All Products
Search
Document Center

Simple Log Service:Ingest OSS Bucket access logs into Log Audit

Last Updated:Jul 17, 2026

Use Log Audit to collect access logs from OSS Buckets in different regions into a single Log Service Project.

How it works

image

Prerequisites

1. Associate a Project

The associated Project collects logs from your OSS Buckets.

  1. Log in to the Log Service console. In the Log Application section, on the Audit & Security tab, click Log Audit Service (New Version).

  2. On the Log Audit Service (New) page, click Associate Project. In the dialog box, configure the Project and click Associate.

    The dialog box has three settings: Region (for example, select China (Shanghai)), Project (for example, select audit-oss-bucket), and Comment.

2. Create a collection rule

2.1 Configure the collection rule

  1. On the Log Audit Service (New) page, click the name of your associated Project.

  2. On the Rules tab, click Create Rule. In the dialog box, configure the parameters as detailed below. We recommend naming the new Logstore in the format central-${cloud-service-name}-${log-type-name}-${collection-rule-name}. For more information on the parameters, see Collection notes for cloud services.

    Note

    If you select Instance Mode for Instance Mode and the target Bucket is not in the instance list, enter its name manually. A Bucket appears in the list only after you create a collection rule for it.

    In the dialog box, set a custom Rule Name, such as oss-bucket-1. Select OSS for Cloud Service and Access Log for Log Type. Under Resource Matching Mode, select Instance Mode and your target instance. For Central Project, select the destination region and project, for example, China (Shanghai) and audit-oss-bucket. For Central Logstore, select Create, enter a name that follows your convention, and set the Retention Period to 30 days. Click OK.

2.2 Verify log collection

  1. On the Rules tab, click the name of the collection rule you created.

  2. On the Query and Analysis > access log page, query and analyze the collected logs. For descriptions of the access log fields, see Log fields.

    To view the index configuration, click Properties of Query and Analysis and select Properties from the drop-down menu.

Related documents

  • To view, create, modify, or delete Log Audit rules, see Manage cloud service collection rules.

  • For log types, default Project names, default Logstore names, and billing details for other cloud services, see Cloud service collection notes.

  • The steps above cover single-account log collection. To collect logs from multiple cloud accounts, first enable Resource Directory. Then, use the management account or a delegated administrator of Resource Directory to configure collection rules that collect logs from member accounts into a specified Project. For details, see Multi-account configuration.