When collecting or shipping logs, Simple Log Service adds metadata such as source and timestamp as key-value pairs. These are reserved fields.
-
When writing log data through an API or Logtail, do not use reserved field names as custom keys. Duplicate names cause field conflicts and inaccurate queries.
-
If your Logstore uses the pay-by-ingested-data billing mode, Simple Log Service does not charge for the reserved fields it adds to your logs.
-
If your Logstore uses the pay-by-feature billing mode, charges apply to the added reserved fields. Enabling an index for these fields also incurs minor fees for index traffic and storage.
|
Reserved field |
Type |
Index and analysis |
Description |
|
|
Integer. A standard Unix timestamp. |
|
The log timestamp, specified at write time. Used for log shipping, queries, and analysis. |
|
|
String. |
|
Log source (e.g., IP address or machine identifier). Used for log shipping, queries, analysis, and custom consumption. |
|
|
String. |
|
|
|
|
A string that can be deserialized into a JSON map. |
This field does not exist in the log content. You do not need to create an index for it. |
|
|
|
String. |
|
Public IP address of the log source. Appended by the server when public IP recording is enabled. Used for log queries, analysis, and custom consumption. Enclose in double quotation marks ("") in SQL analysis. tag and Record public IP addresses. |
|
|
String. Convertible to an integer Unix timestamp. |
|
Server receive time. Appended when public IP recording is enabled. Used for log queries, analysis, and custom consumption. tag and Record public IP addresses. |
|
|
String. |
|
Log file path, added by Logtail during collection. Used for log queries, analysis, and custom consumption. Enclose in double quotation marks ("") in SQL analysis. |
|
|
String. |
|
Hostname of the collection machine, added by Logtail. Used for log queries, analysis, and custom consumption. Enclose in double quotation marks ("") in SQL analysis. |
|
|
String. |
Manually create an index (text type) for this field. Enable log analysis as needed. |
|
|
|
String. |
Manually create an index (text type) for this field. Enable log analysis as needed. |
|