Learn about the differences between Log Audit Service (New) and Log Audit Service (Legacy).
Log Audit Service (old version) is no longer being updated. We recommend that you migrate to the new version of Log Audit Service at the earliest opportunity.
Version comparison
|
Criteria |
Legacy: Limitations |
New version: Upgrade highlights |
|
Connection type |
|
|
|
Logstore storage property configuration |
Configurable only on the global configuration page.
Not supported:
|
|
|
Central log project |
|
|
|
Cross-account feature |
Only one audit collection destination is supported.
|
Multiple audit collection destinations are supported. |
|
Data transformation fees for centralized synchronization |
When the Sync to Center feature is enabled, data transformation fees apply for synchronizing logs from regional Logstores to a central Logstore. |
The following fees are waived when collecting logs from a cloud service's default destination Logstore to a central Logstore:
|
|
Collection filtering |
|
|
|
Collect runtime logs |
Not supported. |
Supports collecting runtime logs from open source agents (such as Tetragon and Falco) to a Logstore via Logtail. |
|
OpenAPI |
No external OpenAPI is provided. |
|
|
Terraform |
Coupled cloud service configuration:
|
Configurations are independent and defined per cloud service. Terraform is supported. Usage example. |
Log field comparison
|
Cloud service |
New version |
Previous version |
Description (In the new version, log fields match those displayed in the cloud service console) |
Details |
|
ActionTrail |
The field structure is different. |
The new version adds resource and identity fields (e.g., event.resourceName, event.userIdentity.sessionContext). The previous version included event.requestParameters.HostId, event.requestParameters.Name, and event.requestParameters.Region. The event.requestParameters and event.requestParameterJson fields replace the previous output. |
||
|
Cloud Config |
The field content is different. |
The new version adds log fields for scheduled resource snapshots. |
||
|
Object Storage Service |
The field content is different. |
|
||
|
RDS |
The field content is different. |
|
||
|
Server Load Balancer |
The field content is different. |
The previous version includes owner_id, region, instance_id, instance_name, network_type, and vpc_id fields not present in the new version. |
||
|
VPC |
The field content is different. |
The previous version includes the __topic__ and region fields not present in the new version. |
||
|
Cloud Firewall |
No differences. |
- |
||
|
Anti-DDoS |
The field content is different. |
In the new version, all log fields are categorized into event fields, traffic detection fields, and traffic scrubbing fields. Log field description. |
||
|
Anti-DDoS Proxy |
The field content is different. |
The new version adds more client request parameters, such as ssl_protocol, ssl_cipher, and ssl_handshake_time. |
||
|
Security Center |
The field content is different. |
The new version provides more log fields. Log categories. |
||
|
API Gateway |
No differences. |
- |
||
|
File Storage NAS |
The field content is different. |
|
||
|
Web Application Firewall 3.0 |
The field content is different. |
The new version of WAF supports optional fields, which the previous version does not. |
||
|
Bastionhost |
No differences. |
- |