All Products
Search
Document Center

Simple Log Service:Anti-DDoS Origin logs

Last Updated:Mar 31, 2026

Anti-DDoS Origin integrates with Simple Log Service to provide mitigation log analysis. Enable this feature to query and analyze traffic scrubbing, blackhole filtering, and traffic rerouting events on your Anti-DDoS Origin instances, helping you troubleshoot access anomalies and monitor network operations.

Dedicated resources

  • Dedicated project and Logstore

    When you enable the log analysis feature, the system automatically creates a project named ddosbgp-project-{Alibaba-Cloud-Account-ID}-cn-hangzhou (China (Hangzhou)) and a dedicated Logstore named ddosbgp-LogStore.

    Important

    If you previously enabled the pay-by-ingested-data billing model, the system creates a dedicated Logstore that uses the same model. To switch to the pay-by-feature model, modify the Logstore configuration.

  • Dedicated dashboards

    Simple Log Service generates two dedicated dashboards when you enable this feature.

    Note

    Do not modify the dedicated dashboards because they may be upgraded or updated at any time. To visualize query results, create a custom dashboard. For more information, see Create a dashboard.

    Dashboard

    Description

    DDoS BGP Events Report

    Shows statistics on blackhole filtering and traffic rerouting events for protected resources.

    DDoS BGP Mitigation Report

    Shows statistics on traffic scrubbing events for protected resources, including inbound traffic monitoring, inbound traffic distribution, and protocol type distribution.

Billing

  • Anti-DDoS Origin charges for the mitigation analysis feature based on the log retention period and log storage capacity. This feature is currently in public preview and provides full log analysis and reports for protected traffic free of charge.

  • If the Logstore uses the pay-by-feature billing model, log query, analysis, alerting, monitoring, and visualization are free of charge. Standard Simple Log Service fees apply for traffic reading, data transformation, data shipping, and SMS or voice call notifications. For more information, see Billable items of pay-by-feature.

  • If the Logstore uses the pay-by-ingested-data billing model, log query, analysis, alerting, visualization, data transformation, data shipping, and SMS or voice call notifications are free of charge. Only outbound data traffic over the internet is charged at standard Simple Log Service rates. For more information, see Billable items of pay-by-ingested-data.

Limits

  • The dedicated Logstore does not support writing data from other sources. However, standard features such as log query, analysis, alerting, and consumption are fully supported.

  • The dedicated Logstore cannot be deleted.

  • The log retention period cannot be modified in the Simple Log Service console. Set it in the Anti-DDoS Origin console to a value between 30 and 180 days.

  • Ensure sufficient log storage space. When storage is full, new logs cannot be written.

    Note

    The log storage usage displayed in the Traffic Security console is not updated in real time. A two-hour delay exists between the displayed usage and the actual usage.