All Products
Search
Document Center

Simple Log Service:Anti-DDoS Origin logs

Last Updated:Mar 04, 2025

Simple Log Service, in partnership with Alibaba Cloud Anti-DDoS Origin, offers a mitigation log analysis feature. Once activated, you can query and analyze mitigation logs that document Anti-DDoS Origin instance events, such as traffic scrubbing, blackhole filtering, and traffic rerouting. This aids in diagnosing abnormal website access and evaluating website operations. This topic describes the asset details, billing rules, and limits associated with the Anti-DDoS Origin log analysis feature.

Asset details

  • Dedicated Project and Dedicated Logstores

    Enabling the Anti-DDoS Origin log analysis feature automatically generates a project named ddosbgp-project-Alibaba Cloud account ID-cn-hangzhou and a Logstore called ddosbgp-logstore.

    Important

    If the pay-by-ingested-data billing mode is enabled, Simple Log Service creates a Logstore using this mode by default. To switch to the pay-by-feature billing mode, you can update the Logstore settings. For more information, see Modify Logstore Configuration.

  • Dedicated Dashboards

    By default, Simple Log Service creates two dashboards.

    Note

    We advise against altering the dedicated dashboards as they may be updated or enhanced at any time. You can create custom dashboards to display your query results. For more information, see Quickly Create Dashboards.

    Dashboard

    Description

    Anti-DDoS Origin Events Report

    Displays statistical reports on blackhole filtering and traffic rerouting events for website protection by Anti-DDoS Origin.

    Anti-DDoS Origin Mitigation Report

    Displays reports on traffic scrubbing for protected websites, including inbound traffic monitoring, inbound traffic distribution, and inbound traffic protocol type distribution.

Billing rules

  • Anti-DDoS Origin sells the log analysis feature, with fees based on log storage duration and capacity. During the public preview, the feature is available at no cost, offering comprehensive traffic log analysis and reporting.

  • Once logs are transferred from Anti-DDoS Origin to Simple Log Service, no charges apply for querying, analyzing, alerting, monitoring, or visualizing in Simple Log Service under the pay-by-feature billing mode. Charges apply for traffic reading, data transformation, data shipping, or alert notifications via text message and voice call according to Simple Log Service's standard rates. For more details, see Billable Items of the Pay-by-Feature Billing Mode.

  • After logs are collected from Anti-DDoS Origin to Simple Log Service, if the Logstore operates under the pay-by-ingested-data billing mode, there are no charges for query, analysis, alerting, monitoring, visualization, data transformation, or data shipping. Only read traffic over the Internet incurs charges, which are included in the Simple Log Service bills. For more details, see Billable Items of the Pay-by-Ingested-Data Billing Mode.

Limits

  • Only Anti-DDoS Origin logs can be written to the dedicated Logstore, with no restrictions on querying, analyzing, alerting, or consuming features.

  • A dedicated Logstore cannot be deleted.

  • The retention period of a dedicated Logstore cannot be changed in the Simple Log Service console. However, you can adjust the retention period (30 to 180 days) in the Anti-DDoS console.

  • Sufficient log storage capacity is required. If capacity is full, new logs cannot be stored.

    Note

    The log storage usage shown in the console is not real-time and excludes the past two hours of usage.