Help Center/ SecMaster/ User Guide/ Settings/ Data Integration/ Log Access Supported by SecMaster
Updated on 2024-09-20 GMT+08:00

Log Access Supported by SecMaster

SecMaster can integrate logs of multiple Huawei Cloud services, such as Web Application Firewall (WAF), Host Security Server (HSS), and Object Storage Service (OBS). You can search for and analyze all collected logs in SecMaster. By default, the logs are stored for 7 days.

Table 1 Log access supported by SecMaster

Category

Service

Service Type

Log

Log Description

Supported Region

Host security

Host Security Service (HSS)

Tenant-side cloud service

hss-alarm

HSS security alarms

AP-Singapore, CN-Hong Kong, TR-Istanbul, AP-Bangkok, AF-Johannesburg, LA-Mexico City2 (converged in LA-Mexico City1), LA-Sao Paulo1, LA-Santiago, AP-Jakarta, ME-Riyadh, and AF-Cairo

hss-vul

HSS vulnerability scan results

hss-log

HSS security logs

hss-baseline

HSS baseline check

AP-Singapore, CN-Hong Kong, TR-Istanbul, AP-Bangkok, AF-Johannesburg, LA-Mexico City2, LA-Sao Paulo1, LA-Santiago, AP-Jakarta, ME-Riyadh, and AF-Cairo

Application security

Web Application Firewall (WAF)

Tenant-side cloud service

waf-attack

WAF attack logs

AP-Singapore, CN-Hong Kong, TR-Istanbul, AP-Bangkok, AF-Johannesburg, LA-Mexico City2, LA-Sao Paulo1, LA-Santiago, AP-Jakarta, ME-Riyadh, and AF-Cairo

waf-access

WAF access logs

API Gateway (APIG)

Tenant-side cloud service

apig-access

APIG request logs

NA

Cloud Trace Service (CTS)

Tenant-side cloud service

cts-audit

CTS logs

AP-Singapore, CN-Hong Kong, TR-Istanbul, AP-Bangkok, AF-Johannesburg, LA-Mexico City2, LA-Sao Paulo1, LA-Santiago, AP-Jakarta, ME-Riyadh, and AF-Cairo

Network security

NIP

Huawei device

nip-attack

IPS attack logs

AP-Singapore and AF-Johannesburg

DDoS

Huawei device

ddos-attack

Anti-DDoS attack logs

AF-Johannesburg and AP-Jakarta

Cloud Firewall (CFW)

Tenant-side cloud service

cfw-block

Access control logs

AP-Singapore, CN-Hong Kong, TR-Istanbul, AP-Bangkok, AF-Johannesburg, LA-Mexico City2, LA-Sao Paulo1, LA-Santiago, AP-Jakarta, ME-Riyadh, and AF-Cairo

cfw-flow

Traffic logs

cfw-risk

Attack logs

O&M security

Cloud Bastion Host (CBH)

Tenant-side cloud service

cbh-audit

Bastion host audit logs

NA

Data security

Object Storage Service (OBS)

Tenant-side cloud service

obs-access

OBS access logs

LA-Mexico City2

Database Security Service (DBSS)

Tenant-side cloud service

dbss-alarm

DBSS alarm logs

NA

Data Security Center (DSC)

Tenant-side cloud service

dsc-alarm

DSC alarm logs

AP-Singapore, CN-Hong Kong, TR-Istanbul, AP-Bangkok, AF-Johannesburg, LA-Mexico City2, LA-Sao Paulo1, LA-Santiago, AP-Jakarta, ME-Riyadh, and AF-Cairo

Identity security

Identity and Access Management (IAM)

Tenant-side cloud service

iam-audit

IAM audit logs

NA

Cloud security

Managed Threat Detection (MTD)

Tenant-side cloud service

mtd-alarm

MTD alarm logs

AP-Singapore, CN-Hong Kong, AP-Bangkok, AF-Johannesburg, LA-Sao Paulo1, and LA-Santiago

SecMaster

Tenant-side cloud service

secmaster-baseline

SecMaster baseline inspection

AP-Singapore, CN-Hong Kong, TR-Istanbul, AP-Bangkok, AF-Johannesburg, LA-Mexico City2, LA-Sao Paulo1, LA-Santiago, AP-Jakarta, ME-Riyadh, and AF-Cairo