you want to analyze the traffic between different CIDR blocks, you must turn on Inter-Domain Analysis.

If the preset CIDR blocks do not meet your business requirements, you can add custom CIDR blocks.

Inter-domain analysis

Enable the inter-domain analysis feature

  1. Log on to the Log Service console.
  2. In the Log Application section, click View More Log Applications, and then click Flow Log Center.

  3. In the Flow Log Center section, click the instance that you created.

  4. In the left-side navigation pane, click CIDR Block Settings.

  5. If the preset CIDR blocks do not meet your business requirements, you can add custom CIDR blocks.

    1. On the CIDR Block Settings page, click Add.

    2. In the Network Settings-Add panel, set the parameters and click OK. The following table describes the parameters.

      Parameter

      Description

      CIDR Block Name

      The name for your CIDR blocks.

      CIDR Block

      The CIDR blocks that you want to analyze. Separate multiple CIDR blocks with commas (,). Examples:

      • A CIDR block: 192.168.0.0/16

      • Multiple CIDR blocks: 192.168.0.0/16,10.0.0.0/8

      Remarks

      Add remarks.

  6. On the CIDR Block Settings page, turn on Inter-Domain Analysis.

  7. If you have not authorized Simple Log Service to access the required cloud service resources, complete the authorization as prompted.

    You must use an Alibaba Cloud account to assign the AliyunLogETLRole role to Simple Log Service. After you complete the authorization, Simple Log Service assumes the AliyunLogETLRole role to read data from a source Logstore and write transformed data to a destination Logstore.

    Before you can use a RAM user to enable the inter-domain analysis feature, you must use an Alibaba Cloud account to assign the AliyunLogETLRole role to Simple Log Service. Then, you must grant the RAM user the permissions to transform data. For more information, see Grant a RAM user the permissions to manage a data transformation job.

What to do next

  • View the Inter-domain Traffic, ECS-to-Domain Traffic, and Threat Intelligence dashboards.

  • Query and analyze logs based on your business requirements. For more information, see Query and analyze logs.