The log analysis feature centrally stores and manages all security-related full logs, provides a unified query and analysis entry point, and helps you quickly identify issues and meet compliance audit requirements.
Enable and configure log analysis
-
Log Analysis and Agentic SOC (Log Management) are two independent feature modules in Security Center. Their console entries and purchase configurations are separate.
-
If you obtained log analysis through a version upgrade, you may still need to go to the Log Analysis page to complete authorization before you can use the feature.
-
Log on to the console
Access the Security Center console - Risk Governance - Log Analysis. In the upper-left corner of the page, select the region of your assets: Chinese Mainland or Outside Chinese Mainland.
-
Service authorization (first-time use)
If this is your first time using this feature, follow the on-screen instructions and click Authorize Immediately.
NoteAfter authorization, the system automatically creates the RAM role
AliyunServiceRoleForSas. Security Center uses this role to access your resources in other Alibaba Cloud services for unified security protection and management. For more information, see Service-linked roles for Security Center. -
Configure and complete purchase
After authorization, click Enable Now. You are redirected to the Security Center purchase page. Configure the following settings:
-
Edition: Select the Security Center edition you need. For edition descriptions, see Edition services.
-
Agentic SOC (Log Storage Capacity): Turn the Purchase or Not to Yes, and set the monthly storage capacity based on your business needs.
-
Subscription Duration: Select the subscription duration.
-
-
Read and select I have read and agree to the Security Center Terms of Service, click Order Now, and complete the payment.
-
Create log repository
After purchase, Security Center automatically creates a Project (
sas-log-{Alibaba Cloud account ID}-{region ID}) and a Logstore (sas-log) in Simple Log Service (SLS) based on the regions where your assets are located.Important-
For the mapping between asset regions and log storage regions, see Log storage regions.
-
Do not delete the Project or Logstore. Deletion causes permanent data loss that cannot be recovered.
-
Log capacity analysis and delivery management
If log delivery volume is too large and storage costs are too high, analyze the data volume distribution by log type and selectively disable delivery for high-volume log types to reduce costs.
-
In the upper-right corner of the log page, click Log Settings.
-
On the log management settings page, view the delivered log types, including logon records, network connections, process starts, and other host logs.
-
To view the data volume distribution by log type, go to Simple Log Service console. Find the Project (format:
sas-log-{Alibaba Cloud account ID}-{region ID}) and Logstore (sas-log) that correspond to Security Center. Query the__topic__field to view the log volume distribution by log type. -
On the log management settings page, disable delivery for high-volume log types. After you disable delivery, logs of that type are no longer collected or stored, and storage capacity consumption decreases accordingly.
Billing
Log analysis is a value-added feature billed separately from your Security Center edition.
-
Billing method: Subscription only.
-
Billable item: Subscribed log storage capacity (subscription billing).
NoteIf the monthly log storage capacity is unused, it will be cleared at the start of the next month.
-
Price: USD 0.1/GB/month.
-
Capacity recommendation: Per China's Cybersecurity Law, logs should be retained for at least 180 days. Allocate 50 GB of log storage per server, then adjust based on actual log volume.
-
Cost example: For 10 servers with 50 GB each, total = 500 GB. Monthly cost: .
Limitations
-
Log storage region restrictions
The log storage region is determined by the region where your assets are located. It cannot be customized.
Asset region
Log Project region
Region ID
Description
Chinese Mainland
China (Hangzhou)
cn-hangzhouAll asset logs in the Chinese Mainland region are consolidated and stored in the Hangzhou region.
Outside Chinese Mainland
Singapore
ap-southeast-1All asset logs outside the Chinese Mainland, including Hong Kong (China), are consolidated and stored in the Singapore region.
-
Logstore restrictions
To preserve data integrity and format consistency, the dedicated Logstore (sas-log) has the following restrictions:
-
You cannot write data to the Logstore via API or SDK.
-
You cannot modify Logstore properties such as the storage period.
-
The dedicated Logstore (sas-log) is automatically created by Security Center and is exclusive to your Alibaba Cloud account. It is not a multi-tenant shared instance, ensuring data isolation and security.
-
FAQ
-
What happens when storage capacity is exhausted?
-
Impact: New logs cannot be written to storage.
-
Solution: Go to the Security Center console - Overview page, find the Subscription section, and click Change Configuration > Upgrade Now. For details, see Upgrade and downgrade Security Center.
-
-
I already use Simple Log Service (SLS). Do I still need to enable log analysis for Security Center?
Yes. The comparison is as follows:
-
Self-managed SLS: Typically collects OS or application logs from servers.
-
Log Analysis: In addition to basic host logs, it also centrally stores and analyzes security event logs generated by Security Center itself — including security alerts, vulnerabilities, and baseline check results — providing a comprehensive security audit and forensic platform.
-
-
I accidentally deleted the dedicated
sas-logLogstore. What should I do?All stored data is permanently lost and cannot be recovered, and log analysis stops immediately. Return to the Log Analysis page in the Security Center console and re-enable the feature as prompted. The system creates a new Project and Logstore, but historical data cannot be retrieved.
-
Why does the console still show log analysis as not enabled after I purchased it?
Troubleshoot as follows:
-
Verify that you purchased the Log Analysis add-on service, not Agentic SOC or other security modules. Different modules have separate console entries and independent features.
-
Try logging in using an incognito browser window to rule out browser cache issues.
-
Check RAM permissions. Ensure the current account has the
AliyunSASFullAccessaccess policy. -
Confirm you have completed the first-time service authorization (the system needs to create the RAM role
AliyunServiceRoleForSas). If not yet authorized, go to the Log Analysis page and follow the on-screen instructions.
-
-
Why can't I find historical logs after enabling log analysis?
Log analysis only collects and stores logs after the feature is enabled. If you did not enable the feature immediately after purchase — for example, you did not turn on the feature switch or complete SLS authorization — no logs are collected during that period. As a result, you cannot query logs from that time. Enable and configure the feature as soon as possible after purchase to ensure continuous log collection.
-
I have purchased log storage capacity, but log usage or log count shows 0. Does this mean the feature is not working?
Not necessarily. Follow these steps to troubleshoot:
-
On the Overview page, in the pay-as-you-go services section, check whether the switch for the log analysis feature is turned on and the service status shows as enabled.
-
Go to the Risk GovernanceLog Analysis page and check the query time range. By default, the query time range is set to Last 15 Minutes. If no logs were generated during that window, the log usage shows 0 GB and the log count shows 0. Change the time range to Last 7 Days or Today, and click Search & Analyze to query again.
-
Clear any query statement in the search box, and click Search & Analyze to check whether log data is returned.
-
Use the log type drop-down list to switch between different log types and confirm whether data exists for the selected type.
NoteLogs are automatically uploaded by the underlying system of Security Center, including logon records, process starts, and network connections. If no log data appears for an extended period, check whether the Security Center agent is installed on the asset.
-
-
Why is the log capacity displayed as 0?
A log capacity of 0 usually does not mean that logs are not being collected. In most cases, this happens because the query time range is too narrow. The default query time range in the console is 15 minutes, and no capacity is shown if no logs were written during that window. Troubleshoot as follows:
-
Check the current query time range on the log query page. The default time range is 15 minutes.
-
Expand the time range (for example, to 1 week) and query again to see if the log capacity is displayed correctly.
-
If the capacity is still 0 after expanding the time range, go to and click Log Settings in the upper-right corner of the page, then confirm that delivery of the required log type has not been disabled (once delivery is disabled, logs of that type are no longer collected or stored).
-
If log delivery is enabled but there is still no data, confirm that log analysis has been enabled and authorized (see "Enable and configure log analysis" in this topic), because no log data is generated for periods before the feature is enabled.
-