All Products
Search
Document Center

Simple Log Service:WAF 3.0 logs

Last Updated:Jun 23, 2026

Web Application Firewall (WAF) is integrated with Simple Log Service to collect and store access logs and protection logs for protected objects such as cloud service instances and domain names. You can query and analyze logs, configure charts and alert rules, and deliver logs to downstream services for consumption.

Asset details

Warning

Do not delete the projects and Logstores related to WAF logs. If you delete them, existing logs are purged, and new logs cannot be delivered to Simple Log Service.

  • Subscription WAF instances

    When you enable the log service, you must specify a Simple Log Service region. WAF then creates a project named wafng-project-<Alibaba Cloud account ID>-<region ID> in the specified region. WAF also creates a dedicated Logstore named wafng-logstore in the project.

    Important

    If you previously enabled the pay-by-ingested-data billing mode, the system creates a dedicated Logstore that uses this billing mode by default. To switch to the pay-by-feature billing mode, you must modify the Logstore configuration. For more information, see Modify Logstore configurations.

  • Pay-as-you-go WAF instances

    When you enable the log service, you must specify a Simple Log Service region. WAF then creates a project named wafnew-project-<Alibaba Cloud account ID>-<region ID> in the specified region. WAF also creates a dedicated Logstore named wafnew-logstore in the project.

Billing

  • Subscription WAF instances

    Log service fees are included in your WAF bill. You are charged based on the log retention period and storage capacity. For more information, see Billing overview.

  • Pay-as-you-go WAF instances

    • After you enable the log service feature for a pay-as-you-go instance, WAF does not charge any fees. All log fees are billed by Simple Log Service.

    • With the pay-by-feature billing mode, Simple Log Service charges for storage space, read traffic, requests, data transformation, and data shipping. For more information, see Billable items of the pay-by-feature mode.

    • With the pay-by-ingested-data billing mode, Simple Log Service charges based on the amount of raw data ingested. For more information, see Billable items of the pay-by-ingested-data mode.

Limits

  • If you have overdue payments for Simple Log Service, the log service feature for WAF becomes unavailable.

  • You cannot write other data to the dedicated Logstore. Other features such as query, statistics, alerting, and consumption are not restricted.

  • Ensure sufficient storage capacity for WAF logs. New logs cannot be stored after the storage capacity is exhausted.

    Note

    The log storage capacity displayed in the Simple Log Service console is not updated in real time.

Benefits

  • Classified protection compliance: Retains website access logs for more than six months to help meet classified protection requirements.

  • Simple configuration: Collects access logs and attack protection logs from your website in real time with minimal setup. You can specify a custom retention period and storage capacity, and select specific websites for log collection.

  • Real-time analysis: Provides real-time log analysis and out-of-the-box dashboards with insights into attacks and user access details.

  • Real-time alerting: Supports custom monitoring and near-real-time alerting for specific metrics, enabling you to respond to critical business exceptions promptly.

  • Ecosystem: Integrates with stream computing, cloud storage, and visualization solutions to help you extract more value from your data.

Scenarios

  • Trace web attack logs to identify the source of security threats.

  • Monitor web requests in real time and view traffic trends.

  • Track the efficiency of security operations and resolve issues promptly.

  • Generate security network logs and deliver them to self-managed data and computing centers.