Help Center/ Cloud Search Service/ API Reference/ API V1/ Log Management/ Enabling Log Backup or Log Collection
Updated on 2026-08-10 GMT+08:00

Enabling Log Backup or Log Collection

Function

This API is used to enable log backup or log ingestion for a cluster. You can enable log backup and log ingestion separately.

  • Log backup: Cluster logs are periodically synchronized to OBS buckets. You can download them for in-depth analysis at any time.

  • Log ingestion: Cluster logs are transmitted in real time to the current cluster or another cluster on the same network. (Relevant version and network compatibility requirements must be met.) You can use Kibana or other visualization tools for log search and analysis.

Constraints

  • Log ingestion is supported only when the Elasticsearch cluster version is 7.10.2 and the image version is no earlier than 7.10.2_24.2.0_×.×.×.

  • Log ingestion is supported only when the OpenSearch cluster version is 1.3.6 or 2.19.0 and the image version is no earlier than ×.×.×_24.2.0_×.×.×.

Calling Method

For details, see Calling APIs.

Authorization Information

Each account has all the permissions required to call all APIs, but IAM users must be assigned the required permissions.

  • If you are using role/policy-based authorization, see Permissions Policies and Supported Actions for details on the required permissions.
  • If you are using identity policy-based authorization, the following identity policy-based permissions are required.

    Action

    Access Level

    Resource Type (*: required)

    Condition Key

    Alias

    Dependencies

    css:cluster:openLogSetting

    Write

    cluster *

    • g:EnterpriseProjectId

    • g:ResourceTag/<tag-key>

    css:log:enableOrDisableLogFunction

    • iam:agencies:pass
    • obs:bucket:listAllMyBuckets
    • obs:bucket:getBucketLocation
    • obs:bucket:getBucketStoragePolicy
    • iam:agencies:listAgencies

URI

POST /v1.0/{project_id}/clusters/{cluster_id}/logs/open

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

project_id

Yes

String

Definition

Project ID. For details about how to obtain the project ID and name, see Obtaining the Project ID and Name.

Constraints

N/A

Range

Project ID of an account. The value contains 32 characters, consisting of lowercase letters and digits.

Default Value

N/A

cluster_id

Yes

String

Definition

ID of the cluster for which log backup or ingestion is to be enabled. For details about how to obtain the cluster ID, see Obtaining the Cluster ID.

Constraints

N/A

Range

The value is a UUID containing 36 characters.

Default Value

N/A

Table 2 Query Parameters

Parameter

Mandatory

Type

Description

action

No

String

Definition:

Configure log backup or log ingestion for a cluster.

Constraints:

N/A

Value range:

  • base_log_collect: Enables log backup.

  • real_time_log_collect: Enables log ingestion.

Default value:

base_log_collect

Request Parameters

Table 3 Request body parameters

Parameter

Mandatory

Type

Description

agency

No

String

Definition

Name of the agency that authorizes CSS to store logs in specified OBS buckets.

Constraints

This parameter is mandatory when action is set to base_log_collect.

Range

The agency name can contain at most 64 characters. Only letters, digits, underscores (_), and hyphens (-) are allowed.

Default Value

N/A

log_base_path

No

String

Definition

Storage path of backed up logs in the OBS bucket.

The service will back up logs to the ${[/topic/body/section/table/tgroup/tbody/row/entry/p/b/br {""}) (br]} directory under the corresponding backup path.

Constraints

  • This parameter is mandatory when action is set to base_log_collect.

  • The backup path cannot contain the following characters: \:*?"<>|'{}. Additionally, it cannot:

  • Start with a slash (/).

  • Start or end with a period (.).

  • Contain more than two consecutive slashes (/) or periods (.).

  • Exceed 512 characters.

Range

N/A

Default Value

N/A

log_bucket

No

String

Definition

OBS bucket name for log backup.

Constraints

This parameter is mandatory when action is set to base_log_collect.

Range

The bucket name can contain 3 to 63 characters. Only lowercase letters, digits, hyphens (-), and periods (.) are allowed.

Default Value

N/A

auto_enable

No

Boolean

Definition:

Whether to enable automatic backup of cluster logs.

Constraints:

N/A

Value range:

  • true: Enable automatic backup of cluster logs.

  • false: Disable automatic backup of cluster logs.

Default value:

false

period

No

String

Definition:

Cluster log backup start time.

Constraints:

This parameter is mandatory when action is set to base_log_collect and auto_enable is set to true.

Value range:

Format: Greenwich Mean Time (GMT). Example: 00:00 GMT+08:00

Default value:

N/A

index_prefix

No

String

Definition:

Index prefix used for log ingestion. The log index is named using the format "index prefix+Log ingestion date".

Constraints:

This parameter is mandatory when action is set to real_time_log_collect.

Value range:

The index name can contain 1 to 128 characters. Only digits, lowercase letters, underscores (_), and hyphens (-) are allowed.

Default value:

N/A

keep_days

No

Integer

Definition

Log retention period. Ingested logs will be deleted upon expiration of this period.

Constraints

This parameter is mandatory when action is set to real_time_log_collect.

Range

1 to 3,650 (days)

Default Value

N/A

target_cluster_id

No

String

Definition

ID of the target cluster for log storage. For details, see Obtaining the Cluster ID.

Constraints

  • This parameter is mandatory when action is set to real_time_log_collect.

  • The target cluster can be the current cluster or another cluster. If you select another cluster, you need to use the log collection connectivity test API to verify whether the cluster can be used as the target cluster. If the status code is 200, it can be used as the target cluster. Otherwise, it cannot.

Range

N/A

Default Value

N/A

Response Parameters

Status code: 200

Request succeeded.

None

Example Requests

  • Enable the log backup function.

    POST https://{Endpoint}/v1.0/{project_id}/clusters/4f3deec3-efa8-4598-bf91-560aad1377a3/logs/open
    
    {
      "agency" : "css_obs_agency",
      "log_base_path" : "css_repository/logs",
      "log_bucket" : "000-words",
      "auto_enable" : true,
      "period" : "00:00 GMT+08:00"
    }
  • Enable real-time log collection function.

    POST https://{Endpoint}/v1.0/{project_id}/clusters/4f3deec3-efa8-4598-bf91-560aad1377a3/logs/open?action=real_time_log_collect
    
    {
      "index_prefix" : "css_log",
      "keep_days" : 30,
      "target_cluster_id" : "4f3deec3-efa8-4598-bf91-560aad1377a3"
    }

Example Responses

None

SDK Sample Code

The SDK sample code is as follows.

Java

  • Enable the log backup function.

     1
     2
     3
     4
     5
     6
     7
     8
     9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    21
    22
    23
    24
    25
    26
    27
    28
    29
    30
    31
    32
    33
    34
    35
    36
    37
    38
    39
    40
    41
    42
    43
    44
    45
    46
    47
    48
    49
    50
    51
    52
    53
    54
    55
    package com.huaweicloud.sdk.test;
    
    import com.huaweicloud.sdk.core.auth.ICredential;
    import com.huaweicloud.sdk.core.auth.BasicCredentials;
    import com.huaweicloud.sdk.core.exception.ConnectionException;
    import com.huaweicloud.sdk.core.exception.RequestTimeoutException;
    import com.huaweicloud.sdk.core.exception.ServiceResponseException;
    import com.huaweicloud.sdk.css.v1.region.CssRegion;
    import com.huaweicloud.sdk.css.v1.*;
    import com.huaweicloud.sdk.css.v1.model.*;
    
    
    public class StartLogsSolution {
    
        public static void main(String[] args) {
            // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
            // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
            String ak = System.getenv("CLOUD_SDK_AK");
            String sk = System.getenv("CLOUD_SDK_SK");
            String projectId = "{project_id}";
    
            ICredential auth = new BasicCredentials()
                    .withProjectId(projectId)
                    .withAk(ak)
                    .withSk(sk);
    
            CssClient client = CssClient.newBuilder()
                    .withCredential(auth)
                    .withRegion(CssRegion.valueOf("<YOUR REGION>"))
                    .build();
            StartLogsRequest request = new StartLogsRequest();
            request.withClusterId("{cluster_id}");
            StartLogsReq body = new StartLogsReq();
            body.withPeriod("00:00 GMT+08:00");
            body.withAutoEnable(true);
            body.withLogBucket("000-words");
            body.withLogBasePath("css_repository/logs");
            body.withAgency("css_obs_agency");
            request.withBody(body);
            try {
                StartLogsResponse response = client.startLogs(request);
                System.out.println(response.toString());
            } catch (ConnectionException e) {
                e.printStackTrace();
            } catch (RequestTimeoutException e) {
                e.printStackTrace();
            } catch (ServiceResponseException e) {
                e.printStackTrace();
                System.out.println(e.getHttpStatusCode());
                System.out.println(e.getRequestId());
                System.out.println(e.getErrorCode());
                System.out.println(e.getErrorMsg());
            }
        }
    }
    
  • Enable real-time log collection function.

     1
     2
     3
     4
     5
     6
     7
     8
     9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    21
    22
    23
    24
    25
    26
    27
    28
    29
    30
    31
    32
    33
    34
    35
    36
    37
    38
    39
    40
    41
    42
    43
    44
    45
    46
    47
    48
    49
    50
    51
    52
    53
    package com.huaweicloud.sdk.test;
    
    import com.huaweicloud.sdk.core.auth.ICredential;
    import com.huaweicloud.sdk.core.auth.BasicCredentials;
    import com.huaweicloud.sdk.core.exception.ConnectionException;
    import com.huaweicloud.sdk.core.exception.RequestTimeoutException;
    import com.huaweicloud.sdk.core.exception.ServiceResponseException;
    import com.huaweicloud.sdk.css.v1.region.CssRegion;
    import com.huaweicloud.sdk.css.v1.*;
    import com.huaweicloud.sdk.css.v1.model.*;
    
    
    public class StartLogsSolution {
    
        public static void main(String[] args) {
            // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
            // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
            String ak = System.getenv("CLOUD_SDK_AK");
            String sk = System.getenv("CLOUD_SDK_SK");
            String projectId = "{project_id}";
    
            ICredential auth = new BasicCredentials()
                    .withProjectId(projectId)
                    .withAk(ak)
                    .withSk(sk);
    
            CssClient client = CssClient.newBuilder()
                    .withCredential(auth)
                    .withRegion(CssRegion.valueOf("<YOUR REGION>"))
                    .build();
            StartLogsRequest request = new StartLogsRequest();
            request.withClusterId("{cluster_id}");
            StartLogsReq body = new StartLogsReq();
            body.withTargetClusterId("4f3deec3-efa8-4598-bf91-560aad1377a3");
            body.withKeepDays(30);
            body.withIndexPrefix("css_log");
            request.withBody(body);
            try {
                StartLogsResponse response = client.startLogs(request);
                System.out.println(response.toString());
            } catch (ConnectionException e) {
                e.printStackTrace();
            } catch (RequestTimeoutException e) {
                e.printStackTrace();
            } catch (ServiceResponseException e) {
                e.printStackTrace();
                System.out.println(e.getHttpStatusCode());
                System.out.println(e.getRequestId());
                System.out.println(e.getErrorCode());
                System.out.println(e.getErrorMsg());
            }
        }
    }
    

Python

  • Enable the log backup function.

     1
     2
     3
     4
     5
     6
     7
     8
     9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    21
    22
    23
    24
    25
    26
    27
    28
    29
    30
    31
    32
    33
    34
    35
    36
    37
    38
    39
    # coding: utf-8
    
    import os
    from huaweicloudsdkcore.auth.credentials import BasicCredentials
    from huaweicloudsdkcss.v1.region.css_region import CssRegion
    from huaweicloudsdkcore.exceptions import exceptions
    from huaweicloudsdkcss.v1 import *
    
    if __name__ == "__main__":
        # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
        # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
        ak = os.environ["CLOUD_SDK_AK"]
        sk = os.environ["CLOUD_SDK_SK"]
        projectId = "{project_id}"
    
        credentials = BasicCredentials(ak, sk, projectId)
    
        client = CssClient.new_builder() \
            .with_credentials(credentials) \
            .with_region(CssRegion.value_of("<YOUR REGION>")) \
            .build()
    
        try:
            request = StartLogsRequest()
            request.cluster_id = "{cluster_id}"
            request.body = StartLogsReq(
                period="00:00 GMT+08:00",
                auto_enable=True,
                log_bucket="000-words",
                log_base_path="css_repository/logs",
                agency="css_obs_agency"
            )
            response = client.start_logs(request)
            print(response)
        except exceptions.ClientRequestException as e:
            print(e.status_code)
            print(e.request_id)
            print(e.error_code)
            print(e.error_msg)
    
  • Enable real-time log collection function.

     1
     2
     3
     4
     5
     6
     7
     8
     9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    21
    22
    23
    24
    25
    26
    27
    28
    29
    30
    31
    32
    33
    34
    35
    36
    37
    # coding: utf-8
    
    import os
    from huaweicloudsdkcore.auth.credentials import BasicCredentials
    from huaweicloudsdkcss.v1.region.css_region import CssRegion
    from huaweicloudsdkcore.exceptions import exceptions
    from huaweicloudsdkcss.v1 import *
    
    if __name__ == "__main__":
        # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
        # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
        ak = os.environ["CLOUD_SDK_AK"]
        sk = os.environ["CLOUD_SDK_SK"]
        projectId = "{project_id}"
    
        credentials = BasicCredentials(ak, sk, projectId)
    
        client = CssClient.new_builder() \
            .with_credentials(credentials) \
            .with_region(CssRegion.value_of("<YOUR REGION>")) \
            .build()
    
        try:
            request = StartLogsRequest()
            request.cluster_id = "{cluster_id}"
            request.body = StartLogsReq(
                target_cluster_id="4f3deec3-efa8-4598-bf91-560aad1377a3",
                keep_days=30,
                index_prefix="css_log"
            )
            response = client.start_logs(request)
            print(response)
        except exceptions.ClientRequestException as e:
            print(e.status_code)
            print(e.request_id)
            print(e.error_code)
            print(e.error_msg)
    

Go

  • Enable the log backup function.

     1
     2
     3
     4
     5
     6
     7
     8
     9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    21
    22
    23
    24
    25
    26
    27
    28
    29
    30
    31
    32
    33
    34
    35
    36
    37
    38
    39
    40
    41
    42
    43
    44
    45
    46
    47
    48
    49
    50
    51
    52
    53
    54
    55
    56
    57
    58
    59
    60
    61
    62
    package main
    
    import (
    	"fmt"
    	"github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic"
        css "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/css/v1"
    	"github.com/huaweicloud/huaweicloud-sdk-go-v3/services/css/v1/model"
        region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/css/v1/region"
    )
    
    func main() {
        // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
        // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
        ak := os.Getenv("CLOUD_SDK_AK")
        sk := os.Getenv("CLOUD_SDK_SK")
        projectId := "{project_id}"
    
        auth, err := basic.NewCredentialsBuilder().
            WithAk(ak).
            WithSk(sk).
            WithProjectId(projectId).
            SafeBuild()
    
        if err != nil {
            fmt.Println(err)
            return
        }
    
        hcClient, err := css.CssClientBuilder().
             WithRegion(region.ValueOf("<YOUR REGION>")).
             WithCredential(auth).
             SafeBuild()
    
    
        if err != nil {
            fmt.Println(err)
            return
        }
    
        client := css.NewCssClient(hcClient)
    
        request := &model.StartLogsRequest{}
    	request.ClusterId = "{cluster_id}"
    	periodStartLogsReq:= "00:00 GMT+08:00"
    	autoEnableStartLogsReq:= true
    	logBucketStartLogsReq:= "000-words"
    	logBasePathStartLogsReq:= "css_repository/logs"
    	agencyStartLogsReq:= "css_obs_agency"
    	request.Body = &model.StartLogsReq{
    		Period: &periodStartLogsReq,
    		AutoEnable: &autoEnableStartLogsReq,
    		LogBucket: &logBucketStartLogsReq,
    		LogBasePath: &logBasePathStartLogsReq,
    		Agency: &agencyStartLogsReq,
    	}
    	response, err := client.StartLogs(request)
    	if err == nil {
            fmt.Printf("%+v\n", response)
        } else {
            fmt.Println(err)
        }
    }
    
  • Enable real-time log collection function.

     1
     2
     3
     4
     5
     6
     7
     8
     9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    21
    22
    23
    24
    25
    26
    27
    28
    29
    30
    31
    32
    33
    34
    35
    36
    37
    38
    39
    40
    41
    42
    43
    44
    45
    46
    47
    48
    49
    50
    51
    52
    53
    54
    55
    56
    57
    58
    package main
    
    import (
    	"fmt"
    	"github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic"
        css "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/css/v1"
    	"github.com/huaweicloud/huaweicloud-sdk-go-v3/services/css/v1/model"
        region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/css/v1/region"
    )
    
    func main() {
        // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security.
        // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment
        ak := os.Getenv("CLOUD_SDK_AK")
        sk := os.Getenv("CLOUD_SDK_SK")
        projectId := "{project_id}"
    
        auth, err := basic.NewCredentialsBuilder().
            WithAk(ak).
            WithSk(sk).
            WithProjectId(projectId).
            SafeBuild()
    
        if err != nil {
            fmt.Println(err)
            return
        }
    
        hcClient, err := css.CssClientBuilder().
             WithRegion(region.ValueOf("<YOUR REGION>")).
             WithCredential(auth).
             SafeBuild()
    
    
        if err != nil {
            fmt.Println(err)
            return
        }
    
        client := css.NewCssClient(hcClient)
    
        request := &model.StartLogsRequest{}
    	request.ClusterId = "{cluster_id}"
    	targetClusterIdStartLogsReq:= "4f3deec3-efa8-4598-bf91-560aad1377a3"
    	keepDaysStartLogsReq:= int32(30)
    	indexPrefixStartLogsReq:= "css_log"
    	request.Body = &model.StartLogsReq{
    		TargetClusterId: &targetClusterIdStartLogsReq,
    		KeepDays: &keepDaysStartLogsReq,
    		IndexPrefix: &indexPrefixStartLogsReq,
    	}
    	response, err := client.StartLogs(request)
    	if err == nil {
            fmt.Printf("%+v\n", response)
        } else {
            fmt.Println(err)
        }
    }
    

More

For SDK sample code of more programming languages, see the Sample Code tab in API Explorer. SDK sample code can be automatically generated.

Status Codes

Status Code

Description

200

Request succeeded.

400

Invalid request.

Modify the request before retry.

409

The request could not be completed due to a conflict with the current state of the resource.

The resource that the client attempts to create already exists, or the update request fails to be processed because of a conflict.

412

The server did not meet one of the preconditions contained in the request.

Error Codes

See Error Codes.