All Products
Search
Document Center

Web Application Firewall:Web Application Firewall Web Core Protection, Bot Management, and Log Service upgrade notice

Last Updated:Sep 10, 2026

Dear Alibaba Cloud users,

Alibaba Cloud Web Application Firewall (WAF) 3.0 will upgrade the Web Core Protection, Bot Management, and Log Service modules in terms of functionality and billing.

Effective dates

  • Billing adjustment for Web Core Protection rules: Effective from 2026-09-10 00:00:00 (UTC+8).

  • Billing criteria adjustment for Bot Management request processing fee: Effective from 2026-09-10 00:00:00 (UTC+8).

  • Log Service upgrade: Phased rollout starting from 2026-08-14 00:00:00 (UTC+8).

Changes

1. Billing adjustment for Web Core Protection rules

Scope: WAF 3.0 pay-as-you-go edition

Description:

The billing criteria for Web Core Protection rules are adjusted as follows:

New billing logic

Previous billing logic

  • Default template

    • No protected objects exist under the WAF instance: 0 SeCU/hour.

    • Protected objects already exist under the WAF instance: 10 SeCU/hour.

    • Note: Billing applies at the above rates regardless of whether the template is enabled or disabled.

  • Non-default template

    • Billing rate: 10 SeCU/hour.

    • Note: Billing applies at the above rates regardless of whether the template is enabled or disabled.

  • Default template

    • Template not bound to protected objects: 0 SeCU/hour.

    • Template bound to protected objects: 3 SeCU/hour.

    • Note: Billing starts from the time protected objects are bound, regardless of whether the template is enabled or disabled.

  • Non-default template

    • Billing rate: 3 SeCU/template/hour.

    • Note: Billing applies at the above rates regardless of whether the template is enabled or disabled.

2. Billing criteria adjustment for Bot Management request processing fee

Scope: WAF 3.0 pay-as-you-go edition users who have activated Bot Management

Description:

The billing criteria for Bot Management - request processing fee will be strictly aligned with the existing billing rules documented on the official website, which define the billable request count as "the number of requests that hit protected objects within a complete hour." After this alignment, the system will more accurately cover requests that hit protected objects.

Compared to the historical billing criteria, the revised billable request count will more completely and accurately reflect the actual protection status. As a result, this fee may increase.

During the phased rollout, the fee displayed in Billing may be inaccurate. The actual billed amount prevails.

3. Log Service upgrade

Scope: WAF 3.0 pay-as-you-go edition users who have activated Log Service

Description:

1. Underlying storage architecture upgrade and parallel strategy

WAF Log Service will undergo an underlying storage architecture upgrade. During the upgrade, the system will create a new Logstore for users who have activated Log Service and implement a dual-write mechanism for both the old and new Logstores, with log data stored in both simultaneously. This parallel period lasts 180 days, during which the new Logstore incurs no additional fees. After the parallel period ends, the old Logstore will stop accepting writes, and the system will retain only the new Logstore as the sole storage, billed at standard rates.

During the parallel period, it is normal for the Simple Log Service (SLS) console to display data from both the old and new Logstores simultaneously.

After the parallel period ends, the original Logstore will still be retained and continue to incur fees. After you confirm that all configurations are migrated, delete or retain the original Logstore based on your business requirements.

2. Automatically migrated configurations

This upgrade will automatically migrate the following low-risk configurations, which will take effect automatically on the new Logstore without requiring manual action:

  • Hot storage TTL

  • Infrequent access storage TTL

  • Data retention period

  • Index data lifecycle

  • Logstore creation parameters such as Shard splitting

3. Manually handled configurations

Some configurations cannot be automatically migrated and require manual configuration on the new Logstore. For detailed instructions, see Log service migration guide.

Strictly follow Log service migration guide to complete the migration within the parallel period. If configurations that require manual migration are not completed, new logs may not be properly indexed or queried, which could affect your business operations.

4. Console changes during the phased rollout

A Logstore switching entry is added below the Log Service title, which allows you to switch between the old and new Logstores. After switching, the storage usage and button states are updated accordingly. Pay-as-you-go users can perform operations such as upgrading capacity, downgrading, configuring log settings, enabling log encryption, and disabling the service on both the old and new Logstores through the console.

5. Billing description

A new "Log Storage" billing item is added to the billing statement. The specific rules are as follows:

  • During the parallel period: The billed amount for the new Logstore is 0 during the 180-day free period.

  • After the parallel period: The new Logstore is billed at standard rates. The original Logstore will still be retained and continue to incur fees. After you confirm that all configurations are migrated, delete or retain the original Logstore based on your business requirements.

For WAF instances not covered during the phased rollout, the billed amount for this item is 0.

6. Operation mapping rules during the transition period

  • Disabling Log Service: During the transition period, disabling Log Service will close both the old and new Logstores simultaneously.

  • Re-enabling Log Service: If you re-enable Log Service after disabling it, the system will only activate the new Logstore and will no longer perform dual-write.

  • Scaling operations: Capacity adjustments are performed simultaneously on both the old and new Logstores.

If you have any questions, feel free to contact us through the DingTalk security service group or your account manager. Thank you for your support and cooperation.