All Products
Search
Document Center

Simple Log Service:Log collection reference for cloud services

Last Updated:Jun 02, 2026

After you create a collection rule in Log Audit Service, cloud service logs are delivered to the associated project. This topic lists the service codes, log type codes, log types, default projects, and default Logstores for each cloud service.

Log Service

Cloud service code

sls

project

Log type code

audit_log

error_log

monitor_metric

operation_log

run_log

Log type

Global audit logs

Global error logs

Performance metrics

Detailed logs

Operational logs

Default project

log-service-{UID}-{Region}

log-service-{UID}-{Region}

Default logstore

internal-audit_log

internal-error_log

internal-monitor-metric

internal-operation_log

internal-diagnostic_log

Additional information

  • You must configure the storage region for global log types.

  • You must set the resource matching mode to All Resources.

  • When you create a project or enable CloudLens for SLS, the system automatically creates a built-in rule named internal_cloudlens_{productCode}_{dataCode}. Enable the log collection feature.

None

None

Billing

The default logstore for log delivery and the centralized logstore in Log Audit Service both use standard logstore pricing. Billable items for pay-by-feature and Billable items of the pay-by-ingested-data mode.

Object Storage Service (OSS)

Cloud service code

oss

Log type code

access_log

metering_log

Log type

access logs

metering logs

Default project

oss-log-{UID}-{Region}

oss-log-{UID}-{Region}

Default logstore

oss-log-store

oss-metering-log

Additional information

None

You must configure a storage region for global log types.

Billing

  • The default project and logstore for log ingestion are billed based on the pricing of the corresponding cloud service.

  • Standard charges apply to centralized logstores in Log Audit Service.

ApsaraDB RDS

Service code

rds

Log type code

audit_log

slow_log

error_log

perf_metric

Log type

Audit log

Slow query log

Error log

Performance metrics

Default destination project

aliyun-product-data-{UID}-{Region}

aliyun-product-data-{UID}-{Region}

Default destination Logstore

rds_audit_log

slow_error_log

slow_error_log

rds_metric

Notes

  • ApsaraDB RDS for MySQL: Basic Edition is not supported.

  • ApsaraDB RDS for PostgreSQL: Basic Edition is not supported.

  • Simple Log Service writes logs by assuming the AliyunLogArchiveRole. You must manually create this role using your Alibaba Cloud account.

Additional charges

  • The default Logstore for log collection and the centralized Logstore for Log Audit Service use standard Logstore pricing. Billable items for Pay-By-Feature and Billable items for Pay-By-Ingested-Data.

  • After you enable audit log collection for ApsaraDB RDS, SQL Explorer and Audit is automatically enabled for eligible ApsaraDB RDS instances. Eligible instances include non-Basic Edition instances of ApsaraDB RDS for MySQL and ApsaraDB RDS for PostgreSQL High-availability Edition instances. Billable items.

  • To manually disable SQL Explorer and Audit in the ApsaraDB RDS console, first disable all collection rules for ApsaraDB RDS audit logs in Log Audit Service and ensure that automatic collection is also disabled for CloudLens for RDS and earlier Log Audit Service versions. SQL Explorer and Audit.

The default Logstore for log collection and the centralized Logstore for Log Audit Service use standard Logstore pricing. Billable items for Pay-By-Feature and Billable items for Pay-By-Ingested-Data.

PolarDB

Product code

polardb

Log type code

audit_log

slow_log

error_log

perf_metric

Log type

audit log

slow log

error log

performance monitoring

Default Project

aliyun-product-data-{UID}-{Region}

aliyun-product-data-{UID}-{Region}

Default Logstore

polardb_audit_log

polardb_log

polardb_log

polardb_metric

Additional information

  • Only MySQL is supported.

Additional fees for Log Service and the cloud product

  • Standard charges apply to the default Logstore for log delivery and the centralized Logstore in Log Audit.

  • Enabling audit log collection for PolarDB automatically enables SQL Insight for the MySQL cluster. Billable Items.

  • You can manually disable SQL Insight in the PolarDB console if you have disabled all collection rules for PolarDB audit logs in Log Audit and ensured that automatic collection is also disabled in CloudLens for PolarDB and the previous version of Log Audit. SQL Insight.

The default Logstore and the centralized Logstore in Log Audit use standard Logstore pricing. Billable Items for Pay-by-Function Mode and Billable Items for Pay-by-Write-Volume Mode.

E-MapReduce

Product code

Log type code

Type

Default ingestion project

Default ingestion logstore

Description

Billing

emr

yarn_log

YARN component log

emr-log-{UID}-{Region}

emr_yarn_log

None

host_log

host log

emr_host_log

spark_log

Spark component log

emr_spark_log

hive_log

Hive component log

emr_hive_log

yarn_application_log

YARN container log

emr_yarn_application_log

tez_log

Tez component log

emr_tez_log

hdfs_log

HDFS component log

emr_hdfs_log

flink_log

Flink component log

emr_flink_log

jindo_log

Jindo component log

emr_jindo_log

hbase_log

HBase component log

emr_hbase_log

zookeeper_log

ZooKeeper component log

emr_zookeeper_log

kafka_log

Kafka component log

emr_kafka_log

presto_log

Presto component log

emr_presto_log

impala_log

Impala component log

emr_impala_log

flume_log

Flume component log

emr_flume_log

starrocks_log

StarRocks component log

emr_starrocks_log

clickhouse_log

ClickHouse component log

emr_clickhouse_log

kyuubi_log

Kyuubi component log

emr_kyuubi_log

kudu_log

Kudu component log

emr_kudu_log

rss_log

RSS component log

emr_rss_log

ranger_log

Ranger component log

emr_ranger_log

trino_log

Trino component log

emr_trino_log

ldap_log

OpenLDAP component log

emr_ldap_log

Application Load Balancer (ALB)

Product code

alb

Log type code

access_log

Log type

access log

Default Log Service Project

aliyun-product-data-{UID}-{Region}

Default Log Service Logstore

alb_access_log

Additional information

None

Additional charges

  • Standard charges apply to the default Logstore for log delivery and the centralized Logstore for log audit.

  • By default, the default Logstore also receives related metrics in addition to access logs.

Classic Load Balancer (CLB)

Service code

clb

Type code

access_log

Type

access log

Default project

aliyun-product-data-{UID}-{Region}

Default logstore

clb_access_log

Description

None

Billing

Standard charges apply to the default logstore and the destination logstore in Log Audit Service.

Virtual Private Cloud (VPC)

Product code

vpc

Log type code

flow_log

Log type

flow log

Default destination Project

aliyun-product-data-{UID}-{Region}

Default destination Logstore

vpc_log

Additional information

To enable VPC flow logs, you must meet these prerequisites:

  1. Activate Simple Log Service.

  2. You must authorize the AliyunVPCLogArchiveRole role, which VPC uses by default to access Simple Log Service.

Flow logs.

Additional fee information

  • The total cost for flow logs includes log generation fees and Simple Log Service fees.

  • Standard charges apply to both the default Logstore that receives logs and the centralized destination Logstore used for auditing.

  • VPC charges a fee to generate flow logs. Flow log billing.

MongoDB

Cloud service code

dds

Log type code

audit_log

Log type

Audit logs

Default project

nosql-{UID}-{Region}

Default Logstore

mongo_audit_log_standard

Additional information

  • Ensure that the AliyunServiceRoleForMongoDB service-linked role is authorized. If not, follow the linked instructions to grant the required permissions.

  • When you enable audit logs for ApsaraDB for MongoDB, the slow query logs feature is also automatically enabled.

Additional fees

None

Alibaba Cloud DNS

Cloud service code

dns

Log type code

intranet_log

Log type

private DNS log

Default project

aliyun-product-data-{UID}-{Region}

Default Logstore

dns_log

Additional information

  • Instance-related resources configured in a rule map to instances within the VPCs in your Alibaba Cloud account.

  • For each Alibaba Cloud account, go to the new DNS console and activate the PrivateZone service.

Billing details

  • Private DNS log collection incurs costs for two services: network traffic analysis and SLS. Alibaba Cloud DNS charges a fee to generate network traffic analysis data. Network Traffic Analysis.

  • Delivering logs to the default Logstore and the centralized destination Logstore in Log Audit Service incurs standard charges.

NAS

Cloud service code

nas

Log type code

common_log

Log type

NAS access logs

Default project

nas-log-{UID}-{Region}

Default logstore

nas-nfs

Additional information

Additional fees

None

Bastionhost

Service code

bastion

Log type code

audit_log

Log type

audit log

Default project

aliyun-product-data-{UID}-{Region}

Default logstore

bastion_log

Description

  • This service relies on cloud resource for asset synchronization. If this integration is disabled, you must manually create it to ensure that automated log collection works correctly.

Fees

None

Web application firewall (WAF) 2.0

Cloud service code

waf

Log type code

access_log

Log type

access log

Default project

waf-project-{UID}-{region}

Default Logstore

waf-Logstore

Notes

  • The resource matching mode must be set to attribute mode.

  • In attribute mode, you must specify the list of regions for the default Logstore.

Billing

  • The default Logstore is billed according to the pricing of the cloud service.

  • Standard charges apply to the destination Logstore.

  • You must enable log collection in the cloud service console to deliver logs to the default Logstore. Log Audit Service then delivers these logs to the destination Logstore.

WAF 3.0 (Pay-as-you-go)

Cloud service code

wafnew

Log type code

access_log

Log type

access log

Default destination Project

wafnew-Project-{UID}-{region}

Default destination Logstore

wafnew-Logstore

Notes

  • You must set the Resource Matching Mode to Attribute Mode.

  • In Attribute Mode, you must configure the regions for the default destination Logstores.

Additional charges

  • Charges for the default destination Logstore are based on the cloud service's pricing.

  • The centralized Logstore in Log Audit is billed at the standard rate.

  • You must enable log delivery to the default destination Project in the WAF console. Log Audit only processes and centrally stores the logs.

Web Application Firewall 3.0 (Subscription)

Product code

wafng

Log type code

access_log

Log type

access log

Default project

wafng-project-{UID}-{region}

Default LogStore

wafng-LogStore

Notes

  • The resource mode must be attribute mode.

  • In attribute mode, you must configure the list of regions for the LogStore used for default log delivery.

Additional fees

  • The default LogStore for log delivery is billed according to the cloud product's pricing.

  • Standard charges apply to the centralized LogStore for log audit.

  • You must enable log delivery to the default Project in the console. Log audit only processes and stores the logs in centralized storage.

Security Center

Cloud service code

sas

Log type code

sas_log

Log type

Security Center logs

Default Project

sas-log-{UID}-{region}

Default Logstore

sas-log

Additional information

  • The resource matching mode must be attribute mode.

  • In attribute mode, specify the regions where the default Logstores are located.

Important

Effective March 27, 2025, you can no longer create new delivery services for network logs (including web access, DNS resolution, network sessions, and local DNS data), but you can still query historical logs. Announcement.

Additional fees

  • The default Logstore for log delivery is charged according to the cloud service's pricing.

  • Standard charges apply to the centralized Logstore in Log Audit Service.

  • Enable log collection in the cloud service console to deliver logs to the default Project. Log Audit Service is only responsible for processing and centrally storing the logs.

Security Center (pay-as-you-go)

Service code

Log type code

Log type

Default project

Default logstore

Notes

Additional fees

sasnew

http

Web access log

sasnew-log-{UID}-{Region}

sas-log-http

Important

Starting March 27, 2025, you can no longer create new delivery configurations for network logs, including web access log, DNS resolution log, network session log, and local DNS log. However, you can still query historical logs. Notice.

  • You must set Resource Matching Mode to Attribute Mode.

  • In Attribute Mode, you must configure the list of regions for the default Logstore.

  • Log delivery to the default Project and Logstore is billed according to the cloud service's pricing.

  • Standard charges apply to the centralized Logstore in Log Audit Service.

  • You must enable log collection on the cloud service console to deliver logs to the default Project. Log Audit Service processes and centrally stores the logs.

session

Network session log

sas-log-session

dns

DNS resolution log

sas-log-dns

local_dns

Local DNS log

local-dns

snapshot_process

Process snapshot log

aegis-snapshot-process

snapshot_port

Network snapshot log

aegis-snapshot-port

snapshot_host

Account snapshot log

aegis-snapshot-host

login

Logon log

aegis-log-login

network

Network connection log

aegis-log-network

process

Process startup log

aegis-log-process

dns_query

DNS request log

aegis-log-dns-query

crack

Brute-force attack log

aegis-log-crack

client

Client event log

aegis-log-client

security

Vulnerability log

sas-security-log

Baseline log

Alert log

Configuration assessment log

Network defense log

Application defense log

Anti-DDoS Origin

Cloud service code

ddosbgp

Log type code

access_log

Log type

access log

Default log collection Project

ddosbgp-project--{UID}-{Region}

Default log collection Logstore

ddosbgp-logstore

Additional information

  • The resource matching mode must be set to Attribute Mode.

  • In Attribute Mode, you must configure the list of regions for the default Logstore.

Additional fees for Simple Log Service and the related cloud service

  • The default Logstore for log delivery is billed based on the pricing of the cloud service.

  • Standard charges apply to the centralized Logstore in Log Audit Service.

  • You must enable log collection in the cloud service console to deliver logs to the default Project. Log Audit Service processes and centrally stores the logs.

Anti-DDoS Proxy (Chinese Mainland)

Cloud service code

ddoscoo

Log type code

access_log

Log type

access log

Default project

ddoscoo-project-{UID}-{Region}

Default Logstore

ddoscoo-LogStore

Additional information

  • The resource matching mode must be attribute mode.

  • In attribute mode, specify the regions for the default Logstore.

Additional fees

  • The cloud service's pricing applies to log delivery to the default Logstore.

  • Standard charges apply to the centralized Logstore in Log Audit Service.

  • Enable log collection in the cloud service console to deliver logs to the default project. Log Audit Service then processes and centrally stores the logs.

Anti-DDoS Proxy (Outside Chinese Mainland)

Product code

ddosdip

Log type code

access_log

Log type

access logs

Default project

ddosdip-project-{UID}-{region}

Default logstore

ddosdip-Logstore

Notes

  • You must set the resource matching mode to attribute mode.

  • In attribute mode, specify the list of regions for the Logstore that handles default log delivery.

Additional fees

  • Log delivery to the default Logstore is billed based on the pricing of the cloud service.

  • Standard charges apply to the centralized Logstore for Log Audit Service.

  • You must enable log collection in the cloud service console. Log Audit Service only processes the logs and provides centralized storage.

KMS

Cloud service code

kms

Log type code

audit_log

Log type

audit log

Default Project for log collection

kms-log-{instanceId}

Default Logstore for log collection

kms_audit_log

Additional information

  • Set the resource matching mode to Attribute Mode.

  • In Attribute Mode, configure the regions for the Logstores used for default log delivery.

Additional fee information for Simple Log Service and the cloud service

  • The pricing of the cloud service applies to the default Logstore for log delivery.

  • Standard charges apply to the centralized Logstore in Log Audit.

  • Enable log collection in the cloud service console to deliver logs to the default Logstore. Log Audit then processes and centrally stores the logs.

Cloud Firewall

Product code

cloudfirewall

Log type code

firewall_log

Log type

firewall log

Default project

cloudfirewall-Project-{UID}-{region}

Default Logstore

cloudfirewall-Logstore

Additional information

  • The resource matching mode must be attribute mode.

  • In attribute mode, configure the list of regions for the default Logstore.

Additional charges

  • Log delivery to the default Logstore incurs charges based on the pricing of the cloud service.

  • Standard charges apply to the centralized Logstore for Log Audit Service.

  • Enable log delivery to the default Project in the cloud service console. Log Audit Service then processes these logs and stores them in centralized storage.

Cloud Firewall (pay-as-you-go)

Product code

cloudfirewallnew

Log type code

firewall_log

Log type

firewall log

Default log project

cloudfirewallnew-project-{UID}-{Region}

Default Logstore

cloudfirewallnew-Logstore

Notes

  • You must set the resource model to the attribute model.

  • In the attribute model, you must configure the regions for the default log delivery Logstores.

Billing

  • The default log delivery Logstore is billed based on the cloud product's pricing.

  • Standard charges apply to the centralized Logstore for log auditing.

  • You must enable logging for the default log delivery Project in the cloud product console. Log auditing only processes and stores the logs in the centralized Logstore.

Container Service for Kubernetes (ACK)

Product code

Log type code

Log type

Default Project

Default Logstore

Notes

Fee description

k8s

k8s_audit_log

Kubernetes audit log

k8s-log-{{cluster_id}}

audit-log-{{cluster_id}}

  • Asset synchronization for this service relies on data from the Cloud Resource Center. Enable the Get Cloud Resource Center properties feature. If not, manually create a Cloud Resource Center. Otherwise, automated log collection may not function correctly.

  • This service only centrally aggregates Kubernetes-related logs. You must enable the source logs.

  • Pricing for the associated cloud service applies to log delivery to the default Project and Logstore.

  • Standard charges apply to the centralized Logstore in Log Audit.

  • Enable log delivery in the console of the source cloud product. Log Audit only processes and centrally stores the collected logs.

k8s_nginx_ingress

Nginx Ingress log

nginx-ingress

k8s_event

Kubernetes event log

k8s-event

API Gateway

Product code

apigw

Log type code

access_log

Log type

API Gateway access log

Default log project

aliyun-product-data-${account-id}-${regionId} 

Default Logstore

acs_apigateway-${regionId}

Additional information

Fees for Log Service and the cloud product

  • The cloud product's pricing applies to log delivery to the default Logstore.

  • Standard charges apply to the centralized Logstore for log audit.