Dear Alibaba Cloud users,
To improve our security services, Security Center will update the log analysis and Cloud Threat Detection and Response (CTDR) features on March 27, 2025, UTC+8.
Update details
-
Log Analysis
-
Starting March 27, 2025, the log analysis feature no longer supports the delivery of network logs, including web access logs, DNS logs, network session logs, and local DNS logs.
-
If you have activated network log delivery, the delivery will stop on March 27, 2025. New network log data will not be delivered, but previously delivered data will be preserved and remain available for queries.
-
-
CTDR
-
Starting March 27, 2025, the CTDR feature no longer supports adding DNS logs, web access logs, network session logs, and failed MySQL/FTP logon logs.
-
From March 27, 2025, log management in CTDR no longer supports the delivery of the aforementioned network logs.
-
If you have enabled log management for delivering network logs before this date, the delivery will stop on March 27, 2025. New network log data will not be delivered, but previously delivered data will be preserved and remain available for queries.
-
Update impacts
Effective March 27, 2025, Security Center will discontinue support for network log delivery. This update applies exclusively to Security Center Enterprise and Ultimate. If you require network log delivery, see the alternative solutions below.
Alternative solutions for adding or delivering network logs
Security Center provides alternative solutions for each type of network log. Select the option that best fits your needs.
DNS logs
Consider the DNS request log feature provided by Security Center. For more information, see Log categories and fields.
-
DNS request logs do not support recording DNS requests within containers.
-
For Linux servers, only systems with a kernel version of 4.X.X or higher are supported.
-
For Windows servers, only Windows Server 2012 and later versions are supported.
Web access logs
Consider Cloud Firewall and Web Application Firewall (WAF) as alternatives:
-
Cloud Firewall: Enable NAT firewall and log analysis features to collect and store web server request logs. For more information, see NAT firewalls.
-
WAF: Enable the WAF log service to collect and store web server response logs. For more information, see Log fields.
Network session logs
Use the Network Connection and Network Snapshot log features provided by Security Center. For more information, see Log categories and fields and Log categories and fields.
Network connection logs capture all outbound network requests and successful connection attempts. Security Center records network connectivity data for servers in real time. An outbound connection (connect) triggers a record upon initiation, while an inbound connection (accept) triggers a record upon success.
Local DNS logs
-
Log analysis feature of Security Center
Consider the DNS request log feature provided by Security Center. For more information, see Log categories and fields.
Note-
DNS request logs do not support recording DNS requests within containers.
-
For Linux servers, only systems with a kernel version of 4.X.X or higher are supported.
-
For Windows servers, only Windows Server 2012 and later versions are supported.
-
-
Alibaba Cloud DNS
Failed MySQL/FTP logon logs
No alternative solution is available at this time.