tencent cloud

Cloud Security Center

Log Analysis Overview

Baixar
Modo Foco
Tamanho da Fonte
Última atualização: 2026-05-20 17:37:25

Basic Concepts

Log Analysis is a unified ingestion and centralized management service for cloud security logs provided by CSC. By integrating various cloud security and cloud products such as CSC, CWPP, and CFW, it centrally aggregates and stores log data scattered across different products, providing users with a one-stop portal for log search and query. The Log Analysis service covers the full lifecycle management of logs, from collection and storage to search and delivery, helping users efficiently conduct security operations analysis, threat investigation, and compliance audits.

Features

Unified Log Ingestion and Centralized Storage

It supports unified ingestion and centralized storage of logs from various cloud security and cloud products, providing a one-stop portal for log search and query. Users can select target products and log types for search on a unified page, eliminating data silos and facilitating rapid security event identification, efficient log analysis, and investigation.

Powerful CQL Search and Analysis

It features a built-in CQL search syntax and supports two modes: statement search and filter search. Statement search enables rich condition combinations and complex query expressions. Filter search allows quick filtering by selecting specific fields and filter criteria. It also provides two display modes, raw data view and table view, to meet the requirements for multi-dimensional, refined log search and in-depth analysis.

Flexible Storage Policy Configuration

It provides global monitoring and fine-grained configuration capabilities for log storage, supporting the viewing of storage usage overviews and trends. Users can flexibly configure whether to store logs and the retention duration by product and log type. It also supports quick operations such as batch enabling, batch disabling, and batch configuration of storage time.

Log Delivery

It supports real-time delivery of log data to external platforms such as Kafka (Message Queue), CLS (Log Service), and Splunk, meeting diverse data flow requirements including data archiving, cross-platform collaborative analysis, and building a self-managed security operations system.

Multi-Account Storage Sharing and Unified Operations

In multi-account scenarios, it supports administrator accounts/delegated administrator accounts in flexibly sharing log storage capacity with multiple member accounts. It also supports capabilities such as cross-account storage policy configuration, log delivery policy configuration, and configuration synchronization. This reduces operational complexity in multi-account environments and enables centralized management of log resources.


Ajuda e Suporte

Esta página foi útil?

comentários