Simple Log Service integrates Alibaba Cloud Anti-DDoS Origin to provide the log analysis feature. After you enable the log analysis feature, you can query and analyze mitigation logs that record the events of an Anti-DDoS Origin instance. The events include traffic scrubbing, blackhole filtering, and traffic rerouting. The feature can be used to identify website access exceptions and analyze website operations. This topic describes the assets, billing, and limits of the log analysis feature for Anti-DDoS Origin.
Assets
Dedicated project and Logstore
After you enable the log analysis feature, Simple Log Service creates a project named ddosbgp-project-Alibaba Cloud account ID-cn-hangzhou and a dedicated Logstore named ddosbgp-logstore by default.
ImportantIf you have enabled the pay-by-ingested-data billing mode, Simple Log Service creates a dedicated Logstore that uses the pay-by-ingested-data billing mode by default. If you want to switch the billing mode from pay-by-ingested-data to pay-by-feature, you can modify the configuration of the Logstore. For more information, see Modify the configurations of a Logstore.
Dedicated dashboards
By default, Simple Log Service generates two dashboards after you enable the feature.
NoteWe recommend that you do not make changes to the dedicated dashboards. This may affect the usability of the dashboards. You can create a custom dashboard to view log analysis results. For more information, see Create a dashboard.
Dashboards
Description
Anti-DDoS Origin Events Report
The report records Anti-DDoS Origin statistics on blackhole filtering and traffic rerouting for protected websites.
Anti-DDoS Origin Mitigation Report
The report records how Anti-DDoS Origin scrubs the attack traffic of the protected websites. The report includes data such as Inbound Traffic Monitor, Distribution of Inbound Traffic (sort by scrub center) and Protocol of Inbound Traffic.
Billing
If you enable the log analysis feature in the Anti-DDoS Origin console, you are billed based on the log retention period and storage space. During the public preview analysis step, the full log analysis and event reports of protected traffic for Anti-DDoS Origin is provided free of charge.
If the dedicated Logstore uses the pay-by-feature billing mode, you are not charged for query, analysis, alerting, monitoring, or visualization. You are charged for read traffic, data transformation, and data shipping after the logs are collected from Anti-DDoS Origin to Simple Log Service. You are also charged for alert notifications that are sent by text message and voice call. The fees are included in the bills of Simple Log Service. For more information, see Billable items of pay-by-feature.
If the dedicated Logstore uses the pay-by-ingested-data billing mode, you are not charged for query, analysis, alerting, monitoring, visualization, data transformation, or data shipping. You are also not charged for alert notifications that are sent by text message and voice call. You are charged only for read traffic over the Internet after the logs are collected from Anti-DDoS Origin to Simple Log Service. The fees are included in the bills of Simple Log Service. For more information, see Billable items of pay-by-ingested-data.
Limits
You can write only Anti-DDoS Origin logs to a dedicated Logstore.
You cannot delete a dedicated Logstore.
You cannot modify the log retention period for a dedicated Logstore on the Simple Log Service console. However, you can modify the log retention period in the Anti-DDoS Origin console. You can set the value. The value ranges from 30 to 180 days.
If the storage space of a dedicated Logstore is full, no more logs can be written to the Logstore.
NoteYou can view the usage of log storage space in the Anti-DDoS Origin console. However, the usage is not updated in real time. The displayed usage is delayed by two hours.