Updated on 2026-09-03 GMT+08:00

Overview

This document describes the following best practices of Log Tank Service (LTS):

Table 1 Best practice overview

Category

Best Practice

Scenario

Log ingestion

Collecting Host Logs from Third-Party Clouds, Internet Data Centers, and Other Huawei Cloud Regions to LTS

This practice describes how to collect Alibaba Cloud host logs to Huawei Cloud LTS. The method is similar to that of collecting logs from Internet Data Centers (IDCs) or across Huawei Cloud regions.

Log ingestion

Collecting Kubernetes Logs from Third-Party Clouds, IDCs, and Other Huawei Cloud Regions to LTS

This practice describes how to collect Alibaba Cloud Kubernetes logs to Huawei Cloud LTS. The method is similar to that of collecting logs from IDCs or across Huawei Cloud regions.

Log ingestion

Collecting Syslog Aggregation Server Logs to LTS

This practice describes how to use the syslog protocol to upload logs to LTS. You need to buy an Elastic Cloud Server (ECS) to serve as a syslog aggregation server. Syslog comes preinstalled by default on Linux servers. However, Huawei Cloud ECSs do not receive remote syslog writes by default. You need to manually enable this function.

Log ingestion

Importing Logs of Self-built ELK to LTS

This practice describes how to use a custom Python script and ICAgent (LTS collector) to transfer logs from Elasticsearch to LTS.

Log ingestion

Using Flume to Report Logs to LTS

This practice describes how to collect logs using Flume and report logs using Kafka provided by LTS.

Log ingestion

Collecting Zabbix Data Through ECS Log Ingestion

This practice describes how to collect monitoring data from Zabbix to an LTS log stream.

Log ingestion

Collecting Logs from Multiple Channels to LTS

This practice describes how to collect log data from multiple channels to LTS.

Log ingestion

Importing Log Files from OBS to LTS

This practice describes how to transfer logs to Object Storage Service (OBS) and import them back to LTS.

Log ingestion

Implementing Cross-Account Ingestion

This practice describes how to implement cross-account ingestion.

Log search and analysis

Analyzing Huawei Cloud ELB Logs on LTS

This practice describes how to search for and analyze logs after Elastic Load Balance (ELB) logs are ingested to and structured in LTS.

Log search and analysis

Viewing ELB Log Analysis Results on the LTS Dashboards

This practice describes how to display logs in dashboards after ELB logs are ingested to and structured in LTS.

Log search and analysis

Viewing CCE Application Logs on Charts

This practice describes how to use SQL statements to search for and analyze logs ingested to LTS, and generate charts to display log data and monitor trends.

Log search and analysis

Analyzing Huawei Cloud WAF Logs on LTS

This practice describes how to search for and analyze logs after Web Application Firewall (WAF) logs are ingested to and structured in LTS.

Log search and analysis

Embedding the LTS Log Query Page into a User-built System

This practice describes how to use the federation proxy mechanism of Identity and Access Management (IAM) for custom identity broker and embed a login link to your systems so you can view LTS logs in your systems without logging in to the Huawei Cloud console.

Log search and analysis

Displaying Query and Analysis Results on Pages

This practice describes how to display query and analysis results on multiple pages.

Log search and analysis

Using Time Functions to Convert Log Time Fields to a Specified Format

This practice describes common conversion examples of time fields.

Log search and analysis

Optimizing Regular Expressions for Faster Log Parsing

This practice describes how to optimize regular expressions to improve parsing efficiency.

Log search and analysis

Querying and Analyzing Website Logs

This practice describes how to use LTS to query and analyze website logs.

Log search and analysis

Using LTS to Implement Top N Statistics Ranking and Time-based Sorting

This practice describes how to compile SQL statements for top N statistics ranking and time-based sorting, and how to configure charts such as line charts, helping you learn the entire process from log collection to visualized analysis.

Log transfer

Changing File Time Zones for Log Transfer in a Batch

This practice describes how to use Python scripts and LTS APIs to implement custom operations in a batch.

Log transfer

Creating a Custom Policy for a Log Transfer Destination OBS Bucket

This practice describes how to create a custom policy for OBS bucket actions in IAM and attach the policy to a user group, thereby granting its users the specified permissions.

Log alarms

Using Multi-Chart Query Results for Alarm Detection and Notification

This practice describes how to use the query results of multiple charts to configure alarm rules.

Billing

Collecting Statistics on LTS Expenses of Different Departments Based on Log Stream Tags

This practice describes how to collect statistics on the LTS expenses of different departments in an enterprise. You can add tags to LTS log streams to distinguish business departments. LTS will add these tags to CDRs sent to the Billing Center.

Log jobs

Log Jobs (Beta)

This practice describes how to use Domain Specific Language (DSL) processing functions to clean log data, determine events, process date and time functions, and anonymize log data.

Suggestions on LTS security configuration

Suggestions on LTS Security Configuration

This section provides actionable guidance for enhancing the overall security of LTS. You can continuously evaluate the security of your LTS resources and enhance their overall defensive capabilities by combining different security capabilities provided by LTS. By doing this, data stored in LTS can be protected from leakage and tampering both at rest and in transit.