The Web Application Firewall (WAF) log service uses Log Service to collect full logs in real time from website services that are protected by WAF. You can query and analyze the collected log data and view the query results in rich dashboards to meet classified protection compliance requirements and the protection and operational needs of your website services. This topic describes how to enable and use the WAF log service.
Background information
The WAF log service stores logs only for websites where log collection is enabled. If log collection is disabled for a website, WAF does not store its logs.
After you enable log collection for a website domain, WAF automatically stores the log data of the domain based on the default configurations described in the following table.
Log storage configuration | Default configuration | Customizable |
Log retention period | Logs are stored for 180 days. | Yes. Valid range: 15 to 360 days. |
Custom field configuration | Includes all required fields and some optional fields by default. | Yes. You can modify the optional fields in WAF logs. |
Storage type | Stores full logs for the website domain by default. | Yes. You can change this to store only blocked logs. |
WAF allows you to modify the preceding default configurations. For more information, see Modify log settings.
Prerequisites
You have a subscription WAF instance of the Advanced Edition, Enterprise, Enterprise, or Exclusive edition.
You have added your website domain to WAF for protection.
If a domain is not added to WAF, no logs are generated for it, even if the log service is enabled. Before you proceed, add your website domain to WAF. For more information about how to add a website domain, see Tutorials.
You have enabled Log Service.
When you log on to the Log Service console for the first time, you can enable Log Service as prompted.
The WAF Logstore requires an active Log Service subscription for your Alibaba Cloud account.
NoteIf your Log Service account has an overdue payment, WAF log collection is suspended. Collection resumes automatically after you settle the payment.
Step 1: Enable the WAF log service
-
Log on to the Web Application Firewall (WAF) console. In the top menu bar, select the resource group and region for your WAF instance: Chinese Mainland or Outside Chinese Mainland.
-
In the left navigation pane, choose .
On the Log Service page, click Upgrade Now and follow the on-screen instructions to upgrade.
NoteIf you enabled the Log Service when you purchased the WAF instance, you can skip this step.
Procedure:
On the Upgrade/Downgrade page, enable Log Service and select a Log Storage Capacity.
Click Proceed to Payment and complete the payment.
Authorize WAF to access related cloud resources. For more information, see Create a service-linked role.
After you enable the WAF log service, Log Service automatically creates a dedicated WAF Project and Logstore for your Alibaba Cloud account to collect logs. For information about the default configurations of the dedicated WAF Project and Logstore, see Dedicated WAF Project and Logstore.
Step 2: Use the WAF log service
-
Log on to the Web Application Firewall (WAF) console. In the top menu bar, select the resource group and region for your WAF instance: Chinese Mainland or Outside Chinese Mainland.
-
In the left navigation pane, choose .
From the domain name drop-down list, select the domain for which you want to collect logs, and turn on the Status switch.
The domain name drop-down list (labeled ① in the figure) includes only website domains that are added to WAF. If you have not added your website domain to WAF, do so first. For more information, see Tutorials.
On the Log Search tab, use query statements to analyze WAF logs. For more information, see Log query.
For more examples of log queries and analysis, see Query and analysis examples.
On the Log Analysis tab, view the dashboards that WAF generates from your log data.
A log analysis dashboard is a set of predefined reports that visualize your log data, allowing you to directly monitor your web services and security status.
Operation Center: Displays business operation metrics for your website, including request trends and attack overviews.
Access Center: Displays access metrics, client distribution, traffic, and performance data for your website.
Security Center: Displays attack metrics, trends, and source distribution for your website.
You only need to set a time range to query the dashboards. You can also create subscriptions to receive dashboard reports periodically by email. For more information about the charts included in the log analysis dashboards and how to create subscriptions, see View a log analysis dashboard.
Dedicated WAF Project and Logstore
The following table describes the default configurations of the dedicated WAF Project and Logstore that are automatically created by Log Service.
Do not delete or modify the default Project, Logstore, indexes, or dashboard settings that Log Service creates. Log Service periodically updates and upgrades the WAF log query and analysis features. The indexes and default reports in the dedicated Logstore are also automatically updated.
Resource type | Description |
Project | Log Service automatically creates a Project for WAF.
You can find the dedicated WAF Project on the homepage of the Log Service console. Click the Project name to open it. For more information about Projects, see Manage Projects. |
Logstore | A Logstore named You cannot use an API or SDK to write non-WAF logs to this Logstore. However, features such as querying, statistics, alerting, and stream-based consumption are fully supported. |
Shard | The WAF Logstore includes two Shards by default and has automatic splitting enabled. You can view Shard properties in the Logstore Details section. For more information about Shards, see Manage Shards. |
Dashboard | The WAF Project includes three predefined dashboards by default: Operation Center, Access Center, and Security Center. You can find the WAF log dashboards within the WAF Project. For more information about WAF log dashboards, see View a log analysis dashboard. |
Next steps
If a RAM user needs to use the WAF log query and analysis feature, you must grant the RAM user the required Log Service permissions. For more information, see Grant a RAM user permissions to query and analyze logs.
To learn more about how to use WAF log query and analysis, see Log application tutorials.
If you need to modify settings such as WAF log storage rules or storage capacity, see Manage log storage.