Cloud Log Service

Last Updated At: 2025-10-30 14:19:41

This document describes how to view CFW-related logs.

Viewing Access Control Logs

  1. Log in to the CFW console. In the left sidebar, choose CLS > Access Control Logs to go to the Access Control Logs page.
  2. On the Access Control Logs page, you can view the rule hit logs generated by CFW based on the access control rules configured on the NAT Firewall and Inter-VPC Firewall pages. On the NAT Firewall page, you can also see two rule hit lists generated based on the inbound and outbound directions, respectively.
  3. In the rule hit list, click View in the Operation column on the right side.
  4. On the Rule Hit Details page, view the hit details of the current rule.
Note:

- If the rule is deleted after the log generation time, its status is displayed as deleted.

- If the rule is edited after the log generation time, its status is displayed as edited.

- If the rule has not been deleted or edited since the log generation time, its status is displayed as newly added.

  1. To further speed up access control log search and filtering, click the magnifier icon on the right side of the access source or destination to view all rule hit information between the two IP addresses.
  2. You can manually download logs and filter them based on different conditions. A maximum of 60,000 records can be downloaded each time.

Viewing Intrusion Prevention Logs

  1. Log in to the CFW console. In the left sidebar, choose CLS > Intrusion Prevention Logs to go to the Intrusion Prevention Logs page.
  2. On the Intrusion Prevention Logs page, view the details of inbound, outbound, and inter-VPC security events in the External Intrusion, Host Compromise, and Horizontal Movement lists, respectively.

Viewing Traffic Logs

  1. Log in to the CFW console. In the left sidebar, choose CLS > Traffic Logs to go to the Traffic Logs page.
  2. On the Traffic Logs page, view the north-south traffic information generated by the NAT firewall based on outbound and inbound directions, as well as the east-west traffic between VPCs.
  3. Query and filter logs by asset instance name. To obtain a comprehensive view of traffic based on assets, click All Assets in the upper left corner of the Traffic Logs page, and select an asset instance name in the search dropdown list to filter logs and query all traffic logs of the asset.
  4. To further speed up the retrieval and filtering of logs, click the magnifier button on the right side of the access source or destination to view all traffic information between the two IP addresses.

Viewing Operation Logs

  1. Log in to the CFW console. In the left sidebar, choose Log Audit > Operation Logs to go to the Operation Logs page.
  2. On the Operation Logs page, view all operations you performed on the security policy page and the firewall toggles page within the current account, as well as their details.
Tag Name Tag Description
Firewall Switch Logs Records the firewall switch status and users' operation details on the instance configuration.
Access Control Logs Records users' operations for adding, editing, and deleting access control rules.
Intrusion Prevention Logs Records users' operations in the intrusion prevention module.
Login Logs Records users' account login information.