All Products
Search
Document Center

Security Center:CTDR 2.0 Process File Write Logs and CTDR 1.0 File Read/Write Logs Capability Upgrade Notice

Last Updated:Jun 22, 2026

Background and purpose

To improve log processing efficiency and reduce resource consumption, Security Center will retire the Process File Write Logs data source for Threat Detection and Response (CTDR) 2.0 and the File Read/Write Logs data source for CTDR 1.0. The host alert aggregation and automated investigation path for CTDR security events will switch from these data sources to Security Center's host traceability investigation capability, with results provided by the SAS business center.

Affected users

  • CTDR 1.0 users: Alibaba Cloud accounts that activated CTDR on or before April 3, 2025.

  • CTDR 2.0 users: Alibaba Cloud accounts that activate CTDR after April 3, 2025.

Upgrade timing

The data sources will be retired and the automated investigation path for CTDR security event host alerts will be switched on June 19, 2025.

Impact of the upgrade

  • Switch in the automated investigation path for host alert-aggregated security events

    Automated investigation for CTDR security event host alerts will use Security Center’s host traceability investigation capability to retrieve results directly, instead of relying on the CTDR 1.0 File Read/Write Logs or CTDR 2.0 Process File Write Logs data sources.

  • Data source removal

    Security Center will remove the CTDR 2.0 Process File Write Logs data source and the CTDR 1.0 File Read/Write Logs data source.

  • Traffic and cost optimization

    After the data sources are removed, ingested log traffic decreases, reducing log storage and transmission costs.

  • Cessation of Log Delivery Tasks

    If you enabled log delivery for Security Center's File Read/Write Logs or Process File Write Logs data sources, delivery will stop automatically after the data sources are retired.

  • Disabling of the Log Delivery Toggle

    The CTDR 1.0 console will disable the File Read/Write Logs delivery toggle in Log Management. Once disabled, you cannot re-enable this toggle. Previously delivered File Read/Write Logs data remains available for viewing and is unaffected.

  • Deletion of Attached Access Policies

    Security Center will delete any access policies attached to the File Read/Write Logs and Process File Write Logs data sources.

For help, submit a ticket.