All Products
Search
Document Center

Simple Log Service:Log collection for Alibaba Cloud services

Last Updated:Aug 26, 2026

Simple Log Service collects logs from Alibaba Cloud services, such as elastic compute, storage, security, and database. These logs detail operations, service status, and business activity.

Overview

Automatic collection

When you enable log collection for a cloud service, the system automatically performs the following operations:

  1. Deploys a built-in agent, such as Logtail, to the target cloud service instance. No manual installation is required.

  2. Creates a corresponding LogStore in Simple Log Service (SLS) to store log data for the cloud service.

  3. Transmits log data to Simple Log Service in real time through the agent for storage and categorization by cloud service type.

Stop billing

To avoid charges for cloud service log collection, you must stop data collection and clean up storage resources.

  1. Disable log collection

    • Go to the console of the cloud service and turn off the Simple Log Service integration feature.

    • After you disable collection, the agent will no longer transmit new logs.

  2. Clean up storage resources

    • Log in to the Simple Log Service console and delete the Project and LogStore for the cloud service.

    • Ensure you delete all associated resources to avoid storage charges.

Cloud product log collection

Elastic computing

Cloud service

Actions

Default project and LogStore

Log fields

Description

ECS

Collect host logs

Custom

-

Select a custom Project and LogStore.

ACK One

Enable or disable control plane component logs and audit logs for ACK One master instances

  • Project:

    • Custom

    • k8s-log-master instance ID

  • LogStore:

    • apiserver-master instance ID

    • kcm-master instance ID

    • application-controller-master instance ID

    • cluster-operator-master instance ID

    • audit-master instance ID

-

A Project name starts with k8s-log. For example, a Project automatically created by the system is named k8s-log-ab79abd******************f2a8f45, where ab79abd******************f2a8f45 is the master instance ID. A Logstore that includes the master instance ID is also automatically created in this Project.

Enable or disable GitOps control plane logs and audit logs for ACK One

  • Project: k8s-log-master instance ID

  • LogStore: gitops-argocd-logstore

-

The Project name starts with k8s-log. For example, a system-generated Project is named k8s-log-ab79abd******************f2a8f45, where ab79abd******************f2a8f45 represents the master instance ID. A LogStore named gitops-argocd-logstore is also created in this Project.

Enable or disable workflow logs for ACK One

  • Project: k8s-log-master instance ID

  • LogStore: workflow-logstore

-

A Project name starts with k8s-log. For example, a system-generated Project is named k8s-log-ab79abd******************f2a8f45, where ab79abd******************f2a8f45 represents the master instance ID. Additionally, a LogStore named workflow-logstore is created in this Project.

ACK Managed and Dedicated Clusters

Enable or disable control plane component logs for ACK Managed and Dedicated Clusters

  • Project:

    • Custom

    • k8s-log-cluster ID

  • LogStore:

    • apiserver-cluster ID

    • ccm-cluster ID

    • scheduler-cluster ID

    • kcm-cluster ID

Default fields for ACK Pro control plane logs

A Project name starts with k8s-log. For example, the system automatically creates a Project named k8s-log-cb70fbd******************f2a8f45, where cb70fbd******************f2a8f45 is the cluster ID. A LogStore that contains the cluster ID is also automatically created in this Project.

Collect cluster container logs (standard output/file) via the console

  • Project: k8s-log-cluster ID

  • LogStore: config-operation-log

The Project name starts with k8s-log. For example, the system automatically creates a Project named k8s-log-cb70fbd******************f2a8f45, where cb70fbd******************f2a8f45 is the cluster ID. A LogStore named config-operation-log is also automatically created in this Project.

Enable or disable container internal operation audit logs for ACK Managed and Dedicated Clusters

  • Project: k8s-log-cluster ID

  • LogStore: advaudit-cluster ID

-

Project names start with k8s-log, and LogStore names start with advaudit. For example, the system automatically creates a Project named k8s-log-cb70fbd******************f2a8f45 and a LogStore named advaudit-cb70fbd******************f2a8f45 in this Project, where cb70fbd******************f2a8f45 is the cluster ID.

Enable Kubernetes event logs for ACK Managed and Dedicated Clusters

  • Project:

    • Custom

    • k8s-log-cluster ID

  • LogStore:

    • k8s-event

    • internal-alert-history

    • security-inspector-configaudit-cluster ID

-

The name of a Project starts with k8s-log. For example, the system automatically creates a Project named k8s-log-cb70fbd******************f2a8f45, where cb70fbd******************f2a8f45 is the cluster ID. A LogStore with a predefined name that includes the cluster ID is also automatically created in this Project.

Enable Nginx Ingress access logs for ACK Managed and Dedicated Clusters

  • Project: k8s-log-cluster ID

  • LogStore:

    • nginx-ingress

    • nginx-ingress-metrics-result

A Project name starts with k8s-log. For example, the system automatically creates a Project named k8s-log-cb70fbd******************f2a8f45, where cb70fbd******************f2a8f45 is the cluster ID. LogStores named nginx-ingress and nginx-ingress-metrics-result are also automatically created in this Project.

ACK Serverless Cluster

Enable or disable control plane component logs for ACK Serverless clusters

  • Project:

    • Custom

    • k8s-log-cluster ID

  • LogStore:

    • apiserver-cluster ID

    • ccm-cluster ID

    • kcm-cluster ID

-

The Project name starts with k8s-log. For example, a Project is automatically created with a name such as k8s-log-cb70fbd******************f2a8f45, where cb70fbd******************f2a8f45 is the cluster ID. A LogStore that has a fixed name and contains the cluster ID is also automatically created in this Project.

ACK Edge Cluster

Enable or disable control plane component logs for ACK Edge clusters

  • Project:

    • Custom

    • k8s-log-cluster ID

  • LogStore:

    • alb-cluster ID

    • apiserver-cluster ID

    • audit-cluster ID

    • ccm-cluster ID

    • controlplane-events-cluster ID

    • k8s-event

    • kcm-cluster ID

    • scheduler-cluster ID

-

The Project name starts with k8s-log. For example, a Project that is automatically created by the system is named k8s-log-cb70fbd******************f2a8f45, where cb70fbd******************f2a8f45 is the cluster ID. A Logstore with a fixed name that includes the cluster ID is also automatically created in this Project.

WUYING Workspace

Enable operation logs for WUYING Workspace

  • Project: elastic-desktop-custom-suffix

  • LogStore: elastic_desktop_custom-suffix

-

The name of a Project starts with elastic-desktop. For example, if you create a Project named elastic-desktop-test, a LogStore named elastic_desktop_test is automatically created in the Project.

Function Compute 2.0

Enable access logs for Function Compute 2.0

  • Project:

    • Custom

    • aliyun-fc-cn-region ID-random ID

  • LogStore: function-log

Function Compute 2.0 metric fields

  • When you enable logging while creating a service:

    • The system automatically creates a Project named aliyun-fc-cn-hangzhou-cc****d0-d**3-5**4-a**d-698******d7d, where cn-hangzhou is the region ID, indicating that the Project is created in the Hangzhou region.

    • By default, a LogStore named function-log is created.

  • If you do not enable logging during service creation, you must manually select a custom Project and LogStore when you update the service.

Function Compute 3.0

Enable access logs for Function Compute 3.0

  • Project: serverless-cn-region ID-random ID

  • LogStore: default-logs

Function Compute 3.0 metric fields

  • When you create a function, logging is enabled by default.

    • The system automatically creates a Project named serverless-cn-hangzhou-cc****d0-d**3-5**4-a**d-698******d7d, where cn-hangzhou is the region ID, indicating that the Project is created in the Hangzhou region.

    • By default, a LogStore named default-logs is created.

  • If you did not enable logging during service creation, you must manually select a custom Project and LogStore when you update the service.

Storage

Cloud service

Actions

Default project and Logstore

Log fields

Description

OSS

Enable/Disable access logs for OSS

  • Project: oss-log-Alibaba Cloud account ID-region ID

  • Logstore: oss-log-store

-

The system automatically creates a Project named oss-log-1290********9680-cn-hangzhou, which contains a Logstore named oss-log-store. In this example, 1290********9680 is your Alibaba Cloud account ID.

NAS

  • Project: nas-Alibaba Cloud account ID-region ID

  • Logstore:

    • general-purpose NAS:

      • NFS protocol file system: nas-nfs

      • SMB protocol file system: nas-smb-access-log

    • Extreme NAS: nas-extreme-nfs

NAS log fields

The system automatically creates a Project named nas-1290********9680-cn-hangzhou, where 1290********9680 is your Alibaba Cloud account ID. It then creates different Logstores in this Project based on the NAS type:

  • general-purpose NAS: nas-nfs for NFS protocol file systems or nas-smb-access-log for SMB protocol file systems.

  • Extreme NAS: nas-extreme-nfs.

EBS

Enable/Disable access logs for EBS

  • Project: aliyun-product-data-Alibaba Cloud account ID-region ID

  • Metricstore: ebs_disk_metric

EBS monitoring metrics

The system automatically creates a Project named aliyun-product-data-1290********9680-cn-hangzhou, which contains a Metricstore named ebs_disk_metric. In this example, 1290********9680 is your Alibaba Cloud account ID.

Security

Cloud service

Enable/disable

Default Project and Logstore

Log fields

Remarks

Anti-DDoS Proxy

Enable full logs for Anti-DDoS Proxy

  • Anti-DDoS Proxy (Chinese mainland)

    • Project: ddoscoo-project-Alibaba Cloud account ID-cn-hangzhou

    • Logstore: ddoscoo-logstore

  • Anti-DDoS Proxy (outside Chinese mainland)

    • Project: ddosdip-project-Alibaba Cloud account ID-ap-southeast-1

    • Logstore: ddosdip-logstore

Anti-DDoS Proxy full log fields

The system automatically creates a Project named ddoscoo-project-1290********9680-cn-hangzhou and a Logstore named ddoscoo-logstore in this Project. In the Project name, 1290********9680 is your Alibaba Cloud account ID, and cn-hangzhou indicates the service is for the Chinese mainland.

Anti-DDoS Origin

Enable protection logs for Anti-DDoS Origin

  • Project: ddosbgp-project-Alibaba Cloud account ID-cn-hangzhou

  • Logstore: ddosbgp-logstore

Anti-DDoS Origin log fields

The system automatically creates a Project named ddosbgp-project-1290********9680-cn-hangzhou and a Logstore named ddosbgp-logstore in this Project. In the Project name, 1290********9680 is your Alibaba Cloud account ID.

Security Center

Enable logon logs for Security Center

  • Project: sas-log-Alibaba Cloud account ID-region ID

  • Logstore: sas-log

The system automatically creates a Project named sas-log-1290********9680-cn-hangzhou and a Logstore named sas-log in this Project. In the Project name, 1290********9680 is your Alibaba Cloud account ID.

WAF 2.0

Enable full logs for WAF 2.0

  • WAF instances in the Chinese mainland

    • Project: waf-project-Alibaba Cloud account ID-cn-hangzhou, which is in the China (Hangzhou) region.

    • Logstore: waf-logstore

  • WAF instances outside the Chinese mainland

    • Project: waf-project-Alibaba Cloud account ID-ap-southeast-1, which is in the Singapore region.

    • Logstore: waf-logstore

WAF 2.0 log fields

The system automatically creates a Project named waf-project-1290********9680-cn-hangzhou and a Logstore named waf-logstore in this Project. In the Project name, 1290********9680 is your Alibaba Cloud account ID. The Project is created in the China (Hangzhou) region for WAF instances in the Chinese mainland.

WAF 3.0

Enable or disable full logs for WAF 3.0

  • WAF instances in the Chinese mainland

    • Pay-as-you-go instances

      • Project: wafnew-project-Alibaba Cloud account ID-cn-hangzhou, which is in the China (Hangzhou) region.

      • Logstore: wafnew-logstore

    • Subscription instances

      • Project: wafng-project-Alibaba Cloud account ID-cn-hangzhou, which is in the China (Hangzhou) region.

      • Logstore: wafnew-logstore

  • WAF instances outside the Chinese mainland

    • Pay-as-you-go instances

      • Project: wafnew-project-Alibaba Cloud account ID-ap-southeast-1, which is in the Singapore region.

      • Logstore: wafnew-logstore

    • Subscription instances

      • Project: wafng-project-Alibaba Cloud account ID-ap-southeast-1, which is in the Singapore region.

      • Logstore: wafnew-logstore

WAF 3.0 log fields

The system automatically creates a Project named wafnew-project-1290********9680-cn-hangzhou and a Logstore named wafnew-logstore in this Project. In the Project name, 1290********9680 is your Alibaba Cloud account ID. This Project is in the China (Hangzhou) region. The wafnew-project prefix indicates the logs are for a pay-as-you-go WAF instance.

Cloud Firewall

Enable traffic logs for Cloud Firewall

  • Project: cloudfirewallnew-project-Alibaba Cloud account ID-region ID

  • Logstore: cloudfirewallnew-logstore

Cloud Firewall log fields

The system automatically creates a Project named cloudfirewallnew-project-1290********9680-cn-hangzhou and a Logstore named cloudfirewallnew-logstore in this Project. In the Project name, 1290********9680 is your Alibaba Cloud account ID. The Project is created in the China (Hangzhou) region.

ActionTrail

  • Project: Custom

  • Logstore: actiontrail_trail name

ActionTrail event log fields

You can store logs in a custom Project and Logstore.

When you create a trail and select a custom Project, the system creates a Logstore named actiontrail_test001 in that Project, where test001 is the name of your trail.

Enable Alibaba Cloud-initiated events for ActionTrail

Custom

Alibaba Cloud-initiated events fields

You can store logs in a custom Project and Logstore.

Cloud Config

Enable audit logs for Cloud Config

Custom

Cloud Config log fields

You can store logs in a custom Project and Logstore.

Networking

Cloud service

Actions

Default Project and Logstore

Log fields

Note

Classic Load Balancer (CLB) Layer 7

Enable/Disable access logs for CLB

Custom

CLB access log fields

Select a custom Project and Logstore.

Virtual Private Cloud (VPC)

Enable/Disable flow logs for VPC

Custom

VPC flow log fields

Select a custom Project and Logstore.

Cloud Enterprise Network (CEN)

Enable/Disable flow logs for CEN

Custom

CEN flow log fields

Select a custom Project and Logstore.

Smart Access Gateway (SAG)

Custom

SAG flow log fields

Select a custom Project and Logstore.

Elastic IP Address (EIP)

Enable/Disable high-precision second-level monitoring for EIP

Custom

-

Select a custom Project and Logstore.

Cloud-native API Gateway

Enable gateway logs for Cloud-native API Gateway

  • Project: aliyun-product-data-Alibaba Cloud account ID-region ID

  • Logstore:

    • apig-access-log

    • apig-plugin-log

Cloud-native API Gateway log fields

The system automatically creates a Project named aliyun-product-data-1290********9680-cn-hangzhou and Logstores named apig-access-log and apig-plugin-log to store access logs and plugin logs, respectively. In this example, 1290********9680 is your Alibaba Cloud account ID, and cn-hangzhou is the region ID for China (Hangzhou).

Dynamic Content Delivery Network (DCDN)

Enable/Disable real-time logs for DCDN

  • Project:

    • Chinese Mainland: dcdn-edge-rtlog-cn-random ID

    • Outside Chinese Mainland: dcdn-edge-rtlog-sg-random ID

  • Logstore: dcdn-edge-rtlog

-

The system automatically creates a Project named dcdn-edge-rtlog-cn-02****c4 and a Logstore named dcdn-edge-rtlog. In this example, 02****c4 is a random ID, and cn is the region code for the Chinese Mainland.

Global Accelerator (GA)

Enable/Disable access logs for GA

Custom

GA log fields

Select a custom Project and Logstore.

Database service

Cloud service

Actions

Project and Logstore

Log fields

Description

ApsaraDB RDS

Enable audit logs for ApsaraDB RDS

Custom

ApsaraDB RDS audit log fields

You can select a custom Project and Logstore.

Tair

Enable audit logs for Tair

  • Project: nosql-Alibaba Cloud account ID-region ID

  • Logstore:

    • redis_audit_log_standard

    • redis_slow_run_log

-

The system automatically creates a Project named nosql-1290********9680-cn-hangzhou that contains Logstores named redis_audit_log_standard and redis_slow_run_log. In this example, 1290********9680 is your Alibaba Cloud account ID, and the region ID cn-hangzhou represents China (Hangzhou).

ApsaraDB for MongoDB

  • Project: nosql-Alibaba Cloud account ID-region ID

  • Logstore:

    • mongo_audit_log_standard

    • mongo_slow_run_log

ApsaraDB for MongoDB log field details

The system automatically creates a Project named nosql-1290********9680-cn-hangzhou that contains Logstores named mongo_audit_log_standard and mongo_slow_run_log. In this example, 1290********9680 is your Alibaba Cloud account ID, and the region ID cn-hangzhou represents China (Hangzhou).

Big data analytics

Cloud service

Enable/Disable

Default Project and Logstore

Log Fields

Note

Data Management Service (DMS)

Enable the operation log for DMS

Custom

DMS operation log fields

Select a custom Project and LogStore for storage.

Open-source big data platform E-MapReduce (EMR)

Enable/disable E-MapReduce operation logs

  • Project: custom

  • LogStore: emr_EMR service name_log

-

Select a custom Project and LogStore for storage.

Cloud communications

Cloud service

Enable/disable

Default Project and LogStore

Log fields

Note

Short Message Service (SMS)

Enable/disable SMS logs for Short Message Service

  • Project: sms-log-Alibaba Cloud account ID

  • LogStore: sms-log

Short Message Service log fields

The system automatically creates a Project named sms-log-1290********9680 and a LogStore named sms-log in this Project. In this example, 1290********9680 is your Alibaba Cloud account ID.

Internet of Things

Cloud service

Actions

Default Project and Logstore

Log fields

Description

IoT Platform

Enable/disable operational logs for IoT

  • Project: iot-log-Alibaba Cloud account ID-Region ID

  • Logstore: iot_logs

IoT operational log fields

The system automatically creates a Project named iot-log-1290********9680-cn-hangzhou and a Logstore named iot_logs within it. In the Project name, 1290********9680 is your Alibaba Cloud account ID, and cn-hangzhou is the Region ID for China (Hangzhou).

Middleware

Cloud service

Enable/disable

Default Project and Logstore

Log fields

Note

Microservices Engine (MSE)

Enable gateway logs for MSE

  • Project:

    • Custom

    • aliyun-product-data-Alibaba Cloud account ID-region ID

  • Logstore: mse_gw_access_log

MSE gateway log delivery fields

The system automatically creates a Project named aliyun-product-data-1290********9680-cn-hangzhou and a Logstore named mse_gw_access_log in this Project. In this example, 1290********9680 is your Alibaba Cloud account ID, and cn-hangzhou is the region ID for China (Hangzhou).

Enterprise Distributed Application Service (EDAS)

Enable business logs for EDAS

Custom

-

Select a custom Project and Logstore.

Service Mesh (ASM)

Enable control plane logs for ASM

  • Project:

    • Custom

    • mesh-log-ASM instance ID

  • Logstore:

    • istio-ASM instance ID

    • audit-ASM instance ID

-

The system automatically creates a Project named mesh-log-cbc49***********************5449b and Logstores named audit-cbc49***********************5449b and istio-cbc49***********************5449b in this Project. In this example, cbc49***********************5449b is the ASM instance ID.

Observability

Cloud service

Enable/Disable

Default Project and Logstore

Log fields

Note

Managed Service for Prometheus

Enable usage logs for Managed Service for Prometheus

  • Project: workspace-default-cms-Alibaba Cloud account ID-region ID

  • MetricStore:

    • container cluster: aliyun-prom-cluster ID

    • Other: aliyun-prom-Prometheus instance ID

Managed Service for Prometheus usage metrics

The system automatically creates a Project named workspace-default-cms-1290********9680-cn-hangzhou and a MetricStore named aliyun-prom-c4cb*************************d9a9 in this Project. In these names, 1290********9680 is your Alibaba Cloud account ID, aliyun-prom-c4cb*************************d9a9 is the Prometheus instance ID, and the region ID cn-hangzhou indicates that the region is China (Hangzhou).