All Products
Search
Document Center

Cloud Firewall:Log fields

Last Updated:Sep 18, 2026

After enabling the log analysis feature, Cloud Firewall automatically collects and stores traffic and event logs in real time. You can query logs by specifying fields to aid in analysis and troubleshooting. This topic describes the supported log types and the meaning of each field.

Note

This topic contains a large number of log fields. To find a specific field, press Ctrl + F.

Log types

Cloud Firewall collects the following log types, distinguished by the log_type field:

log_type

Type

__topic__

internet_log

internet firewall IPv4 asset traffic logs

cloudfirewall_access_log

vpc_firewall_log

VPC firewall traffic logs

cloudfirewall_access_log

nat_firewall_log

NAT firewall traffic logs

cloudfirewall_access_log

ipv6_firewall_log

internet firewall IPv6 asset traffic logs

cloudfirewall_access_log

dns_firewall_log

DNS firewall traffic logs

cloudfirewall_access_log

internet_ips_log

internet firewall IPS logs

cloudfirewall_ips_log

vpc_ips_log

VPC firewall IPS logs

cloudfirewall_vpc_ips_log

tls

internet firewall TLS inspection logs

event_log

appid_ctrl

internet firewall application control logs

event_log

web_filter

internet firewall web filtering logs

event_log

  • Fields common to all log types:

    log_type, src_ip, dst_ip, src_port, dst_port, aliuid, __topic__, and __time__

  • Fields for each log type: Expand the following sections for details.

internet_log

log_type, src_ip, dst_ip, src_port, dst_port, ip_protocol, new_conn, direction, domain, acl_rule_id, rule_result, rule_source, in_packet_bytes, in_packet_count, out_packet_bytes, out_packet_count, total_packet_bytes, total_packet_count, start_time, end_time, aliuid, region_id, tcp_seq, start_time_min, url, app_name, app_dpi_state, loose_allow_acl_id, ips_rule_id, vul_level, total_pps, total_bps, in_pps, in_bps, out_pps, out_bps, city_id, country_id, member_uid, l4_protocol, l7_protocol, net_connect_dir, and traffic_type

SLS system fields: __topic__ and __time__

vpc_firewall_log

log_type, src_ip, dst_ip, src_port, dst_port, ip_protocol, new_conn, domain, acl_rule_id, rule_result, rule_source, in_packet_bytes, in_packet_count, out_packet_bytes, out_packet_count, total_packet_bytes, total_packet_count, start_time, end_time, firewall_id, tcp_seq, start_time_min, app_name, app_dpi_state, loose_allow_acl_id, ips_rule_id, vul_level, total_pps, total_bps, in_pps, in_bps, out_pps, out_bps, aliuid, src_region, dst_region, src_network_instance_id, and dst_network_instance_id

SLS system fields: __topic__ and __time__

nat_firewall_log

log_type, src_ip, dst_ip, src_port, dst_port, ip_protocol, new_conn, direction, domain, acl_rule_id, rule_result, rule_source, in_packet_bytes, in_packet_count, out_packet_bytes, out_packet_count, total_packet_bytes, total_packet_count, start_time, end_time, aliuid, src_vpc_id, tcp_seq, start_time_min, app_name, app_dpi_state, loose_allow_acl_id, total_pps, total_bps, in_pps, in_bps, out_pps, out_bps, src_region, and cloud_instance_id

SLS system fields: __topic__ and __time__

ipv6_firewall_log

log_type, src_ip, dst_ip, src_port, dst_port, ip_protocol, direction, domain, acl_rule_id, rule_result, in_packet_bytes, in_packet_count, out_packet_bytes, out_packet_count, total_packet_bytes, total_packet_count, start_time, end_time, aliuid, region_id, tcp_seq, start_time_min, url, app_name, ips_rule_id, vul_level, total_pps, total_bps, in_pps, in_bps, out_pps, out_bps, city_id, country_id, l4_protocol, l7_protocol, net_connect_dir, and traffic_type

SLS system fields: __topic__ and __time__

dns_firewall_log

log_type, src_ip, dst_ip, src_port, dst_port, ip_protocol, direction, domain, acl_rule_id, rule_result, in_packet_bytes, in_packet_count, out_packet_bytes, out_packet_count, total_packet_bytes, total_packet_count, start_time, end_time, aliuid, region_id, src_vpc_id, and src_region

SLS system fields: __topic__ and __time__

internet_ips_log

src_ip, dst_ip, src_port, dst_port, rule_id, rule_source, aliuid, attack_type, direction, proto, time, action_user, uuid, vul_level, payload, region_id, city_id, country_id, isp_id, firewall_id, user_ips_mode, payload_text, ips_rule_name, attack_type_name, and log_type

SLS system fields: __tag__:__receive_time__, __topic__, and __time__

vpc_ips_log

src_ip, dst_ip, src_port, dst_port, rule_id, rule_source, member_uid, attack_type, direction, proto, time, action_user, uuid, vul_level, payload, region_id, firewall_id, src_vpc_id, dst_vpc_id, payload_text, user_ips_mode, ips_rule_name, attack_type_name, aliuid, and log_type

SLS system fields: __tag__:__receive_time__, __topic__, and __time__

tls

log_type, time, src_ip, src_port, dst_ip, dst_port, ip_protocol, region_id, aliuid, member_uid, session_id, ssl_handshake_res, ssl_error_index, ssl_error_msg, sni, ssl_protocol, and ssl_cipher

SLS system fields: __topic__, __tag__:__receive_time__, and __time__

appid_ctrl

log_type, time, src_ip, src_port, dst_ip, dst_port, ip_protocol, region_id, aliuid, member_uid, direction, session_id, rule_id, action, and appid_ctrl_appid

SLS system fields: __topic__, __tag__:__receive_time__, and __time__

web_filter

log_type, time, src_ip, src_port, dst_ip, dst_port, ip_protocol, region_id, aliuid, member_uid, direction, session_id, rule_id, action, url, http_method, and category

SLS system fields: __topic__, __tag__:__receive_time__, and __time__

Log fields

Parameter

Description

Example

__time__

The time the log is written to a Logstore. The value is a Unix timestamp in seconds.

1703483369

__topic__

The log topic. The value is fixed to cloudfirewall_access_log, which indicates a traffic log from Cloud Firewall.

cloudfirewall_access_log

__tag__:__receive_time__

An SLS system tag that indicates the time the SLS server received the log.

1785833241

acl_rule_id

The ID of the access control policy that the traffic matched.

A value of 00000000-0000-0000-0000-000000000000 indicates that no access control policy was matched.

073a1475-6e11-43e2-8b28-98cee9c6****

action

The action performed by the rule.

deny

action_user

The action taken on traffic that matched the rule. Possible values:

  • 0 (pass): The traffic is allowed.

  • 1 (alert): An alert is generated.

  • 2 (drop): The traffic is dropped.

1

aliuid

The ID of the Alibaba Cloud account.

1233333333****

app_dpi_state

The status of application identification. Possible values:

  • success: The application was successfully identified.

  • policy_discard: The traffic was blocked by a policy.

  • tcp_not_establish: The TCP connection failed to be established.

  • analysing: The application is being identified.

  • no_payload: No payload has been received.

  • unknown_loose: The application could not be identified in loose mode.

  • unknown_strict: The application identification failed in strict mode.

  • none: Stateless.

success

app_name

The application type of the traffic. For example: HTTPS, NTP, SIP, SMB, NFS, DNS, or Unknown (indicates an unknown protocol type).

HTTPS

appid_ctrl_appid

The application ID.

10010470000

attack_type

The attack type. Possible values:

  • 1: Anomalous connection

  • 2: Command execution

  • 3: Brute-force attack

  • 4: Scan

  • 5: Other

  • 6: Information leakage

  • 7: DoS attack

  • 8: Buffer overflow attack

  • 9: Web attack

  • 10: Trojan backdoor

  • 11: Virus or worm

  • 12: mining behavior

  • 13: Reverse shell

11

attack_type_name

The Chinese name of the detected attack type.

Mining behavior

attack_type_name_en

The English name of the detected attack type.

mining behavior

category

The URL category for web filtering.

country_id

The two-letter country or region code, which is defined in ISO 3166-1.

Note

The code YY indicates an unknown country or region.

  • If direction is in, this field indicates the source country or region.

  • If direction is out, this field indicates the destination country or region.

CN

city_id

The unique identifier for the city. This field uses the six-digit administrative division code for cities in the Chinese mainland at or above the county level. For example, the code for Beijing is 110000.

110000

cloud_instance_id

The ID of the protected asset instance.

ngw-bp1d5bx2orlw1p2wn****

dst_vpc_id

The instance ID of the destination VPC.

vpc-xxxxxxxxxxxxxxxxxxxx1

direction

The direction of traffic flow. Possible values:

  • in: Inbound traffic from the internet or other ECS instances on the internal network to your asset.

  • out: Outbound traffic from your asset to the internet or other ECS instances on the internal network.

Note

VPC firewalls do not distinguish between inbound and outbound directions. For VPC firewall logs, this field defaults to out.

in

domain

The destination domain name.

Note
  • This field is populated only if the traffic contains domain name information.

  • If app_name is DNS, domain indicates the domain name being resolved in the DNS request.

www.aliyundoc.com

dst_ip

The destination IP address.

39.108.XX.XX

dst_network_instance_id

The destination network instance.

vpc-bp18ina819injc9zs****

dst_port

The destination port.

443

dst_region

The destination region.

cn-beijing

end_time

The time when the session ended. The value is a Unix timestamp, in seconds.

1702367350

firewall_id

The ID of the VPC firewall instance.

cen-m9y9u2hgc0t9im****

http_method

The HTTP request method.

GET

in_bps

The rate of inbound traffic, in bit/s.

42

in_packet_bytes

The size of inbound traffic, in bytes.

58

in_packet_count

The number of packets in the inbound traffic.

1

in_pps

The average rate of inbound traffic, in packets per second (pps).

Note

If the rate is less than 1 pps, this field displays 0 and does not show decimal places.

1

ip_protocol

The IP protocol. Possible values:

  • tcp

  • udp

  • icmp

tcp

ips_ai_rule_id

The ID of the intelligently recommended access control policy that the traffic matched.

A value of 00000000-0000-0000-0000-000000000000 indicates that no intelligently recommended access control policy was matched.

00000000-0000-0000-0000-000000000000

ips_rule_id

The ID of the intrusion prevention rule that the traffic matched.

A value of 00000000-0000-0000-0000-000000000000 indicates that no intrusion prevention rule was matched.

00000000-0000-0000-0000-000000000000

ips_rule_name

The Chinese name of the matched intrusion prevention rule.

The host exhibits mining behavior.

ips_rule_name_en

The English name of the matched intrusion prevention rule.

Mining behavior on the host

isp_id

The identifier of the Internet Service Provider (ISP).

50003280

l4_protocol

The Layer 4 protocol, such as tcp or udp.

tcp

l7_protocol

The Layer 7 application protocol, such as HTTP or Unknown.

HTTP

log_type

The log type. Possible values:

  • internet_log: Traffic logs from the Internet firewall.

  • vpc_firewall_log: Traffic logs from the VPC firewall.

  • nat_firewall_log: Traffic logs from the NAT firewall.

  • dns_firewall_log: Logs from the DNS firewall.

  • ipv6_firewall_log: Traffic protection logs for IPv6 assets.

  • internet_ips_log: Intrusion prevention event logs from the Internet firewall.

  • vpc_ips_log: Intrusion prevention event logs from the VPC firewall.

  • appid_ctrl: Application control logs from the Internet firewall.

  • web_filter: Web filtering logs from the Internet firewall.

  • tls: TLS inspection logs from the Internet firewall.

internet_log

loose_allow_acl_id

The ID of the access control policy that allows traffic with an unidentified application type. Possible values:

  • 00000000-0000-0000-0000-000000000000: Indicates that no unidentified traffic was allowed.

  • Other: Indicates that traffic with an unidentified application type was allowed. The value is the ID of the policy.

00000000-0000-0000-0000-000000000000

member_uid

In a multi-account management scenario, this is the UID of the member account associated with the log.

1234567890654321

net_connect_dir

The direction of the network connection, in or out.

in

new_conn

Indicates whether a new connection is established. Possible values:

  • 1: Yes

  • 0: No

1

out_bps

The rate of outbound traffic, in bit/s.

0

out_packet_bytes

The size of outbound traffic, in bytes.

0

out_packet_count

The number of packets in the outbound traffic.

0

out_pps

The average rate of outbound traffic, in packets per second (pps).

Note

If the rate is less than 1 pps, this field displays 0 and does not show decimal places.

0

payload

The packet payload that triggered an intrusion prevention event, formatted in hexadecimal. This field is populated only when the log_type is internet_ips_log or vpc_ips_log.

302602010104067075626c6963a1190204dc63c29a0201000xxxxx

payload_text

The packet payload, decoded from the payload field into ASCII plaintext.

The ASCII plaintext of the payload

proto

The IP protocol number. Possible values:

  • 6: TCP

  • 17: UDP

  • 1: ICMP

6

region_id

The region ID. For more information, see Supported regions.

  • If direction is in, this field indicates the ID of the region where the destination asset is located.

  • If direction is out, this field indicates the ID of the region where the source asset is located.

cn-beijing

rule_id

The ID of the matched rule.

For intrusion prevention logs, this is a numeric rule ID. For application control or web filtering logs, this is a rule instance ID prefixed with ati- or wft-.

Intrusion prevention log: 20000080; appid_ctrl: ati-xxxx; web_filter: wft-xxxx

rule_result

The action taken on traffic that matched an access control policy. Possible values:

  • pass: The traffic is allowed.

  • alert: The traffic is monitored.

  • drop: The traffic is denied.

The action taken on traffic that matched an intrusion prevention event. Possible values:

  • alert: An alert is generated.

  • drop: The traffic is dropped.

alert

rule_source

The source of the matched policy or rule. Possible values:

  • basic_acl: access control

  • dns_acl_rule: DNS firewall access control policy

  • intelligence: threat intelligence

  • ips_basic_rule: Basic protection

  • virtual_patch: virtual patching

  • unknown: Unknown

basic_acl

session_id

The session ID.

16000208880536122104

ssl_protocol

The TLS protocol version. Possible values:

  • TLSv1

  • TLSv1.1

  • TLSv1.2

  • TLSv1.3

TLSv1.3

ssl_cipher

The cipher suite.

TLS_AES_128_GCM_SHA256

ssl_handshake_res

Indicates whether the TLS offload was successful. Possible values:

  • success: The offload was successful.

  • failed: The offload failed.

success

ssl_error_index

The error category. Possible values:

  • Empty: No error occurred.

  • Certificate: Certificate error, such as a missing certificate or a verification failure.

  • Protocol: Unsupported protocol version.

  • Syscall: An underlying system call failed.

  • Error: General SSL error.

Certificate

ssl_error_msg

The error details.

certificate verify failed

sni

Server Name Indication (SNI).

example.com

src_ip

The source IP address.

167.94.XX.XX

src_network_instance_id

The source network instance.

vpc-bp18ina819injc9zs****

src_port

The source port.

47915

src_region

The source region.

cn-beijing

src_vpc_id

The ID of the source VPC.

vpc-bp18ina819injc9zs****

start_time

The time when the session started. The value is a Unix timestamp, in seconds.

1701759171

start_time_min

The start time of the session, rounded down to the minute. The value is a Unix timestamp, in seconds.

1701759120

tcp_seq

The TCP sequence number.

388367****

time

The time when the event occurred. The value is a Unix timestamp, in seconds.

1785833221

total_bps

The total transmission rate for both inbound and outbound traffic, in bit/s.

42

total_packet_bytes

The total size of both inbound and outbound traffic, in bytes.

58

total_packet_count

The total number of packets in both inbound and outbound traffic.

1

total_pps

The average packet transmission rate for both inbound and outbound traffic, in packets per second (pps).

Note

If the rate is less than 1 pps, this field displays 0 and does not show decimal places.

0

traffic_type

The data source of the log. For Cloud Firewall, this value is always 2, indicating the log is generated from flow collection, not packet capture.

2

url

The URL of the website accessed by the server.

Note

This field has a value only if app_name is HTTP.

http://aliyundoc.com/index.html

user_ips_mode

The intrusion prevention mode. Possible values:

  • 0: Off

  • 1: Block - Loose

  • 2: Block - Medium

  • 3: Block - Strict

1

uuid

A unique identifier for an intrusion prevention event. Use this ID to correlate an event log with the traffic logs from the corresponding session.

a1b2c3d4-0000-0000-0000-000000000002

vul_level

The risk level of the vulnerability exploited by the traffic. Possible values:

  • 0: No vulnerability exploitation was detected.

  • 1: A low-risk vulnerability was exploited.

  • 2: A medium-risk vulnerability was exploited.

  • 3: A high-risk vulnerability was exploited.

1

ndr_log_type

The NDR protocol log type, which identifies the protocol of the log.

HTTP

net_type

The location where NDR detected the traffic. Possible values:

  • 0: Public network

  • 1: Private network

0

request_uri

  • The complete request URI, including the path and query parameters, for example, /api/data?id=123. This field is used for route matching, locating resources, and auditing the full request path.

  • The difference between this field and request_path is that request_uri includes query parameters, whereas request_path contains only the path.

/api?key=value

request_path

The path part of the URI, which does not include query parameters.

/api

host

The destination hostname and port number from the Host header of the request.

aliyun.com:8080

request_method

The HTTP request method, such as GET, POST, PUT, or DELETE.

POST

http_user_agent

The client identifier from the User-Agent header of the request.

Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.6261.95 Safari/537.36

status

The three-digit HTTP response status code.

200