The log management feature can store and query logs to help accurately locate alerts, trace attacks, and improve response speed. This topic describes the basic information about the log management feature and how to use it.
Log type description
|
Log type |
Usage conditions |
Data source description |
Supported categories and field description |
|
Security Center logs |
Enable the log management feature. |
Store logs generated by various feature modules of Alibaba Cloud Security Center. Examples include vulnerability logs, security alert logs, and client event logs. |
View the log center library address, EtlMetaName, and field descriptions |
|
Standardized logs |
Enable the log management feature and the Agentic SOC feature. |
|
On the Standardized Rule tab, click View Standard Fields. You can view the categories and field descriptions of standardized logs in the Standard Fields panel. |
Billing description
-
Subscription mode: Fees are charged based on the purchased log storage capacity and subscription duration, USD 100/1000 GB/month (minimum purchase: 1,000 GB; increment: 1,000 GB).
-
Pay-as-you-go mode: After you enable pay-as-you-go for log management, the system calculates the daily cumulative storage volume (GB) for each calendar day and charges fees based on USD 7.2/1000 GB per calendar day.
ImportantThe minimum billing unit for pay-as-you-go log management is 1,000 GB. Volumes less than 1,000 GB are billed as 1,000 GB. For example, if the daily usage is 1,900 GB, you are charged for 2,000 GB.
No additional fees are generated when you query or export logs in the Security Center console. After the log management feature delivers logs to Simple Log Service (SLS), if you process or ship log data in the SLS console, you may need to pay additional fees for these operations.
-
When the billing mode of the Logstore is pay-by-feature, data transformation, shipping, and streaming reads from an Internet-facing endpoint in SLS are charged by SLS. For more information, see Billable items in the pay-by-feature billing mode.
-
When the billing mode of the Logstore is pay-by-ingested-data, data transformation and shipping in SLS are free of charge. Only Internet data reads are charged based on the standard SLS rates. For more information, see Billable items in the pay-by-ingested-data billing mode.
Log storage description
After you enable the log management feature, the system automatically creates a dedicated project (named aliyun-cloudsiem-data-<Alibaba Cloud account ID>-<RegionID>) and a Logstore in SLS to store Security Center logs and standardized logs. The log storage region depends on the service region that you select in the upper-left corner of the Security Center console.
-
If you select Chinese Mainland, logs are stored in the China (Shanghai) region by default.
-
If you select Outside Chinese Mainland, logs are stored in the Singapore region.
-
You can change the log storage region only in the dialog box that appears when you enable pay-as-you-go for log management. Users who purchase log storage capacity on a subscription basis cannot change the log storage region.
-
You can log on to the SLS console to view the dedicated project and Logstore. Do not delete the project or Logstore.
If you accidentally delete the Logstore, the corresponding log data is lost. Lost log data cannot be recovered.
After a delivery task is enabled, Security Center automatically delivers logs to the corresponding log library. Delivered logs are retained until the configured retention period expires, and then the corresponding log data is deleted. If log storage space is exhausted in subscription mode, new logs stop being delivered. When the used log capacity exceeds 80% of the total capacity, Security Center supports sending notification messages. For more information about notification settings, see Configure log overlimit alerts.
Enable or disable log management
Before you perform the following operations, make sure that the account has the following permissions:
-
Alibaba Cloud account: All permissions by default.
-
RAM user: Must be granted the management permissions of Security Center (for example,
AliyunYundunSASFullAccess).
Enable log management
You can enable the log management feature only by using either the subscription or pay-as-you-go billing method. For more information about billing, see Billing description.
-
Log on to Security Center console.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
For users who have purchased Agentic SOC log ingestion traffic on a subscription basis or enabled pay-as-you-go for Agentic SOC, the left-side navigation pane entry changes to .
-
On the Log Management page, click Subscribe (Annual/Monthly) or Activate Pay-as-you-go.
NoteFor users who have purchased Agentic SOC log ingestion traffic on a subscription basis or enabled pay-as-you-go for Agentic SOC, click Enable Pay-as-you-go for Log Management in the upper-right corner of the current page, or upgrade to purchase Agentic SOC log storage capacity. For more information, see Upgrade or downgrade.
-
Enable subscription mode: On the purchase page, set Purchase or Not for Agentic SOC to Yes, select the required log storage capacity, and click Order Now to complete the payment.
You can purchase other Security Center features as needed. For more information, see Purchase guide.
-
Enable pay-as-you-go mode: In the dialog box, read the billing rules, select a storage region, and click Activate and Authorize.
-
-
After the feature is enabled, return to the Log Management page and check whether the service status is Enabled. Log data will start being delivered to SLS within a few minutes.
Disable log management
-
Log on to Security Center console.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
-
On the Log Management page, make sure that Log Usage is 0 GB.
If the log usage is not 0, click Delete in the upper-right corner of the current page, wait for the log usage to be cleared, and then proceed to the next step.
-
You can disable the log management feature in the following ways.
-
Subscription mode
-
Method 1: Downgrade
-
On the Overview page, click to go to the Downgrade page.
-
On the Order Downgrade tab, set Agentic SOC (Log Storage Capacity) in the Agentic SOC section to 0 GB.
-
Read and select the Security Center Service Agreement, and then click Order Now.
-
-
Method 2: Unsubscribe from the purchased Security Center instance. For more information, see Unsubscribe from a subscription.
-
-
Pay-as-you-go mode: On the Overview page of the Security Center console, in the Enable Pay-as-You-Go Service section, turn off the Log Management switch.
ImportantAfter you disable the log management switch, log delivery is automatically disabled, and the corresponding Logstore is deleted. Deleted log data cannot be restored. We recommend that you proceed with caution.
-
Description for users who only purchase log ingestion traffic or enable pay-as-you-go for Agentic SOC
If you have purchased Agentic SOC log ingestion traffic on a subscription basis or enabled pay-as-you-go for Agentic SOC but have not purchased log storage capacity, you can query some standardized logs on the Log Management page. The supported logs are from access policies whose Standardization Method is Scan Query.
In this scenario, Security Center logs cannot be delivered or viewed, and standardized logs from access policies whose Standardization Method is Real-time Consumption cannot be delivered or viewed. For more information about features supported by different billing items, see Log management billing overview.
Security Center logs
Enable delivery
After you purchase log storage capacity, Agentic SOC enables delivery for all Security Center log types by default. If you have not purchased the corresponding value-added services, such as application protection or malicious file detection, the delivery switches for the corresponding log types remain disabled.
You can click Log Management Settings on the Log Management page to view and configure the delivery status of each log type.
On the log management settings page, the Basic Settings area displays the log delivery region as China (Shanghai) and the log delivery language as Chinese. In the Log Storage Management area, on the Security Center Logs tab, the host log types include:
-
Brute-force attacks (aegis-log-crack)
-
Process snapshots (aegis-snapshot-process)
-
DNS requests (aegis-log-dns-query)
-
Account snapshots (aegis-snapshot-host)
-
Client events (aegis-log-client)
-
Logon logs (aegis-log-login)
-
Network connections (aegis-log-network)
-
Network snapshots (aegis-snapshot-port)
-
Process startup (aegis-log-process)
All delivery switches are turned on, and the log retention period is 180 days.
Query logs
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
-
In the upper-left corner of the Log Management page, click Security Center Logs and select the log type that you want to view.
-
Set a query time range, retrieve logs by using query statements, and view log analysis data.
The log query methods of Agentic SOC log management are the same as those of Security Center log analysis. For more information, see Log analysis.
Standardized logs
Delivery description
-
Standardized logs are logs produced after Agentic SOC consumes and analyzes ingested logs and standardizes them into a common schema. Standardized logs contain standard fields mapped by SPL (Search Processing Language) syntax. You cannot enable or disable the delivery of standardized logs. Delivery is enabled in the following scenarios:
-
When the Standardization Method of an access policy is set to Real-time Consumption, Agentic SOC delivers normalized logs to the corresponding Logstore by standardized category by default. A log delivery task is created when you create the access policy.
-
After you create custom rules, standardized alert logs generated by the custom rules are delivered. Examples include EDR alert logs and firewall alert logs.
-
-
If Extended Field Ingestion of the standardized rule is set to Retain As Is, unmapped original fields are also included in standardized logs (stored in a flattened Key-Value format). For more information, see View log format standardization V2.
View log reference count
-
On the Log Management page, click Log Settings.
-
You can view the reference count of standardized structures on the Log Settings panel, on the Standardized Log tab.
NoteThe reference count indicates the number of access policies that use the corresponding standardized category and structure and whose Standardization Method is Real-time Consumption.
Query logs
Agentic SOC supports searching logs by standardized log structure and querying data across multiple Logstores by using datasets (StoreView). For more information about Logstore query and analysis, see Query and analyze logs.
Log storage management
Modify log retention period
The default retention period for delivered logs is 180 days. You can modify the log retention period as needed.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
-
In the upper-right corner of the Log Management page, click Log Settings.
-
On the Log Settings panel, on the Security Center Logs or Standardized Log tab, click the
icon in the Log Retention Period (TTL) column to modify the log retention period.
Scale out or delete storage capacity
You can view the current log usage and total capacity on the page. You can scale out or clear log storage space as needed.
-
Click Scale Out to purchase more log storage capacity.
Make sure that log storage space is sufficient. If log storage space is full, new logs cannot be delivered.
-
Click Delete to clear all storage space. It takes approximately 0 to 24 hours to clear logs. Please be patient.
WarningAfter storage space is cleared, log data cannot be restored. Export and back up logs before you clear storage space.
Reduce log delivery volume
When log storage costs are high, you can view the storage proportion of each log type and disable unnecessary log types to reduce delivery volume and storage costs.
-
Log on to the SLS console, find the dedicated project of Security Center (named in the format
aliyun-cloudsiem-data-{Alibaba Cloud account ID}-{RegionID}). In the query box of the Logstore, group and count logs by the__topic__field to view the distribution of each log type and identify log types with high storage usage (such as logon logs, network connection logs, and process startup logs). -
-
On the Log Management page, click Log Settings.
-
On the Log Settings panel, switch to the Security Center Logs tab and turn off the delivery switch for the log type that you want to stop delivering.
After log delivery is disabled, logs of the corresponding type are no longer delivered to SLS. Historical logs that are already stored are not affected and are automatically deleted after the original retention period expires. We recommend that you evaluate security compliance requirements before disabling a log type.
FAQ
Why can't I enable pay-as-you-go for log management?
Any of the following reasons can prevent you from enabling pay-as-you-go for log management.
-
Reason 1: You have purchased Agentic SOC log storage capacity or log analysis on a subscription basis.
Solution:
-
Reason 2: Agentic SOC uses the 1.0 architecture.
Solution:
NoteIf you decide not to upgrade to Agentic SOC 2.0 architecture for now but need to use log management, you can purchase Agentic SOC log storage capacity on a subscription basis.
-
Reason 3: You purchased Agentic SOC log storage capacity on a subscription basis on or before April 26, 2024, and use Agentic SOC features.
After these users upgrade to Agentic SOC 2.0 architecture, they retain the same amount of Agentic SOC log storage capacity as previously purchased (subscription mode) and can use log management normally. To switch from subscription to pay-as-you-go, refer to the solution for Reason 1. For more information about Agentic SOC architecture upgrade, see [Notice] Agentic SOC upgrade.
What is the difference between log analysis and log management?
Both log analysis and log management are security log query and analysis capabilities provided by Security Center. Compared with log analysis, log management not only provides delivery and analysis capabilities for logs from Security Center modules (vulnerabilities, security alerts, and client events), but also supports delivery and storage of logs normalized by Agentic SOC. If you have classified protection compliance or other security log storage and analysis requirements, we recommend that you use log management.
-
Log analysis is suitable for scenarios where you need to quickly view Security Center logs.
-
Log management is suitable for scenarios where you need long-term storage, compliance auditing, and querying of standardized logs and network logs.
The following table describes the differences between the two features:
|
Feature name |
Supported log types |
Billing method |
Storage region management |
Log retention period management |
|
Log management (recommended) |
|
|
Default: China (Shanghai). You can change the storage region only when enabling pay-as-you-go. |
You can set the log retention period in the Log Settings panel. |
|
Security Center logs |
Subscription |
Default: China (Hangzhou). Cannot be changed. |
Default: 180 days. Cannot be changed. |
Related documents
-
You can download logs or query analysis results to your local machine from the console, Cloud Shell, or command-line tool. For more information, see Download logs.
-
You can deliver logs to OSS for storage. For more information, see Deliver logs to OSS.
-
If log storage space is full, new logs cannot be written. You can enable Agentic SOC log overlimit alerts to scale out log storage capacity in a timely manner. For more information, see Configure log overlimit alerts.