Updated on 2025-11-18 GMT+08:00

Ingesting WAF Logs to LTS

LTS can collect logs from WAF.

For details, see Configuring WAF Log Ingestion.

Configuring WAF Log Ingestion

  1. Log in to the LTS console.
  2. In the navigation pane, choose Log Ingestion > Ingestion Center. On the displayed page, select Cloud services under Type. Hover the cursor over the WAF card and click Ingest Log (LTS).
  3. Select a log stream.

    1. Select a log group from the Log Group drop-down list. If there are no desired log groups, click Create Log Group to create one.
    2. Select a log stream from the Log Stream drop-down list. If there are no desired log streams, click Create Log Stream to create one.
    3. Click Next: Configure WAF.

  4. Click Configure WAF. For details about the procedure and parameter settings, see Using LTS to Record WAF Logs.
  5. Click Next: Configure Log Stream.

    Table 1 Log stream parameter

    Parameter

    Description

    Auto Structure and Index

    If this function is enabled, the structuring for the log stream is based on the WAF system template, and the indexing enables quick analysis for all parsed WAF fields. Enabling structuring and indexing is required for SQL analysis of WAF logs with visual charts.

  6. Click Submit.