Log Shipping

Last Updated At: 2025-10-29 17:01:36

Log Shipping

Log shipping allows you to send logs to CLS, helping you gain more out of logs and meet user needs for operation and maintenance. To ship custom fields for your access logs, submit a ticket.

Note:

• For any exception with log shipping, contact us.
• To ship attack logs/access logs, activate the paid feature you need.
• After the shipping destination is configured, enable log shipping as instructed.
• Log shipping can be used with log service. Enable these features as needed.

Shipping Logs to CLS

To ship logs to CLS, you need to activate CLS and grant WAF required permissions.

Note:

If CLS is already activated, skip to Step 3.

  1. Log in to the WAF console. Select Access Logs/Attack Logs on the left sidebar and the Log shipping tab.
  2. If you have not activated CLS, click Activate now. For details, see Cloud Log Service.
  3. Authorize WAF to ship data to CLS.
    3.1 In the Shipping to CLS section, click Configure.
    3.2 In the pop-up window, click Authorize now.
    3.3 On the CAM authorization page, click Authorize to allow WAF to ship logs to CLS. If you encounter problems during the process, see Cloud Access Management.
    3.4 Return to the log shipping page and click Configure now. Select the shipping region and log topic and then click OK. Alternatively, click Create to automatically create a WAF logset waf_post_logset. See the CLS console for details.
    3.5 After logs are sent to CLS, you can enable log shipping for the desired domain names. For details, see Enabling Log Shipping.
Note:

For any exception with authorization, submit a ticket.

Enabling Log Shipping

After shipping logs to CLS, you need to enable log delivery for the specified domain name/instance.

Note:

• Shipping attack logs is enabled at the instance level. This feature is only available for instances of Enterprise and above editions.
• Shipping access logs is enabled at the domain level. This feature is available for all instances, regardless of the edition.

Enabling attack log shipping

  1. Log in to the WAF console and select Instance Management on the left sidebar.
  2. On the instance management page, click Instance name to bring up the sidebar.
  3. In the instance details, click to enable attack log shipping for the current instance.

Enabling access log shipping

  1. Log in to the WAF console and navigate to Connection Management > Domain names.
  2. On the page displayed, select a target domain name and click More > Log shipping.
  3. In the advanced settings window, select logs to ship and click Save.