All Products
Search
Document Center

Security Center:Log management

Last Updated:Aug 24, 2026

The log management feature can store and query logs to help accurately locate alerts, trace attacks, and improve response speed. This topic describes the basic information about the log management feature and how to use it.

Log type description

Log type

Usage conditions

Data source description

Supported categories and field description

Security Center logs

Enable the log management feature.

Store logs generated by various feature modules of Alibaba Cloud Security Center. Examples include vulnerability logs, security alert logs, and client event logs.

View the log center library address, EtlMetaName, and field descriptions

Standardized logs

Enable the log management feature and the Agentic SOC feature.

  • Store standardized logs generated when an Alibaba Cloud user purchases log ingestion traffic on a subscription basis or enables pay-as-you-go for Agentic SOC, and the standardization method of the access policy is Real-time Consumption.

  • After you create custom rules, standardized alert logs generated by the custom rules are stored. Examples include endpoint detection and response (EDR) alert logs and firewall alert logs.

On the Agentic SOC > Manage > Integration SettingsStandardized Rule tab, click View Standard Fields. You can view the categories and field descriptions of standardized logs in the Standard Fields panel.

Billing description

  • Subscription mode: Fees are charged based on the purchased log storage capacity and subscription duration, USD 100/1000 GB/month (minimum purchase: 1,000 GB; increment: 1,000 GB).

  • Pay-as-you-go mode: After you enable pay-as-you-go for log management, the system calculates the daily cumulative storage volume (GB) for each calendar day and charges fees based on USD 7.2/1000 GB per calendar day.

    Important

    The minimum billing unit for pay-as-you-go log management is 1,000 GB. Volumes less than 1,000 GB are billed as 1,000 GB. For example, if the daily usage is 1,900 GB, you are charged for 2,000 GB.

No additional fees are generated when you query or export logs in the Security Center console. After the log management feature delivers logs to Simple Log Service (SLS), if you process or ship log data in the SLS console, you may need to pay additional fees for these operations.

  • When the billing mode of the Logstore is pay-by-feature, data transformation, shipping, and streaming reads from an Internet-facing endpoint in SLS are charged by SLS. For more information, see Billable items in the pay-by-feature billing mode.

  • When the billing mode of the Logstore is pay-by-ingested-data, data transformation and shipping in SLS are free of charge. Only Internet data reads are charged based on the standard SLS rates. For more information, see Billable items in the pay-by-ingested-data billing mode.

Log storage description

After you enable the log management feature, the system automatically creates a dedicated project (named aliyun-cloudsiem-data-<Alibaba Cloud account ID>-<RegionID>) and a Logstore in SLS to store Security Center logs and standardized logs. The log storage region depends on the service region that you select in the upper-left corner of the Security Center console.

  • If you select Chinese Mainland, logs are stored in the China (Shanghai) region by default.

  • If you select Outside Chinese Mainland, logs are stored in the Singapore region.

Important
  • You can change the log storage region only in the dialog box that appears when you enable pay-as-you-go for log management. Users who purchase log storage capacity on a subscription basis cannot change the log storage region.

  • You can log on to the SLS console to view the dedicated project and Logstore. Do not delete the project or Logstore.

    If you accidentally delete the Logstore, the corresponding log data is lost. Lost log data cannot be recovered.

After a delivery task is enabled, Security Center automatically delivers logs to the corresponding log library. Delivered logs are retained until the configured retention period expires, and then the corresponding log data is deleted. If log storage space is exhausted in subscription mode, new logs stop being delivered. When the used log capacity exceeds 80% of the total capacity, Security Center supports sending notification messages. For more information about notification settings, see Configure log overlimit alerts.

Enable or disable log management

Important

Before you perform the following operations, make sure that the account has the following permissions:

  • Alibaba Cloud account: All permissions by default.

  • RAM user: Must be granted the management permissions of Security Center (for example, AliyunYundunSASFullAccess).

Enable log management

You can enable the log management feature only by using either the subscription or pay-as-you-go billing method. For more information about billing, see Billing description.

  1. Log on to Security Center console.

  2. In the left-side navigation pane, choose Detection and Response > Log Management. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

    For users who have purchased Agentic SOC log ingestion traffic on a subscription basis or enabled pay-as-you-go for Agentic SOC, the left-side navigation pane entry changes to Agentic SOC > Log.

  3. On the Log Management page, click Subscribe (Annual/Monthly) or Activate Pay-as-you-go.

    Note

    For users who have purchased Agentic SOC log ingestion traffic on a subscription basis or enabled pay-as-you-go for Agentic SOC, click Enable Pay-as-you-go for Log Management in the upper-right corner of the current page, or upgrade to purchase Agentic SOC log storage capacity. For more information, see Upgrade or downgrade.

    • Enable subscription mode: On the purchase page, set Purchase or Not for Agentic SOC to Yes, select the required log storage capacity, and click Order Now to complete the payment.

      You can purchase other Security Center features as needed. For more information, see Purchase guide.

    • Enable pay-as-you-go mode: In the dialog box, read the billing rules, select a storage region, and click Activate and Authorize.

  4. After the feature is enabled, return to the Log Management page and check whether the service status is Enabled. Log data will start being delivered to SLS within a few minutes.

Disable log management

  1. Log on to Security Center console.

  2. In the left-side navigation pane, choose Agentic SOC > Log. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  3. On the Log Management page, make sure that Log Usage is 0 GB.

    If the log usage is not 0, click Delete in the upper-right corner of the current page, wait for the log usage to be cleared, and then proceed to the next step.

  4. You can disable the log management feature in the following ways.

    • Subscription mode

      • Method 1: Downgrade

        1. On the Overview page, click Change Configuration > Downgrade to go to the Downgrade page.

        2. On the Order Downgrade tab, set Agentic SOC (Log Storage Capacity) in the Agentic SOC section to 0 GB.

        3. Read and select the Security Center Service Agreement, and then click Order Now.

      • Method 2: Unsubscribe from the purchased Security Center instance. For more information, see Unsubscribe from a subscription.

    • Pay-as-you-go mode: On the Overview page of the Security Center console, in the Enable Pay-as-You-Go Service section, turn off the Log Management switch.

      Important

      After you disable the log management switch, log delivery is automatically disabled, and the corresponding Logstore is deleted. Deleted log data cannot be restored. We recommend that you proceed with caution.

Description for users who only purchase log ingestion traffic or enable pay-as-you-go for Agentic SOC

If you have purchased Agentic SOC log ingestion traffic on a subscription basis or enabled pay-as-you-go for Agentic SOC but have not purchased log storage capacity, you can query some standardized logs on the Log Management page. The supported logs are from access policies whose Standardization Method is Scan Query.

In this scenario, Security Center logs cannot be delivered or viewed, and standardized logs from access policies whose Standardization Method is Real-time Consumption cannot be delivered or viewed. For more information about features supported by different billing items, see Log management billing overview.

Security Center logs

Enable delivery

After you purchase log storage capacity, Agentic SOC enables delivery for all Security Center log types by default. If you have not purchased the corresponding value-added services, such as application protection or malicious file detection, the delivery switches for the corresponding log types remain disabled.

You can click Log Management Settings on the Log Management page to view and configure the delivery status of each log type.

On the log management settings page, the Basic Settings area displays the log delivery region as China (Shanghai) and the log delivery language as Chinese. In the Log Storage Management area, on the Security Center Logs tab, the host log types include:

  • Brute-force attacks (aegis-log-crack)

  • Process snapshots (aegis-snapshot-process)

  • DNS requests (aegis-log-dns-query)

  • Account snapshots (aegis-snapshot-host)

  • Client events (aegis-log-client)

  • Logon logs (aegis-log-login)

  • Network connections (aegis-log-network)

  • Network snapshots (aegis-snapshot-port)

  • Process startup (aegis-log-process)

All delivery switches are turned on, and the log retention period is 180 days.

Query logs

  1. In the left-side navigation pane, choose Agentic SOC > Log. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  2. In the upper-left corner of the Log Management page, click Security Center Logs and select the log type that you want to view.

  3. Set a query time range, retrieve logs by using query statements, and view log analysis data.

    The log query methods of Agentic SOC log management are the same as those of Security Center log analysis. For more information, see Log analysis.

Standardized logs

Delivery description

  • Standardized logs are logs produced after Agentic SOC consumes and analyzes ingested logs and standardizes them into a common schema. Standardized logs contain standard fields mapped by SPL (Search Processing Language) syntax. You cannot enable or disable the delivery of standardized logs. Delivery is enabled in the following scenarios:

    • When the Standardization Method of an access policy is set to Real-time Consumption, Agentic SOC delivers normalized logs to the corresponding Logstore by standardized category by default. A log delivery task is created when you create the access policy.

    • After you create custom rules, standardized alert logs generated by the custom rules are delivered. Examples include EDR alert logs and firewall alert logs.

  • If Extended Field Ingestion of the standardized rule is set to Retain As Is, unmapped original fields are also included in standardized logs (stored in a flattened Key-Value format). For more information, see View log format standardization V2.

View log reference count

  1. On the Log Management page, click Log Settings.

  2. You can view the reference count of standardized structures on the Log Settings panel, on the Standardized Log tab.

    Note

    The reference count indicates the number of access policies that use the corresponding standardized category and structure and whose Standardization Method is Real-time Consumption.

Query logs

Agentic SOC supports searching logs by standardized log structure and querying data across multiple Logstores by using datasets (StoreView). For more information about Logstore query and analysis, see Query and analyze logs.

Log storage management

Modify log retention period

The default retention period for delivered logs is 180 days. You can modify the log retention period as needed.

  1. In the left-side navigation pane, choose Agentic SOC > Log. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  2. In the upper-right corner of the Log Management page, click Log Settings.

  3. On the Log Settings panel, on the Security Center Logs or Standardized Log tab, click the image icon in the Log Retention Period (TTL) column to modify the log retention period.

Scale out or delete storage capacity

You can view the current log usage and total capacity on the Agentic SOC > Log page. You can scale out or clear log storage space as needed.

  • Click Scale Out to purchase more log storage capacity.

    Make sure that log storage space is sufficient. If log storage space is full, new logs cannot be delivered.

  • Click Delete to clear all storage space. It takes approximately 0 to 24 hours to clear logs. Please be patient.

    Warning

    After storage space is cleared, log data cannot be restored. Export and back up logs before you clear storage space.

Reduce log delivery volume

When log storage costs are high, you can view the storage proportion of each log type and disable unnecessary log types to reduce delivery volume and storage costs.

  1. Log on to the SLS console, find the dedicated project of Security Center (named in the format aliyun-cloudsiem-data-{Alibaba Cloud account ID}-{RegionID}). In the query box of the Logstore, group and count logs by the __topic__ field to view the distribution of each log type and identify log types with high storage usage (such as logon logs, network connection logs, and process startup logs).

  2. In the left-side navigation pane, choose Agentic SOC > Log. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  3. On the Log Management page, click Log Settings.

  4. On the Log Settings panel, switch to the Security Center Logs tab and turn off the delivery switch for the log type that you want to stop delivering.

After log delivery is disabled, logs of the corresponding type are no longer delivered to SLS. Historical logs that are already stored are not affected and are automatically deleted after the original retention period expires. We recommend that you evaluate security compliance requirements before disabling a log type.

FAQ

Why can't I enable pay-as-you-go for log management?

Any of the following reasons can prevent you from enabling pay-as-you-go for log management.

What is the difference between log analysis and log management?

Both log analysis and log management are security log query and analysis capabilities provided by Security Center. Compared with log analysis, log management not only provides delivery and analysis capabilities for logs from Security Center modules (vulnerabilities, security alerts, and client events), but also supports delivery and storage of logs normalized by Agentic SOC. If you have classified protection compliance or other security log storage and analysis requirements, we recommend that you use log management.

  • Log analysis is suitable for scenarios where you need to quickly view Security Center logs.

  • Log management is suitable for scenarios where you need long-term storage, compliance auditing, and querying of standardized logs and network logs.

The following table describes the differences between the two features:

Feature name

Supported log types

Billing method

Storage region management

Log retention period management

Log management (recommended)

  • Security Center logs

  • Standardized logs

  • Subscription

  • Pay-as-you-go

Default: China (Shanghai).

You can change the storage region only when enabling pay-as-you-go.

You can set the log retention period in the Log Settings panel.

Log analysis

Security Center logs

Subscription

Default: China (Hangzhou). Cannot be changed.

Default: 180 days. Cannot be changed.

Related documents

  • You can download logs or query analysis results to your local machine from the console, Cloud Shell, or command-line tool. For more information, see Download logs.

  • You can deliver logs to OSS for storage. For more information, see Deliver logs to OSS.

  • If log storage space is full, new logs cannot be written. You can enable Agentic SOC log overlimit alerts to scale out log storage capacity in a timely manner. For more information, see Configure log overlimit alerts.