- What's New
- Function Overview
- Service Overview
- Billing
- Getting Started
-
User Guide
- Buying SecMaster
- Authorizing SecMaster
- Viewing Security Overview
- Workspaces
- Viewing Purchased Resources
- Security Situation
- Resource Manager
- Risk Prevention
- Threat Operations
- Security Orchestration
-
Playbook Overview
- Ransomware Incident Response Solution
- Attack Link Analysis Alert Notification
- HSS Isolation and Killing of Malware
- Automatic Renaming of Alert Names
- Auto High-Risk Vulnerability Notification
- Automatic Notification of High-Risk Alerts
- Auto Blocking for High-risk Alerts
- Real-time Notification of Critical Organization and Management Operations
-
Settings
- Data Integration
-
Log Data Collection
- Data Collection Overview
- Adding a Node
- Configuring a Component
- Adding a Connection
- Creating and Editing a Parser
- Adding and Editing a Collection Channel
- Managing Connections
- Managing Parsers
- Managing Collection Channels
- Viewing Collection Nodes
- Managing Nodes and Components
- Partitioning a Disk
- Logstash Configuration Description
- Connector Rules
- Parser Rules
- Upgrading the Component Controller
- Customizing Directories
- Permissions Management
- Key Operations Recorded by CTS
-
Best Practices
-
Log Access and Transfer Operation Guide
- Solution Overview
- Resource Planning
- Process Flow
-
Procedure
- (Optional) Step 1: Buy an ECS
- (Optional) Step 2: Buy a Data Disk
- (Optional) Step 3: Attach a Data Disk
- Step 4: Create a Non-administrator IAM User
- Step 5: Configure Network Connection
- Step 6: Install the Component Controller (isap-agent)
- Step 7: Install the Log Collection Component (Logstash)
- (Optional) Step 8: Creating a Log Storage Pipeline
- Step 9: Configure a Connector
- (Optional) Step 10: Configure a Log Parser
- Step 11: Configure a Log Collection Channel
- Step 12: Verify Log Access and Transfer
- Credential Leakage Response Solution
-
Log Access and Transfer Operation Guide
-
API Reference
- Before You Start
- API Overview
- Calling APIs
-
API
- Alert Management
- Incident Management
- Indicator Management
- Playbook Management
- Alert Rule Management
- Playbook Version Management
- Playbook Rule Management
- Playbook Instance Management
- Playbook Approval Management
- Playbook Action Management
- Incident Relationship Management
- Data Class Management
- Workflow Management
- Data Space Management
- Pipelines
- Workspace Management
- Metering and Billing
- Metric Query
- Baseline Inspection
- Appendix
- FAQs
Enabling Log Access
Scenario
SecMaster can access logs of Huawei Cloud services with your authorization, services such as Web Application Firewall (WAF), Host Security Server (HSS), and Object Storage Service (OBS). After you authorize the access, you can manage logs centrally and search and analyze all collected logs. For details, see Cloud Service Log Access Supported by SecMaster.
You are advised to enable access to asset details, asset alerts, baseline inspection results, vulnerability data, and logs in one workspace. This will make it easier for centralized security operations and association analysis.
This topic describes how to access logs and view where logs are stored.
Limitations and Constraints
It takes about 10 minutes for the log access settings to take effect.
Allowing SecMaster to Access Cloud Service Logs
- Log in to the management console.
- Click
in the upper left corner of the management console and select a region or project.
- Click
in the upper left corner of the page and choose Security & Compliance > SecMaster.
- In the navigation pane on the left, choose Workspaces > Management. In the workspace list, click the name of the target workspace.
Figure 1 Workspace management page
- In the navigation pane on the left, choose Settings > Data Integration.
Figure 2 Data Integration page
- Locate the target cloud service and click
in the Logs column.
To access logs of cloud services supported in the current region, click
on the left of Access Service Logs.
- Set the lifecycle.
Set the data storage duration as required.
- Set Automatically converts alarms.
Locate the row containing the target security products. In the Automatically converts alarms column of that row, click
to enable the function. After that, SecMaster will automatically convert cloud service logs into alerts when the logs meet certain alert rules. Those alerts will be displayed on the Alerts page.
NOTE:
- If this function is disabled, logs that meet certain alert rules will not be converted into alerts or displayed on the Alerts page.
- You can access host vulnerability scan results on the Vulnerabilities page of SecMaster. If such results have been accessed during data integration but this conversion function is disabled, the results will not be displayed on the Vulnerabilities page.
- Click Save. In the displayed dialog box, click OK.
NOTE:
It takes about 10 minutes for the log access settings to take effect. After the access completes, a default data space and pipeline are created.
Viewing Logs and Storage Locations
After log integration, choose Security Analysis > Security Data Tables and view integrated logs.
- Go to the target workspace. In the navigation pane on the left, choose Threat Operations > Security Analysis. The Security Analysis page is displayed.
- In the data space navigation tree on the left, click a data space name to show the pipeline list. Click a pipeline name. On the page displayed on the right, you can search the pipeline data.
You can view the integrated logs on the pipeline data query page.
Related Operations
- Canceling Data Access
- In the Logs column of the target cloud services, click
to disable the access to cloud service logs.
- Click Save.
- In the Logs column of the target cloud services, click
- Editing the Data Access Lifecycle
- In the Lifecycle column of the target cloud services, enter the data storage period.
- Click Save.
- Canceling Automatic Converting Logs into Alarms
- In the Automatically converts alarms column of the target cloud products, click
to disable the alarms.
- Click Save.
- In the Automatically converts alarms column of the target cloud products, click
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.