The Log Service feature is disabled by default for Web Application Firewall (WAF). You must enable Log Service to store, query, and analyze the logs of objects that are protected by WAF. This topic describes how to enable Log Service for WAF.
Prerequisites
A WAF 3.0 instance is purchased. For more information, see Purchase a subscription WAF 3.0 instance and Purchase a pay-as-you-go WAF 3.0 instance.
Procedure
Dedicated project and Logstore for WAF
The following table describes the default configurations of the dedicated project and Logstore for WAF.
Resource type | Description |
---|---|
Project | Log Service automatically creates a dedicated project for WAF based on the region
where your WAF instance resides.
To query the dedicated project for WAF, log on to the Log Service console and click the name of the project. For more information about projects, see Manage a project. |
Logstore | A Logstore is created by default in the project. The name of the Logstore is wafnew-logstore . All logs that are collected by WAF are stored in the Logstore. You can view the
Logstore in the dedicated project for WAF.
Only WAF logs can be written to the dedicated Logstore. Different write methods are supported, such as calling the API or using an SDK. The dedicated Logstore has no limits on features such as query, statistics, alerting, or streaming consumption. You are not charged for the dedicated Logstore. However, you can use the dedicated
Logstore only when Log Service is running in your Alibaba Cloud account as expected.
Important If Log Service has an overdue bill, the log collection feature of WAF is suspended
until you settle the bill.
For more information about Logstores, see Manage a Logstore. |