After enabling the log analysis feature, Cloud Firewall automatically collects and stores traffic and event logs in real time. You can query logs by specifying fields to aid in analysis and troubleshooting. This topic describes the supported log types and the meaning of each field.
This topic contains a large number of log fields. To find a specific field, press Ctrl + F.
Log types
Cloud Firewall collects the following log types, distinguished by the log_type field:
| Type |
|
internet_log | internet firewall IPv4 asset traffic logs | cloudfirewall_access_log |
vpc_firewall_log | VPC firewall traffic logs | cloudfirewall_access_log |
nat_firewall_log | NAT firewall traffic logs | cloudfirewall_access_log |
ipv6_firewall_log | internet firewall IPv6 asset traffic logs | cloudfirewall_access_log |
dns_firewall_log | DNS firewall traffic logs | cloudfirewall_access_log |
internet_ips_log | internet firewall IPS logs | cloudfirewall_ips_log |
vpc_ips_log | VPC firewall IPS logs | cloudfirewall_vpc_ips_log |
tls | internet firewall TLS inspection logs | event_log |
appid_ctrl | internet firewall application control logs | event_log |
web_filter | internet firewall web filtering logs | event_log |
Fields common to all log types:
log_type,src_ip,dst_ip,src_port,dst_port,aliuid,__topic__, and__time__Fields for each log type: Expand the following sections for details.
internet_log
vpc_firewall_log
nat_firewall_log
ipv6_firewall_log
dns_firewall_log
internet_ips_log
vpc_ips_log
tls
appid_ctrl
web_filter
Log fields
Parameter | Description | Example |
__time__ | The time the log is written to a Logstore. The value is a Unix timestamp in seconds. | 1703483369 |
__topic__ | The log topic. The value is fixed to cloudfirewall_access_log, which indicates a traffic log from Cloud Firewall. | cloudfirewall_access_log |
__tag__:__receive_time__ | An SLS system tag that indicates the time the SLS server received the log. | 1785833241 |
acl_rule_id | The ID of the access control policy that the traffic matched. A value of 00000000-0000-0000-0000-000000000000 indicates that no access control policy was matched. | 073a1475-6e11-43e2-8b28-98cee9c6**** |
action | The action performed by the rule. | deny |
action_user | The action taken on traffic that matched the rule. Possible values:
| 1 |
aliuid | The ID of the Alibaba Cloud account. | 1233333333**** |
app_dpi_state | The status of application identification. Possible values:
| success |
app_name | The application type of the traffic. For example: HTTPS, NTP, SIP, SMB, NFS, DNS, or Unknown (indicates an unknown protocol type). | HTTPS |
appid_ctrl_appid | The application ID. | 10010470000 |
attack_type | The attack type. Possible values:
| 11 |
attack_type_name | The Chinese name of the detected attack type. | Mining behavior |
attack_type_name_en | The English name of the detected attack type. | mining behavior |
category | The URL category for web filtering. | |
country_id | The two-letter country or region code, which is defined in ISO 3166-1. Note The code YY indicates an unknown country or region.
| CN |
city_id | The unique identifier for the city. This field uses the six-digit administrative division code for cities in the Chinese mainland at or above the county level. For example, the code for Beijing is 110000. | 110000 |
cloud_instance_id | The ID of the protected asset instance. | ngw-bp1d5bx2orlw1p2wn**** |
dst_vpc_id | The instance ID of the destination VPC. | vpc-xxxxxxxxxxxxxxxxxxxx1 |
direction | The direction of traffic flow. Possible values:
Note VPC firewalls do not distinguish between inbound and outbound directions. For VPC firewall logs, this field defaults to out. | in |
domain | The destination domain name. Note
| www.aliyundoc.com |
dst_ip | The destination IP address. | 39.108.XX.XX |
dst_network_instance_id | The destination network instance. | vpc-bp18ina819injc9zs**** |
dst_port | The destination port. | 443 |
dst_region | The destination region. | cn-beijing |
end_time | The time when the session ended. The value is a Unix timestamp, in seconds. | 1702367350 |
firewall_id | The ID of the VPC firewall instance. | cen-m9y9u2hgc0t9im**** |
http_method | The HTTP request method. | GET |
in_bps | The rate of inbound traffic, in bit/s. | 42 |
in_packet_bytes | The size of inbound traffic, in bytes. | 58 |
in_packet_count | The number of packets in the inbound traffic. | 1 |
in_pps | The average rate of inbound traffic, in packets per second (pps). Note If the rate is less than 1 pps, this field displays 0 and does not show decimal places. | 1 |
ip_protocol | The IP protocol. Possible values:
| tcp |
ips_ai_rule_id | The ID of the intelligently recommended access control policy that the traffic matched. A value of 00000000-0000-0000-0000-000000000000 indicates that no intelligently recommended access control policy was matched. | 00000000-0000-0000-0000-000000000000 |
ips_rule_id | The ID of the intrusion prevention rule that the traffic matched. A value of 00000000-0000-0000-0000-000000000000 indicates that no intrusion prevention rule was matched. | 00000000-0000-0000-0000-000000000000 |
ips_rule_name | The Chinese name of the matched intrusion prevention rule. | The host exhibits mining behavior. |
ips_rule_name_en | The English name of the matched intrusion prevention rule. | Mining behavior on the host |
isp_id | The identifier of the Internet Service Provider (ISP). | 50003280 |
l4_protocol | The Layer 4 protocol, such as | tcp |
l7_protocol | The Layer 7 application protocol, such as | HTTP |
log_type | The log type. Possible values:
| internet_log |
loose_allow_acl_id | The ID of the access control policy that allows traffic with an unidentified application type. Possible values:
| 00000000-0000-0000-0000-000000000000 |
member_uid | In a multi-account management scenario, this is the UID of the member account associated with the log. | 1234567890654321 |
net_connect_dir | The direction of the network connection, | in |
new_conn | Indicates whether a new connection is established. Possible values:
| 1 |
out_bps | The rate of outbound traffic, in bit/s. | 0 |
out_packet_bytes | The size of outbound traffic, in bytes. | 0 |
out_packet_count | The number of packets in the outbound traffic. | 0 |
out_pps | The average rate of outbound traffic, in packets per second (pps). Note If the rate is less than 1 pps, this field displays 0 and does not show decimal places. | 0 |
payload | The packet payload that triggered an intrusion prevention event, formatted in hexadecimal. This field is populated only when the | 302602010104067075626c6963a1190204dc63c29a0201000xxxxx |
payload_text | The packet payload, decoded from the | The ASCII plaintext of the payload |
proto | The IP protocol number. Possible values:
| 6 |
region_id | The region ID. For more information, see Supported regions.
| cn-beijing |
rule_id | The ID of the matched rule. For intrusion prevention logs, this is a numeric rule ID. For application control or web filtering logs, this is a rule instance ID prefixed with | Intrusion prevention log: 20000080; appid_ctrl: ati-xxxx; web_filter: wft-xxxx |
rule_result | The action taken on traffic that matched an access control policy. Possible values:
The action taken on traffic that matched an intrusion prevention event. Possible values:
| alert |
rule_source | The source of the matched policy or rule. Possible values:
| basic_acl |
session_id | The session ID. | 16000208880536122104 |
ssl_protocol | The TLS protocol version. Possible values:
| TLSv1.3 |
ssl_cipher | The cipher suite. | TLS_AES_128_GCM_SHA256 |
ssl_handshake_res | Indicates whether the TLS offload was successful. Possible values:
| success |
ssl_error_index | The error category. Possible values:
| Certificate |
ssl_error_msg | The error details. | certificate verify failed |
sni | Server Name Indication (SNI). | example.com |
src_ip | The source IP address. | 167.94.XX.XX |
src_network_instance_id | The source network instance. | vpc-bp18ina819injc9zs**** |
src_port | The source port. | 47915 |
src_region | The source region. | cn-beijing |
src_vpc_id | The ID of the source VPC. | vpc-bp18ina819injc9zs**** |
start_time | The time when the session started. The value is a Unix timestamp, in seconds. | 1701759171 |
start_time_min | The start time of the session, rounded down to the minute. The value is a Unix timestamp, in seconds. | 1701759120 |
tcp_seq | The TCP sequence number. | 388367**** |
time | The time when the event occurred. The value is a Unix timestamp, in seconds. | 1785833221 |
total_bps | The total transmission rate for both inbound and outbound traffic, in bit/s. | 42 |
total_packet_bytes | The total size of both inbound and outbound traffic, in bytes. | 58 |
total_packet_count | The total number of packets in both inbound and outbound traffic. | 1 |
total_pps | The average packet transmission rate for both inbound and outbound traffic, in packets per second (pps). Note If the rate is less than 1 pps, this field displays 0 and does not show decimal places. | 0 |
traffic_type | The data source of the log. For Cloud Firewall, this value is always | 2 |
url | The URL of the website accessed by the server. Note This field has a value only if app_name is HTTP. | http://aliyundoc.com/index.html |
user_ips_mode | The intrusion prevention mode. Possible values:
| 1 |
uuid | A unique identifier for an intrusion prevention event. Use this ID to correlate an event log with the traffic logs from the corresponding session. | a1b2c3d4-0000-0000-0000-000000000002 |
vul_level | The risk level of the vulnerability exploited by the traffic. Possible values:
| 1 |
ndr_log_type | The NDR protocol log type, which identifies the protocol of the log. | HTTP |
net_type | The location where NDR detected the traffic. Possible values:
| 0 |
request_uri |
| /api?key=value |
request_path | The path part of the URI, which does not include query parameters. | /api |
host | The destination hostname and port number from the | aliyun.com:8080 |
request_method | The HTTP request method, such as | POST |
http_user_agent | The client identifier from the | Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.6261.95 Safari/537.36 |
status | The three-digit HTTP response status code. | 200 |