Implementing Cross-Account Ingestion
In an enterprise, different departments or teams may use different Identity and Access Management (IAM) accounts to manage their resources. As a result, log data is scattered and difficult to manage and analyze in a unified manner. To solve this problem, Huawei Cloud Log Tank Service (LTS) provides cross-account log ingestion. With this function, you can implement unified management, real-time monitoring, and security isolation, thereby improving management efficiency and data security. This section describes how to use LTS to achieve cross-account ingestion.
Prerequisites
Two IAM accounts are available, which are account A and account B. Account A is the delegator account, and account B is the delegated account.
Restrictions
- Before data synchronization is complete, data in the target and source log streams may be different. Check them one hour later.
- Log stream mapping will not stop even when an agency becomes invalid. To stop mapping, manually disable or delete the ingestion task.
Creating an Agency
- Log in to the IAM console as account A (delegator account).
- On the IAM console, choose Agencies from the navigation pane on the left, and click Create Agency in the upper right corner.
- On the Create Agency page, configure the Agency Name, Agency Type, and Delegated Account. For details, see Creating an Agency and Assigning Permissions.
The delegated account must be assigned the Agent Operator role for verification. During authorization, set the authorization scope to all resources for Agent Operator. After the authorization is successful, the Project [Region] of Agent Operator must be All resources [Regions of existing and future projects]. If not, re-assign the role by referring to Creating a User Group and Assigning Permissions.
Implementing Cross-Account Ingestion
- Log in to the LTS console as account B (delegated account).
- Choose Log Ingestion > Ingestion Center in the navigation pane and click Cross-Account Ingestion - Log Stream Mapping.
Alternatively, choose Log Ingestion > Ingestion Management in the navigation pane and click Create. On the displayed page, click Cross-Account Ingestion - Log Stream Mapping.
- Configure agency parameters. After the configuration is complete, click Next: Log stream mapping.
Table 1 Agency parameters Parameter
Description
Agency Name
Name of the agency created by the delegator in IAM. A delegator account can create an agency to delegate resource management permissions to another account.
Delegator Account Name
Name of the delegator account, which is used for delegation verification.
- On the log stream mapping page, configure an ingestion rule. There are the following two configuration methods:
- Automatic configuration
- Click Auto Configure.
- On the displayed page, set required parameters and click OK.
Table 2 Parameters of automatic ingestion rule configuration Parameter
Description
Rule Name Prefix
Enter a rule name prefix. In automatic configuration, ingestion rules with this prefix will be generated.
Use only letters, digits, hyphens (-), underscores (_), and periods (.). Do not start with a period or underscore or end with a period. Max.: 59 characters. If you do not specify any prefix, default prefix rule will be used.
Select the log groups or log streams that you want to ingest from the delegator account
Up to 20 log groups or log streams can be selected.
By default, the names of the target log groups and streams of the delegated account are the same as those of the source log groups and streams of the delegator account. Change them if needed.
- Click Preview. There are two types of preview results:
- A new target log stream will be created: A target log group or log stream will be created in the delegated account.
- An existing target log stream will be ingested: The target log group or log stream already exists in the delegated account.
- After the preview is complete, click Submit.
- Manual configuration
- On the log stream mapping page, click Add Rule and set the rule by referring to Table 3.
Table 3 Parameters for manual configuration Parameter
Description
Rule Name
The default value is rule_xxx. You can also enter a custom name.
Use only letters, digits, hyphens (-), underscores (_), and periods (.). Do not start with a period or underscore or end with a period. Enter 1 to 64 characters.
Delegator Account
Source Log Group
Log group of the delegator account. Select an existing log group.
Source Log Stream
Log stream of the delegator account. Select an existing log stream.
Delegated Account
Target Log Group
Log group of the delegated account. Select an existing log group or enter a name to create one.
Target Log Stream
Log stream of the delegated account. Select an existing log stream or enter a name to create one.
- Click Preview. There are two types of preview results:
- A new target log stream will be created: A target log group or log stream will be created in the delegated account.
- An existing target log stream will be ingested: The target log group or log stream already exists in the delegated account.
- After the preview is complete, click Submit and wait until the log ingestion task is created.
- On the log stream mapping page, click Add Rule and set the rule by referring to Table 3.
- Automatic configuration
- Wait for data synchronization (within an hour).
- If multiple log streams are ingested, click Back to Ingestion Configurations to view the log ingestion configuration list.
- If a single log stream is ingested, click Back to Ingestion Configurations to view the log ingestion configuration and click View Log Stream to view ingested logs.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot
