All Products
Search
Document Center

Simple Log Service:TagResources

Last Updated:Mar 27, 2026

Creates and adds tags to a resource. You can add tags only to projects.

Operation description

Usage notes

  • Host consists of a project name and a Simple Log Service endpoint. You must specify a project in Host.

  • An AccessKey pair is created and obtained. For more information, see AccessKey pair.

The AccessKey pair of an Alibaba Cloud account has permissions on all API operations. Using these credentials to perform operations in Simple Log Service is a high-risk operation. We recommend that you use a Resource Access Management (RAM) user to call API operations or perform routine O&M. To create a RAM user, log on to the RAM console. Make sure that the RAM user has the management permissions on Simple Log Service resources. For more information, see Create a RAM user and authorize the RAM user to access Simple Log Service.

  • The information that is required to query logs is obtained. The information includes the name of the project to which the logs belong and the region of the project. For more information, see Manage a project

  • For more information, see Authorization rules. The following types of resources are supported: project, Logstore, dashboard, machine group, and Logtail configuration.

Authentication resources

The following table describes the authorization information that is required for this operation. You can add the information to the Action element of a RAM policy statement to grant a RAM user or a RAM role the permissions to call this operation.

Action Resource
log:TagResources The resource format varies based on the resource type.-acs:log:{#regionId}:{#accountId}:project/{#ProjectName}-acs:log:${regionName}:${accountId}:project/${projectName}/logstore/${logstoreName}-acs:log:${regionName}:${accountId}:project/${projectName}/dashboard/${dashboardName}-acs:log:${regionName}:${accountId}:project/${projectName}/machinegroup/${machineGroupName}-acs:log:${regionName}:${accountId}:project/${projectName}/logtailconfig/${logtailConfigName}

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

log:TagResources

create

*Project

acs:log:{#regionId}:{#accountId}:project/{#ProjectName}

  • log:TLSVersion
None

Request syntax

POST /tag HTTP/1.1

Request parameters

Parameter

Type

Required

Description

Example

body

object

Yes

The request struct.

resourceType

string

Yes

The type of the resource. Valid values:

  • project

  • logstore

  • dashboard

  • machinegroup

  • logtailconfig

project

resourceId

array

Yes

The resource IDs. You can specify only one resource and add tags to the resource.

string

No

The resource ID. In this example, a Logstore is used. projectName indicates the project name. # is used to concatenate strings. logstore indicates the Logstore name.

  • project: projectName

  • logstore: projectName#logstore

  • dashboard: projectName#dashboard

  • machinegroup: projectName#machinegroup

  • logtailconfig: projectName#logtailconfig

ali-test-project

tags

array<object>

Yes

The tags that you want to add to the resource. You can specify up to 20 tags in each call. Each tag is a key-value pair.

object

No

key

string

Yes

The key of the tag. The key must meet the following requirements:

  • The key must be 1 to 128 characters in length.

  • The key cannot contain http:// or https://.

  • The key cannot start with acs: or aliyun.

key1

value

string

Yes

The value of the tag. The value must meet the following requirements:

  • The value must be 1 to 128 characters in length.

  • The value cannot contain http:// or https://.

value1

Response elements

Element

Type

Description

Example

None defined.

Examples

Success response

JSON format

{}

Error codes

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.