Enabling Advanced Query and Configuring Field Indexing
Scenarios
CTS records details of user operations, such as creating, modifying, and deleting cloud service resources, and stores these records as traces in the CTS trace list for seven days. To store traces for more than seven days, you can enable advanced query. This function allows CTS to periodically transfer traces to LTS log streams for long-term audit log storage.
In addition, advanced query offers enhanced trace search capabilities. It supports additional search criteria, LTS query syntax, and professional log interpretation, helping you easily locate and analyze system issues.
Constraints
- Enabling advanced query will transfer audit logs to LTS, which will incur fees. Ensure that your account balance is sufficient. For details about LTS pricing, see Log Tank Service Pricing Details.
- After advanced query is enabled, the system automatically creates a log group and a log stream in LTS. The log group name defaults to CTS and cannot be changed. The log stream name defaults to system-trace. By default, logs in this log stream are retained for seven days. You can change the log retention period on the LTS console. For details, see Managing Log Streams.
- After the index settings of this log stream are modified in LTS, the modification takes effect only for newly written log data, not for historical log data.
Prerequisites
You have enabled CTS. For details, see Overview.
Enabling Advanced Query for Traces
- Log in to the CTS console.
- In the navigation pane, choose Advanced Query.
- If you have configured Transfer to LTS for the management tracker, skip this step.
Click Enable and then OK. LTS automatically creates a log group and a log stream. You can view and search the audit logs transferred to LTS on the Advanced Query page of the CTS console.
- (Optional) To perform more operations on logs, such as creating alarm rule notifications, click Log Tank Service in the upper part of the page to go to the LTS console.
Configuring Cloud Structuring Parsing and Field Indexing
You need to configure structuring parsing before configuring field indexing.
Configuring cloud structuring parsing
- On the Advanced Query page, click Log Tank Service in the upper part of the page to go to the LTS console.
- On the system-trace log stream page, click
to access the log stream setting page.

- Click the Cloud Structuring Parsing tab.
- Select Structuring Template > System Template > CTS, and click Save.

Configuring field indexing
- On the displayed log stream setting page, click the Index Settings tab.
- Click Auto Configure under Index Fields. The system will automatically extract fields from log structuring and adds them for log data statistics and analysis. To manually add a field index, click Add Field. For details, see Configuring Log Indexing.

- Click OK. After the index settings are modified, the modification takes effect only for newly written log data, not for historical log data.
You can quickly query traces based on specific fields on the Advanced Query page of the CTS console.
Helpful Links
- You can use the advanced query function to quickly query traces related to your access key and Huawei Cloud account. For details, see Querying Access Key Traces and Querying Huawei Cloud Account Traces.
- For details about LTS's log search and analysis functions, see Log Search and Analysis Overview.
- You can use SQL syntax on the Advanced Query page to query or analyze audit logs transferred to LTS. For details about the SQL syntax, see Using SQL Analysis Syntax.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.